Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"websocket",
"wamp",
"messaging",
"mqtt",
"rest",
"server",
"broker",
"networking-stack",
"networking"
],
"is_fork": false,
"size_kb": 41907,
"has_wiki": true,
"homepage": "https://crossbario.readthedocs.io/",
"languages": {
"CSS": 2854,
"HTML": 49601,
"Just": 89664,
"COBOL": 612,
"Shell": 66414,
"Python": 4285480,
"Gherkin": 344,
"Makefile": 21574,
"Mustache": 2120,
"Solidity": 293,
"Dockerfile": 688,
"JavaScript": 1983464,
"Jupyter Notebook": 145804
},
"pushed_at": "2026-07-27T05:17:19Z",
"created_at": "2013-10-14T11:10:50Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T12:10:34Z",
"description": "Crossbar.io - WAMP application router",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "master",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Python",
"significant_languages": [
"Python",
"JavaScript"
]
},
"owner": {
"blog": "https://crossbar.io",
"name": "Crossbar.io",
"type": "Organization",
"login": "crossbario",
"company": null,
"location": "Worldwide",
"followers": 56,
"avatar_url": "https://avatars.githubusercontent.com/u/5656948?v=4",
"created_at": "2013-10-10T15:08:59Z",
"is_verified": null,
"public_repos": 38,
"account_age_days": 4673
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "pr2282-null-dependabot_uv_python_minor_patch_fb33d8da79-202607270516",
"kind": "other",
"published_at": "2026-07-27T05:17:19Z"
},
{
"tag": "pr2281-null-dependabot_github_actions_github_actions_45c4131e33-202607270433",
"kind": "other",
"published_at": "2026-07-27T04:33:35Z"
},
{
"tag": "pr2278-null-dependabot_uv_setuptools_83_0_0-202607200521",
"kind": "other",
"published_at": "2026-07-20T05:21:51Z"
},
{
"tag": "pr2277-null-dependabot_uv_treq_26_7_0-202607200519",
"kind": "other",
"published_at": "2026-07-20T05:20:16Z"
},
{
"tag": "pr2276-null-dependabot_uv_python_minor_patch_0cdb8b688f-202607200517",
"kind": "other",
"published_at": "2026-07-20T05:17:33Z"
},
{
"tag": "pr2275-null-dependabot_github_actions_github_actions_45c4131e33-202607200435",
"kind": "other",
"published_at": "2026-07-20T04:36:18Z"
},
{
"tag": "v26_7_1",
"kind": "other",
"published_at": "2026-07-17T13:02:31Z"
},
{
"tag": "master-202607171229",
"kind": "other",
"published_at": "2026-07-17T12:30:18Z"
},
{
"tag": "fork-3761abc7-oberstet_crossbar-fix_2254-202607171217",
"kind": "other",
"published_at": "2026-07-17T12:17:41Z"
},
{
"tag": "fork-0060a478-oberstet_crossbar-fix_2254-202607171136",
"kind": "other",
"published_at": "2026-07-17T11:36:23Z"
},
{
"tag": "master-202607171114",
"kind": "other",
"published_at": "2026-07-17T11:15:06Z"
},
{
"tag": "fork-c8ae04ec-oberstet_crossbar-fix_2253-202607171101",
"kind": "other",
"published_at": "2026-07-17T11:02:14Z"
},
{
"tag": "master-202607171028",
"kind": "other",
"published_at": "2026-07-17T10:28:49Z"
},
{
"tag": "fork-c776560b-oberstet_crossbar-fix_2252-202607171012",
"kind": "other",
"published_at": "2026-07-17T10:12:49Z"
},
{
"tag": "master-202607170924",
"kind": "other",
"published_at": "2026-07-17T09:24:51Z"
},
{
"tag": "fork-2061b51f-oberstet_crossbar-fix_2251-202607170848",
"kind": "other",
"published_at": "2026-07-17T08:48:40Z"
},
{
"tag": "master-202607170759",
"kind": "other",
"published_at": "2026-07-17T07:59:37Z"
},
{
"tag": "fork-4d4e1737-oberstet_crossbar-fix_2250_2-202607170731",
"kind": "other",
"published_at": "2026-07-17T07:32:15Z"
},
{
"tag": "fork-6e1b8eaa-oberstet_crossbar-fix_2256-202607151424",
"kind": "other",
"published_at": "2026-07-15T14:24:33Z"
},
{
"tag": "pr2246-null-dependabot_uv_sphinx_9_0_4-202606220529",
"kind": "other",
"published_at": "2026-06-22T05:29:39Z"
},
{
"tag": "pr2245-null-dependabot_uv_setuptools_82_0_1-202606220524",
"kind": "other",
"published_at": "2026-06-22T05:24:55Z"
},
{
"tag": "pr2244-null-dependabot_uv_service_identity_26_1_0-202606220522",
"kind": "other",
"published_at": "2026-06-22T05:23:10Z"
},
{
"tag": "pr2243-null-dependabot_uv_python_minor_patch_b63b0b0112-202606220519",
"kind": "other",
"published_at": "2026-06-22T05:19:45Z"
},
{
"tag": "pr2242-null-dependabot_github_actions_github_actions_45c4131e33-202606220434",
"kind": "other",
"published_at": "2026-06-22T04:34:24Z"
},
{
"tag": "v26_6_1",
"kind": "other",
"published_at": "2026-06-21T20:07:21Z"
},
{
"tag": "master-202606211943",
"kind": "other",
"published_at": "2026-06-21T19:43:46Z"
},
{
"tag": "fork-b363adb2-oberstet_crossbar-fix_2147_2152-202606211747",
"kind": "other",
"published_at": "2026-06-21T17:47:37Z"
},
{
"tag": "master-202606211717",
"kind": "other",
"published_at": "2026-06-21T17:17:50Z"
},
{
"tag": "fork-f8da7752-oberstet_crossbar-fix_2156-202606211704",
"kind": "other",
"published_at": "2026-06-21T17:04:28Z"
},
{
"tag": "fork-9582ad9c-oberstet_crossbar-fix_2156-202606211634",
"kind": "other",
"published_at": "2026-06-21T16:35:18Z"
},
{
"tag": "master-202606211615",
"kind": "other",
"published_at": "2026-06-21T16:15:26Z"
},
{
"tag": "fork-5dc7c541-oberstet_crossbar-fix_2187-202606211551",
"kind": "other",
"published_at": "2026-06-21T15:52:02Z"
},
{
"tag": "master-202606211414",
"kind": "other",
"published_at": "2026-06-21T14:14:54Z"
},
{
"tag": "fork-dfeffde9-oberstet_crossbar-fix_2224-202606211020",
"kind": "other",
"published_at": "2026-06-21T10:20:53Z"
},
{
"tag": "pr2219-null-dependabot_uv_tornado_6_5_7-202606171812",
"kind": "other",
"published_at": "2026-06-17T18:12:57Z"
},
{
"tag": "pr2217-null-dependabot_uv_aiohttp_3_14_1-202606170321",
"kind": "other",
"published_at": "2026-06-17T03:22:32Z"
},
{
"tag": "pr2206-null-dependabot_uv_eth_typing_6_0_0-202606131121",
"kind": "other",
"published_at": "2026-06-13T11:22:04Z"
},
{
"tag": "pr2205-null-dependabot_uv_pyopenssl_26_3_0-202606131118",
"kind": "other",
"published_at": "2026-06-13T11:18:55Z"
},
{
"tag": "pr2204-null-dependabot_uv_attrs_26_1_0-202606131116",
"kind": "other",
"published_at": "2026-06-13T11:16:49Z"
},
{
"tag": "pr2198-null-dependabot_uv_importlib_resources_7_1_0-202606131112",
"kind": "other",
"published_at": "2026-06-13T11:13:07Z"
},
{
"tag": "pr2199-null-dependabot_uv_cryptography_49_0_0-202606131112",
"kind": "other",
"published_at": "2026-06-13T11:13:06Z"
},
{
"tag": "pr2201-null-dependabot_uv_cbor2_6_1_2-202606131112",
"kind": "other",
"published_at": "2026-06-13T11:12:57Z"
},
{
"tag": "pr2200-null-dependabot_uv_pip_26_1_2-202606131112",
"kind": "other",
"published_at": "2026-06-13T11:12:54Z"
},
{
"tag": "pr2203-null-dependabot_uv_idna_3_18-202606131112",
"kind": "other",
"published_at": "2026-06-13T11:12:45Z"
},
{
"tag": "pr2202-null-dependabot_uv_txtorcon_26_6_0-202606131110",
"kind": "other",
"published_at": "2026-06-13T11:12:14Z"
},
{
"tag": "pr2197-null-dependabot_uv_python_minor_patch_ad2d7e32bb-202606131056",
"kind": "other",
"published_at": "2026-06-13T11:05:22Z"
},
{
"tag": "pr2194-null-dependabot_github_actions_github_actions_bac2deeea1-202606131003",
"kind": "other",
"published_at": "2026-06-13T10:04:15Z"
},
{
"tag": "vfork_0ce56187_oberstet_crossbar_fix_2191_202606130950",
"kind": "other",
"published_at": "2026-06-13T10:02:32Z"
},
{
"tag": "fork-0ce56187-oberstet_crossbar-fix_2191-202606130950",
"kind": "other",
"published_at": "2026-06-13T09:50:57Z"
},
{
"tag": "master-202606130851",
"kind": "other",
"published_at": "2026-06-13T08:52:16Z"
},
{
"tag": "pr2188-null-dependabot_uv_tornado_6_5_6-202606122209",
"kind": "other",
"published_at": "2026-06-12T22:10:12Z"
},
{
"tag": "pr2185-null-dependabot_uv_aiohttp_3_14_0-202606032319",
"kind": "other",
"published_at": "2026-06-03T23:19:46Z"
},
{
"tag": "pr2177-null-dependabot_uv_ujson_5_12_1-202605300953",
"kind": "other",
"published_at": "2026-05-30T09:54:23Z"
},
{
"tag": "pr2178-null-dependabot_uv_idna_3_15-202605300949",
"kind": "other",
"published_at": "2026-05-30T09:49:42Z"
},
{
"tag": "pr2176-null-dependabot_uv_pip_26_1-202605300948",
"kind": "other",
"published_at": "2026-05-30T09:49:02Z"
},
{
"tag": "pr2175-null-dependabot_uv_urllib3_2_7_0-202605300947",
"kind": "other",
"published_at": "2026-05-30T09:47:35Z"
},
{
"tag": "pr2174-null-dependabot_uv_nbconvert_7_17_1-202605300944",
"kind": "other",
"published_at": "2026-05-30T09:44:49Z"
},
{
"tag": "pr2173-null-dependabot_uv_mistune_3_2_1-202605300941",
"kind": "other",
"published_at": "2026-05-30T09:44:23Z"
},
{
"tag": "master-202604021207",
"kind": "other",
"published_at": "2026-04-02T12:08:02Z"
},
{
"tag": "fork-dd8f0aa1-oberstet_crossbar-fix_2164-202604021150",
"kind": "other",
"published_at": "2026-04-02T11:50:50Z"
},
{
"tag": "fork-b957e731-oberstet_crossbar-fix_2164-202604021102",
"kind": "other",
"published_at": "2026-04-02T11:03:05Z"
},
{
"tag": "master-202601041214",
"kind": "other",
"published_at": "2026-01-04T12:14:56Z"
},
{
"tag": "master-202601040913",
"kind": "other",
"published_at": "2026-01-04T09:13:55Z"
},
{
"tag": "master-202601040859",
"kind": "other",
"published_at": "2026-01-04T09:00:24Z"
},
{
"tag": "master-202512180247",
"kind": "other",
"published_at": "2025-12-18T02:47:51Z"
},
{
"tag": "v25_12_1",
"kind": "other",
"published_at": "2025-12-18T02:22:55Z"
},
{
"tag": "master-202512180210",
"kind": "other",
"published_at": "2025-12-18T02:11:27Z"
},
{
"tag": "master-202512180118",
"kind": "other",
"published_at": "2025-12-18T01:18:55Z"
},
{
"tag": "master-202512180056",
"kind": "other",
"published_at": "2025-12-18T00:57:26Z"
},
{
"tag": "master-202512180025",
"kind": "other",
"published_at": "2025-12-18T00:26:16Z"
}
],
"recent_commits": [
{
"oid": "29b797cf4da46b77a971cd7f7f0846995f547d6c",
"body": "* start new dev branch; add audit file\n\n* add new release key (Crossbar.io 26.7 public key)\n\n* Finalize 26.7.1: codename 'Shields Up' + accept max_message_size=0 (#2254)\n\nRelease-prep content for 26.7.1:\n\n- Assign the 26.7 series codename 'Shields Up' (crossbar/_codename.py) — the\n release raises t\n[…]\nbario.readthedocs.io\n-> 200 (old crossbar.readthedocs.io -> 404); projects/crossbario badge -> passing\n(old crossbar badge -> failing).\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2254 (#2271)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-17T12:18:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe205250591ff782e96daeccac8df40cc153819d",
"body": "* start new dev branch; add audit file\n\n* Add failing tests: WebSocket max_frame_size must be range-validated (#2253)\n\ncheck_websocket_options() validates max_frame_size as an int only — nothing\nbounds it. That is a silent footgun: autobahn enforces frames with\n'0 < maxFramePayloadSize < length', so\n[…]\n #2250).\n\nTurns the max_frame_size tests green; full local gate: ruff + ty clean,\ntest_checkconfig 44 passed, Sphinx dummy build clean.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2253 (#2267)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-17T11:03:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "46c782d01d16dfc7def5881a9924b1ece0a30d08",
"body": "* start new dev branch; add audit file\n\n* Add failing tests: RawSocket max_message_size must be validated over [512, 16MB] (#2252)\n\ncheck_rawsocket_options() reuses the WebSocket-shaped\ncheck_transport_max_message_size(), which accepts [1, 64MB]. But the RawSocket\ntransport hands the value to autoba\n[…]\ns own range is unaffected. Full\nlocal gate: ruff + ty clean, test_checkconfig 40 passed, Sphinx dummy build\nclean on the changed pages.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2252 (#2263)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-17T10:17:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d73ba8292b4bd504dd795b563573c212a0bfe3c9",
"body": "* start new dev branch; add audit file\n\n* Add failing tests: max_message_size must default to 16MB on both transports (#2251)\n\nCrossbar's two WAMP transports disagree on the default receive size limit, and\nthe WebSocket default is no limit at all:\n\n- WebSocket (router/protocol.py:126 server, :151 cl\n[…]\nreen (5/5). Full local gate: ruff + ty clean,\nrouter unit suite 100 passed / 13 skipped, Sphinx dummy build clean on the\nchanged pages.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2251 (#2260)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-17T09:13:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a447065eec04808a6719cf3d9e8f9b0bfabc0921",
"body": "* Pin autobahn>=26.7.1 and relock to the coordinated 26.7.1 set (#2250)\n\nBump the autobahn floor 26.6.2 -> 26.7.1 to require the payload size-limit\nsecurity fix (GHSA-hxp9-w8x3-p566 / autobahn #1907: permessage-deflate\ndecompression-bomb enforcement against the reassembled, UNCOMPRESSED message\nsize\n[…]\ng zlmdb>=26.7.1 guarantees the musl wheels. cfxdb and txaio stay at\n>=26.6.1 (not part of the 26.7.1 train). Locked versions unchanged.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2250 2 (#2258)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-17T07:48:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc619cd8a9aca137225f572e65323a003ab3d728",
"body": "* start new dev branch; add audit file\n\n* Sync the ty ignore allowlist with Autobahn|Python (#2256)\n\n`just check` (Code Quality Checks) was red on master, independently of any PR:\n`ty` reported \"Found 35 diagnostics\", all in files unrelated to whatever was\nbeing changed. The 35 were exactly two rule\n[…]\nified locally: `just check-typing cpy311` -> \"All checks passed!\", and the\nfull `just check cpy311` (format + typing + bandit) exits 0.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2256 (#2257)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-15T14:23:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f8f2ce8382d4f3d7925a25ae5ab438ad2d8f673",
"body": "* start new dev branch; add audit file\n\n* Add failing tests: WebSocket compression config must be validated (#2250)\n\ncheck_websocket_compression() is an empty \"# FIXME\" stub, yet it is wired into\ncheck_websocket_options(), so WebSocket `compression` config is accepted\nentirely unvalidated: unknown c\n[…]\nditionally accepts 0, matching autobahn's\n\"do not request a window size\" semantics.\n\nMakes the tests added in the previous commit pass.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2250 (#2255)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-07-15T14:02:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c4d9d4210b91ab87336b13e65c41e04bab13fe0f",
"body": "* start new dev branch; add audit file\n\n* Document test-driven Bug Fix Workflow + PR audit-file requirement (#2152)\n\nExpand CONTRIBUTING.md so contributors (especially new ones) submit convincing,\nregression-guarded PRs:\n\n- new \"Bug Fix Workflow (Test-Driven)\" section: file/agree on the issue, open \n[…]\neds no repo change - all in-repo doc URLs\nalready point to crossbar.readthedocs.io; it is an RTD project-registration\n(dashboard) task.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2147 2152 (#2238)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-06-21T19:32:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "df7a6e5e7200803481e9056c4e853946487e99c7",
"body": "* start new dev branch; add audit file\n\n* Report vendored LMDB version in `crossbar version` (#2156)\n\n`crossbar version` showed a blank \"LMDB :\" line: _get_versions() did a\ntop-level `import lmdb`, but crossbar has no top-level \"lmdb\" dependency (it\nalways goes through zlmdb, which vendors its own C\n[…]\n_version__, so it is currently ineffective; reported separately. crossbar\ndeliberately compares the meaningful __version__ values here.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2156 (#2235)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-06-21T17:06:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8c37f2ede376c1bd56ad670343a1039291f8d16c",
"body": "* start new dev branch; add audit file\n\n* Add failing regression test for swallowed RPC / zombie registration (#2187)\n\nTDD red half. Adds\nTestDealer.test_callee_detach_after_canceled_call_and_caller_gone, which\nreproduces the #2187 root cause at the Dealer level:\n\n 1. a callee WITHOUT call-cancelin\n[…]\nession test passes; full dealer and router suites green on\nboth CPython and PyPy.\n\nNote: This work was completed with AI assistance (Claude Code).\n\n* Normalize audit filename to .md convention (#2187)",
"is_bot": false,
"headline": "Fix 2187 (#2233)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-06-21T16:04:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "90597742f8c52d1627ff93e5837e8b2ed1699e9d",
"body": "* start new dev branch; add audit file\n\n* Fix release.yml: use absolute path for verified artifact download (#2227)\n\nThe release jobs passed a relative `path: dist` to the shared\ndownload-artifact-verified action. That action verifies in a staging temp dir,\n`cd`s into it, then `mkdir -p \"$DOWNLOAD_P\n[…]\npears in `crossbar version`, the banner/codename/UBJSON line are\nintact, and UBJSON still round-trips. No-op on PyPy (no bjdata there).\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2227 (#2228)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-06-21T14:03:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26eb3a560b61a70beea8deb7758ba0e6cc242c13",
"body": "* start new dev branch; add audit file\n\n* add crossbar release key for 26.6\n\n* Release 26.6.1: coordinated WAMP 26.6.x floor + CI chain-of-custody (#2224)\n\nFinal package of the coordinated WAMP 26.6.x release train.\n\n- bump version 26.4.1.dev1 -> 26.6.1 (_version.py, pyproject.toml)\n- pin coordinate\n[…]\nypo is still\nrejected. Added regression tests in crossbar.router.test.test_serializer\n(run on both CPython and PyPy via the CI matrix).\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2224 (#2225)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-06-21T10:24:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ce61c8d3dbb45ac2455aaa4d3fa578bfde55899d",
"body": "* add dev branch audit file\n\n* Add version-controlled Dependabot config and document update policy\n\nCloses #2191.\n\n- Add .github/dependabot.yml managing the uv (Python) and github-actions\n ecosystems: weekly schedule, grouped patch/minor bumps, and ignore rules\n for major-version updates of the de\n[…]\n CI), pyproject.toml-touching PRs are the manual lane (review the\n rewritten constraint), with just update-uvlock remaining canonical.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2191 (#2192)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-06-13T09:50:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d885fe7f256f2d53d5d864b119a201370f0546c3",
"body": "Bumps [mistune](https://github.com/lepture/mistune) from 3.1.4 to 3.2.1.\n- [Release notes](https://github.com/lepture/mistune/releases)\n- [Changelog](https://github.com/lepture/mistune/blob/main/docs/changes.rst)\n- [Commits](https://github.com/lepture/mistune/compare/v3.1.4...v3.2.1)\n\n---\nupdated-de\n[…]\nendency-version: 3.2.1\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump mistune from 3.1.4 to 3.2.1 (#2173)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-13T08:40:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2f0439aadae3fbcdb34573087e6bc8d790feec59",
"body": "* add branch audit file\n\n* fix: add missing @inlineCallbacks decorators (#2164)\n\nAdd missing @inlineCallbacks decorator to RouterWebServiceWebhook.create()\nand MarketMaker.revoke_offer(). Without the decorator, these functions\nsilently return generator objects instead of executing the async code.\n\nN\n[…]\n\nacross different ty versions.\n\nNote: This work was completed with AI assistance (Claude Code).\n\n* docs: add changelog entry for 26.4.1\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Fix 2164 (#2165)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-04-02T11:56:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "99392515763090c2235abc2c6e942d7bc44cea2c",
"body": null,
"is_bot": false,
"headline": "add Crossbar.io 26.1 release key",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-01-04T12:03:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d2c0933fd6504934e93eb111fb9e6a0d4e18f7d",
"body": null,
"is_bot": false,
"headline": "chore: bump version to 26.1.1.dev1",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-01-04T11:26:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4733e5b5e4703cf5a9d99441df8d418a174857b",
"body": null,
"is_bot": false,
"headline": "fix #2155",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-01-04T11:26:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5e591abba1731113723ec74f892a6767cb8e1b00",
"body": "* test: Add test for caller detach cleanup during in-flight RPC without cancel support\n\n* add audit file\n\n* typo\n\n* fix: Prevent callee session crash when caller disconnects during RPC\n\nWhen a caller disconnects while an RPC is in-flight, the router must\nclean up invocation tracking regardless of wh\n[…]\nallee supports call_canceling\n- Log appropriately in both cases\n\nFixes: https://github.com/crossbario/crossbar/issues/2133\n\n---------\n\nCo-authored-by: Marko Petzold <marko.petzold@record-evolution.de>",
"is_bot": false,
"headline": "Test/caller disconnect callee crash (#2153)",
"author_name": "Marko Petzold",
"author_login": "markope",
"committed_at": "2026-01-04T09:02:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "11e5b9715cd8bf1579a21aa1002370f577e4b487",
"body": "…u mean ?",
"is_bot": false,
"headline": "fix: typo check-typing - warning[unknown-rule]: Unknown rule . Did yo…",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2026-01-04T08:49:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2e2007d613de14cc491c77d35842bf03d4f27da3",
"body": "PyPI rejects packages with direct URL dependencies (git+https://).\nThe dev-latest extra contained git dependencies for testing with\nunreleased WAMP packages, which caused the release workflow to fail\nat the PyPI upload step with \"Can't have direct dependency\".\n\nChanges:\n- Remove dev-latest extra fro\n[…]\n\nFor development with unreleased WAMP packages, use the existing\ninstall-dev-local recipe which installs from local editable checkouts.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "fix: remove dev-latest extra that prevents PyPI upload",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-18T02:34:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c571f22dc8a3026ca8f74a748601c6425ed74d9",
"body": "The release-production job had `permissions: id-token: write` which\nOVERRIDES and REPLACES the workflow-level permissions, removing\n`contents: write` needed for creating GitHub releases.\n\nRemoved the job-level permissions block so the job inherits all\nworkflow-level permissions (including contents: write).\n\nThis aligns with cfxdb and wamp-xbr which don't have job-level\npermissions on release-production.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "fix: remove job-level permissions that override workflow permissions",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-18T01:57:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73b4edf9987b62465ad409feca6e4ec64064bf44",
"body": "Added missing `tags: ['v*']` trigger to main.yml to enable the\nrelease workflow chain when version tags are pushed.\n\nThis aligns with txaio, autobahn-python, zlmdb, cfxdb, and wamp-xbr\nwhich all have this trigger configured.\n\nAlso added `workflow_dispatch` for manual triggering.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "fix: add tag trigger to main.yml workflow",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-18T01:05:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fd58b52bff1ba169e6b8e5e39e6c6ac2277d3365",
"body": "Removed obsolete workflow files:\n- deploy-docs.yml (superseded by release.yml RTD trigger)\n- deploy-wheels.yml.orig (backup file)\n- test-management.yml (superseded by main.yml)\n\nUpdated documentation for v25.12.1 development release:\n- docs/changelog.rst: Added Phase 1.4 modernization changes\n- docs/releases.rst: Added v25.12.1 GitHub release link\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "cleanup: remove outdated workflows, update changelog",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-18T00:45:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ab618a1bff8bdddf64d3184a58fca49a545fa11d",
"body": "* add feature branch audit file\n\n* docs: add Phase 1.4 hatchling migration to MODERNIZATION.md (#159)\n\n- Add Phase 1.4: Build Backend Migration (setuptools → hatchling)\n- Mark phases 0.1, 0.2, 1.1, 1.2.3, 1.2.4, 1.3 as complete\n- Update pyproject.toml template to use hatchling\n- Add hatchling build \n[…]\n paths outside the workspace.\nChanged from `../autobahn-python` to `./autobahn-python` and pass\nthe path explicitly to the test recipe.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Modernization phase 1.4 (#2145)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-18T00:15:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c6cfea022073d7baa2ad2898eff2be6c186cc55",
"body": "* create new feature branch; add audit file\n\n* docs: add Phase 1.3 tracking table to MODERNIZATION.md\n\nAdd table with GitHub Issues and PRs for all 6 repos in Phase 1.3.\n\n* ci: modernize CI/CD with ty type checker and proper workflow order\n\nmain.yml:\n- Upgrade setup-uv@v5 to v6, setup-just@v2 to v3\n\n[…]\nx testing (CPython 3.11-3.14, PyPy 3.11)\n- ty type checking in CI\n- pytest coverage in CI\n- Justfile standardization across all 6 repos\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Phase 1.3: CI/CD Modernization (#2143)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-05T10:30:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cca92485331e03f9b7ff6cb55bb336d4fbf32c7a",
"body": "* add feature branch audit file\n\n* docs: add Phase 1.2 tracking section to MODERNIZATION.md\n\nAdd Phase 1.2 Completion Summary with GitHub issues and PRs for all 6 repos:\n- txaio: Issue #202, PR #203\n- autobahn-python: Issue #1787, PR #1788\n- zlmdb: Issue #79, PR #80\n- cfxdb: Issue #102, PR #103\n- wa\n[…]\nar init\n- Add test-universe-crossbar-start for testing crossbar start\n (uses autobahn-python example router with configurable timeout)\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Phase 1.2: Build Tooling Modernization (#2141)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-12-02T13:58:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a8e95a5847deac848036ebe6069595f0ac4daef3",
"body": "* Add comprehensive WAMP Python Stack modernization tracking matrix\n\nThis document tracks the modernization effort across all 6 WAMP Python packages\n(txaio, autobahn-python, zlmdb, cfxdb, wamp-xbr, crossbar), working from the\nfoundation up through the stack.\n\nKey features:\n- Complete dependency chai\n[…]\n- wamp-cicd (e3d9e93): GitHub templates, CI/CD actions (#1, #2)\n\nThis establishes the foundation upon which all Phase 1 work was built.\n\nNote: This work was completed with AI assistance (Claude Code).",
"is_bot": false,
"headline": "Modernization take1 (#2139)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-25T17:43:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed48ddbbb503c7b4315c8766883d9565c5ffb005",
"body": "Remove all requirements*.txt files and complete the migration to modern\nPython packaging with pyproject.toml as the single source of truth.\n\nChanges:\n\n1. pyproject.toml:\n - Add furo>=2024.1.29 to dev dependencies for Sphinx theme\n\n2. setup.py:\n - Simplify to minimal shim that defers to pyproject\n[…]\nfor all package metadata\n- Modern PEP 517/518/621 compliant packaging\n- Simpler maintenance (no duplicate dependency lists)\n- Better tool support (modern pip, build, twine)\n\nSupersedes commit 0f598dd9",
"is_bot": false,
"headline": "Complete migration from requirements.txt to pyproject.toml",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T21:18:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0f598dd94f3ed149d9a7a2f061b01e75d6dfcab4",
"body": "Add furo>=2024.1.29 to requirements-dev.txt to support the new Sphinx\ndocumentation theme.\n\nInstallation:\n- Run: just install-tools cpy311 (or your venv name)\n- Or: just install-dev cpy311\n\nThis will install Furo and all other development dependencies including\nSphinx documentation tools.\n\nRelated to commit a1d80566 (Modernize Sphinx documentation with Furo theme)",
"is_bot": false,
"headline": "Add Furo theme to development requirements",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T21:14:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a1d80566e67812409faece031ce217f5e3516cd9",
"body": "Major documentation infrastructure improvements:\n\nTheme Updates:\n- Switch from sphinx_rtd_theme to modern Furo theme\n- Add light/dark mode support with custom logos\n- Configure custom color schemes for both modes:\n * Light: Blue (#0077FF) on refined white (#fafafa)\n * Dark: Golden (#F0C359) on ant\n[…]\nme customization\n- Maintain RTD compatibility\n\nTesting:\n- Sphinx build succeeds with new configuration\n- Requires: pip install furo\n\nRelated to documentation modernization efforts across WAMP projects",
"is_bot": false,
"headline": "Modernize Sphinx documentation with Furo theme and enhancements",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T21:09:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f55bd9da247864f4c20b2b9062e807a4adef14d",
"body": "- Document new comprehensive test result categorization\n- Show individual example results with ✓/✗ symbols\n- Display aggregation by backend (twisted/asyncio)\n- Display aggregation by WAMP feature (overview/pubsub/rpc)\n- Update example counts to reflect actual tested examples (28 total: 14 twisted + 14 asyncio)\n- Note TLS examples are skipped on RawSocket transport\n\nRelated to crossbario/autobahn-python#1757",
"is_bot": false,
"headline": "Update integration test docs with enhanced test summary output",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T20:44:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18daf38e95f1f268d5043f6217feef12bf64ec8a",
"body": "This commit adds comprehensive documentation about the integration\ntest that runs the Autobahn|Python example suite against Crossbar.io.\n\nChanges:\n\n- Added docs/testing-autobahn-examples.rst\n - Overview of integration testing approach\n - Running tests locally (3 path configuration methods)\n - Com\n[…]\n CI/CD pipelines.\n\nThe tests verify compatibility between Crossbar.io router and\nAutobahn|Python client library across both WebSocket and RawSocket\ntransports, using both Twisted and asyncio backends.",
"is_bot": false,
"headline": "Add documentation for autobahn-python examples integration testing",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T19:31:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "77d97ae0a760dfb8e0846145bb746b6826112cca",
"body": "This commit adds a just recipe to run the autobahn-python examples\ntest suite against crossbar, testing both WebSocket and RawSocket\ntransports.\n\nChanges:\n\n- Added test-integration-ab-examples recipe to justfile\n - Flexible autobahn-python path resolution:\n * Default: ../autobahn-python (sibling\n[…]\nn crossbar instance from\nautobahn-python/examples/router/.crossbar/.\n\nFor GitHub CI, the autobahn-python path can be configured via\nAB_PYTHON_PATH environment variable or by cloning as a sibling repo.",
"is_bot": false,
"headline": "Add integration test recipe for autobahn-python examples",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T19:09:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4e810707053564686a5a02b6a2b488b8eea24cf7",
"body": "This commit adds comprehensive smoke tests for local CI/CD validation\nand documents the Crossbar.io personality system architecture.\n\nChanges:\n\n1. Smoke Tests (justfile):\n - test-smoke-cli: CLI command validation (version, legal, keys, shell)\n - test-smoke-init: Node initialization and file veri\n[…]\ngration.\n\nThe personality documentation captures the architectural analysis of\nhow crossbar supports different deployment modes (standalone, edge,\nmaster, network) through dynamic personality loading.",
"is_bot": false,
"headline": "Add smoke tests and personality system documentation",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T18:50:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "30441afa8be2cfcf23dbd62b11f28b4ad5b716ef",
"body": "- Bug: Loop variable 'files' in os.walk() shadowed the imported 'files' function\n- Python treats 'files' as local for entire function when assigned in loop\n- Line 74 tried to use files() before loop assignment, causing UnboundLocalError\n- Fix: Renamed loop variable from 'files' to 'filenames' (lines\n[…]\nnit command now works correctly\n\nThe bug was introduced during pkg_resources to importlib.resources migration\nwhen 'files' function was imported but the conflicting loop variable name\nwas not noticed.",
"is_bot": false,
"headline": "Fix UnboundLocalError in template.py from variable shadowing",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T13:25:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "743b5b8a50f5eda12a8cd060dc3da0d8ff077b98",
"body": "- Added 2>/dev/null to zipfile commands to suppress stderr\n- BrokenPipeError occurs when grep -q exits early after finding match\n- Error is cosmetic and doesn't affect verification functionality\n- Output is now clean without warning messages",
"is_bot": false,
"headline": "Suppress harmless BrokenPipeError warnings in build-verifydist",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T13:09:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb6ff27e69eedb5ce27536608b4882f569864a22",
"body": "- Added test-crossbar-keys recipe to test crossbar keys command\n- Renamed verify-dist to build-verifydist with comprehensive checks:\n * Verifies both wheel and source dist exist\n * Checks wheel is pure Python (py2.py3-none-any)\n * Verifies LICENSE and LICENSES-OSS are in wheel\n * Validates sourc\n[…]\nRuns twine check on all distributions\n * Reports detailed summary with pass/fail status\n- Added legacy alias verify-dist pointing to build-verifydist\n- Pattern adapted from zlmdb verify-wheels recipe",
"is_bot": false,
"headline": "Add test-crossbar-keys recipe and comprehensive build-verifydist",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T12:59:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c96285d0c532e7feaf72cd258ea5d8850afdc04",
"body": "- Renamed smoke recipe to test-crossbar-version\n- Added new test-crossbar-legal recipe that runs crossbar legal command\n- Updated setup recipe to reference test-crossbar-version\n- Moved LICENSES-OSS to crossbar/ directory for package data access\n- Updated justfile to generate license metadata at cro\n[…]\nES-OSS\n- Updated setup.py and MANIFEST.in to reference crossbar/LICENSES-OSS\n- Verified both LICENSE and LICENSES-OSS are included in built wheel\n- Both files are accessible via crossbar legal command",
"is_bot": false,
"headline": "Rename smoke recipe to test-crossbar-version and add test-crossbar-legal",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T11:46:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d6258531cd2cd6805981d072ccf6be08fcb83fea",
"body": "- Updated setup.py to reference LICENSES-OSS in root instead of crossbar/\n- Updated MANIFEST.in to reference LICENSES-OSS in root\n- Fixes build error after license metadata cleanup",
"is_bot": false,
"headline": "Fix LICENSES-OSS path in build configuration",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T11:29:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "15a9d18b25ebc5d39f756f16ace35b0361e1883c",
"body": "- Modified test recipe to depend on test-trial, test-pytest, and test-functional\n- Updated comment from 'unit tests' to 'tests' to reflect broader scope\n- Now just test runs all three test suites",
"is_bot": false,
"headline": "Update test recipe to include functional tests",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T10:47:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8b7e12ffff35df4076346b4cc7be73cfa096114",
"body": "Added bandit security checking:\n- New 'just check-bandit' recipe for security vulnerability scanning\n- Scans for MEDIUM and HIGH severity issues only (-ll flag)\n- Added to 'just check' meta-recipe (runs format + typing + bandit)\n- Added nosec comments for 3 legitimate security warnings:\n * B412: CG\n[…]\nfrom=classifier flag)\n * Now shows correct versions (25.x.x) and company name\n * autobahn: 25.10.2, cfxdb: 25.11.1, txaio: 25.9.2, xbr: 25.11.1, zlmdb: 25.10.2\n\nAll security checks now pass cleanly.",
"is_bot": false,
"headline": "Add check-bandit recipe and complete company name migration",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T10:29:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47954e583ccd4d080b9dd31bf60823550714a8c1",
"body": "Added configuration to ignore non-actionable linting and type errors\nuntil tests are running and dependencies have type stubs:\n\nRuff configuration (pyproject.toml):\n- Exclude intentionally malformed test file from all checks\n- Ignore E722 (bare except), E741 (ambiguous names), F823 (undefined)\n unt\n[…]\n real type issues to fix later:\n- 9 assignment type mismatches\n- 4 generator return type issues\n- 4 arg-type issues\n- 3 operator issues\n- 3 var-annotated issues\n- 2 misc issues\n- 1 method-assign issue",
"is_bot": false,
"headline": "Configure ruff and mypy for local CI/CD checks",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T09:40:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92498aba4294590527ddb748a5e7e6eaab51cbf5",
"body": "Ran 'ruff format' and 'ruff check --fix' to automatically fix\ncode style issues across the codebase:\n- 240 files reformatted with consistent formatting\n- Import statements sorted and organized (I001 rules)\n- Code style aligned with PEP 8 conventions\n\nAdded ruff configuration to exclude intentionally\n[…]\npt clauses (need specific exception types)\n- 39 E741: Ambiguous variable names (l, I, O)\n- 1 F823: Undefined name in type annotation\n\nThese require code review as they may affect error handling logic.",
"is_bot": false,
"headline": "Auto-format code with ruff and exclude malformed test file",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-10T09:28:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "be5d5689609b7e0e6936a4424fcc8c03893a3ed8",
"body": "The recipe was attempting to use 'python -m pip_licenses' which fails\nbecause pip-licenses provides a command-line script, not a Python module.\n\nChanged to use the pip-licenses command directly via venv bin path.\n\nAlso added VENV_PATH variable for cleaner command construction.\n\nFixes error: No module named pip_licenses",
"is_bot": false,
"headline": "Fix generate-license-metadata recipe to use pip-licenses command",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T18:23:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1188d4c6ee30b944cdd19f7e3b1c1c9e4f945fdd",
"body": "The install-tools recipe was installing crossbar with [dev] extras only,\nwhich pulls cfxdb 23.12.1 from PyPI. This version has an outdated\nparsimonious constraint (<0.10.0) that conflicts with eth-abi 5.1.0\nwhich requires parsimonious>=0.10.0.\n\nChange install-tools to use [dev,dev-latest] extras ins\n[…]\nes from GitHub master branches with\nupdated dependencies.\n\nFixes dependency resolution error:\n cfxdb 23.12.1 requires parsimonious<0.10.0,>=0.9.0\n eth-abi 5.1.0 requires parsimonious<0.11.0,>=0.10.0",
"is_bot": false,
"headline": "Fix dependency conflict: update install-tools to use dev-latest",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T18:16:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c96f8d2d487885eb04778f3e9d30cca5f311f627",
"body": "Replace deprecated pkg_resources API with modern importlib equivalents:\n- importlib.metadata.version() for package version queries\n- importlib.resources.files() for resource path resolution\n\nUpdated files:\n- crossbar/node/main.py\n- crossbar/node/template.py\n- crossbar/master/node/node.py\n- crossbar/edge/node/node.py\n\nPython >=3.11 requirement allows direct use of these modern APIs.\nEliminates deprecation warnings from pkg_resources.",
"is_bot": false,
"headline": "Modernize resource loading: replace pkg_resources with importlib",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T15:34:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec2df074dda9a47960c6479e789b10664dff5645",
"body": "1. Company Name - Complete Replacement:\n - Replaced all remaining 'Crossbar.io Technologies GmbH' → 'typedef int GmbH'\n - Replaced 'Crossbar.io Technologies' → 'typedef int' in all files\n - Updated across: JavaScript, HTML, Markdown, RST, Makefiles, and docs\n - Total files updated: 69+ occur\n[…]\nable.rst\n - Usage: just generate-license-metadata [venv]\n - Auto-detects system Python venv if not specified\n\nAll company references now point to typedef int GmbH and\nhttps://github.com/typedefint",
"is_bot": false,
"headline": "Complete company name replacement and add license generation recipe",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T15:23:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f9b3484a477897da3480b05e1f6f224bccc2ce3",
"body": "1. Replace 'Crossbar.io Technologies GmbH' with 'typedef int GmbH'\n - Updated copyright headers across all Python files\n\n2. Replace deprecated pkg_resources with modern importlib.resources\n - crossbar/common/key.py: Use files() instead of resource_filename()\n - crossbar/worker/controller.py: U\n[…]\nb.resources is available since Python 3.9, and crossbar\nrequires Python >=3.11, so we can use it directly without backport.\n\nNote: Some files still use pkg_resources and will be updated incrementally.",
"is_bot": false,
"headline": "Replace company name and modernize pkg_resources usage",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T15:14:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "16878c346afebb5280061c78ecd92ea45f59e8d4",
"body": "Created crossbar-25-11.pub as placeholder for the new release.\nThe actual release key will need to be generated properly before\npublishing the official release.\n\nThis allows 'crossbar version' command to run without errors.",
"is_bot": false,
"headline": "Add placeholder release public key for v25.11",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T14:54:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de8483344ef38504b41bc90ee739749a7ff7bd61",
"body": "justfile changes:\n- Add 'run' recipe to execute commands in venv bypassing PATH issues\n Usage: just run cpy312 crossbar version\n just run cpy312 python -m pytest\n- Automatically finds commands in venv/bin or uses venv's python\n- Provides clear error messages and usage examples\n\ncrossbar imp\n[…]\n_backend.py\n- crossbar/node/node.py, interfaces.py\n- test/test_imports.py\n- And several test files\n\nNext steps: Complete the xbr package split by ensuring all required\nmodules are in wamp-xbr package.",
"is_bot": false,
"headline": "Add 'just run' recipe and update xbr imports for split package",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T12:11:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7271e6bce9b8a60be50ded8592530e824ca474b0",
"body": "pyproject.toml changes:\n- Remove wamp-xbr from [dev-latest] (setup.py fix not yet on GitHub)\n- Comment out py-cid and py-multihash dependencies due to conflicts\n - py-cid 0.3.1 requires base58<2.0 which conflicts with base58>=2.1.1\n - These can be installed manually if needed for XBR/IPFS features\n[…]\nard1:\n✅ just install-dev-latest cpy312 - Successfully installs all packages from GitHub\n✅ Relative paths ready for cross-platform use\n\nNext: Test install-dev-local with relative paths on both machines",
"is_bot": false,
"headline": "Fix install-dev-latest and use relative paths in install-dev-local",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T11:38:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "643c8a031402e3e107fe6573d1a7790de943c8a8",
"body": "Added support for installing autobahn-python with required extras in\ninstall-dev-local recipe. This partially addresses the dependency resolution\nissues when installing WAMP packages in editable mode.\n\nCurrent status:\n- ✅ txaio, zlmdb, cfxdb, wamp-xbr install successfully in editable mode\n- ✅ Fixed \n[…]\n from GitHub\ninstead of local editable repos. This works better with pip's resolver.\n\nFor full cross-project development, manual installation steps may be needed\nuntil this pip limitation is resolved.",
"is_bot": false,
"headline": "Improve install-dev-local recipe (work in progress)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T10:44:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5653850a4e34ab6a4811215e897a4c709e919c3",
"body": "Implement modern approach for testing crossbar with unreleased WAMP packages:\n\npyproject.toml changes:\n- Adjust main dependencies to use currently available PyPI versions\n - txaio>=25.9.2 (latest on PyPI, will bump to 25.10.2 when published)\n - cfxdb>=23.12.1 (latest on PyPI, will bump to 25.11.1 \n[…]\non\n✅ Cross-project development in editable mode\n✅ PyPI package stays clean (no git URLs in main deps)\n✅ Standard modern Python packaging approach\n\nTested on asgard1 with wamp-xbr setup.py fix applied.",
"is_bot": false,
"headline": "Add development dependency modes for testing with unreleased packages",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T10:34:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8b2220e460abb4eb8143a685a21e3b7332cb53f",
"body": "Match autobahn-python justfile patterns for venv management:\n- Use VENV_DIR := './.venvs' for common venv directory\n- Add ENVS variable listing supported Python versions\n- Add default parameter support (venv=\"\") for all recipes\n- Auto-detect system Python when no venv specified\n- Use consistent help\n[…]\nross all WAMP projects.\n\nTested:\n- 'just create' auto-detects system Python (cpy311)\n- 'just --list' shows all 37 recipes with proper defaults\n- Venv created in ./.venvs/cpy311 instead of project root",
"is_bot": false,
"headline": "Replicate autobahn-python justfile venv infrastructure",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T10:07:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "39d0683203e89a2aa7fca0b039d1fda867bf5321",
"body": "Replace bash parameter expansion syntax with case statements\nfollowing patterns from autobahn-python and zlmdb justfiles.\n\nChanges:\n- Add helper recipes: _get-spec, _get-system-venv-name, _get-venv-python\n- Replace '${var:offset:length}' syntax with case statements\n- Add default parameter support wi\n[…]\nionality (create, install, test, build, docs)\n\nThis fixes the error:\n error: Unexpected closing delimiter `}`\n ——▶ justfile:45:30\n\nTested: 'just --list' now works correctly showing all 30 recipes.",
"is_bot": false,
"headline": "Fix justfile syntax errors",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-09T10:01:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "31847e087604dc23ead0b8b7b3137a5df4a35ff0",
"body": "Adds standard WAMP project infrastructure:\n\n- .ai submodule (wamp-ai): AI policies and git hooks\n - AI_GUIDELINES.md (guidelines for AI assistants)\n - AI_POLICY.md (policy for human contributors using AI)\n - .githooks/commit-msg (enforces AI authorship disclosure)\n - .githooks/pre-push (prevents\n[…]\noksPath = .ai/.githooks\n\nThis brings crossbar.io in line with autobahn-python, zlmdb, and\ncfxdb, ensuring consistent AI collaboration policies and shared\nCI/CD infrastructure across all WAMP projects.",
"is_bot": false,
"headline": "Add .ai and .cicd git submodules for shared policies and workflows",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-08T20:54:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1bb018b6d7183dbea8243c2dd5d9ce07a60d0bf",
"body": "Major modernization bringing crossbar.io in line with autobahn-python,\nzlmdb, and cfxdb patterns:\n\n**Build System:**\n- Add comprehensive pyproject.toml (migrate from setup.py)\n- Add justfile (uv + just based build system)\n- Bump version: 23.1.2 → 25.11.1\n- Update Python requirement: >=3.7 → >=3.11\n-\n[…]\n CI/CD and prepares for\npublishing crossbar.io v25.11.1 to PyPI with full wheel support.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
"is_bot": false,
"headline": "Modernize crossbar.io build system and CI/CD to v25.11.1",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2025-11-08T20:45:54Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f54478e82d4801b7d0e04940c09e23b7442607f5",
"body": "Co-authored-by: David Ellis <david.ellis@atamate.com>",
"is_bot": false,
"headline": "Unregistering when RemoteSession leaves (#2129)",
"author_name": "Skully17",
"author_login": "Skully17",
"committed_at": "2025-06-19T04:19:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47255cae6558f92cd78bcdf3657fb0b7843e2c87",
"body": "* - Corrected param name\n- Added variable for repetitively accessed dictionary value\n- extended if statement to also check if \"sub\" is not None to see if the subscription has actually been made.\n- Added on_remote_leave to empty dictionary of forwarded subscriptions\n- extended if statement to also ch\n[…]\nistration to _regs\n- sub needs to be unsubscribed, not unregistered\n\n---------\n\nCo-authored-by: David Ellis <david.ellis@atamate.com>\nCo-authored-by: Tobias Oberstein <tobias.oberstein@crossbario.com>",
"is_bot": false,
"headline": "RLink Forwarding Issue (#2080)",
"author_name": "Skully17",
"author_login": "Skully17",
"committed_at": "2025-06-11T16:12:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d76f83c4eb5bb6f584b485c5160cf634fc44f23f",
"body": "Co-authored-by: David Ellis <david.ellis@atamate.com>",
"is_bot": false,
"headline": "Fixing mypy and flake8 error (#2125)",
"author_name": "Skully17",
"author_login": "Skully17",
"committed_at": "2025-06-03T18:30:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "349eeed3fa06a8f2eb0dd0c5c49d1a9ad33b155e",
"body": null,
"is_bot": false,
"headline": "Multiple resource leaks fixed in proxy and dealer (#2098)",
"author_name": "Denis Zabavchik",
"author_login": "DZabavchik",
"committed_at": "2025-06-03T16:44:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1a78363866be39e9e624226980bbe2d90e9fd65",
"body": null,
"is_bot": false,
"headline": "fix wampcra auth with salt (#2121)",
"author_name": "Mahad",
"author_login": "Mahad-10",
"committed_at": "2025-02-21T11:52:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f722a226e75e57511f0eb3771a7bbfadf48f1fdb",
"body": "* Fixing test runners\r\n\r\n* Fixing test runners\r\n\r\n* Fixing test runners\r\n\r\n* Fixing test runners\r\n\r\n* update eth-abi\r\n\r\n* update eth-abi\r\n\r\n* update eth-abi\r\n\r\n* update eth-abi\r\n\r\n* update eth-account\r\n\r\n* intersphinx_mapping format has changed\r\n\r\n* Removed sphinxcontrib.images from list of extensio\n[…]\n GitHub machine\r\n- Satisfied yapf\r\n\r\n* Removed testing on python 3.9\r\n\r\n* Changed the CI trigger back to how it was for production\r\n\r\n---------\r\n\r\nCo-authored-by: David Ellis <david.ellis@atamate.com>",
"is_bot": false,
"headline": "Fix test runners (#2119)",
"author_name": "Skully17",
"author_login": "Skully17",
"committed_at": "2025-01-09T13:53:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0089c1ef6fbbb87fc7316088a91f1859fa84eeb0",
"body": "The imp module is deprecated since Python 3.4 [1]. The import was added\r\neven after it was deprecated in [2]. In Python 3.12 the imp module will\r\nbe removed.\r\n\r\nUse the reload function from importlib, which is the designated\r\nreplacement [1].\r\n\r\nWith #2091 and this change, crossbar can be installed \n[…]\n [3])\r\n\r\n[1] https://docs.python.org/3.11/library/imp.html\r\n[2] https://github.com/crossbario/crossbar/commit/21910b070c79016f7aa5ba62f897ba4f978f593f\r\n[3] https://github.com/methane/wsaccel/issues/30",
"is_bot": false,
"headline": "common/reloader: import reload from importlib (#2093)",
"author_name": "Bastian Krause",
"author_login": "Bastian-Krause",
"committed_at": "2023-08-24T15:50:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "03d7057ee18a0d1e59b33bf1633ee246c1cf908a",
"body": "The first paragraph is lifted from #1122\r\n\r\nCloses #1122.",
"is_bot": false,
"headline": "doc: notes on updating certificates and restarting. (#2067)",
"author_name": "2e0byo",
"author_login": "2e0byo",
"committed_at": "2023-03-18T04:14:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "427cf58e42014499a623d4c17e06c6e3440273f9",
"body": null,
"is_bot": false,
"headline": "fixes and adjust to autobahn 23.1.2",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2023-02-08T02:43:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "706b2311bb4fa532ada81a357a888528ed493209",
"body": "* prepare v23.1.1",
"is_bot": false,
"headline": "prepare v23.1.1 (#2063)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2023-02-07T16:48:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d5d2ec46f5d77ae2901d8c23b81173ecf296645",
"body": "* Fix for #2053\r\n- Fixed PubSub over RLinks by using \"sub_details['id']\" instead of \"sub_id\".\r\n- changed \"sub_id\" to \"sub_session\"\r\nThese changes follow the fix made to registering over RLinks in #1789\r\n\r\n* Fix for #2053\r\n- Changed formatting to fix yapf failure\r\n\r\n* Fix for #2053\r\n- Check if uri be\n[…]\not subscription id\r\n- Fixed some inconsistancy with log levels\r\n\r\n---------\r\n\r\nCo-authored-by: David Ellis <david.ellis@atamate.com>\r\nCo-authored-by: Tobias Oberstein <tobias.oberstein@crossbario.com>",
"is_bot": false,
"headline": "Fix for #2053 (#2055)",
"author_name": "Skully17",
"author_login": "Skully17",
"committed_at": "2023-02-07T14:08:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "07466771714848f4bb1ec4748716a1baf5d1b6c8",
"body": "* start adding support for shared realms",
"is_bot": false,
"headline": "start adding support for shared realms (#2044)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2023-02-07T01:39:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45fcc6c40a19e99db479eab21b0d368148c694da",
"body": "* expand WAMP wildcard URI tests - see https://github.com/wamp-proto/wamp-proto/issues/174\r\n* fix for flake8 6.0.0\r\n* fix for dependency updates\r\n* fix figure\r\n* fix more maintenance glitches\r\n* update deps, refreeze and bump dev version\r\n* update copyright header - no license change!\r\n* fix dependency_links is deprecated\r\n* fix web3 dep flavor\r\n* add test keys into repo",
"is_bot": false,
"headline": "prepare rel v23.1.1 (#2060)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2023-02-01T10:20:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f4e2cb274f0fb80db1586ab4a085379f74348fe",
"body": "…tegory\" for autobahn PR #1590 (#2059)\n\nCo-authored-by: David Ellis <david.ellis@atamate.com>",
"is_bot": false,
"headline": "\"identity_realm_name_category\" was changed to \"identify_realm_name_ca…",
"author_name": "Skully17",
"author_login": "Skully17",
"committed_at": "2023-01-15T09:15:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ccbae0a56ef331fe00192455837aa72578eadc54",
"body": "* bump some deps and refreeze\r\n* wamp-cs: support standalone trustroots",
"is_bot": false,
"headline": "prepare v22.7.1 (#2042)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-08-11T20:50:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3bca55680488b9f302daaa4f2727f5d06f58b2a",
"body": "* wamp-cs: trustroot and certificates\r\n* bump dev version",
"is_bot": false,
"headline": "wamp-cs: trustroot and certificates (#2036)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-07-20T20:51:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "174d32f210e007026b36f7d0632612512f210531",
"body": "Since vmprof has trouble releasing a python 3.10 capable version [1] and\r\nit is only needed for profiling in crossbar, make it a soft dependency.\r\n\r\nAll occurrences of vmprof in actual code are already guarded by\r\ntry except constructs around imports and `_HAS_VMPROF` checks around\r\nvmprof use.\r\n\r\nS\n[…]\nthe various\r\nreqirements/setup/Makefile files as well as corresponding licensing\r\nfiles.\r\n\r\n[1] https://github.com/vmprof/vmprof-python/issues/240\r\n\r\nSigned-off-by: Bastian Krause <bst@pengutronix.de>",
"is_bot": false,
"headline": "make vmprof a soft dependency (#2035)",
"author_name": "Bastian Krause",
"author_login": "Bastian-Krause",
"committed_at": "2022-07-11T13:17:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "42b8bf95a29f17724f2ec120cd3a6ad096d5b396",
"body": "* improve logging; type hints and docs\r\n* add trustroot to cryptosign\r\n* sign router challenge\r\n* use centralized (in node controller) SecurityModuleMemory in all node processes\r\n* use zlmdb.Database.open factory\r\n* bump zlmdb, cfxdb, autobahn deps; re-freeze deps",
"is_bot": false,
"headline": "use node controller centrally hosted security module (#2032)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-07-05T20:09:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0a5a602b2df666a265eb76f33b11f9995d756f5",
"body": "* FIX HTTP-Bridge do not support all possible options for topic publishing. ref #1829\r\n\r\n* MODIFY more pretty diff. ref #1829",
"is_bot": false,
"headline": "HTTP-Bridge Publisher will support all possible options (#2031)",
"author_name": "Kostya Kufta",
"author_login": "yankos",
"committed_at": "2022-06-23T18:43:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1253b0beaf459b44b7dcd7592ec3840f26dff61c",
"body": "* static config for payload validation\r\n* fix uri checking; bump dev version\r\n* deactivate backend router max message size (for now)",
"is_bot": false,
"headline": "static config for payload validation (#2028)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-20T11:11:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71787f9eae220966e6be4a608cc049e336f9a85b",
"body": "* fixes #2025\r\n* fixes #2027",
"is_bot": false,
"headline": "fixes #2025 (#2026)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-15T00:28:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b6e25b1356b0641eff5dc5086d3971ecfb9a421",
"body": "continue with payload validation",
"is_bot": false,
"headline": "continue with payload validation (#2022)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-13T16:50:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "075753f5354edc03087e56f43635211891db50d1",
"body": null,
"is_bot": false,
"headline": "refreeze",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-02T17:43:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8044fc015a609e5a704d2e277615481c7bae14e",
"body": null,
"is_bot": false,
"headline": "bump dep versions",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-02T17:41:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a88f80b325c5e672c8c15ed35ded93970bec47eb",
"body": "* cleanups after the license change to EUPL-1.2 that happened in v21.11.1 already\r\n\r\n* freeze deps; bump release version",
"is_bot": false,
"headline": "Fix agpl eupl (#2021)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-02T16:54:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "edbbf22ef6131e2c7fb67c5f313c13e9f3498da6",
"body": null,
"is_bot": false,
"headline": "improve logging",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-02T15:11:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f779986f569a8f5cbdba1b2618f60050ee172316",
"body": "various fixes and additions",
"is_bot": false,
"headline": "sync (#2018)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-06-02T05:20:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09eaf37ce0dfc58e97ed8e0af428bea28dea61cc",
"body": "* adjust for autobahn changes",
"is_bot": false,
"headline": "adjust for autobahn changes (#2015)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-05-13T14:44:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "95b30b1a03e9596191887af2738f04b9624ff11b",
"body": "* bump dev version\r\n\r\n* improve logging\r\n\r\n* forward both proxy transport frontend details and custom authextra",
"is_bot": false,
"headline": "Fix proxy custom authextra (#2010)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-05-05T20:56:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "847138679831c963c8b313984e060883efa7f15e",
"body": "* fix #2006\r\n* better logging\r\n* update crossbar internal interfaces\r\n* update for interface changes\r\n* fix and improve database realmstore",
"is_bot": false,
"headline": "fix #2006 (#2007)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-05-04T17:03:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f8d4e7386cfe3297cb7dcdb9c37c157fb0a6238",
"body": "* use new autobahn.wamp.types.TransportDetails\r\n* add more type hints and docs",
"is_bot": false,
"headline": "Transport details (#2003)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-28T13:29:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8521972e03e20b56193046343a9f5209ac81ac5c",
"body": "* suppress distutils warn; do not require mock; bump dev version\r\n* polish component config\r\n* polish logging\r\n* improved web archive service logging\r\n* database cookie store support in router and proxy workers",
"is_bot": false,
"headline": "database cookiestore (#1995)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-23T19:42:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "33f48c81595427942935f66e352025674962a51a",
"body": "* add node eth key for every node type\r\n* add missing remove/delete commands in CLI\r\n* allow MagicMock for router worker types to enable CI\r\n* fix ci tests",
"is_bot": false,
"headline": "add node eth key for every node type (#1991)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-20T01:18:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cce29666fd0c173a41ea6e33c7e19b8a0427458b",
"body": null,
"is_bot": false,
"headline": "Update README.rst",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-13T21:00:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca8d383f01231e2b3f986e791f215f12f2deee5d",
"body": "* reduce log noise - fixes #1985\r\n* reactivate actually working rlink tests\r\n* add WAP webservice tests\r\n* fix WAP webservice running in proxy workers",
"is_bot": false,
"headline": "Fix wap webservice (#1987)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-07T12:18:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0bb0c022ec3f9d3f771b0fa089cbbf776e4bf06f",
"body": "* fix dynamic authenticators with proxy workers\r\n* fix test",
"is_bot": false,
"headline": "fix dynamic authenticators with proxy workers (#1986)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-06T17:30:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a261c5502cac4e0b77fd8f857dc9f720a620a31",
"body": "* fix #1982\r\n* fix cryptosign-proxy auth",
"is_bot": false,
"headline": "misc-master (#1984)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-05T19:51:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e86620e810ae0446fd60e0912a98b241483a4cbf",
"body": "…s (#1980)\n\ncomplete cryptosign-proxy authentication for proxy-backend connections",
"is_bot": false,
"headline": "complete cryptosign-proxy authentication for proxy-backend connection…",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-04T18:51:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f133369049c1d8ec4b4163023d1afd1af4bb5e79",
"body": "* enable http bridge in webcluster webservice types\r\n* start proxy transports only after proxy routes+connections\r\n* working on proxy auth\r\n* prepare 22.4.dev1",
"is_bot": false,
"headline": "enable http bridge in webcluster webservice types (#1978)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-04-02T06:24:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ecc8b4e0d9f8fa3efa7d59755cb2e16151055870",
"body": "reactivate a bunch of CI tests",
"is_bot": false,
"headline": "reactivate some tests .. (#1974)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-03-29T05:44:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c988a6e66e2f49a823ca830f0556ac5e1ad0fd8e",
"body": "* more polish\r\n\r\n* freeze deps\r\n\r\n* trigger ci",
"is_bot": false,
"headline": "Rcluster rlinks 2 (#1973)",
"author_name": "Tobias Oberstein",
"author_login": "oberstet",
"committed_at": "2022-03-27T21:15:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05ab33baebd8f556323c9bcc2b9efce64f848265",
"body": "fix #1813 and #1673\r\n\r\nCo-authored-by: Tobias Oberstein <tobias.oberstein@crossbario.com>",
"is_bot": false,
"headline": "corrections MQTT (#1935)",
"author_name": "galactics",
"author_login": "galactics",
"committed_at": "2022-03-27T19:33:07Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 70,
"commits_last_year": 58,
"latest_release_at": "2026-07-27T05:17:19Z",
"latest_release_tag": "pr2282-null-dependabot_uv_python_minor_patch_fb33d8da79-202607270516",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 9,
"days_since_latest_release": 0,
"mean_days_between_releases": 1.1
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 62,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "crossbar",
"exists": true,
"license": "EUPL-1.2",
"keywords": [
"autobahn",
"autobahn.ws",
"crossbar",
"oracle",
"postgres",
"postgresql",
"pubsub",
"realtime",
"rfc6455",
"router",
"rpc",
"wamp",
"websocket",
"Development Status :: 5 - Production/Stable",
"Environment :: Console",
"Environment :: No Input/Output (Daemon)",
"Framework :: Twisted",
"Intended Audience :: Developers",
"Operating System :: OS Independent",
"Programming Language :: Python",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.14",
"Programming Language :: Python :: Implementation :: CPython",
"Programming Language :: Python :: Implementation :: PyPy",
"Topic :: Communications",
"Topic :: Database",
"Topic :: Home Automation",
"Topic :: Internet",
"Topic :: Internet :: WWW/HTTP :: HTTP Servers",
"Topic :: Software Development :: Embedded Systems",
"Topic :: Software Development :: Libraries",
"Topic :: Software Development :: Libraries :: Application Frameworks",
"Topic :: Software Development :: Object Brokering",
"Topic :: System :: Distributed Computing",
"Topic :: System :: Networking"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/crossbar/",
"is_deprecated": false,
"latest_version": "26.7.1",
"repository_url": "https://github.com/crossbario/crossbar",
"versions_count": 110,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": "2013-11-21T18:19:25.119666Z",
"latest_published_at": "2026-07-17T13:02:43.612386Z",
"latest_version_yanked": null,
"days_since_latest_publish": 10
}
]
},
"popularity": {
"forks": 279,
"stars": 2065,
"watchers": 72,
"fork_history": {
"days": [
{
"date": "2013-11-10",
"count": 1
},
{
"date": "2013-11-30",
"count": 1
},
{
"date": "2013-12-06",
"count": 1
},
{
"date": "2014-01-08",
"count": 1
},
{
"date": "2014-01-17",
"count": 1
},
{
"date": "2014-04-04",
"count": 1
},
{
"date": "2014-04-10",
"count": 1
},
{
"date": "2014-06-12",
"count": 2
},
{
"date": "2014-06-16",
"count": 1
},
{
"date": "2014-07-07",
"count": 1
},
{
"date": "2014-08-22",
"count": 1
},
{
"date": "2014-09-01",
"count": 1
},
{
"date": "2014-09-03",
"count": 1
},
{
"date": "2014-09-06",
"count": 1
},
{
"date": "2014-10-11",
"count": 1
},
{
"date": "2014-10-15",
"count": 1
},
{
"date": "2014-10-30",
"count": 1
},
{
"date": "2014-11-02",
"count": 1
},
{
"date": "2014-11-15",
"count": 1
},
{
"date": "2014-11-19",
"count": 1
},
{
"date": "2014-11-20",
"count": 1
},
{
"date": "2014-11-21",
"count": 1
},
{
"date": "2014-11-29",
"count": 1
},
{
"date": "2014-12-02",
"count": 1
},
{
"date": "2014-12-06",
"count": 3
},
{
"date": "2014-12-14",
"count": 1
},
{
"date": "2015-01-05",
"count": 1
},
{
"date": "2015-01-20",
"count": 1
},
{
"date": "2015-02-01",
"count": 1
},
{
"date": "2015-02-13",
"count": 1
},
{
"date": "2015-03-04",
"count": 1
},
{
"date": "2015-04-03",
"count": 1
},
{
"date": "2015-04-05",
"count": 1
},
{
"date": "2015-04-07",
"count": 1
},
{
"date": "2015-04-14",
"count": 1
},
{
"date": "2015-04-16",
"count": 1
},
{
"date": "2015-05-13",
"count": 1
},
{
"date": "2015-05-14",
"count": 1
},
{
"date": "2015-05-21",
"count": 1
},
{
"date": "2015-05-27",
"count": 1
},
{
"date": "2015-06-04",
"count": 1
},
{
"date": "2015-06-18",
"count": 1
},
{
"date": "2015-06-26",
"count": 1
},
{
"date": "2015-06-29",
"count": 1
},
{
"date": "2015-07-06",
"count": 1
},
{
"date": "2015-07-09",
"count": 1
},
{
"date": "2015-07-13",
"count": 1
},
{
"date": "2015-08-31",
"count": 1
},
{
"date": "2015-09-11",
"count": 1
},
{
"date": "2015-09-14",
"count": 1
},
{
"date": "2015-09-18",
"count": 1
},
{
"date": "2015-10-06",
"count": 1
},
{
"date": "2015-10-07",
"count": 1
},
{
"date": "2015-10-15",
"count": 1
},
{
"date": "2015-10-24",
"count": 1
},
{
"date": "2015-10-28",
"count": 1
},
{
"date": "2015-11-02",
"count": 1
},
{
"date": "2015-11-15",
"count": 1
},
{
"date": "2015-11-21",
"count": 1
},
{
"date": "2015-11-25",
"count": 1
},
{
"date": "2015-11-26",
"count": 1
},
{
"date": "2015-12-02",
"count": 1
},
{
"date": "2015-12-22",
"count": 1
},
{
"date": "2016-01-04",
"count": 1
},
{
"date": "2016-01-11",
"count": 1
},
{
"date": "2016-01-12",
"count": 1
},
{
"date": "2016-01-16",
"count": 1
},
{
"date": "2016-01-24",
"count": 1
},
{
"date": "2016-02-01",
"count": 1
},
{
"date": "2016-02-08",
"count": 2
},
{
"date": "2016-02-09",
"count": 1
},
{
"date": "2016-02-22",
"count": 1
},
{
"date": "2016-02-23",
"count": 1
},
{
"date": "2016-02-26",
"count": 2
},
{
"date": "2016-03-08",
"count": 1
},
{
"date": "2016-03-09",
"count": 1
},
{
"date": "2016-03-16",
"count": 1
},
{
"date": "2016-04-01",
"count": 1
},
{
"date": "2016-04-08",
"count": 1
},
{
"date": "2016-04-15",
"count": 1
},
{
"date": "2016-04-17",
"count": 1
},
{
"date": "2016-04-29",
"count": 1
},
{
"date": "2016-05-01",
"count": 1
},
{
"date": "2016-05-19",
"count": 1
},
{
"date": "2016-05-31",
"count": 1
},
{
"date": "2016-06-01",
"count": 2
},
{
"date": "2016-06-11",
"count": 1
},
{
"date": "2016-06-15",
"count": 1
},
{
"date": "2016-06-24",
"count": 1
},
{
"date": "2016-07-06",
"count": 1
},
{
"date": "2016-07-21",
"count": 1
},
{
"date": "2016-07-26",
"count": 1
},
{
"date": "2016-08-10",
"count": 1
},
{
"date": "2016-09-22",
"count": 1
},
{
"date": "2016-09-27",
"count": 1
},
{
"date": "2016-10-08",
"count": 1
},
{
"date": "2016-10-15",
"count": 1
},
{
"date": "2016-10-18",
"count": 1
},
{
"date": "2016-10-20",
"count": 2
},
{
"date": "2016-10-23",
"count": 1
},
{
"date": "2016-10-26",
"count": 1
},
{
"date": "2016-10-28",
"count": 1
},
{
"date": "2016-11-14",
"count": 1
},
{
"date": "2016-12-28",
"count": 1
},
{
"date": "2016-12-29",
"count": 1
},
{
"date": "2017-01-11",
"count": 2
},
{
"date": "2017-01-15",
"count": 1
},
{
"date": "2017-01-19",
"count": 1
},
{
"date": "2017-01-22",
"count": 1
},
{
"date": "2017-02-18",
"count": 1
},
{
"date": "2017-02-21",
"count": 3
},
{
"date": "2017-02-25",
"count": 2
},
{
"date": "2017-03-03",
"count": 1
},
{
"date": "2017-03-09",
"count": 1
},
{
"date": "2017-03-12",
"count": 1
},
{
"date": "2017-03-16",
"count": 1
},
{
"date": "2017-03-25",
"count": 1
},
{
"date": "2017-03-28",
"count": 1
},
{
"date": "2017-04-08",
"count": 1
},
{
"date": "2017-04-12",
"count": 1
},
{
"date": "2017-04-16",
"count": 1
},
{
"date": "2017-04-19",
"count": 1
},
{
"date": "2017-04-26",
"count": 1
},
{
"date": "2017-04-28",
"count": 1
},
{
"date": "2017-05-02",
"count": 1
},
{
"date": "2017-05-03",
"count": 1
},
{
"date": "2017-05-12",
"count": 1
},
{
"date": "2017-05-15",
"count": 1
},
{
"date": "2017-06-04",
"count": 2
},
{
"date": "2017-06-21",
"count": 1
},
{
"date": "2017-07-15",
"count": 1
},
{
"date": "2017-07-20",
"count": 1
},
{
"date": "2017-07-28",
"count": 1
},
{
"date": "2017-08-02",
"count": 1
},
{
"date": "2017-08-16",
"count": 1
},
{
"date": "2017-08-23",
"count": 1
},
{
"date": "2017-09-25",
"count": 1
},
{
"date": "2017-10-09",
"count": 1
},
{
"date": "2017-11-05",
"count": 1
},
{
"date": "2017-11-07",
"count": 1
},
{
"date": "2017-11-10",
"count": 1
},
{
"date": "2017-11-12",
"count": 1
},
{
"date": "2017-11-30",
"count": 1
},
{
"date": "2018-01-17",
"count": 1
},
{
"date": "2018-02-16",
"count": 1
},
{
"date": "2018-02-19",
"count": 1
},
{
"date": "2018-03-19",
"count": 1
},
{
"date": "2018-03-25",
"count": 1
},
{
"date": "2018-04-21",
"count": 1
},
{
"date": "2018-04-30",
"count": 1
},
{
"date": "2018-05-13",
"count": 1
},
{
"date": "2018-06-10",
"count": 1
},
{
"date": "2018-06-25",
"count": 1
},
{
"date": "2018-06-27",
"count": 1
},
{
"date": "2018-07-11",
"count": 1
},
{
"date": "2018-07-22",
"count": 1
},
{
"date": "2018-07-31",
"count": 1
},
{
"date": "2018-08-14",
"count": 1
},
{
"date": "2018-08-30",
"count": 1
},
{
"date": "2018-09-03",
"count": 1
},
{
"date": "2018-09-20",
"count": 1
},
{
"date": "2018-09-24",
"count": 1
},
{
"date": "2018-09-26",
"count": 2
},
{
"date": "2018-10-02",
"count": 1
},
{
"date": "2018-10-27",
"count": 1
},
{
"date": "2018-11-20",
"count": 1
},
{
"date": "2018-12-20",
"count": 1
},
{
"date": "2019-01-10",
"count": 1
},
{
"date": "2019-02-25",
"count": 1
},
{
"date": "2019-02-28",
"count": 1
},
{
"date": "2019-03-13",
"count": 1
},
{
"date": "2019-03-21",
"count": 1
},
{
"date": "2019-03-31",
"count": 1
},
{
"date": "2019-04-02",
"count": 1
},
{
"date": "2019-04-10",
"count": 1
},
{
"date": "2019-04-14",
"count": 2
},
{
"date": "2019-05-03",
"count": 1
},
{
"date": "2019-05-08",
"count": 1
},
{
"date": "2019-05-13",
"count": 2
},
{
"date": "2019-05-25",
"count": 1
},
{
"date": "2019-06-14",
"count": 1
},
{
"date": "2019-07-11",
"count": 1
},
{
"date": "2019-07-16",
"count": 1
},
{
"date": "2019-08-15",
"count": 1
},
{
"date": "2019-10-14",
"count": 1
},
{
"date": "2019-10-17",
"count": 1
},
{
"date": "2019-11-25",
"count": 1
},
{
"date": "2019-12-07",
"count": 1
},
{
"date": "2019-12-16",
"count": 1
},
{
"date": "2020-01-07",
"count": 1
},
{
"date": "2020-04-02",
"count": 1
},
{
"date": "2020-04-06",
"count": 1
},
{
"date": "2020-04-15",
"count": 1
},
{
"date": "2020-06-11",
"count": 1
},
{
"date": "2020-07-09",
"count": 1
},
{
"date": "2020-07-14",
"count": 1
},
{
"date": "2020-10-05",
"count": 1
},
{
"date": "2020-10-27",
"count": 1
},
{
"date": "2020-11-09",
"count": 1
},
{
"date": "2020-11-20",
"count": 1
},
{
"date": "2020-11-27",
"count": 1
},
{
"date": "2020-12-01",
"count": 1
},
{
"date": "2021-01-04",
"count": 1
},
{
"date": "2021-01-14",
"count": 1
},
{
"date": "2021-04-27",
"count": 1
},
{
"date": "2021-05-07",
"count": 1
},
{
"date": "2021-06-04",
"count": 1
},
{
"date": "2021-06-08",
"count": 1
},
{
"date": "2021-07-29",
"count": 1
},
{
"date": "2021-08-31",
"count": 1
},
{
"date": "2021-11-17",
"count": 1
},
{
"date": "2021-12-14",
"count": 1
},
{
"date": "2021-12-18",
"count": 1
},
{
"date": "2022-01-07",
"count": 1
},
{
"date": "2022-01-15",
"count": 1
},
{
"date": "2022-01-26",
"count": 1
},
{
"date": "2022-03-09",
"count": 1
},
{
"date": "2022-04-04",
"count": 1
},
{
"date": "2022-04-28",
"count": 1
},
{
"date": "2022-05-05",
"count": 1
},
{
"date": "2022-05-12",
"count": 1
},
{
"date": "2022-05-18",
"count": 1
},
{
"date": "2022-06-06",
"count": 1
},
{
"date": "2022-10-12",
"count": 1
},
{
"date": "2022-12-16",
"count": 1
},
{
"date": "2023-02-17",
"count": 1
},
{
"date": "2023-02-26",
"count": 1
},
{
"date": "2023-03-19",
"count": 1
},
{
"date": "2023-04-29",
"count": 1
},
{
"date": "2023-07-25",
"count": 1
},
{
"date": "2023-07-27",
"count": 1
},
{
"date": "2023-08-02",
"count": 1
},
{
"date": "2023-08-17",
"count": 1
},
{
"date": "2023-12-27",
"count": 1
},
{
"date": "2024-02-10",
"count": 1
},
{
"date": "2024-03-14",
"count": 1
},
{
"date": "2024-04-09",
"count": 1
},
{
"date": "2024-05-22",
"count": 1
},
{
"date": "2024-06-15",
"count": 1
},
{
"date": "2024-06-30",
"count": 1
},
{
"date": "2024-10-20",
"count": 1
},
{
"date": "2024-11-15",
"count": 1
},
{
"date": "2025-01-13",
"count": 1
},
{
"date": "2025-01-21",
"count": 1
},
{
"date": "2025-02-06",
"count": 1
},
{
"date": "2025-03-04",
"count": 1
},
{
"date": "2025-03-13",
"count": 1
},
{
"date": "2025-07-06",
"count": 1
},
{
"date": "2025-07-11",
"count": 1
},
{
"date": "2025-08-12",
"count": 1
},
{
"date": "2025-09-22",
"count": 1
},
{
"date": "2025-10-17",
"count": 1
},
{
"date": "2025-10-28",
"count": 1
},
{
"date": "2026-05-16",
"count": 1
},
{
"date": "2026-05-19",
"count": 1
},
{
"date": "2026-05-30",
"count": 1
}
],
"complete": true,
"collected": 271,
"total_forks": 279
},
"star_history": null,
"open_issues_and_prs": 305
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples",
"notebooks",
"sample"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"docs-cfx/Makefile",
"docs-cfx/work/kubernetes/Makefile",
"docs/Makefile",
"justfile",
"test/Makefile",
"test/test_automated/Makefile",
"test/test_jupyter/Makefile",
"test/test_pevents/Makefile",
"test/test_xbr_marketmaker/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"mypy.ini",
"src/crossbar/py.typed"
],
"toolchain_manifests": [],
"largest_source_bytes": 982255,
"source_files_sampled": 395,
"oversized_source_files": 15,
"agent_instruction_files": [
".gemini/GEMINI.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 23
},
"dependencies": {
"manifests": [
"pyproject.toml",
"setup.py"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [
{
"name": "idna",
"direct": true,
"version": "2.5.0",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-65pc-fj4g-8rjx",
"GHSA-jjg7-2v4v-x38h",
"PYSEC-2024-60",
"PYSEC-2026-215"
],
"fixed_version": "3.15",
"advisory_count": 4,
"oldest_advisory_days": 837
},
{
"name": "urllib3",
"direct": true,
"version": "1.26.20",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.5,
"advisory_ids": [
"GHSA-2xpw-w6gg-jr37",
"GHSA-38jv-5279-wg99",
"GHSA-gm62-xv2j-4w53",
"GHSA-pq67-6m6q-mj2v",
"GHSA-qccp-gfcp-xxvc",
"PYSEC-2026-141",
"PYSEC-2026-1994",
"PYSEC-2026-1996",
"PYSEC-2026-1998",
"PYSEC-2026-1999"
],
"fixed_version": "2.7.0",
"advisory_count": 10,
"oldest_advisory_days": 404
},
{
"name": "ecdsa",
"direct": false,
"version": "0.19.2",
"severity": "high",
"ecosystem": "pypi",
"cvss_score": 7.4,
"advisory_ids": [
"GHSA-wj6h-64fc-37mp",
"PYSEC-2026-1325"
],
"fixed_version": null,
"advisory_count": 2,
"oldest_advisory_days": 917
},
{
"name": "h2",
"direct": true,
"version": "3.2.0",
"severity": "low",
"ecosystem": "pypi",
"cvss_score": 0,
"advisory_ids": [
"GHSA-847f-9342-265h",
"PYSEC-2026-1435"
],
"fixed_version": "4.3.0",
"advisory_count": 2,
"oldest_advisory_days": 336
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"low": 1,
"high": 3
},
"advisory_count": 18,
"affected_count": 4,
"assessed_count": 142,
"malicious_count": 0,
"assessed_package": "pypi:crossbar@26.7.1",
"unassessed_count": 0,
"direct_affected_count": 3
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "autobahn",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=26.7.1"
},
{
"name": "txaio",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=26.6.1"
},
{
"name": "zlmdb",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=26.7.1"
},
{
"name": "cfxdb",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=26.6.1"
},
{
"name": "xbr",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=26.6.1"
},
{
"name": "twisted",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.10.0"
},
{
"name": "twisted",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.10.0"
},
{
"name": "twisted",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.10.0"
},
{
"name": "treq",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.2.0"
},
{
"name": "txtorcon",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.0.0"
},
{
"name": "eth-abi",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.1.0,<5.2.0"
},
{
"name": "eth-account",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.13.0"
},
{
"name": "eth-typing",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.0.1"
},
{
"name": "py-eth-sig-utils",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.4.0"
},
{
"name": "hexbytes",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.3.0"
},
{
"name": "h2",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.2.0,<4.0.0"
},
{
"name": "hyperframe",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.2.0,<6.0.0"
},
{
"name": "priority",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.3.0,<2.0"
},
{
"name": "attrs",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.2.0"
},
{
"name": "base58",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.1.1"
},
{
"name": "bcrypt",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.0.1"
},
{
"name": "bitstring",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.0.1"
},
{
"name": "cbor2",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.4.6"
},
{
"name": "click",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=8.1.3"
},
{
"name": "colorama",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.4.6"
},
{
"name": "constantly",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=15.1.0"
},
{
"name": "cookiecutter",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.1.1"
},
{
"name": "cryptography",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=39.0.0"
},
{
"name": "docker",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=6.0.1"
},
{
"name": "flask",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.2.2"
},
{
"name": "humanize",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.4.0"
},
{
"name": "idna",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.5,<2.6"
},
{
"name": "importlib-resources",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.10.2"
},
{
"name": "incremental",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=22.10.0"
},
{
"name": "iso8601",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.1.0"
},
{
"name": "jinja2",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.1.2"
},
{
"name": "jinja2-highlight",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.6.1"
},
{
"name": "jsonschema",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=4.0.0"
},
{
"name": "MarkupSafe",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.1.2"
},
{
"name": "mistune",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.0.4"
},
{
"name": "morphys",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.0"
},
{
"name": "netaddr",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.8.0"
},
{
"name": "numpy",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.24.1"
},
{
"name": "parsimonious",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.9.0,<0.11.0"
},
{
"name": "passlib",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.7.4"
},
{
"name": "prompt-toolkit",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.0.36"
},
{
"name": "psutil",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.9.4"
},
{
"name": "py-ubjson",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.16.1"
},
{
"name": "pyasn1",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.4.8"
},
{
"name": "pyasn1-modules",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.2.8"
},
{
"name": "pycryptodome",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=3.16.0"
},
{
"name": "pygments",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.14.0"
},
{
"name": "pynacl",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.5.0"
},
{
"name": "pyopenssl",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=23.0.0"
},
{
"name": "pyqrcode",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.2.1"
},
{
"name": "pytrie",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.4.0"
},
{
"name": "pyyaml",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=6.0"
},
{
"name": "requests",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.28.2"
},
{
"name": "sdnotify",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.3.2"
},
{
"name": "service-identity",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=21.1.0"
},
{
"name": "setproctitle",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.3.2"
},
{
"name": "setuptools",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=67.2.0"
},
{
"name": "six",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.16.0"
},
{
"name": "sortedcontainers",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.4.0"
},
{
"name": "stringcase",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.2.0"
},
{
"name": "tabulate",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.9.0"
},
{
"name": "u-msgpack-python",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.7.2"
},
{
"name": "ujson",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.7.0"
},
{
"name": "urllib3",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.26.14,<1.27"
},
{
"name": "validate-email",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=1.3"
},
{
"name": "watchdog",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.2.1"
},
{
"name": "werkzeug",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=2.2.2"
},
{
"name": "wsaccel",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.6.4"
},
{
"name": "zope.interface",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=5.5.2"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "attrs",
"direct": true,
"version": "25.4.0",
"ecosystem": "pypi"
},
{
"name": "autobahn",
"direct": true,
"version": "26.7.1",
"ecosystem": "pypi"
},
{
"name": "base58",
"direct": true,
"version": "2.1.1",
"ecosystem": "pypi"
},
{
"name": "bcrypt",
"direct": true,
"version": "5.0.0",
"ecosystem": "pypi"
},
{
"name": "bitstring",
"direct": true,
"version": "4.3.1",
"ecosystem": "pypi"
},
{
"name": "cbor2",
"direct": true,
"version": "5.7.1",
"ecosystem": "pypi"
},
{
"name": "cfxdb",
"direct": true,
"version": "26.6.1",
"ecosystem": "pypi"
},
{
"name": "click",
"direct": true,
"version": "8.3.1",
"ecosystem": "pypi"
},
{
"name": "colorama",
"direct": true,
"version": "0.4.6",
"ecosystem": "pypi"
},
{
"name": "constantly",
"direct": true,
"version": "23.10.4",
"ecosystem": "pypi"
},
{
"name": "cookiecutter",
"direct": true,
"version": "2.6.0",
"ecosystem": "pypi"
},
{
"name": "cryptography",
"direct": true,
"version": "46.0.3",
"ecosystem": "pypi"
},
{
"name": "docker",
"direct": true,
"version": "7.1.0",
"ecosystem": "pypi"
},
{
"name": "eth-abi",
"direct": true,
"version": "5.1.0",
"ecosystem": "pypi"
},
{
"name": "eth-account",
"direct": true,
"version": "0.13.7",
"ecosystem": "pypi"
},
{
"name": "eth-typing",
"direct": true,
"version": "5.2.1",
"ecosystem": "pypi"
},
{
"name": "flask",
"direct": true,
"version": "3.1.2",
"ecosystem": "pypi"
},
{
"name": "h2",
"direct": true,
"version": "3.2.0",
"ecosystem": "pypi"
},
{
"name": "hexbytes",
"direct": true,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "humanize",
"direct": true,
"version": "4.14.0",
"ecosystem": "pypi"
},
{
"name": "hyperframe",
"direct": true,
"version": "5.2.0",
"ecosystem": "pypi"
},
{
"name": "idna",
"direct": true,
"version": "2.5",
"ecosystem": "pypi"
},
{
"name": "importlib-resources",
"direct": true,
"version": "6.5.2",
"ecosystem": "pypi"
},
{
"name": "incremental",
"direct": true,
"version": "24.11.0",
"ecosystem": "pypi"
},
{
"name": "iso8601",
"direct": true,
"version": "2.1.0",
"ecosystem": "pypi"
},
{
"name": "jinja2",
"direct": true,
"version": "3.1.6",
"ecosystem": "pypi"
},
{
"name": "jinja2-highlight",
"direct": true,
"version": "0.6.1",
"ecosystem": "pypi"
},
{
"name": "jsonschema",
"direct": true,
"version": "4.25.1",
"ecosystem": "pypi"
},
{
"name": "markupsafe",
"direct": true,
"version": "3.0.3",
"ecosystem": "pypi"
},
{
"name": "mistune",
"direct": true,
"version": "3.2.1",
"ecosystem": "pypi"
},
{
"name": "morphys",
"direct": true,
"version": "1.0",
"ecosystem": "pypi"
},
{
"name": "netaddr",
"direct": true,
"version": "1.3.0",
"ecosystem": "pypi"
},
{
"name": "numpy",
"direct": true,
"version": "2.3.5",
"ecosystem": "pypi"
},
{
"name": "parsimonious",
"direct": true,
"version": "0.10.0",
"ecosystem": "pypi"
},
{
"name": "passlib",
"direct": true,
"version": "1.7.4",
"ecosystem": "pypi"
},
{
"name": "priority",
"direct": true,
"version": "1.3.0",
"ecosystem": "pypi"
},
{
"name": "prompt-toolkit",
"direct": true,
"version": "3.0.52",
"ecosystem": "pypi"
},
{
"name": "psutil",
"direct": true,
"version": "7.1.3",
"ecosystem": "pypi"
},
{
"name": "py-eth-sig-utils",
"direct": true,
"version": "0.4.0",
"ecosystem": "pypi"
},
{
"name": "py-ubjson",
"direct": true,
"version": "0.16.1",
"ecosystem": "pypi"
},
{
"name": "pyasn1",
"direct": true,
"version": "0.6.1",
"ecosystem": "pypi"
},
{
"name": "pyasn1-modules",
"direct": true,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "pycryptodome",
"direct": true,
"version": "3.23.0",
"ecosystem": "pypi"
},
{
"name": "pygments",
"direct": true,
"version": "2.19.2",
"ecosystem": "pypi"
},
{
"name": "pynacl",
"direct": true,
"version": "1.6.1",
"ecosystem": "pypi"
},
{
"name": "pyopenssl",
"direct": true,
"version": "25.3.0",
"ecosystem": "pypi"
},
{
"name": "pyqrcode",
"direct": true,
"version": "1.2.1",
"ecosystem": "pypi"
},
{
"name": "pytrie",
"direct": true,
"version": "0.4.0",
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": true,
"version": "6.0.3",
"ecosystem": "pypi"
},
{
"name": "requests",
"direct": true,
"version": "2.32.5",
"ecosystem": "pypi"
},
{
"name": "sdnotify",
"direct": true,
"version": "0.3.2",
"ecosystem": "pypi"
},
{
"name": "service-identity",
"direct": true,
"version": "24.2.0",
"ecosystem": "pypi"
},
{
"name": "setproctitle",
"direct": true,
"version": "1.3.7",
"ecosystem": "pypi"
},
{
"name": "setuptools",
"direct": true,
"version": "80.9.0",
"ecosystem": "pypi"
},
{
"name": "six",
"direct": true,
"version": "1.17.0",
"ecosystem": "pypi"
},
{
"name": "sortedcontainers",
"direct": true,
"version": "2.4.0",
"ecosystem": "pypi"
},
{
"name": "stringcase",
"direct": true,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "tabulate",
"direct": true,
"version": "0.9.0",
"ecosystem": "pypi"
},
{
"name": "treq",
"direct": true,
"version": "25.5.0",
"ecosystem": "pypi"
},
{
"name": "twisted",
"direct": true,
"version": "25.5.0",
"ecosystem": "pypi"
},
{
"name": "txaio",
"direct": true,
"version": "26.6.1",
"ecosystem": "pypi"
},
{
"name": "txtorcon",
"direct": true,
"version": "24.8.0",
"ecosystem": "pypi"
},
{
"name": "u-msgpack-python",
"direct": true,
"version": "2.8.0",
"ecosystem": "pypi"
},
{
"name": "ujson",
"direct": true,
"version": "5.11.0",
"ecosystem": "pypi"
},
{
"name": "urllib3",
"direct": true,
"version": "1.26.20",
"ecosystem": "pypi"
},
{
"name": "validate-email",
"direct": true,
"version": "1.3",
"ecosystem": "pypi"
},
{
"name": "watchdog",
"direct": true,
"version": "6.0.0",
"ecosystem": "pypi"
},
{
"name": "werkzeug",
"direct": true,
"version": "3.1.4",
"ecosystem": "pypi"
},
{
"name": "wsaccel",
"direct": true,
"version": "0.6.7",
"ecosystem": "pypi"
},
{
"name": "xbr",
"direct": true,
"version": "26.6.1",
"ecosystem": "pypi"
},
{
"name": "zlmdb",
"direct": true,
"version": "26.7.1",
"ecosystem": "pypi"
},
{
"name": "zope-interface",
"direct": true,
"version": "8.1.1",
"ecosystem": "pypi"
},
{
"name": "accessible-pygments",
"direct": false,
"version": "0.0.5",
"ecosystem": "pypi"
},
{
"name": "aiohappyeyeballs",
"direct": false,
"version": "2.6.1",
"ecosystem": "pypi"
},
{
"name": "aiohttp",
"direct": false,
"version": "3.13.2",
"ecosystem": "pypi"
},
{
"name": "aiosignal",
"direct": false,
"version": "1.4.0",
"ecosystem": "pypi"
},
{
"name": "alabaster",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "altgraph",
"direct": false,
"version": "0.17.5",
"ecosystem": "pypi"
},
{
"name": "annotated-types",
"direct": false,
"version": "0.7.0",
"ecosystem": "pypi"
},
{
"name": "anyio",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "appdirs",
"direct": false,
"version": "1.4.4",
"ecosystem": "pypi"
},
{
"name": "argon2-cffi",
"direct": false,
"version": "25.1.0",
"ecosystem": "pypi"
},
{
"name": "argon2-cffi-bindings",
"direct": false,
"version": "25.1.0",
"ecosystem": "pypi"
},
{
"name": "arrow",
"direct": false,
"version": "1.4.0",
"ecosystem": "pypi"
},
{
"name": "astroid",
"direct": false,
"version": "3.3.11",
"ecosystem": "pypi"
},
{
"name": "astroid",
"direct": false,
"version": "4.0.2",
"ecosystem": "pypi"
},
{
"name": "async-generator",
"direct": false,
"version": "1.10",
"ecosystem": "pypi"
},
{
"name": "automat",
"direct": false,
"version": "25.4.16",
"ecosystem": "pypi"
},
{
"name": "babel",
"direct": false,
"version": "2.17.0",
"ecosystem": "pypi"
},
{
"name": "backports-tarfile",
"direct": false,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "bandit",
"direct": false,
"version": "1.9.2",
"ecosystem": "pypi"
},
{
"name": "beautifulsoup4",
"direct": false,
"version": "4.14.3",
"ecosystem": "pypi"
},
{
"name": "binaryornot",
"direct": false,
"version": "0.4.4",
"ecosystem": "pypi"
},
{
"name": "bitarray",
"direct": false,
"version": "3.8.0",
"ecosystem": "pypi"
},
{
"name": "bjdata",
"direct": false,
"version": "0.6.6",
"ecosystem": "pypi"
},
{
"name": "blake3",
"direct": false,
"version": "1.0.8",
"ecosystem": "pypi"
},
{
"name": "bleach",
"direct": false,
"version": "6.3.0",
"ecosystem": "pypi"
},
{
"name": "blinker",
"direct": false,
"version": "1.9.0",
"ecosystem": "pypi"
},
{
"name": "brotli",
"direct": false,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "brotlicffi",
"direct": false,
"version": "1.2.0.0",
"ecosystem": "pypi"
},
{
"name": "build",
"direct": false,
"version": "1.3.0",
"ecosystem": "pypi"
},
{
"name": "cachetools",
"direct": false,
"version": "6.2.4",
"ecosystem": "pypi"
},
{
"name": "certifi",
"direct": false,
"version": "2025.11.12",
"ecosystem": "pypi"
},
{
"name": "cffi",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "chardet",
"direct": false,
"version": "5.2.0",
"ecosystem": "pypi"
},
{
"name": "charset-normalizer",
"direct": false,
"version": "3.4.4",
"ecosystem": "pypi"
},
{
"name": "ckzg",
"direct": false,
"version": "2.1.5",
"ecosystem": "pypi"
},
{
"name": "coverage",
"direct": false,
"version": "7.13.0",
"ecosystem": "pypi"
},
{
"name": "crossbar",
"direct": false,
"version": "26.7.1",
"ecosystem": "pypi"
},
{
"name": "cython-test-exception-raiser",
"direct": false,
"version": "1.0.2",
"ecosystem": "pypi"
},
{
"name": "cytoolz",
"direct": false,
"version": "1.1.0",
"ecosystem": "pypi"
},
{
"name": "decorator",
"direct": false,
"version": "5.2.1",
"ecosystem": "pypi"
},
{
"name": "defusedxml",
"direct": false,
"version": "0.7.1",
"ecosystem": "pypi"
},
{
"name": "distlib",
"direct": false,
"version": "0.4.0",
"ecosystem": "pypi"
},
{
"name": "docutils",
"direct": false,
"version": "0.21.2",
"ecosystem": "pypi"
},
{
"name": "ecdsa",
"direct": false,
"version": "0.19.1",
"ecosystem": "pypi"
},
{
"name": "eth-hash",
"direct": false,
"version": "0.7.1",
"ecosystem": "pypi"
},
{
"name": "eth-keyfile",
"direct": false,
"version": "0.8.1",
"ecosystem": "pypi"
},
{
"name": "eth-keys",
"direct": false,
"version": "0.7.0",
"ecosystem": "pypi"
},
{
"name": "eth-rlp",
"direct": false,
"version": "2.2.0",
"ecosystem": "pypi"
},
{
"name": "eth-utils",
"direct": false,
"version": "5.3.1",
"ecosystem": "pypi"
},
{
"name": "fastjsonschema",
"direct": false,
"version": "2.21.2",
"ecosystem": "pypi"
},
{
"name": "filelock",
"direct": false,
"version": "3.20.1",
"ecosystem": "pypi"
},
{
"name": "frozenlist",
"direct": false,
"version": "1.8.0",
"ecosystem": "pypi"
},
{
"name": "furo",
"direct": false,
"version": "2025.9.25",
"ecosystem": "pypi"
},
{
"name": "greenlet",
"direct": false,
"version": "3.3.0",
"ecosystem": "pypi"
},
{
"name": "h11",
"direct": false,
"version": "0.16.0",
"ecosystem": "pypi"
},
{
"name": "hashin",
"direct": false,
"version": "1.0.5",
"ecosystem": "pypi"
},
{
"name": "hkdf",
"direct": false,
"version": "0.0.3",
"ecosystem": "pypi"
},
{
"name": "hpack",
"direct": false,
"version": "3.0.0",
"ecosystem": "pypi"
},
{
"name": "httpcore",
"direct": false,
"version": "1.0.9",
"ecosystem": "pypi"
},
{
"name": "httpx",
"direct": false,
"version": "0.28.1",
"ecosystem": "pypi"
},
{
"name": "hyperlink",
"direct": false,
"version": "21.0.0",
"ecosystem": "pypi"
},
{
"name": "hypothesis",
"direct": false,
"version": "6.148.7",
"ecosystem": "pypi"
},
{
"name": "id",
"direct": false,
"version": "1.5.0",
"ecosystem": "pypi"
},
{
"name": "imagesize",
"direct": false,
"version": "1.4.1",
"ecosystem": "pypi"
},
{
"name": "importlib-metadata",
"direct": false,
"version": "8.7.0",
"ecosystem": "pypi"
},
{
"name": "iniconfig",
"direct": false,
"version": "2.3.0",
"ecosystem": "pypi"
},
{
"name": "itsdangerous",
"direct": false,
"version": "2.2.0",
"ecosystem": "pypi"
},
{
"name": "jaraco-classes",
"direct": false,
"version": "3.4.0",
"ecosystem": "pypi"
},
{
"name": "jaraco-context",
"direct": false,
"version": "6.0.1",
"ecosystem": "pypi"
},
{
"name": "jaraco-functools",
"direct": false,
"version": "4.3.0",
"ecosystem": "pypi"
},
{
"name": "jeepney",
"direct": false,
"version": "0.9.0",
"ecosystem": "pypi"
},
{
"name": "jsonschema-specifications",
"direct": false,
"version": "2025.9.1",
"ecosystem": "pypi"
},
{
"name": "jupyter-client",
"direct": false,
"version": "8.7.0",
"ecosystem": "pypi"
},
{
"name": "jupyter-core",
"direct": false,
"version": "5.9.1",
"ecosystem": "pypi"
},
{
"name": "jupyterlab-pygments",
"direct": false,
"version": "0.3.0",
"ecosystem": "pypi"
},
{
"name": "keyring",
"direct": false,
"version": "25.7.0",
"ecosystem": "pypi"
},
{
"name": "linkify-it-py",
"direct": false,
"version": "2.0.3",
"ecosystem": "pypi"
},
{
"name": "macholib",
"direct": false,
"version": "1.16.4",
"ecosystem": "pypi"
},
{
"name": "markdown-it-py",
"direct": false,
"version": "3.0.0",
"ecosystem": "pypi"
},
{
"name": "mdit-py-plugins",
"direct": false,
"version": "0.5.0",
"ecosystem": "pypi"
},
{
"name": "mdurl",
"direct": false,
"version": "0.1.2",
"ecosystem": "pypi"
},
{
"name": "mmh3",
"direct": false,
"version": "5.2.0",
"ecosystem": "pypi"
},
{
"name": "mnemonic",
"direct": false,
"version": "0.21",
"ecosystem": "pypi"
},
{
"name": "mock",
"direct": false,
"version": "5.2.0",
"ecosystem": "pypi"
},
{
"name": "more-itertools",
"direct": false,
"version": "10.8.0",
"ecosystem": "pypi"
},
{
"name": "msgpack",
"direct": false,
"version": "1.1.2",
"ecosystem": "pypi"
},
{
"name": "multidict",
"direct": false,
"version": "6.7.0",
"ecosystem": "pypi"
},
{
"name": "multipart",
"direct": false,
"version": "1.3.0",
"ecosystem": "pypi"
},
{
"name": "myst-parser",
"direct": false,
"version": "4.0.1",
"ecosystem": "pypi"
},
{
"name": "nbclient",
"direct": false,
"version": "0.10.2",
"ecosystem": "pypi"
},
{
"name": "nbconvert",
"direct": false,
"version": "7.16.6",
"ecosystem": "pypi"
},
{
"name": "nbformat",
"direct": false,
"version": "5.10.4",
"ecosystem": "pypi"
},
{
"name": "nbsphinx",
"direct": false,
"version": "0.9.8",
"ecosystem": "pypi"
},
{
"name": "nh3",
"direct": false,
"version": "0.3.2",
"ecosystem": "pypi"
},
{
"name": "packaging",
"direct": false,
"version": "25.0",
"ecosystem": "pypi"
},
{
"name": "pandoc",
"direct": false,
"version": "2.4",
"ecosystem": "pypi"
},
{
"name": "pandocfilters",
"direct": false,
"version": "1.5.1",
"ecosystem": "pypi"
},
{
"name": "pefile",
"direct": false,
"version": "2024.8.26",
"ecosystem": "pypi"
},
{
"name": "pip",
"direct": false,
"version": "25.3",
"ecosystem": "pypi"
},
{
"name": "pip-licenses",
"direct": false,
"version": "5.5.0",
"ecosystem": "pypi"
},
{
"name": "platformdirs",
"direct": false,
"version": "4.5.1",
"ecosystem": "pypi"
},
{
"name": "pluggy",
"direct": false,
"version": "1.6.0",
"ecosystem": "pypi"
},
{
"name": "plumbum",
"direct": false,
"version": "1.10.0",
"ecosystem": "pypi"
},
{
"name": "ply",
"direct": false,
"version": "3.11",
"ecosystem": "pypi"
},
{
"name": "prettytable",
"direct": false,
"version": "3.17.0",
"ecosystem": "pypi"
},
{
"name": "propcache",
"direct": false,
"version": "0.4.1",
"ecosystem": "pypi"
},
{
"name": "py-ecc",
"direct": false,
"version": "8.0.0",
"ecosystem": "pypi"
},
{
"name": "py-multihash",
"direct": false,
"version": "3.0.0",
"ecosystem": "pypi"
},
{
"name": "pycparser",
"direct": false,
"version": "2.23",
"ecosystem": "pypi"
},
{
"name": "pydantic",
"direct": false,
"version": "2.12.5",
"ecosystem": "pypi"
},
{
"name": "pydantic-core",
"direct": false,
"version": "2.41.5",
"ecosystem": "pypi"
},
{
"name": "pyenchant",
"direct": false,
"version": "3.3.0",
"ecosystem": "pypi"
},
{
"name": "pyhamcrest",
"direct": false,
"version": "2.1.0",
"ecosystem": "pypi"
},
{
"name": "pyinstaller",
"direct": false,
"version": "6.17.0",
"ecosystem": "pypi"
},
{
"name": "pyinstaller-hooks-contrib",
"direct": false,
"version": "2025.10",
"ecosystem": "pypi"
},
{
"name": "pyobjc-core",
"direct": false,
"version": "12.1",
"ecosystem": "pypi"
},
{
"name": "pyobjc-framework-cfnetwork",
"direct": false,
"version": "12.1",
"ecosystem": "pypi"
},
{
"name": "pyobjc-framework-cocoa",
"direct": false,
"version": "12.1",
"ecosystem": "pypi"
},
{
"name": "pyproject-api",
"direct": false,
"version": "1.10.0",
"ecosystem": "pypi"
},
{
"name": "pyproject-hooks",
"direct": false,
"version": "1.2.0",
"ecosystem": "pypi"
},
{
"name": "pyserial",
"direct": false,
"version": "3.5",
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": "9.0.2",
"ecosystem": "pypi"
},
{
"name": "pytest-cov",
"direct": false,
"version": "7.0.0",
"ecosystem": "pypi"
},
{
"name": "pytest-tap",
"direct": false,
"version": "3.5",
"ecosystem": "pypi"
},
{
"name": "pytest-twisted",
"direct": false,
"version": "1.14.3",
"ecosystem": "pypi"
},
{
"name": "python-dateutil",
"direct": false,
"version": "2.9.0.post0",
"ecosystem": "pypi"
},
{
"name": "python-slugify",
"direct": false,
"version": "8.0.4",
"ecosystem": "pypi"
},
{
"name": "pyunormalize",
"direct": false,
"version": "17.0.0",
"ecosystem": "pypi"
},
{
"name": "pywin32",
"direct": false,
"version": "311",
"ecosystem": "pypi"
},
{
"name": "pywin32-ctypes",
"direct": false,
"version": "0.2.3",
"ecosystem": "pypi"
},
{
"name": "pyzmq",
"direct": false,
"version": "27.1.0",
"ecosystem": "pypi"
},
{
"name": "qrcode",
"direct": false,
"version": "8.2",
"ecosystem": "pypi"
},
{
"name": "readme-renderer",
"direct": false,
"version": "44.0",
"ecosystem": "pypi"
},
{
"name": "referencing",
"direct": false,
"version": "0.37.0",
"ecosystem": "pypi"
},
{
"name": "regex",
"direct": false,
"version": "2025.11.3",
"ecosystem": "pypi"
},
{
"name": "requests-toolbelt",
"direct": false,
"version": "1.0.0",
"ecosystem": "pypi"
},
{
"name": "rfc3986",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "rich",
"direct": false,
"version": "14.2.0",
"ecosystem": "pypi"
},
{
"name": "rlp",
"direct": false,
"version": "4.1.0",
"ecosystem": "pypi"
},
{
"name": "roman-numerals",
"direct": false,
"version": "4.1.0",
"ecosystem": "pypi"
},
{
"name": "roman-numerals-py",
"direct": false,
"version": "4.1.0",
"ecosystem": "pypi"
},
{
"name": "rpds-py",
"direct": false,
"version": "0.30.0",
"ecosystem": "pypi"
},
{
"name": "ruff",
"direct": false,
"version": "0.14.9",
"ecosystem": "pypi"
},
{
"name": "scour",
"direct": false,
"version": "0.38.2",
"ecosystem": "pypi"
},
{
"name": "secretstorage",
"direct": false,
"version": "3.5.0",
"ecosystem": "pypi"
},
{
"name": "sniffio",
"direct": false,
"version": "1.3.1",
"ecosystem": "pypi"
},
{
"name": "snowballstemmer",
"direct": false,
"version": "3.0.1",
"ecosystem": "pypi"
},
{
"name": "soupsieve",
"direct": false,
"version": "2.8",
"ecosystem": "pypi"
},
{
"name": "spake2",
"direct": false,
"version": "0.9",
"ecosystem": "pypi"
},
{
"name": "sphinx",
"direct": false,
"version": "8.2.3",
"ecosystem": "pypi"
},
{
"name": "sphinx-autoapi",
"direct": false,
"version": "3.6.1",
"ecosystem": "pypi"
},
{
"name": "sphinx-autodoc-typehints",
"direct": false,
"version": "3.5.2",
"ecosystem": "pypi"
},
{
"name": "sphinx-basic-ng",
"direct": false,
"version": "1.0.0b2",
"ecosystem": "pypi"
},
{
"name": "sphinx-copybutton",
"direct": false,
"version": "0.5.2",
"ecosystem": "pypi"
},
{
"name": "sphinx-design",
"direct": false,
"version": "0.6.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-applehelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-devhelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-htmlhelp",
"direct": false,
"version": "2.1.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-images",
"direct": false,
"version": "1.0.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-jsmath",
"direct": false,
"version": "1.0.1",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-qthelp",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-serializinghtml",
"direct": false,
"version": "2.0.0",
"ecosystem": "pypi"
},
{
"name": "sphinxcontrib-spelling",
"direct": false,
"version": "8.0.2",
"ecosystem": "pypi"
},
{
"name": "sphinxext-opengraph",
"direct": false,
"version": "0.13.0",
"ecosystem": "pypi"
},
{
"name": "stevedore",
"direct": false,
"version": "5.6.0",
"ecosystem": "pypi"
},
{
"name": "tap-py",
"direct": false,
"version": "3.2.1",
"ecosystem": "pypi"
},
{
"name": "text-unidecode",
"direct": false,
"version": "1.3",
"ecosystem": "pypi"
},
{
"name": "tinycss2",
"direct": false,
"version": "1.4.0",
"ecosystem": "pypi"
},
{
"name": "tomli",
"direct": false,
"version": "2.3.0",
"ecosystem": "pypi"
},
{
"name": "toolz",
"direct": false,
"version": "1.1.0",
"ecosystem": "pypi"
},
{
"name": "tornado",
"direct": false,
"version": "6.5.4",
"ecosystem": "pypi"
},
{
"name": "tox",
"direct": false,
"version": "4.32.0",
"ecosystem": "pypi"
},
{
"name": "traitlets",
"direct": false,
"version": "5.14.3",
"ecosystem": "pypi"
},
{
"name": "twine",
"direct": false,
"version": "6.2.0",
"ecosystem": "pypi"
},
{
"name": "twisted-iocpsupport",
"direct": false,
"version": "25.10.1",
"ecosystem": "pypi"
},
{
"name": "types-requests",
"direct": false,
"version": "2.31.0.6",
"ecosystem": "pypi"
},
{
"name": "types-urllib3",
"direct": false,
"version": "1.26.25.14",
"ecosystem": "pypi"
},
{
"name": "typing-extensions",
"direct": false,
"version": "4.15.0",
"ecosystem": "pypi"
},
{
"name": "typing-inspection",
"direct": false,
"version": "0.4.2",
"ecosystem": "pypi"
},
{
"name": "tzdata",
"direct": false,
"version": "2025.3",
"ecosystem": "pypi"
},
{
"name": "uc-micro-py",
"direct": false,
"version": "1.0.3",
"ecosystem": "pypi"
},
{
"name": "varint",
"direct": false,
"version": "1.0.2",
"ecosystem": "pypi"
},
{
"name": "virtualenv",
"direct": false,
"version": "20.35.4",
"ecosystem": "pypi"
},
{
"name": "wcwidth",
"direct": false,
"version": "0.2.14",
"ecosystem": "pypi"
},
{
"name": "web3",
"direct": false,
"version": "7.14.0",
"ecosystem": "pypi"
},
{
"name": "webencodings",
"direct": false,
"version": "0.5.1",
"ecosystem": "pypi"
},
{
"name": "websockets",
"direct": false,
"version": "15.0.1",
"ecosystem": "pypi"
},
{
"name": "wheel",
"direct": false,
"version": "0.45.1",
"ecosystem": "pypi"
},
{
"name": "wsproto",
"direct": false,
"version": "1.3.2",
"ecosystem": "pypi"
},
{
"name": "yapf",
"direct": false,
"version": "0.29.0",
"ecosystem": "pypi"
},
{
"name": "yarl",
"direct": false,
"version": "1.22.0",
"ecosystem": "pypi"
},
{
"name": "zipp",
"direct": false,
"version": "3.23.0",
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 264,
"direct_count": 72,
"indirect_count": 192
}
},
"maintainership": {
"issues": {
"open_prs": 2,
"merged_prs": 768,
"open_issues": 303,
"closed_ratio": 0.764,
"closed_issues": 980,
"closed_unmerged_prs": 166
},
"bus_factor": 2,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "oberstet",
"commits": 644,
"avatar_url": "https://avatars.githubusercontent.com/u/233340?v=4"
},
{
"type": "User",
"login": "hawkowl",
"commits": 602,
"avatar_url": "https://avatars.githubusercontent.com/u/3307100?v=4"
},
{
"type": "User",
"login": "meejah",
"commits": 310,
"avatar_url": "https://avatars.githubusercontent.com/u/145599?v=4"
},
{
"type": "User",
"login": "om26er",
"commits": 60,
"avatar_url": "https://avatars.githubusercontent.com/u/6350837?v=4"
},
{
"type": "User",
"login": "fijal",
"commits": 47,
"avatar_url": "https://avatars.githubusercontent.com/u/85944?v=4"
},
{
"type": "User",
"login": "goeddea",
"commits": 37,
"avatar_url": "https://avatars.githubusercontent.com/u/1032507?v=4"
},
{
"type": "User",
"login": "codelectron",
"commits": 26,
"avatar_url": "https://avatars.githubusercontent.com/u/1419732?v=4"
},
{
"type": "User",
"login": "markope",
"commits": 24,
"avatar_url": "https://avatars.githubusercontent.com/u/1944925?v=4"
},
{
"type": "User",
"login": "yoch",
"commits": 11,
"avatar_url": "https://avatars.githubusercontent.com/u/795960?v=4"
},
{
"type": "User",
"login": "wilbertom",
"commits": 10,
"avatar_url": "https://avatars.githubusercontent.com/u/2273055?v=4"
}
],
"contributors_sampled": 58,
"top_contributor_share": 0.341
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"main.yml",
"release-post-comment.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".pylintrc"
],
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"uv.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 7,
"reason": "15 out of 20 merged PRs checked by a CI test -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 1/29 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 36 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "14 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 1,
"reason": "dependency not pinned by hash detected -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "101 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "29b797cf4da46b77a971cd7f7f0846995f547d6c",
"ran_at": "2026-07-28T01:03:26Z",
"aggregate_score": 5.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-27T05:17:33Z",
"oldest_open_prs": [
{
"number": 2281,
"created_at": "2026-07-27T04:21:52Z",
"last_comment_at": "2026-07-27T04:21:53Z",
"last_comment_author": "dependabot"
},
{
"number": 2282,
"created_at": "2026-07-27T05:05:20Z",
"last_comment_at": "2026-07-27T05:05:21Z",
"last_comment_author": "dependabot"
}
],
"last_merged_pr_at": "2026-07-17T12:18:33Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 33,
"created_at": "2014-03-13T18:02:56Z",
"last_comment_at": "2018-10-28T10:16:23Z",
"last_comment_author": "markope"
},
{
"number": 55,
"created_at": "2014-05-24T17:04:35Z",
"last_comment_at": "2022-03-31T05:04:47Z",
"last_comment_author": "oberstet"
},
{
"number": 60,
"created_at": "2014-05-31T15:42:03Z",
"last_comment_at": "2016-05-01T16:07:49Z",
"last_comment_author": "goeddea"
},
{
"number": 85,
"created_at": "2014-06-26T10:45:21Z",
"last_comment_at": "2015-08-06T15:14:57Z",
"last_comment_author": "meejah"
},
{
"number": 91,
"created_at": "2014-07-11T14:31:34Z",
"last_comment_at": "2016-05-01T16:06:06Z",
"last_comment_author": "goeddea"
},
{
"number": 106,
"created_at": "2014-08-15T15:22:14Z",
"last_comment_at": "2016-05-01T16:07:13Z",
"last_comment_author": "goeddea"
},
{
"number": 120,
"created_at": "2014-09-06T15:09:41Z",
"last_comment_at": "2016-05-01T15:57:08Z",
"last_comment_author": "goeddea"
},
{
"number": 194,
"created_at": "2015-01-03T21:24:55Z",
"last_comment_at": "2016-05-01T16:01:34Z",
"last_comment_author": "goeddea"
},
{
"number": 203,
"created_at": "2015-01-11T09:22:04Z",
"last_comment_at": "2016-05-01T16:00:24Z",
"last_comment_author": "goeddea"
},
{
"number": 212,
"created_at": "2015-01-19T22:21:31Z",
"last_comment_at": "2018-10-10T11:42:30Z",
"last_comment_author": "haizaar"
},
{
"number": 216,
"created_at": "2015-01-23T15:52:45Z",
"last_comment_at": "2016-05-01T16:02:42Z",
"last_comment_author": "goeddea"
},
{
"number": 226,
"created_at": "2015-01-29T22:36:44Z",
"last_comment_at": "2023-11-16T17:15:06Z",
"last_comment_author": "pratman"
},
{
"number": 240,
"created_at": "2015-02-10T12:38:14Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 241,
"created_at": "2015-02-10T16:23:46Z",
"last_comment_at": "2015-10-01T15:34:50Z",
"last_comment_author": "Arttii"
},
{
"number": 261,
"created_at": "2015-03-01T22:13:47Z",
"last_comment_at": "2016-08-31T17:18:33Z",
"last_comment_author": "jegger"
},
{
"number": 297,
"created_at": "2015-04-10T16:36:06Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 301,
"created_at": "2015-04-12T19:10:10Z",
"last_comment_at": "2019-04-22T05:43:00Z",
"last_comment_author": "oberstet"
},
{
"number": 369,
"created_at": "2015-06-23T11:16:27Z",
"last_comment_at": "2015-08-23T13:56:49Z",
"last_comment_author": "oberstet"
},
{
"number": 410,
"created_at": "2015-08-26T22:23:49Z",
"last_comment_at": "2016-04-08T13:18:26Z",
"last_comment_author": "oberstet"
},
{
"number": 413,
"created_at": "2015-08-27T17:44:53Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/crossbario/crossbar",
"host": "github.com",
"name": "crossbar",
"owner": "crossbario"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"security": 54,
"vitality": 77,
"community": 78,
"governance": 72,
"engineering": 90
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 77,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"commits_last_year": 58,
"human_commit_share": 0.99,
"days_since_last_push": 0,
"active_weeks_last_year": 9
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "9/52 weeks with commits",
"points": 6.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 9
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "58 commits in the last year",
"points": 15.9,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 58
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "14 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 70,
"latest_release_tag": "pr2282-null-dependabot_uv_python_minor_patch_fb33d8da79-202607270516",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 1.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "70 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 70
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~1.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 1.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 10,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 10 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 10
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 78,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "good",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"forks": 279,
"stars": 2065,
"watchers": 72,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "2,065 stars",
"points": 53.8,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 2065
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "279 forks",
"points": 20.4,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 279
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "72 watchers",
"points": 10.3,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 72
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 71,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 72,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "moderate",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 58,
"top_contributor_share": 0.341
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 34% of commits",
"points": 14.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 34
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "58 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 58
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 36 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"merged_prs": 768,
"open_issues": 303,
"closed_issues": 980,
"issue_closed_ratio": 0.764,
"closed_unmerged_prs": 166
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "76% of issues closed",
"points": 35.7,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 76
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "768/934 decided PRs merged",
"points": 31.5,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 768,
"decided": 934
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 1/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"followers": 56,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "crossbario",
"public_repos": 38,
"account_age_days": 4673
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "56 followers of crossbario",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 56,
"login": "crossbario"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "38 public repos, account ~12 yr old",
"points": 23.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 38
}
},
{
"code": "account_age_years",
"params": {
"years": 12
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"crossbar"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 10
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 10 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 10
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "110 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 110
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 90,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "3 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 3
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".pylintrc",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".pylintrc"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "15 out of 20 merged PRs checked by a CI test -- score normalized to 7",
"points": 14,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"websocket",
"wamp",
"messaging",
"mqtt",
"rest",
"server",
"broker",
"networking-stack",
"networking"
],
"has_wiki": true,
"homepage": "https://crossbario.readthedocs.io/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://crossbario.readthedocs.io/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "9 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 9
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 54,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 5.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "15 out of 20 merged PRs checked by a CI test -- score normalized to 7",
"points": 1.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 1/29 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 36 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "14 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 0.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "101 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "at_risk",
"name": "Dependency advisories",
"note": "Matched the pypi:crossbar@26.7.1 runtime dependency closure — what installing the published package pulls in — 142 packages. Reachability is not analyzed.",
"notes": [
{
"code": "advisories_scope_published",
"params": {
"package": "pypi:crossbar@26.7.1",
"assessed": 142
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 48,
"inputs": {
"source": "osv",
"advisories": 18,
"affected_packages": 4,
"assessed_packages": 142,
"unassessed_packages": 0,
"affected_by_severity": "high 3, low 1",
"direct_affected_packages": 3
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "3 affected: idna 2.5.0 (high 7.5), urllib3 1.26.20 (high 7.5), h2 3.2.0 (low)",
"points": 11.8,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 3,
"packages": "idna 2.5.0 (high 7.5), urllib3 1.26.20 (high 7.5), h2 3.2.0 (low)"
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "1 affected: ecdsa 0.19.2 (high 7.4)",
"points": 10.2,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 1,
"packages": "ecdsa 0.19.2 (high 7.4)"
}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "4 advisory-carrying package(s) unaddressed past 90 days; oldest published 917 days ago",
"points": 25.6,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 4,
"oldest": 917
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 142,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 10
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 69,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "moderate",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 58,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.939,
"agent_instruction_files": [
".gemini/GEMINI.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 23
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": ".gemini/GEMINI.md, CLAUDE.md (stub)",
"points": 18,
"status": "partial",
"details": [
{
"code": "file_list",
"params": {
"files": ".gemini/GEMINI.md, CLAUDE.md"
}
},
{
"code": "agent_instructions_stub",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "93 of 99 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 93,
"sampled": 99
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"uv.lock"
],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [
"Makefile",
"docs-cfx/Makefile",
"docs-cfx/work/kubernetes/Makefile",
"docs/Makefile",
"justfile",
"test/Makefile",
"test/test_automated/Makefile",
"test/test_jupyter/Makefile",
"test/test_pevents/Makefile",
"test/test_xbr_marketmaker/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"mypy.ini",
"src/crossbar/py.typed"
],
"agent_commit_share": 0.01,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.01
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, docs-cfx/Makefile, docs-cfx/work/kubernetes/Makefile, docs/Makefile, justfile, test/Makefile, test/test_automated/Makefile, test/test_jupyter/Makefile, test/test_pevents/Makefile, test/test_xbr_marketmaker/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, docs-cfx/Makefile, docs-cfx/work/kubernetes/Makefile, docs/Makefile, justfile, test/Makefile, test/test_automated/Makefile, test/test_jupyter/Makefile, test/test_pevents/Makefile, test/test_xbr_marketmaker/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".pylintrc",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".pylintrc"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "mypy.ini, src/crossbar/py.typed",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "mypy.ini, src/crossbar/py.typed"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "1 of the last 100 commits agent-authored or agent-credited",
"points": 2,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "1 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 1,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "good",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 982255,
"source_files_sampled": 395,
"oversized_source_files": 15
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python with type-check config (mypy.ini, src/crossbar/py.typed)",
"points": 27,
"status": "partial",
"details": [
{
"code": "typecheck_config_language",
"params": {
"files": "mypy.ini, src/crossbar/py.typed",
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "15/395 source files over 60KB",
"points": 52.9,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 395,
"oversized": 15
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples",
"notebooks",
"sample"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples, notebooks, sample",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples, notebooks, sample"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-28T01:03:52.906582Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/crossbario/crossbar.svg",
"full_name": "crossbario/crossbar",
"license_state": "custom",
"license_spdx": null
}