Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-24 11:45 UTC

dapr / java-sdk

Dapr SDK for Java

JavaApache-2.0★ 299 stars⑂ 229 forkssince Oct 2019View on GitHub ↗

dapr/java-sdk holds a health index of 78 out of 100, placing it in the Good band. It scores highest on Vitality (96/100) and lowest on Security (65/100). It was last updated 2 days ago. 3 contributors account for most of its recent work.

78
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

78
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

DaprOrganization
1,947 followers45 public repossince Jun 2019

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Mavenio.dapr:dapr-sdk1.18.1-1194 days ago
Mavenio.dapr:dapr-sdk-actors1.18.1-1194 days ago
Mavenio.dapr:dapr-sdk-autogen1.18.1-1194 days ago
Mavenio.dapr:dapr-sdk-workflows1.18.1-654 days ago
Mavenio.dapr:dapr-sdk-springboot1.18.1-1124 days ago
Mavenio.dapr:durabletask-client1.18.1-294 days ago
Mavenio.dapr:testcontainers-dapr1.18.1-534 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

96Excellent · 22% of overall
How it's scored
36/36Push recency — last push 2 days ago
29.1/36Commit cadence — 42/52 weeks with commits
18/18Commit volume — 155 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year155
human_commit_share0.85
days_since_last_push2
active_weeks_last_year42

Release discipline

100Excellent
How it's scored
27/27Ships releases — 37 releases published
36/36Release recency — latest release 4 days ago
27/27Release cadence — a release every ~34 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count37
latest_release_tagv1.18.1
releases_from_tagsno
days_since_latest_release4
mean_days_between_releases34
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

72Good · 18% of overall
How it's scored
40.1/60Stars — 299 stars
19.7/25Forks — 229 forks
7.7/15Watchers — 25 watchers
Inputs used
forks229
stars299
watchers25
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

82Good · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
14.5/22.5Commit distribution — top contributor authored 35% of commits
13.5/13.5Contributor breadth — 96 contributors
10/10OpenSSF Scorecard: Contributors — project has 26 contributing companies or organizations
Inputs used
bus_factor3
contributors_sampled96
top_contributor_share0.354
How it's scored
38.6/46.8Issue resolution — 82% of issues closed
31.8/38.3PR acceptance — 919/1,105 decided PRs merged
10.5/15OpenSSF Scorecard: Code-Review — Found 18/24 approved changesets -- score normalized to 7
Inputs used
merged_prs919
open_issues115
closed_issues543
issue_closed_ratio0.825
closed_unmerged_prs186
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
23.7/25Owner reach — 1,947 followers of dapr
24.1/25Track record — 45 public repos, account ~7 yr old
Inputs used
followers1,947
owner_typeOrganization
is_verified
owner_logindapr
public_repos45
account_age_days2,593
How it's scored
25/25Published & resolvable — 7 package(s) on maven
35/35Publish recency — latest publish 4 days ago
20/20Version history — 119 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesio.dapr:dapr-sdk, io.dapr:dapr-sdk-actors, io.dapr:dapr-sdk-autogen, io.dapr:dapr-sdk-workflows, io.dapr:dapr-sdk-springboot, io.dapr:durabletask-client, io.dapr:testcontainers-dapr
ecosystemsmaven
any_deprecatedno
min_days_since_publish4

Engineering Quality

Are baseline engineering and documentation practices in place?

71Good · 20% of overall
How it's scored
24/24CI workflows — 8 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 24 out of 24 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

65Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 24 out of 24 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
5.2/7.5Code-Review — Found 18/24 approved changesets -- score normalized to 7
2.5/2.5Contributors — project has 26 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6.2
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
8.4/25Indirect dependencies free of known advisories — 3 affected: io.netty:netty-codec 4.1.135.Final (high 7.5), io.netty:netty-codec-http 4.1.135.Final (high 7.5), io.netty:netty-codec-http2 4.1.135.Final (low)
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories9
affected_packages3
assessed_packages40
unassessed_packages0
affected_by_severityhigh 2, low 1
direct_affected_packages0
Matched the maven:io.dapr:dapr-sdk@1.18.1 runtime dependency closure — what installing the published package pulls in — 40 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

66Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 74 of 85 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.871
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — mise.toml
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Java (statically typed)
0/10Reproducible environment
8/10Demonstrated agent practice — 4 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 15 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageyes
bootstrap_filesmise.toml
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.04
toolchain_manifestsdapr-spring/dapr-spring-bom/pom.xml, dapr-spring/dapr-spring-boot-autoconfigure/pom.xml, dapr-spring/dapr-spring-boot-observation/pom.xml, dapr-spring/dapr-spring-boot-properties/pom.xml, dapr-spring/dapr-spring-boot-starters/dapr-spring-boot-starter-test/pom.xml, dapr-spring/dapr-spring-boot-starters/dapr-spring-boot-starter/pom.xml, dapr-spring/dapr-spring-boot-tests/pom.xml, dapr-spring/dapr-spring-data/pom.xml, dapr-spring/dapr-spring-messaging/pom.xml, dapr-spring/dapr-spring-workflows/pom.xml, dapr-spring/pom.xml, durabletask-client/pom.xml, examples/pom.xml, pom.xml, sdk-actors/pom.xml, sdk-autogen/pom.xml, sdk-bom/pom.xml, sdk-springboot/pom.xml, sdk-tests/pom.xml, sdk-workflows/pom.xml, sdk/pom.xml, spring-boot-examples/consumer-app/pom.xml, spring-boot-examples/pom.xml, spring-boot-examples/producer-app/pom.xml, spring-boot-examples/workflows/multi-app/orchestrator/pom.xml, spring-boot-examples/workflows/multi-app/pom.xml, spring-boot-examples/workflows/multi-app/worker-one/pom.xml, spring-boot-examples/workflows/multi-app/worker-two/pom.xml, spring-boot-examples/workflows/patterns/pom.xml, spring-boot-examples/workflows/pom.xml, spring-boot-examples/workflows/versioning/full-version-worker-one/pom.xml, spring-boot-examples/workflows/versioning/full-version-worker-two/pom.xml, spring-boot-examples/workflows/versioning/patch-version-worker-one/pom.xml, spring-boot-examples/workflows/versioning/patch-version-worker-two/pom.xml, spring-boot-examples/workflows/versioning/pom.xml, spring-boot-examples/workflows/versioning/version-orchestrator/pom.xml, spring-boot-sdk-tests/pom.xml, testcontainers-dapr/pom.xml
dependency_bot_commit_share0.15
How it's scored
45/45Type-checkable code — Java (statically typed)
54.6/55Manageable file sizes — 7/915 source files over 60KB
Inputs used
primary_languageJava
largest_source_bytes3,725,456
source_files_sampled915
oversized_source_files7
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — examples/proto/helloworld.proto, sdk-tests/proto/methodinvokeservice.proto
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_filesexamples/proto/helloworld.proto, sdk-tests/proto/methodinvokeservice.proto

Key facts

299GitHub stars
96contributors
155commits, last 12 months
2days since last push
37releases
3bus factor
115open issues
Mavenpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch maven package 'io.dapr:dapr-sdk-tests' from its registry

More detail

Star and fork history 0 ★ / 229 ⇿
0Stars
229Forks
35Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0408012016020024022462019-102023-032026-07
Major 1Minor 18Patch 16

Each point covers 7 days.

OpenSSF Scorecard 6.2 / 10
6.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-24 11:44 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests24 out of 24 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
7Code-ReviewFound 18/24 approved changesets -- score normalized to 7
10Contributorsproject has 26 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 136
RegistryPackageVersion constraintManifest
Mavenio.dapr.spring:dapr-spring-data${project.version}dapr-spring/pom.xml
Mavenio.dapr.spring:dapr-spring-messaging${project.version}dapr-spring/pom.xml
Mavenio.dapr.spring:dapr-spring-workflows${project.version}dapr-spring/pom.xml
Mavenio.dapr.spring:dapr-spring-boot-autoconfigure${project.version}dapr-spring/pom.xml
Mavenio.dapr.spring:dapr-spring-boot-properties${project.version}dapr-spring/pom.xml
Mavenio.dapr.spring:dapr-spring-boot-observation${project.version}dapr-spring/pom.xml
Mavenio.dapr.spring:dapr-spring-boot-tests${project.version}dapr-spring/pom.xml
Mavenio.grpc:grpc-protobufdurabletask-client/pom.xml
Mavenio.grpc:grpc-stubdurabletask-client/pom.xml
Mavenio.grpc:grpc-nettydurabletask-client/pom.xml
Mavencom.google.protobuf:protobuf-javadurabletask-client/pom.xml
Mavencom.fasterxml.jackson.core:jackson-coredurabletask-client/pom.xml
Mavencom.fasterxml.jackson.core:jackson-databinddurabletask-client/pom.xml
Mavencom.fasterxml.jackson.core:jackson-annotationsdurabletask-client/pom.xml
Mavencom.fasterxml.jackson.datatype:jackson-datatype-jsr310durabletask-client/pom.xml
Mavenorg.apache.commons:commons-lang3durabletask-client/pom.xml
Mavenio.micrometer:micrometer-observationdurabletask-client/pom.xml
Mavenio.opentelemetry:opentelemetry-apidurabletask-client/pom.xml
Mavenio.opentelemetry:opentelemetry-contextdurabletask-client/pom.xml
Mavenio.netty:netty-bom${netty.version}pom.xml
Mavenio.grpc:grpc-bom${grpc.version}pom.xml
Mavencom.fasterxml.jackson:jackson-bom${jackson.version}pom.xml
Mavenorg.junit:junit-bom${junit-bom.version}pom.xml
Mavenorg.springframework.boot:spring-boot-dependencies${springboot.version}pom.xml
Mavenorg.testcontainers:testcontainers-bom${testcontainers.version}pom.xml
Mavencom.google.protobuf:protobuf-bom${protobuf.version}pom.xml
Mavenio.opentelemetry:opentelemetry-bom${opentelemetry.version}pom.xml
Mavenorg.apache.commons:commons-compress${commons-compress.version}pom.xml
Mavencommons-codec:commons-codec1.17.2pom.xml
Mavenorg.testcontainers:testcontainers${testcontainers.version}pom.xml
Mavenorg.testcontainers:testcontainers-junit-jupiter${testcontainers.version}pom.xml
Mavenorg.testcontainers:testcontainers-kafka${testcontainers.version}pom.xml
Mavenorg.testcontainers:testcontainers-postgresql${testcontainers.version}pom.xml
Mavenorg.testcontainers:testcontainers-rabbitmq${testcontainers.version}pom.xml
Mavenorg.slf4j:slf4j-api${slf4j.version}pom.xml
Mavenorg.mockito:mockito-core${mockito.version}pom.xml
Mavenorg.jetbrains.kotlin:kotlin-stdlib${kotlin.version}pom.xml
Mavenorg.yaml:snakeyaml${snakeyaml.version}pom.xml
Mavenio.dapr:dapr-sdk${dapr.sdk.version}pom.xml
Mavenio.rest-assured:rest-assured${rest-assured.version}pom.xml
Mavenio.dapr.spring:dapr-spring-boot-starter${dapr.sdk.version}pom.xml
Mavenio.dapr.spring:dapr-spring-boot-starter-test${dapr.sdk.version}pom.xml
Mavenio.dapr:testcontainers-dapr${dapr.sdk.version}pom.xml
Mavenjakarta.annotation:jakarta.annotation-api${jakarta.annotation.version}pom.xml
Mavenjavax.annotation:javax.annotation-api${javax.annotation.version}pom.xml
Mavenorg.apache.commons:commons-lang3${commons-lang.version}pom.xml
Mavencommons-cli:commons-cli${commons-cli.version}pom.xml
Mavencommons-io:commons-io${commons-io.version}pom.xml
Mavenio.zipkin.reporter2:zipkin-reporter${zipkin.version}pom.xml
Mavenio.zipkin.reporter2:zipkin-sender-urlconnection${zipkin.version}pom.xml
Mavenio.dapr:dapr-sdk-actors${dapr.sdk.version}pom.xml
Mavenio.dapr:dapr-sdk-springboot${dapr.sdk.version}pom.xml
Mavenio.dapr:dapr-sdk-workflows${dapr.sdk.version}pom.xml
Mavenorg.wiremock:wiremock-standalone${wiremock.version}pom.xml
Mavencommons-validator:commons-validator${commons-validator.version}pom.xml
Mavencom.jayway.jsonpath:json-path${json-path.version}pom.xml
Mavencom.evanlennick:retry4j${retry4j.version}pom.xml
Mavencom.github.stefanbirkner:system-rules${system-rules.version}pom.xml
Mavenuk.org.webcompere:system-stubs-jupiter${system-stubs.version}pom.xml
Mavenorg.mockito:mockito-inline${mockito-inline.version}pom.xml
Mavenorg.junit.platform:junit-platform-console-standalone${junit-platform-console.version}pom.xml
Mavenorg.junit.jupiter:junit-jupiter${junit-bom.version}pom.xml
Mavenorg.junit.jupiter:junit-jupiter-api${junit-bom.version}pom.xml
Mavenorg.junit.jupiter:junit-jupiter-engine${junit-bom.version}pom.xml
Mavenorg.junit.jupiter:junit-jupiter-params${junit-bom.version}pom.xml
Mavenio.projectreactor:reactor-core${reactor.version}pom.xml
Mavencom.redis:testcontainers-redis${testcontainers-redis.version}pom.xml
Mavenio.github.microcks:microcks-testcontainers${microcks.version}pom.xml
Mavenorg.assertj:assertj-core${assertj.version}pom.xml
Mavencom.puppycrawl.tools:checkstyle${checkstyle.version}pom.xml
Mavenio.dapr:dapr-sdk${project.version}sdk-actors/pom.xml
Mavencom.fasterxml.jackson.datatype:jackson-datatype-jsr310sdk-actors/pom.xml
Mavenio.grpc:grpc-nettysdk-autogen/pom.xml
Mavenio.grpc:grpc-protobufsdk-autogen/pom.xml
Mavenio.grpc:grpc-stubsdk-autogen/pom.xml
Mavenio.dapr:dapr-sdk-autogen${dapr.sdk.version}sdk-bom/pom.xml
Mavenio.dapr:dapr-sdk${dapr.sdk.version}sdk-bom/pom.xml
Mavenio.dapr:dapr-sdk-actors${dapr.sdk.version}sdk-bom/pom.xml
Mavenio.dapr:dapr-sdk-workflows${dapr.sdk.version}sdk-bom/pom.xml
Mavenio.dapr:testcontainers-dapr${dapr.sdk.version}sdk-bom/pom.xml
Mavenio.dapr:durabletask-client${dapr.sdk.version}sdk-bom/pom.xml
Mavenio.netty:netty-bom${netty.version}sdk-bom/pom.xml
Mavencom.fasterxml.jackson:jackson-bom${jackson.version}sdk-bom/pom.xml
Mavenorg.apache.commons:commons-compress${commons-compress.version}sdk-bom/pom.xml
Mavencommons-codec:commons-codec1.17.2sdk-bom/pom.xml
Mavenio.dapr:dapr-sdk${project.version}sdk-springboot/pom.xml
Mavenio.dapr:dapr-sdk-actors${project.version}sdk-springboot/pom.xml
Mavenorg.springframework:spring-websdk-springboot/pom.xml
Mavenorg.springframework:spring-contextsdk-springboot/pom.xml
Mavenorg.springframework.boot:spring-boot-startersdk-springboot/pom.xml
Mavenorg.springframework.boot:spring-boot-configuration-processorsdk-springboot/pom.xml
Mavenio.netty:netty-bom${netty.version}sdk-tests/pom.xml
Mavenorg.springframework.boot:spring-boot-dependencies${springboot4.version}sdk-tests/pom.xml
Mavencommons-cli:commons-clisdk-tests/pom.xml
Mavenio.grpc:grpc-protobufsdk-tests/pom.xml
Mavenio.grpc:grpc-stubsdk-tests/pom.xml
Mavenio.grpc:grpc-apisdk-tests/pom.xml
Mavencommons-io:commons-iosdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-sdksdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-apisdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-contextsdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-sdk-commonsdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-sdk-tracesdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-sdk-metricssdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-exporter-commonsdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-exporter-loggingsdk-tests/pom.xml
Mavenio.opentelemetry:opentelemetry-exporter-zipkinsdk-tests/pom.xml
Mavenio.zipkin.reporter2:zipkin-reportersdk-tests/pom.xml
Mavenio.zipkin.reporter2:zipkin-sender-urlconnectionsdk-tests/pom.xml
Mavenio.dapr.spring:dapr-spring-boot-startersdk-tests/pom.xml
Mavenorg.testcontainers:testcontainers-junit-jupitersdk-tests/pom.xml
Mavenorg.springframework.data:spring-data-keyvaluesdk-tests/pom.xml
Mavenjakarta.annotation:jakarta.annotation-apisdk-tests/pom.xml
Mavenjavax.annotation:javax.annotation-apisdk-tests/pom.xml
Mavenjakarta.servlet:jakarta.servlet-apisdk-tests/pom.xml
Mavenio.dapr:dapr-sdk${project.parent.version}sdk-workflows/pom.xml
Mavenio.dapr:durabletask-client${project.parent.version}sdk-workflows/pom.xml
Mavenio.opentelemetry:opentelemetry-apisdk-workflows/pom.xml
Mavenorg.slf4j:slf4j-apisdk/pom.xml
Mavenio.dapr:dapr-sdk-autogen${project.version}sdk/pom.xml
Mavencom.fasterxml.jackson.core:jackson-databindsdk/pom.xml
Mavencom.google.protobuf:protobuf-java-utilsdk/pom.xml
Mavenio.projectreactor:reactor-coresdk/pom.xml
Mavenio.grpc:grpc-nettysdk/pom.xml
Maventools.jackson:jackson-bom3.1.1spring-boot-examples/pom.xml
Mavenio.netty:netty-bom${netty.version}spring-boot-examples/pom.xml
Mavenorg.springframework.boot:spring-boot-dependencies${springboot4.version}spring-boot-examples/pom.xml
Mavenorg.springframework.boot:spring-boot-starter-webmvc${springboot4.version}spring-boot-examples/pom.xml
Mavenorg.springframework.boot:spring-boot-starter-restclient${springboot4.version}spring-boot-examples/pom.xml
Mavenio.netty:netty-bom${netty.version}spring-boot-sdk-tests/pom.xml
Mavenorg.springframework.boot:spring-boot-dependencies${springboot4.version}spring-boot-sdk-tests/pom.xml
Mavenorg.testcontainers:testcontainers-junit-jupiterspring-boot-sdk-tests/pom.xml
Mavenorg.yaml:snakeyamltestcontainers-dapr/pom.xml
Mavenorg.testcontainers:testcontainerstestcontainers-dapr/pom.xml
Mavencommons-codec:commons-codectestcontainers-dapr/pom.xml
Mavencom.fasterxml.jackson.core:jackson-databindtestcontainers-dapr/pom.xml
All dependencies 201

Full resolved dependency set from the GitHub dependency graph: 139 direct and 62 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Mavencom.evanlennick:retry4jdirect
Mavencom.evanlennick:retry4j0.15.0direct
Mavencom.fasterxml.jackson.core:jackson-annotationsdirect
Mavencom.fasterxml.jackson.core:jackson-coredirect
Mavencom.fasterxml.jackson.core:jackson-databinddirect
Mavencom.fasterxml.jackson.datatype:jackson-datatype-jsr310direct
Mavencom.fasterxml.jackson:jackson-bom2.21.2direct
Mavencom.github.stefanbirkner:system-rulesdirect
Mavencom.github.stefanbirkner:system-rules1.19.0direct
Mavencom.google.protobuf:protobuf-bom3.25.5direct
Mavencom.google.protobuf:protobuf-javadirect
Mavencom.google.protobuf:protobuf-java-utildirect
Mavencom.jayway.jsonpath:json-pathdirect
Mavencom.jayway.jsonpath:json-path2.9.0direct
Mavencom.puppycrawl.tools:checkstyle10.17.0direct
Mavencom.redis:testcontainers-redisdirect
Mavencom.redis:testcontainers-redis2.2.4direct
Mavencommons-cli:commons-clidirect
Mavencommons-cli:commons-cli1.9.0direct
Mavencommons-codec:commons-codecdirect
Mavencommons-codec:commons-codec1.17.2direct
Mavencommons-io:commons-iodirect
Mavencommons-io:commons-io2.14.0direct
Mavencommons-validator:commons-validatordirect
Mavencommons-validator:commons-validator1.7direct
Mavenio.dapr.spring:dapr-spring-boot-autoconfiguredirect
Mavenio.dapr.spring:dapr-spring-boot-autoconfigure1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-boot-observationdirect
Mavenio.dapr.spring:dapr-spring-boot-observation1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-boot-propertiesdirect
Mavenio.dapr.spring:dapr-spring-boot-properties1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-boot-starterdirect
Mavenio.dapr.spring:dapr-spring-boot-starter1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-boot-starter-testdirect
Mavenio.dapr.spring:dapr-spring-boot-starter-test1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-boot-testsdirect
Mavenio.dapr.spring:dapr-spring-boot-tests1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-datadirect
Mavenio.dapr.spring:dapr-spring-data1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-messagingdirect
Mavenio.dapr.spring:dapr-spring-messaging1.19.0-SNAPSHOTdirect
Mavenio.dapr.spring:dapr-spring-workflowsdirect
Mavenio.dapr.spring:dapr-spring-workflows1.19.0-SNAPSHOTdirect
Mavenio.dapr:dapr-sdkdirect
Mavenio.dapr:dapr-sdk1.19.0-SNAPSHOTdirect
Mavenio.dapr:dapr-sdk-actorsdirect
Mavenio.dapr:dapr-sdk-actors1.19.0-SNAPSHOTdirect
Mavenio.dapr:dapr-sdk-autogen1.19.0-SNAPSHOTdirect
Mavenio.dapr:dapr-sdk-springbootdirect
Mavenio.dapr:dapr-sdk-springboot1.19.0-SNAPSHOTdirect
Mavenio.dapr:dapr-sdk-workflowsdirect
Mavenio.dapr:dapr-sdk-workflows1.19.0-SNAPSHOTdirect
Mavenio.dapr:durabletask-clientdirect
Mavenio.dapr:durabletask-client1.19.0-SNAPSHOTdirect
Mavenio.dapr:testcontainers-daprdirect
Mavenio.dapr:testcontainers-dapr1.19.0-SNAPSHOTdirect
Mavenio.github.microcks:microcks-testcontainersdirect
Mavenio.github.microcks:microcks-testcontainers0.3.1direct
Mavenio.grpc:grpc-apidirect
Mavenio.grpc:grpc-bom1.79.0direct
Mavenio.grpc:grpc-nettydirect
Mavenio.grpc:grpc-protobufdirect
Mavenio.grpc:grpc-stubdirect
Mavenio.micrometer:micrometer-observationdirect
Mavenio.netty:netty-bomdirect
Mavenio.netty:netty-bom4.1.132direct
Mavenio.opentelemetry:opentelemetry-apidirect
Mavenio.opentelemetry:opentelemetry-bom1.41.0direct
Mavenio.opentelemetry:opentelemetry-contextdirect
Mavenio.opentelemetry:opentelemetry-exporter-commondirect
Mavenio.opentelemetry:opentelemetry-exporter-loggingdirect
Mavenio.opentelemetry:opentelemetry-exporter-zipkindirect
Mavenio.opentelemetry:opentelemetry-sdkdirect
Mavenio.opentelemetry:opentelemetry-sdk-commondirect
Mavenio.opentelemetry:opentelemetry-sdk-metricsdirect
Mavenio.opentelemetry:opentelemetry-sdk-tracedirect
Mavenio.projectreactor:reactor-coredirect
Mavenio.projectreactor:reactor-core3.5.12direct
Mavenio.rest-assured:rest-assureddirect
Mavenio.rest-assured:rest-assured5.5.1direct
Mavenio.zipkin.reporter2:zipkin-reporterdirect
Mavenio.zipkin.reporter2:zipkin-reporter3.4.0direct
Mavenio.zipkin.reporter2:zipkin-sender-urlconnectiondirect
Mavenio.zipkin.reporter2:zipkin-sender-urlconnection3.4.0direct
Mavenjakarta.annotation:jakarta.annotation-apidirect
Mavenjakarta.annotation:jakarta.annotation-api2.1.1direct
Mavenjakarta.servlet:jakarta.servlet-apidirect
Mavenjavax.annotation:javax.annotation-apidirect
Mavenjavax.annotation:javax.annotation-api1.3.2direct
Mavenorg.apache.commons:commons-compress1.26.0direct
Mavenorg.apache.commons:commons-lang3direct
Mavenorg.apache.commons:commons-lang33.18.0direct
Mavenorg.assertj:assertj-coredirect
Mavenorg.assertj:assertj-core3.27.7direct
Mavenorg.jetbrains.kotlin:kotlin-stdlib2.1.0direct
Mavenorg.junit.jupiter:junit-jupiterdirect
Mavenorg.junit.jupiter:junit-jupiter5.11.4direct
Mavenorg.junit.jupiter:junit-jupiter-apidirect
Mavenorg.junit.jupiter:junit-jupiter-api5.11.4direct
Mavenorg.junit.jupiter:junit-jupiter-engine5.11.4direct
Mavenorg.junit.jupiter:junit-jupiter-paramsdirect
Mavenorg.junit.jupiter:junit-jupiter-params5.11.4direct
Mavenorg.junit.platform:junit-platform-console-standalonedirect
Mavenorg.junit.platform:junit-platform-console-standalone1.7.0direct
Mavenorg.junit:junit-bom5.11.4direct
Mavenorg.mockito:mockito-coredirect
Mavenorg.mockito:mockito-core3.11.2direct
Mavenorg.mockito:mockito-inlinedirect
Mavenorg.mockito:mockito-inline4.2.0direct
Mavenorg.slf4j:slf4j-apidirect
Mavenorg.slf4j:slf4j-api2.0.9direct
Mavenorg.springframework.boot:spring-boot-configuration-processordirect
Mavenorg.springframework.boot:spring-boot-dependencies4.0.5direct
Mavenorg.springframework.boot:spring-boot-starterdirect
Mavenorg.springframework.boot:spring-boot-starter-restclientdirect
Mavenorg.springframework.boot:spring-boot-starter-restclient4.0.5direct
Mavenorg.springframework.boot:spring-boot-starter-webmvcdirect
Mavenorg.springframework.boot:spring-boot-starter-webmvc4.0.5direct
Mavenorg.springframework.data:spring-data-keyvaluedirect
Mavenorg.springframework:spring-contextdirect
Mavenorg.springframework:spring-webdirect
Mavenorg.testcontainers:testcontainersdirect
Mavenorg.testcontainers:testcontainers2.0.5direct
Mavenorg.testcontainers:testcontainers-bom2.0.5direct
Mavenorg.testcontainers:testcontainers-junit-jupiterdirect
Mavenorg.testcontainers:testcontainers-junit-jupiter2.0.5direct
Mavenorg.testcontainers:testcontainers-kafkadirect
Mavenorg.testcontainers:testcontainers-kafka2.0.5direct
Mavenorg.testcontainers:testcontainers-postgresqldirect
Mavenorg.testcontainers:testcontainers-postgresql2.0.5direct
Mavenorg.testcontainers:testcontainers-rabbitmqdirect
Mavenorg.testcontainers:testcontainers-rabbitmq2.0.5direct
Mavenorg.wiremock:wiremock-standalonedirect
Mavenorg.wiremock:wiremock-standalone3.9.1direct
Mavenorg.yaml:snakeyamldirect
Mavenorg.yaml:snakeyaml2.0direct
Maventools.jackson:jackson-bom3.1.1direct
Mavenuk.org.webcompere:system-stubs-jupiterdirect
Mavenuk.org.webcompere:system-stubs-jupiter2.1.1direct
Mavencom.fasterxml.jackson.dataformat:jackson-dataformat-xmlindirect
Mavencom.github.spotbugs:spotbugs-maven-pluginindirect
Mavencom.github.spotbugs:spotbugs-maven-plugin4.8.2.0indirect
Mavencom.googlecode.maven-download-plugin:download-maven-pluginindirect
Mavencom.googlecode.maven-download-plugin:download-maven-plugin1.6.0indirect
Mavenio.dapr:dapr-sdk-bom1.19.0-SNAPSHOTindirect
Mavenio.dapr:worker-one1.19.0-SNAPSHOTindirect
Mavenio.dapr:worker-two1.19.0-SNAPSHOTindirect
Mavenio.grpc:grpc-inprocessindirect
Mavenio.grpc:grpc-testingindirect
Mavenio.micrometer:micrometer-observation-testindirect
Mavenio.projectreactor:reactor-testindirect
Mavenio.projectreactor:reactor-test3.5.12indirect
Mavenorg.apache.maven.plugins:maven-checkstyle-pluginindirect
Mavenorg.apache.maven.plugins:maven-checkstyle-plugin3.4.0indirect
Mavenorg.apache.maven.plugins:maven-compiler-pluginindirect
Mavenorg.apache.maven.plugins:maven-compiler-plugin3.13.0indirect
Mavenorg.apache.maven.plugins:maven-failsafe-pluginindirect
Mavenorg.apache.maven.plugins:maven-failsafe-plugin3.5.3indirect
Mavenorg.apache.maven.plugins:maven-gpg-plugin3.1.0indirect
Mavenorg.apache.maven.plugins:maven-jar-pluginindirect
Mavenorg.apache.maven.plugins:maven-javadoc-pluginindirect
Mavenorg.apache.maven.plugins:maven-javadoc-plugin3.7.0indirect
Mavenorg.apache.maven.plugins:maven-project-info-reports-plugin3.7.0indirect
Mavenorg.apache.maven.plugins:maven-resources-pluginindirect
Mavenorg.apache.maven.plugins:maven-resources-plugin3.3.1indirect
Mavenorg.apache.maven.plugins:maven-site-pluginindirect
Mavenorg.apache.maven.plugins:maven-site-plugin3.12.1indirect
Mavenorg.apache.maven.plugins:maven-source-pluginindirect
Mavenorg.apache.maven.plugins:maven-source-plugin3.3.1indirect
Mavenorg.apache.maven.plugins:maven-surefire-pluginindirect
Mavenorg.apache.maven.plugins:maven-surefire-plugin3.2.2indirect
Mavenorg.jacoco:jacoco-maven-pluginindirect
Mavenorg.jacoco:jacoco-maven-plugin0.8.11indirect
Mavenorg.junit.jupiter:junit-jupiter-migrationsupportindirect
Mavenorg.junit.platform:junit-platform-commonsindirect
Mavenorg.junit.platform:junit-platform-engineindirect
Mavenorg.mockito:mockito-junit-jupiterindirect
Mavenorg.sonatype.plugins:nexus-staging-maven-pluginindirect
Mavenorg.sonatype.plugins:nexus-staging-maven-plugin1.7.0indirect
Mavenorg.springframework.boot:spring-boot-autoconfigureindirect
Mavenorg.springframework.boot:spring-boot-autoconfigure-processorindirect
Mavenorg.springframework.boot:spring-boot-jacksonindirect
Mavenorg.springframework.boot:spring-boot-maven-pluginindirect
Mavenorg.springframework.boot:spring-boot-maven-plugin4.0.5indirect
Mavenorg.springframework.boot:spring-boot-starter-actuatorindirect
Mavenorg.springframework.boot:spring-boot-starter-testindirect
Mavenorg.springframework.boot:spring-boot-starter-webindirect
Mavenorg.springframework.boot:spring-boot-starter-webmvc-testindirect
Mavenorg.springframework.boot:spring-boot-starter-webmvc-test4.0.5indirect
Mavenorg.springframework.boot:spring-boot-testcontainersindirect
Mavenorg.springframework.data:spring-data-commonsindirect
Mavenorg.springframework:spring-beansindirect
Mavenorg.testcontainers:testcontainers-mysqlindirect
Mavenorg.testcontainers:testcontainers-mysql2.0.5indirect
Mavenorg.testcontainers:testcontainers-toxiproxyindirect
Mavenorg.testcontainers:testcontainers-toxiproxy2.0.5indirect
Mavenorg.xolstice.maven.plugins:protobuf-maven-pluginindirect
Mavenorg.xolstice.maven.plugins:protobuf-maven-plugin0.6.1indirect
Mavenredis.clients:jedisindirect
Mavenredis.clients:jedis5.1.0indirect
Maventools.jackson.core:jackson-databindindirect
Dependency advisories 3

Installing maven:io.dapr:dapr-sdk@1.18.1 pulls in 40 packages, direct and transitive: 3 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
io.netty:netty-codec4.1.135.Finalindirecthigh14.2.16.Final
io.netty:netty-codec-http4.1.135.Finalindirecthigh74.2.16.Final
io.netty:netty-codec-http24.1.135.Finalindirectlow14.2.16.Final

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 121465,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Java": 3647029,
        "Shell": 2488
      },
      "pushed_at": "2026-07-22T11:08:50Z",
      "created_at": "2019-10-09T17:30:19Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T11:09:18Z",
      "description": "Dapr SDK for Java",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "master",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Java",
      "significant_languages": [
        "Java"
      ]
    },
    "owner": {
      "blog": "https://dapr.io",
      "name": "Dapr",
      "type": "Organization",
      "login": "dapr",
      "company": null,
      "location": null,
      "followers": 1947,
      "avatar_url": "https://avatars.githubusercontent.com/u/51932459?v=4",
      "created_at": "2019-06-17T21:50:10Z",
      "is_verified": null,
      "public_repos": 45,
      "account_age_days": 2593
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.18.1",
          "kind": "patch",
          "published_at": "2026-07-20T09:32:51Z"
        },
        {
          "tag": "v1.17.5",
          "kind": "patch",
          "published_at": "2026-07-20T08:18:23Z"
        },
        {
          "tag": "v1.17.4",
          "kind": "patch",
          "published_at": "2026-07-06T08:52:00Z"
        },
        {
          "tag": "v1.17.3",
          "kind": "patch",
          "published_at": "2026-06-12T08:07:26Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2026-06-11T06:28:54Z"
        },
        {
          "tag": "v1.17.2",
          "kind": "patch",
          "published_at": "2026-04-10T10:01:37Z"
        },
        {
          "tag": "v1.17.1",
          "kind": "patch",
          "published_at": "2026-04-02T07:54:24Z"
        },
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2026-03-02T15:10:48Z"
        },
        {
          "tag": "v1.16.1",
          "kind": "patch",
          "published_at": "2026-01-22T22:27:36Z"
        },
        {
          "tag": "v1.16.0",
          "kind": "minor",
          "published_at": "2025-09-17T13:45:01Z"
        },
        {
          "tag": "v1.15.1",
          "kind": "patch",
          "published_at": "2025-08-26T13:34:05Z"
        },
        {
          "tag": "v1.15.0",
          "kind": "minor",
          "published_at": "2025-08-14T20:36:54Z"
        },
        {
          "tag": "v1.14.2",
          "kind": "patch",
          "published_at": "2025-08-04T14:12:22Z"
        },
        {
          "tag": "v1.14.1",
          "kind": "patch",
          "published_at": "2025-05-13T17:01:56Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2025-03-19T22:11:59Z"
        },
        {
          "tag": "v1.13.3",
          "kind": "patch",
          "published_at": "2025-01-27T17:38:56Z"
        },
        {
          "tag": "v1.13.2",
          "kind": "patch",
          "published_at": "2025-01-09T08:37:36Z"
        },
        {
          "tag": "v1.13.1",
          "kind": "patch",
          "published_at": "2024-12-09T18:53:32Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2024-12-06T19:02:56Z"
        },
        {
          "tag": "v1.12.1",
          "kind": "patch",
          "published_at": "2024-09-20T17:08:25Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2024-08-14T02:36:41Z"
        },
        {
          "tag": "v1.11.0",
          "kind": "minor",
          "published_at": "2024-03-06T15:35:01Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2023-10-12T10:44:40Z"
        },
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2023-08-01T19:56:27Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2023-03-10T06:34:17Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2022-11-15T17:19:06Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2022-11-15T01:05:19Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2022-07-12T16:08:24Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2022-04-08T07:55:02Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2022-01-25T05:18:22Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2021-10-14T18:49:30Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2021-10-13T17:18:16Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2021-08-12T21:41:17Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2021-05-26T22:53:26Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2021-03-18T03:45:10Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2021-03-17T21:41:24Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2021-03-17T21:36:51Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3258337c0bcec3ff1b21664b39ccd678fb7f5f28",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: pin Netty to the gRPC-supported version in Spring modules (#1793)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-07-22T11:08:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9612cba89f6a7d762bd508aeac8d850f51e1ed25",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.18.1",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-07-20T09:32:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b60c8deb8945e3d64af150a4daa5dbd33c41f5f",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.17.5",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-07-20T08:18:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc1c1a0caba9c80949b56b1e5642ff937c430ebc",
          "body": "Bumps [nick-fields/retry](https://github.com/nick-fields/retry) from 3 to 4.\n- [Release notes](https://github.com/nick-fields/retry/releases)\n- [Commits](https://github.com/nick-fields/retry/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: nick-fields/retry\n  dependency-version: '4'\n  \n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump nick-fields/retry from 3 to 4 (#1792)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:37:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ca983385c4282f1638e8a3995d5427e58b3a4bd",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-go\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump actions/setup-go from 6 to 7 (#1791)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:37:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c60f0df083bef89ca5521f407d2953910bcbe0b0",
          "body": "* chore: migrate to Spring Boot 4.0\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* fix: keep core modules on JUnit 5\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* fix: run sdk-tests integration tests on JUnit 6\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* test: re-enable orders \n[…]\n Aliaga <javier@diagrid.io>\n\n* docs: add SUPPORT.md with Spring Boot compatibility matrix\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: migrate to Spring Boot 4.0 (#1772)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-07-15T07:40:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a036feed66e76f0c55da1a16a789bf4582605b8",
          "body": "* Add design doc: finish sdk-tests Testcontainers migration + strip legacy CI\n\nMigrates the last 7 sdk-tests ITs off the dapr-run CLI harness onto\nBaseContainerIT/DaprContainer so the build job can drop the Dapr CLI,\ndapr init/uninstall, host Kafka, and host ToxiProxy setup. Covers the\napp-restart, \n[…]\nf-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* Update readme\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n---------\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "Move most of the remaining tests to Test Containers as well (#1785)",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-07-13T15:32:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9065a3e2c781b23bb3b250da860bef96a4fd9886",
          "body": "* Fix durable task\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* Fix durable task\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* test: de-flake longTimeStampTimer by anchoring timer to orchestration clock\n\nThe assertion on the internal sub-timer count (counter >= 4\n[…]\nrma Vegiraju <siri.varma@outlook.com>\n\n---------\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Fix durable task flaky integration test (#1784)",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-07-13T15:01:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26b232777c04cf18913517ca58d63a3e2f340f66",
          "body": "Bumps [fossas/fossa-action](https://github.com/fossas/fossa-action) from 1.9.0 to 2.0.0.\n- [Release notes](https://github.com/fossas/fossa-action/releases)\n- [Commits](https://github.com/fossas/fossa-action/compare/v1.9.0...v2.0.0)\n\n---\nupdated-dependencies:\n- dependency-name: fossas/fossa-action\n  \n[…]\n..\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump fossas/fossa-action from 1.9.0 to 2.0.0 (#1781)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T00:46:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "426e6c42e7d0538f78b6eb854281d8f87aedbd83",
          "body": "* auto open issue on ci failure during release\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\n\n* only open issue on publish\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\n\n---------\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "auto open issue on ci failure during release (#1778)",
          "author_name": "Cassie Coyle",
          "author_login": "cicoyle",
          "committed_at": "2026-07-10T00:00:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f45063edebe8eede68f6d7f6c402a35927e8e7",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.1 to 7.0.0.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/codecov/codecov-action/c\n[…]\n..\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump codecov/codecov-action from 6.0.1 to 7.0.0 (#1762)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T22:54:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c9875a8f84e4bd3551cc904c99fb0c8bef13fbe",
          "body": "…#1754)\n\n* feat: Add compensation workflow pattern to Spring Boot examples\n\nPort the BookTrip compensation (Saga) workflow from the plain Java\nexamples into the Spring Boot workflow patterns module, adding\n@Component-annotated activities and a /wfp/compensation REST endpoint.\n\nSigned-off-by: Siri Va\n[…]\nrma Vegiraju <siri.varma@outlook.com>\n\n---------\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Fix Flaky Integration Tests + Migrate some tests to Test Containers (…",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-07-09T21:36:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c3d4ac84f47ffaf081de397c15bc8c9ff293296a",
          "body": "* feat: propagate caller trace context when scheduling workflows\n\nUpstream half of workflow trace propagation (follow-up to #1619).\n\nDaprWorkflowClient gains a DaprWorkflowClient(Properties, Tracer)\nconstructor that passes the tracer to the internal\nDurableTaskGrpcClientBuilder. DurableTaskGrpcClien\n[…]\nhes to it,\nand failures record the exception on the span in addition to the error\nstatus.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: propagate caller trace context when scheduling workflows (#1783)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-07-08T14:52:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c12975caeca1c58be3ec91dadba00e38379e2d5",
          "body": "…workflow with an active instance ID (#1782)\n\n* feat: throw WorkflowInstanceAlreadyExistsException when scheduling a workflow with an active instance ID\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* fix: address Copilot review feedback on already-exists mapping\n\nAnnotate nullable instanceId f\n[…]\nllision message, and\nassert instance ID propagation into NewOrchestrationInstanceOptions.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: throw WorkflowInstanceAlreadyExistsException when scheduling a …",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-07-07T20:53:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79d9812ff001d21189ee5af58b81b15d1be61a7e",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.17.4",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-07-06T08:51:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f42e0d23fc1c3de36018a2e70e390ab8c57a7f6e",
          "body": "newRequestBuilder resolves relativePath raw and now rethrows\nIllegalArgumentException on illegal chars (e.g. spaces), pointing at\nencodePath. encodePath percent-encodes each path segment, preserving\nseparators and a leading slash and appending any query unchanged,\nmirroring DaprHttp/invokeMethod.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: add DaprInvokeHttpClient.encodePath for URI path encoding (#1774)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-06-30T14:55:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c4590c325aac139f00493237c21d3381a849d6c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump actions/checkout from 4 to 7 (#1773)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-23T05:54:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "625d0f89a0abaa4965277116849f9f648edba098",
          "body": "… completion (#1769)\n\nWhen an orchestrator returns without calling ctx.complete(), the executor\nauto-completes only if no pending actions remain. Since #1733 every\nwaitForExternalEvent emits a CreateTimer action, so when the final event\narrives in the same work item as the completion that resumed th\n[…]\npletion check. All other pending actions block completion as\nbefore.\n\nThe regression test reconstructs the failing production history\nfield-for-field.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix(durabletask): don't let resolved event-wait timers block implicit…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-06-15T16:32:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "38f13b91301f9f41efa2c9c513817c83cb40296e",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.17.3",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-06-12T08:07:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d06cb4bc457beae888e9371b8d8c44453be5305",
          "body": "dapr/durabletask-protobuf#51 reserved the unused router fields on\nScheduleTaskAction (4) and CreateChildWorkflowAction (5), which broke\ncompilation since protos are downloaded from main at build time.\n\nThe runtime only reads the enclosing WorkflowAction.router, which was\nalways set alongside the inner ones, so dropping the inner setters and\ntheir test assertions has no behavior change.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: remove usage of reserved per-action router fields (#1767)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-06-11T14:51:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a6ccef7f462bf089d331c5767135e8c72ea003a",
          "body": "* use v1.18.0\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\n\n* update testcontainers\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\n\n---------\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "use v1.18.0 (#1766)",
          "author_name": "Cassie Coyle",
          "author_login": "cicoyle",
          "committed_at": "2026-06-11T07:04:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43740637bc8879b6d9d4f9485d03fe9bf1cb1f6f",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.18.0",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-06-11T06:28:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43cf7c651ea01eafd1ac61ae744a617227a1bc9e",
          "body": "…odyPublishers.json scope (#1758)\n\nnewRequestBuilder now sets the User-Agent header to the SDK version, matching\nwhat the deprecated invokeMethod path emitted via DaprHttp. This is the only\ndefault the SDK can supply that callers cannot, and it is useful for runtime\nside triage. Other implicit invok\n[…]\ning a length-known BodyPublisher, which keeps the JDK on\nContent-Length framing and sidesteps the Transfer-Encoding: chunked race\nreported under load.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: attach SDK User-Agent in DaprInvokeHttpClient and clarify DaprB…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-05-28T17:08:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a56c984f695c1b201241aba727faef028e513c7b",
          "body": "…757)\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: reset gRPC channel backoff between worker reconnect attempts (#1…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-05-28T13:09:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44c07ee91ebf402f0db2c82719b7e4e5c01af244",
          "body": "Signed-off-by: Cassandra Coyle <cassie@diagrid.io>",
          "is_bot": false,
          "headline": "bump to rc4 and jobs api stable (#1755)",
          "author_name": "Cassie Coyle",
          "author_login": "cicoyle",
          "committed_at": "2026-05-27T01:01:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3faa11b8472f5a3034e5e2f74c608a676981c1c",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.0 to 6.0.1.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/codecov/codecov-action/c\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump codecov/codecov-action from 6.0.0 to 6.0.1 (#1752)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-25T07:43:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d87a84cadb086072b68f6d7394b4ffbd27e8d43c",
          "body": "* Apply suggestions from code review\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* Refactor BookTripWorkflow to use CompensationHelper\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* Add CompensationHelper class for managing compensations\n\nSigned-off-by: Siri Varma \n[…]\ny: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* Address comments\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n---------\n\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "Add support for workflow history propagation (#1739)",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-05-22T00:20:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9539d705df3ec160a44921792c34df97734d1b36",
          "body": "* chore: rewrite invoke/http example to use native HttpClient\n\nThe DaprClient.invokeMethod wrappers were deprecated by #1666. Rewrite\nthe invoke/http sample to use java.net.http.HttpClient through the Dapr\nsidecar, demonstrating both URL forms accepted by the sidecar — the\ndapr-app-id header against\n[…]\nprClient.invokeHttpClient and DaprInvokeHttpClient Javadoc as well as\nthe example README.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: add DaprClient.invokeHttpClient(appId) factory (#1742)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-05-20T13:48:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93c5acc7751a91f6cb89092c5c4cda7d198550e8",
          "body": "…) (#1746)\n\nAdds optional deadLetterTopic parameter to the streaming subscribe APIs\non DaprPreviewClient / DaprClientImpl, wiring it through to the\nSubscribeTopicEventsRequestInitialAlpha1.dead_letter_topic proto field.\n\nNew overloads:\n- subscribeToEvents(pubsubName, topic, deadLetterTopic, listener\n[…]\nld on the gRPC initial frame.\n\nFixes: https://github.com/dapr/java-sdk/issues/1608\n\nSigned-off-by: Siri Varma Vegiraju <s_vegiraju@apple.com>\nCo-authored-by: Siri Varma Vegiraju <s_vegiraju@apple.com>",
          "is_bot": false,
          "headline": "feat: add dead-letter topic support to streaming subscriptions (#1608…",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-05-20T09:42:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89708aee19d830a00702180f753d26261f23afd8",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Update master version to 1.19.0-SNAPSHOT",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-05-14T14:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c038f4726bb0a924f842ea3226510e49375a60a",
          "body": "…-bom (#1744)\n\nThe release script bumps the dapr.sdk.version property in all reactor\nPOMs (including dapr-spring-bom) before bumping the standalone BOMs.\nThe later 'mvn versions:set -f dapr-spring/dapr-spring-bom/pom.xml'\nruns in single-POM mode (no reactor) and tries to resolve the import\ndapr-sdk-bom at the new version, which is not yet installed.\n\nInstall sdk-bom into the local repo between the two BOM updates so the\nimport resolves.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix(release): install dapr-sdk-bom locally before bumping dapr-spring…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-05-14T12:36:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4927d2a115940ff311f13d13580c9ab41bdee39b",
          "body": "* feat: download attestation.proto for durabletask-client\n\nAdd attestation.proto to the list of proto files fetched by the\ndownload-maven-plugin so it is compiled alongside the other\ndurabletask protos.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Update to 1.18.0-rc.1\n\nSigned-off-by:\n[…]\nle failed test\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Update runtime\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: download attestation.proto and use Runtime 1.18.0-rc.3 (#1738)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-05-14T07:29:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "00c1858622183f8b40bfc950a04931f50f66961f",
          "body": "… to JUnit 5 (#1736)\n\nUpgrade Testcontainers to v2.0.5 which removes the transitive JUnit 4\ndependency and modernizes the test infrastructure. This includes renaming\nall module artifact IDs with the testcontainers- prefix, migrating\ncontainer class imports to their new packages, removing JUnit 4 run\n[…]\ngine, and ensuring third-party TC dependencies\n(testcontainers-redis 2.2.4, microcks-testcontainers 0.3.1) are\ncompatible via TC 1.x exclusions.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>",
          "is_bot": false,
          "headline": "feat: upgrade Testcontainers from 1.21.4 to 2.0.5 and migrate JUnit 4…",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-04-29T01:36:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9135b8838610a14ee832fe61c35ac011257ae851",
          "body": "* Update github runners to oci gh arc runners\n\nSigned-off-by: Koray Oksay <koray.oksay@gmail.com>\n\n* correct the runner size\n\nSigned-off-by: Koray Oksay <koray.oksay@gmail.com>\n\n* Move to the VM instead of container runner\n\nSigned-off-by: Koray Oksay <koray.oksay@gmail.com>\n\n* chore: Increase timeou\n[…]\nthored-by: artur-ciocanu <artur.ciocanu@gmail.com>\nCo-authored-by: salaboy <Salaboy@gmail.com>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "Update github runners to oci gh arc runners (#1326)",
          "author_name": "Koray Oksay",
          "author_login": "koksay",
          "committed_at": "2026-04-27T09:40:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43962159f796cd20876a23c9870243473ebf81d4",
          "body": "…tional timers (#1733)\n\n* feat(durabletask): implement timer origin and backwards-compatible optional timers\n\nAnnotate every CreateTimerAction the SDK emits with the new origin oneof\nfrom durabletask-protobuf (CreateTimer / ExternalEvent / ActivityRetry /\nChildWorkflowRetry), and emit a synthetic \"o\n[…]\nvalues so the tests stay robust if the SDK ever adds\n  stricter validation on that field.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat(durabletask): implement timer origin and backwards-compatible op…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-04-25T05:32:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ec9b89114ef35400c0927b96772a2b6236e874e",
          "body": "* fix: detect shutdown and break DurableTaskGrpcWorker loop\n\nThe worker loop ran `while (true)` and only exited if an\nInterruptedException happened during the 5-second retry sleep.\nIf `close()` was called while the gRPC stream was blocking, the\nCANCELLED exception was logged but the loop kept retryi\n[…]\ngrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(durabletask): detect shutdown and break gRPC worker loop (#1727)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-04-20T07:46:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e289298fc377f1a306d33e4b8bd8e3c8e794e78b",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Add test to verify workflow reconnection logic (#1692)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-04-17T08:59:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54833d721269c4f0d3e98b42e993733d9e140271",
          "body": "* adding trace propagation to local observations\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* refactor(spring): extract Observation decorators into shared dapr-spring-boot-observation module\n\nEliminates the verbatim duplication between dapr-spring-b\n[…]\ngned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "Adding trace propagation to local observations (#1724)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-04-15T14:11:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5cf3f310daef868bec3fb63cec58470a50a2cb2",
          "body": "…ent (#1722)\n\n* feat: add dapr-sdk-bom module for dependency version management (#1720)\n\nStandalone BOM (no parent inheritance) so consumers only get Dapr SDK\nartifact versions and security-critical transitive dependency overrides\nwithout inheriting the parent's 1500+ internal managed dependencies.\n\n[…]\noff-by: Javier Aliaga <javier@aliaga.dev>\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@aliaga.dev>\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: publish dapr-sdk-bom artifact for transitive dependency managem…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-04-13T14:37:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c3d5b91bb8a982683fdc1e1f612e40d480fba2a",
          "body": "Bumps [actions/github-script](https://github.com/actions/github-script) from 8 to 9.\n- [Release notes](https://github.com/actions/github-script/releases)\n- [Commits](https://github.com/actions/github-script/compare/v8...v9)\n\n---\nupdated-dependencies:\n- dependency-name: actions/github-script\n  depend\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump actions/github-script from 8 to 9 (#1726)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-13T09:30:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b80cfc897c60c2d50fbfd9478edab19ed460054",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.17.2",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-04-10T10:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2206d1b2392786d77c7a1eab298072977494aa07",
          "body": "Update maven.compiler.source, target, and release from 11 to 17 in\nroot pom.xml and dapr-spring/pom.xml. Update all example README\nprerequisites to reference JDK 17 download links.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: bump minimum Java version from 11 to 17 (#1721)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-04-09T14:11:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa296fa78c4b2b251349cb22d2f23862ccf97346",
          "body": "* adding sdk tracing capabilities on spring\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* fix: guard highCardinalityKeyValue calls against null values in ObservationDaprClient\n\nMicrometer's highCardinalityKeyValue throws NPE when the value is null.\nAdded a safe() helper that coalesces nulls to empt\n[…]\nSigned-off-by: salaboy <Salaboy@gmail.com>\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Yaron Schneider <schneider.yaron@live.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "Adding sdk tracing capabilities on spring (#1713)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-04-09T13:35:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78cf7b48569a63ef0535d7d0a87ddffd111c1f85",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5.5.3 to 6.0.0.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/codecov/codecov-action/c\n[…]\nver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": true,
          "headline": "chore(deps): Bump codecov/codecov-action from 5.5.3 to 6.0.0 (#1711)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-08T09:23:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce33e1601f9e651df8de940e03046e6bccfd4fd9",
          "body": "Bumps [fossas/fossa-action](https://github.com/fossas/fossa-action) from 1.8.0 to 1.9.0.\n- [Release notes](https://github.com/fossas/fossa-action/releases)\n- [Commits](https://github.com/fossas/fossa-action/compare/v1.8.0...v1.9.0)\n\n---\nupdated-dependencies:\n- dependency-name: fossas/fossa-action\n  \n[…]\nver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": true,
          "headline": "chore(deps): Bump fossas/fossa-action from 1.8.0 to 1.9.0 (#1712)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-08T08:26:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e64d2bcd16f24b9e6f2855e4c9e9915337dcdaf3",
          "body": "* fix: bump jackson to 2.21.2 to address CVE (SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551)\n\nUpgrade jackson-bom from 2.16.2 to 2.21.2 to fix the high-severity\nAllocation of Resources Without Limits or Throttling vulnerability\nin jackson-core reported in #1714.\n\nSigned-off-by: Javier Aliaga <javier@di\n[…]\n as a direct dependency so it's\navailable at runtime for commons-compress/testcontainers.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix(deps): Upgrade dependencies to address critical CVEs (#1716)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-04-07T17:05:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14c41cfdd5a722639feaf9c211e8a065a388cb75",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.17.1",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-04-02T07:54:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "383d8bf0130cdfd322bcf784609add91b759fabb",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5.5.2 to 5.5.3.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/codecov/codecov-action/c\n[…]\nauthored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump codecov/codecov-action from 5.5.2 to 5.5.3 (#1700)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-31T14:49:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6b25cb17d90911e44f3119fe0c6bb6169703fc0",
          "body": "* fix: upgrade dependencies to address critical CVEs\n\nUpgrade jackson-bom 2.16.2 → 2.18.6 (CVE-2025-52999, CVSS 8.7 DoS),\nadd netty-bom 4.1.132.Final (CVE-2026-33871 CVSS 8.7, CVE-2026-33870\nCVSS 7.5), and bump Spring Boot 3.4.9 → 3.4.10 which pulls Tomcat\n10.1.46 (CVE-2025-55754 CVSS 9.6, CVE-2025-\n[…]\n (latest patch).\n\nNo jackson-bom override needed — Spring Boot 4.0.5 manages it natively.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: upgrade dependencies to address critical CVEs (#1706)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-31T13:32:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12d8c7a2f8fb29fa028daa9c983f5d1f0a94311d",
          "body": "* chore: Deprecate invoke methods\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Deprecate invoke methods\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Deprecate invoke methods\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Change examples\n\nSigned-off-by: Javi\n[…]\niraju <siri.varma@outlook.com>\nCo-authored-by: salaboy <Salaboy@gmail.com>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: Deprecate invoke methods (#1666)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-27T12:08:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ee71c0937f6a4b78485ec527643c5bd9065752d",
          "body": "…buf#33) (#1704)\n\nUpdate Java type references to match the Workflow terminology rename\nin dapr/durabletask-protobuf#33. Point proto base URL to JoshVanL's\nfix-named-reserved branch (durabletask-protobuf#36) which fixes the\nmixed reserved syntax incompatible with protoc 3.x, and remove the\nantrun workaround.\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: adapt to Orchestration→Workflow proto renames (durabletask-proto…",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-26T18:45:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c8e26117451b02c0fe28fdb662cc8162954e63f",
          "body": "* create the release + release notes automatically\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\n\n* Apply suggestions from code review\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nSigned-off-by: Cassie Coyle <cassie.i.coyle@gmail.com>\n\n* pr feedback\n\nSigned-off-by: Cas\n[…]\n Coyle <cassie@diagrid.io>\nSigned-off-by: Cassie Coyle <cassie.i.coyle@gmail.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Create the release + release notes automatically (#1689)",
          "author_name": "Cassie Coyle",
          "author_login": "cicoyle",
          "committed_at": "2026-03-26T15:00:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8fda1c26dd03d75e53a3cd13a6ef8417c0cd264a",
          "body": "The dapr/durabletask-protobuf#32 PR refactored protos by concept,\nsplitting orchestrator_service.proto into orchestration.proto,\nhistory_events.proto, and orchestrator_actions.proto. This broke\nthe build because only the single file was being downloaded.\n\n- Download all 4 proto files in durabletask-\n[…]\nt pom\n- Update Java type references from OrchestratorService.* to the\n  correct new outer classes: Orchestration, HistoryEvents,\n  OrchestratorActions\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: adapt to durabletask-protobuf proto file split (#1702)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-26T13:22:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f304f60d43903db25f07efd252b2974a1325b5e",
          "body": "* Add baggage\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n* Update sdk/src/test/java/io/dapr/client/DaprClientGrpcBaggageTest.java\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\n\n* Apply suggestions from code\n[…]\nma@outlook.com>\nSigned-off-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add baggage support (#1659)",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-03-16T09:17:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f63a4a4030fbb239806370ef2d2fc675313b5772",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Removed unused protos (#1690)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-10T15:19:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2877aa1c237be7efe2790fa35b8d136d28c3de0",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: MaxRetryInterval was not propagate (#1685)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-03T21:41:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "129c29dcaa8960aaa118ca04661222d2225cd9ee",
          "body": "* chore: Use dapr 1.17.0 official release\n\n\n\n* fix: Remove ==APP== prefix from MM examples\n\n\n\n* try stderr instead\n\n\n\n* tweak to mechanical markdown for pubsub\n\n\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>",
          "is_bot": false,
          "headline": "[1.17] Update latest dapr 1.17 (#1683) (#1682)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-03-02T14:22:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc5b8e88c12e344e3017d8533eab0037802612dd",
          "body": "Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6 to 7.\n- [Release notes](https://github.com/actions/upload-artifact/releases)\n- [Commits](https://github.com/actions/upload-artifact/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/upload-artifac\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump actions/upload-artifact from 6 to 7 (#1684)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-02T05:44:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e66394ca7efedab3da5be3cde503b9cb05a08f9c",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.17.0",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-02-27T22:48:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e84b7d52f3012775315913bee9365ef92ea993f5",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: Backport run by daprbot (#1681)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-26T11:56:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e505cddb8239f7181863f705282c9f5389cc8e7a",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Use latest rc version (#1679)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-24T15:16:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba620842ca8fa641c51ee8c518a0ef36d65e4dac",
          "body": "* Fix things\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n* fix things\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n* Update things\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n* Add sub orchestration its\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n* Add sub orchestr\n[…]\n.com>\n\n* fix things\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n* fix things\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>\n\n---------\n\nSigned-off-by: siri-varma <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "[Part 1] Add Sub Orchestration to Durable Task Java (#1649)",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-02-24T10:13:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5cca2f05f05ba33178b10113fe583e47d08a8d3f",
          "body": "Signed-off-by: salaboy <Salaboy@gmail.com>",
          "is_bot": false,
          "headline": "fixing dependency to sb3 autoconfigure (#1675)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-02-23T12:53:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46da9af05d622514c2fbd86fcce13431deb9679",
          "body": "* wip: tracing\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Propagate traceparent to workflow activity\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Refactor durable task and introduce telemetry\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Fix bug, return \n[…]\niaga <javier@diagrid.io>\n\n* chore: Checkstyle\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: salaboy <Salaboy@gmail.com>",
          "is_bot": false,
          "headline": "feat: Propagate tracing info (#1619)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-23T10:10:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "834b6b355b28d1c60738640f2cee093a0b86e8cb",
          "body": "* initial restructure for spring-boot-4-autoconfigure\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* updating sb4 with Jackson3 support and tests\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* Renaming streaming subscription to \"subscribeToTopic\" (#1626)\n\n* Renaming streaming subscription to \"subscr\n[…]\nnu@gmail.com>\nCo-authored-by: artur-ciocanu <artur.ciocanu@gmail.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "Supporting Jackson3 DaprObjectSerializer (#1657)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-02-20T09:36:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb24664a83d6d3b31922cfe3762ef192b8e57917",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "fix: Fix failure policy marshall error (#1668)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-19T14:59:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ff08c5136664f2d40b66bb2a4036ce9f75cc78c",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Update grpc version to avoid CVE (#1665)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-19T10:17:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8299b6ba07745f13650f51e51dcb05d224ca9ead",
          "body": "* chore: Update dapr runtime and fix pom (#1658)\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* [1.17] make bulk pubsub stable (#1641)\n\n* make bulk pubsub stable, update all tests/examples/code to the stable API\n\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\n\n* fix checkstyle\n\nSigned-off-\n[…]\navier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nSigned-off-by: Cassandra Coyle <cassie@diagrid.io>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>",
          "is_bot": false,
          "headline": "Cherrypick pubsub spring6 fix (#1664)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-18T15:13:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f6affbddcd767c8d3c516be1b48f3b19577b0aa",
          "body": "Signed-off-by: Sridhar Suthapalli <sridharsuthapalli@gmail.com>",
          "is_bot": false,
          "headline": "docs: fix broken links (#1663)",
          "author_name": "Illuminati9",
          "author_login": "Illuminati9",
          "committed_at": "2026-02-17T22:03:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ca4264beb85523ab19af4ccc6c27d76dbeea553",
          "body": "Bumps [fossas/fossa-action](https://github.com/fossas/fossa-action) from 1.7.0 to 1.8.0.\n- [Release notes](https://github.com/fossas/fossa-action/releases)\n- [Commits](https://github.com/fossas/fossa-action/compare/v1.7.0...v1.8.0)\n\n---\nupdated-dependencies:\n- dependency-name: fossas/fossa-action\n  \n[…]\nnoreply.github.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump fossas/fossa-action from 1.7.0 to 1.8.0 (#1645)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-17T16:14:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aff88cd1ad4c6eb8e22b096d4dc7054459a29e76",
          "body": "* ci: Add backport action\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Force rerun\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "ci: Add backport action (#1662)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-17T15:33:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ae043b85c11ac0cc8cc18bf6bc3867c66a42827",
          "body": "* Renaming streaming subscription to \"subscribeToTopic\".\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Bring back subscribeToEvents for backward compatibility.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Fix rebase conflicts\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gm\n[…]\nethods.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n---------\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Renaming streaming subscription to \"subscribeToTopic\" (#1626)",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-02-16T20:13:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "addb3c5bbca6ce1c6e611e0d70e7be6b79777eeb",
          "body": "* adding spring boot 4.0.2 tests to the matrix\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* removing ignoring autoconfig for hibernate and datasource\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* adding spring-data-6 and spring-boot-4-starters\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* adding\n[…]\ny: Dapr Bot <daprweb@microsoft.com>\nCo-authored-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Paul Lindner <plindner@metropolis.io>",
          "is_bot": false,
          "headline": "Adding spring boot 4.0.2 tests to the matrix (#1638)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-02-13T16:14:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0d276a1d5eb74fc321dc3715fb72e9bce98b9e2",
          "body": "* feat: Spring workflow version support\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Add workflow and activity annoations\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Rename annotation\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Fix spring boot examples\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "Spring workflow versioning (#1646)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-13T14:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb84ad1772f5bcf09fb4ade49ae61cc53679e941",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Update testcontainers (#1654)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-13T11:36:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f283e3a71e0a727bf8d8b36521d7c414c3a6f151",
          "body": "* chore: Fix waitForLoopEvent test\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* fix: Code style\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Fix singleTimer Test\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Fix LoopWithTimer\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* fix: longTimer test\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Fix Durable tasks flaky tests (#1653)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-13T06:55:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f660eb844b41e2fac86b2e332ed08828f0d4fa0a",
          "body": "* feat: Use dapr 1.17.0-rc.6\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Update pubsubIt to use resiliency policies\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: Use dapr 1.17.0-rc.6 (#1651)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-12T13:27:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91cf0807ea70cb1ebda70398840ecd40b09668c0",
          "body": null,
          "is_bot": false,
          "headline": "Add PATCH constant to HttpExtension for service invocation (#1644)",
          "author_name": "Paul Lindner",
          "author_login": "lindner",
          "committed_at": "2026-02-12T07:11:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff5f43ffaaf3233199d4dd1394f64e8053dbda58",
          "body": "* feat: Add failure policy to actor reminders\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Use jackson to serialize/deserialize FailurePolicies\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: salaboy <Salaboy@gmail.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "feat: Add failure policy to actor reminders (#1643)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-10T09:18:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60f01d93b6547f46c29e15f5c7af718540b8550f",
          "body": "* feat: Add new fields to conversation api\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Modify conversation examples\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\nCo-authored-by: salaboy <Salaboy@gmail.com>",
          "is_bot": false,
          "headline": "feat: Add new fields to conversation api (#1640)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-06T18:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24f8b91197c61e772d7334c18dbb3dd665893d88",
          "body": "Signed-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "feat: Add workflow versioning (#1624)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-02-06T15:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6c540022b4687fcba29691965eafaaf7921d070",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Update master version to 1.18.0-SNAPSHOT",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-02-02T11:00:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "528451ff220b8ff49dbab7312e84c24782b9dfc1",
          "body": "* Add PATCH to HttpMethods enum for service invocation\n\nAdds PATCH to the HttpMethods enum to enable using DaprClient.invokeMethod()\nwith PATCH requests through HTTPEndpoints. This is commonly required for\npartial updates when calling external REST APIs via Dapr service invocation.\n\nFixes #1622\n\nSig\n[…]\nio>\n\n* Add test for PATCH HTTP method\n\nSigned-off-by: Paul Lindner <plindner@metropolis.io>\n\n---------\n\nSigned-off-by: Paul Lindner <plindner@metropolis.io>\nCo-authored-by: salaboy <Salaboy@gmail.com>",
          "is_bot": false,
          "headline": "Add PATCH to HttpMethods enum for service invocation (#1623)",
          "author_name": "Paul Lindner",
          "author_login": "lindner",
          "committed_at": "2026-02-02T08:59:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a47a62a53adc5184cb9b3b2b96f94e0c3cef7dbe",
          "body": "* Replace old log based waits with DaprWait strategy.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Revert ConsumerAppIT to make tests pass.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Revert ConsumerAppIT so there are no changes.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Disable the IT test for failing CI.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n---------\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>",
          "is_bot": false,
          "headline": "Replace old log based waits with DaprWait strategy. (#1635)",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-02-02T08:29:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ce6863f2fb6ddf68ee351b755fc9a020bcf0af2",
          "body": "Signed-off-by: salaboy <Salaboy@gmail.com>",
          "is_bot": false,
          "headline": "push removing unnecesary var (#1634)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-01-30T20:02:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd16fe2afff22c8690d72d72f12fb8155b4b00fa",
          "body": "* chore: Update dapr version\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Refator Proto classes\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Update to 1.17.0-rc.2\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n* chore: Disable mysql it test until new RC\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>\n\n---------\n\nSigned-off-by: Javier Aliaga <javier@diagrid.io>",
          "is_bot": false,
          "headline": "chore: Update dapr version to 1.17.0-rc2 (#1620)",
          "author_name": "Javier Aliaga",
          "author_login": "javier-aliaga",
          "committed_at": "2026-01-30T12:04:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bdfe409372abc6796c930557f839fb10b3694f0e",
          "body": "…tories (#1630)\n\n* Allow to register custom TaskOrchestrationFactory and TaskActivityFactory factories\n\nSigned-off-by: Matheus Cruz <matheuscruz.dev@gmail.com>\n\n* Add test to registerTaskOrchestrationFactory and registerValidTaskActivityFactory methods\n\nSigned-off-by: Matheus Cruz <matheuscruz.dev@gmail.com>\n\n---------\n\nSigned-off-by: Matheus Cruz <matheuscruz.dev@gmail.com>",
          "is_bot": false,
          "headline": "Allow to register custom TaskOrchestrationFactory and TaskActivityFac…",
          "author_name": "Matheus Cruz",
          "author_login": "mcruzdev",
          "committed_at": "2026-01-30T08:13:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02fa2c8d0970b10d3f203a5485478875e62ab562",
          "body": "Signed-off-by: salaboy <Salaboy@gmail.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>",
          "is_bot": false,
          "headline": "WIP named timers (#1628)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-01-29T05:43:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e82e23907c442a0a9ef42ad24be3321d1eee53e",
          "body": "* initial workflow dashboard config\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* adding test for dashboard container\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* adding URL to output\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* Adding a Flux based subscribeToEvents method (#1598)\n\n* Adding a F\n[…]\nub.com>\nCo-authored-by: wlfgang <14792753+wlfgang@users.noreply.github.com>\nCo-authored-by: wlfgang <wlfgang@westridgesystems.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Initial workflow dashboard config for testcontainers (#1601)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-01-28T08:36:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3004bbf9013dbb3c932e77b752101f0ba455aeee",
          "body": "Bumps [org.assertj:assertj-core](https://github.com/assertj/assertj) from 3.27.3 to 3.27.7.\n- [Release notes](https://github.com/assertj/assertj/releases)\n- [Commits](https://github.com/assertj/assertj/compare/assertj-build-3.27.3...assertj-build-3.27.7)\n\n---\nupdated-dependencies:\n- dependency-name:\n[…]\ndency-version: 3.27.7\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.assertj:assertj-core from 3.27.3 to 3.27.7 (#1627)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-01-27T15:07:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99b3267148600ccbe502d412b7c4158a923723ec",
          "body": "Signed-off-by: Dapr Bot <daprweb@microsoft.com>",
          "is_bot": false,
          "headline": "Generate updated javadocs for 1.16.1",
          "author_name": "Dapr Bot",
          "author_login": "dapr-bot",
          "committed_at": "2026-01-22T18:29:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab44c159c436fa38d5c80ebe1c39bcbd9298fd0c",
          "body": "* Adding raw event subscription.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Use proper method overloads for subscribeToEvents()\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Updating the examples to use the latest changes.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gma\n[…]\ned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* FIx CI failures, take 2\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n---------\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>",
          "is_bot": false,
          "headline": "Adding raw event subscription alongside CloudEvent subscription (#1617)",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-01-16T16:51:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "08652dbde72a42c4b29b435e84de058be59e44fc",
          "body": "Signed-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>",
          "is_bot": false,
          "headline": "Bring DurableTask Client to the same Maven standards. (#1618)",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-01-11T22:35:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f119720c89d0c8f29a5d72e17d620f5f622170e",
          "body": "…ier ITs authoring (#1610)\n\n* Adding DaprSpringBootTest and DaprSidecarContainer annotation for easier IT authoring.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n# Conflicts:\n#\ttestcontainers-dapr/pom.xml\n\n* Adding DaprSpringBootTest and DaprSidecarContainer annotation for easier IT auth\n[…]\n things are internal.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n---------\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>",
          "is_bot": false,
          "headline": "Adding DaprSpringBootTest and DaprSidecarContainer annotation for eas…",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-01-06T19:32:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "42fba18714236033f9f81d5c3f91498973333400",
          "body": "* Bringing Durable Task Java as a Maven module inside the Java SDK (#1575)\n\n* fixing checkstyle and javadocs\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* Replace openjdk:17-jdk-slim to eclipse-temurin:17-jdk-jammy (#1574)\n\nSigned-off-by: Matheus Cruz <matheuscruz.dev@gmail.com>\nSigned-off-by: sala\n[…]\ngithub.com>\nCo-authored-by: wlfgang <14792753+wlfgang@users.noreply.github.com>\nCo-authored-by: wlfgang <wlfgang@westridgesystems.com>\nCo-authored-by: Marc Duiker <marcduiker@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add Cryptography APIs to the Java SDK (#1599)",
          "author_name": "Siri Varma Vegiraju",
          "author_login": "siri-varma",
          "committed_at": "2026-01-06T17:42:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "001a4d2acb9c18520f5117d57988ca91de587d8d",
          "body": "* job promotion to DaprClient\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* updating Jobs readme\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* fixing IT tests for Jobs\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* Remove SDK docs due to migration to main Docs repo (#1593)\n\n* Remove SDK docs due t\n[…]\nom>\nCo-authored-by: Marc Duiker <marcduiker@users.noreply.github.com>\nCo-authored-by: Siri Varma Vegiraju <siri.varma@outlook.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Jobs promotion to DaprClient (#1602)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2026-01-05T15:04:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "304fb2b0dc8a23c2e4c242b062a81b773ac00b35",
          "body": "Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 6.\n- [Release notes](https://github.com/actions/upload-artifact/releases)\n- [Commits](https://github.com/actions/upload-artifact/compare/v4...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/upload-artifac\n[…]\ned-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Cassie Coyle <cassie.i.coyle@gmail.com>\nCo-authored-by: Dapr Bot <56698301+dapr-bot@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/upload-artifact from 4 to 6 (#1606)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-01-03T03:35:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18ea036b939fab3adbada19b36c9291b1b323e17",
          "body": "* Create Dapr WaitStrategy to improve ITs ergonomics\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Improve unit tests naming and coverage\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Fix a potential NPE and remove extra \"for...\" methods for pubsub and topic.\n\nSigned-off-by\n[…]\nby: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n* Disable pubsub outbox for now.\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>\n\n---------\n\nSigned-off-by: Artur Ciocanu <artur.ciocanu@gmail.com>",
          "is_bot": false,
          "headline": "Create Dapr WaitStrategy to improve ITs ergonomics (#1609)",
          "author_name": "artur-ciocanu",
          "author_login": "artur-ciocanu",
          "committed_at": "2026-01-03T02:15:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9508747a9fc30dad81e9e7e5c78d4ac25e29308e",
          "body": "Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5.5.1 to 5.5.2.\n- [Release notes](https://github.com/codecov/codecov-action/releases)\n- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/codecov/codecov-action/c\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump codecov/codecov-action from 5.5.1 to 5.5.2 (#1607)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-16T22:34:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fe698b2658a9d7645b0172a9f370a1c2ddaa68c",
          "body": "* fixing checkstyle and javadocs\n\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* Replace openjdk:17-jdk-slim to eclipse-temurin:17-jdk-jammy (#1574)\n\nSigned-off-by: Matheus Cruz <matheuscruz.dev@gmail.com>\nSigned-off-by: salaboy <Salaboy@gmail.com>\n\n* Align Java API with other languages (#1560)\n\n* Al\n[…]\ngithub.com>\nCo-authored-by: wlfgang <14792753+wlfgang@users.noreply.github.com>\nCo-authored-by: wlfgang <wlfgang@westridgesystems.com>\nCo-authored-by: Marc Duiker <marcduiker@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Bringing Durable Task Java as a Maven module inside the Java SDK (#1575)",
          "author_name": "salaboy",
          "author_login": "salaboy",
          "committed_at": "2025-12-13T04:06:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 37,
      "commits_last_year": 155,
      "latest_release_at": "2026-07-20T09:32:51Z",
      "latest_release_tag": "v1.18.1",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 42,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 34
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "io.dapr:dapr-sdk",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/dapr-sdk",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 119,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:47Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "io.dapr:dapr-sdk-actors",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/dapr-sdk-actors",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 119,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:47Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "io.dapr:dapr-sdk-autogen",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/dapr-sdk-autogen",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 119,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:45Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "io.dapr:dapr-sdk-workflows",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/dapr-sdk-workflows",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 65,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:55Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "io.dapr:dapr-sdk-springboot",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/dapr-sdk-springboot",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 112,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:47Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "io.dapr:durabletask-client",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/durabletask-client",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 29,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:47Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "io.dapr:testcontainers-dapr",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/io.dapr/testcontainers-dapr",
          "is_deprecated": false,
          "latest_version": "1.18.1",
          "repository_url": null,
          "versions_count": 53,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T10:14:52Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 229,
      "stars": 299,
      "watchers": 25,
      "fork_history": {
        "days": [
          {
            "date": "2019-10-17",
            "count": 1
          },
          {
            "date": "2019-10-18",
            "count": 1
          },
          {
            "date": "2019-10-26",
            "count": 1
          },
          {
            "date": "2019-11-20",
            "count": 1
          },
          {
            "date": "2019-12-06",
            "count": 1
          },
          {
            "date": "2019-12-15",
            "count": 1
          },
          {
            "date": "2019-12-19",
            "count": 1
          },
          {
            "date": "2020-01-24",
            "count": 1
          },
          {
            "date": "2020-01-28",
            "count": 1
          },
          {
            "date": "2020-02-05",
            "count": 3
          },
          {
            "date": "2020-02-06",
            "count": 2
          },
          {
            "date": "2020-03-10",
            "count": 1
          },
          {
            "date": "2020-03-19",
            "count": 1
          },
          {
            "date": "2020-04-12",
            "count": 1
          },
          {
            "date": "2020-04-13",
            "count": 1
          },
          {
            "date": "2020-04-19",
            "count": 1
          },
          {
            "date": "2020-05-07",
            "count": 1
          },
          {
            "date": "2020-05-20",
            "count": 2
          },
          {
            "date": "2020-05-31",
            "count": 1
          },
          {
            "date": "2020-08-01",
            "count": 1
          },
          {
            "date": "2020-08-17",
            "count": 1
          },
          {
            "date": "2020-08-29",
            "count": 1
          },
          {
            "date": "2020-09-18",
            "count": 1
          },
          {
            "date": "2020-10-07",
            "count": 1
          },
          {
            "date": "2020-11-09",
            "count": 1
          },
          {
            "date": "2020-12-10",
            "count": 1
          },
          {
            "date": "2021-01-20",
            "count": 1
          },
          {
            "date": "2021-01-22",
            "count": 1
          },
          {
            "date": "2021-01-26",
            "count": 1
          },
          {
            "date": "2021-01-31",
            "count": 1
          },
          {
            "date": "2021-02-04",
            "count": 1
          },
          {
            "date": "2021-02-24",
            "count": 1
          },
          {
            "date": "2021-02-26",
            "count": 1
          },
          {
            "date": "2021-02-27",
            "count": 2
          },
          {
            "date": "2021-03-03",
            "count": 1
          },
          {
            "date": "2021-03-08",
            "count": 1
          },
          {
            "date": "2021-03-11",
            "count": 1
          },
          {
            "date": "2021-03-13",
            "count": 1
          },
          {
            "date": "2021-03-23",
            "count": 1
          },
          {
            "date": "2021-03-31",
            "count": 1
          },
          {
            "date": "2021-04-01",
            "count": 1
          },
          {
            "date": "2021-04-06",
            "count": 1
          },
          {
            "date": "2021-04-13",
            "count": 1
          },
          {
            "date": "2021-04-14",
            "count": 1
          },
          {
            "date": "2021-05-03",
            "count": 1
          },
          {
            "date": "2021-05-24",
            "count": 1
          },
          {
            "date": "2021-05-26",
            "count": 1
          },
          {
            "date": "2021-05-31",
            "count": 1
          },
          {
            "date": "2021-06-03",
            "count": 2
          },
          {
            "date": "2021-06-07",
            "count": 2
          },
          {
            "date": "2021-06-29",
            "count": 1
          },
          {
            "date": "2021-07-03",
            "count": 1
          },
          {
            "date": "2021-07-15",
            "count": 1
          },
          {
            "date": "2021-07-16",
            "count": 1
          },
          {
            "date": "2021-07-29",
            "count": 1
          },
          {
            "date": "2021-08-09",
            "count": 1
          },
          {
            "date": "2021-08-12",
            "count": 1
          },
          {
            "date": "2021-08-17",
            "count": 1
          },
          {
            "date": "2021-08-19",
            "count": 2
          },
          {
            "date": "2021-08-22",
            "count": 2
          },
          {
            "date": "2021-08-24",
            "count": 2
          },
          {
            "date": "2021-08-30",
            "count": 1
          },
          {
            "date": "2021-08-31",
            "count": 2
          },
          {
            "date": "2021-09-06",
            "count": 1
          },
          {
            "date": "2021-09-09",
            "count": 1
          },
          {
            "date": "2021-09-10",
            "count": 1
          },
          {
            "date": "2021-09-13",
            "count": 1
          },
          {
            "date": "2021-09-22",
            "count": 1
          },
          {
            "date": "2021-10-18",
            "count": 1
          },
          {
            "date": "2021-10-19",
            "count": 1
          },
          {
            "date": "2021-10-20",
            "count": 2
          },
          {
            "date": "2021-10-27",
            "count": 1
          },
          {
            "date": "2021-10-30",
            "count": 1
          },
          {
            "date": "2021-11-09",
            "count": 1
          },
          {
            "date": "2021-11-10",
            "count": 1
          },
          {
            "date": "2021-11-15",
            "count": 1
          },
          {
            "date": "2021-11-16",
            "count": 1
          },
          {
            "date": "2021-11-19",
            "count": 1
          },
          {
            "date": "2021-11-26",
            "count": 1
          },
          {
            "date": "2021-12-06",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2021-12-21",
            "count": 1
          },
          {
            "date": "2022-01-10",
            "count": 1
          },
          {
            "date": "2022-01-14",
            "count": 1
          },
          {
            "date": "2022-01-25",
            "count": 1
          },
          {
            "date": "2022-01-26",
            "count": 1
          },
          {
            "date": "2022-02-17",
            "count": 1
          },
          {
            "date": "2022-02-18",
            "count": 1
          },
          {
            "date": "2022-02-23",
            "count": 1
          },
          {
            "date": "2022-03-03",
            "count": 1
          },
          {
            "date": "2022-03-08",
            "count": 2
          },
          {
            "date": "2022-03-29",
            "count": 1
          },
          {
            "date": "2022-03-30",
            "count": 1
          },
          {
            "date": "2022-04-18",
            "count": 1
          },
          {
            "date": "2022-04-21",
            "count": 1
          },
          {
            "date": "2022-04-26",
            "count": 2
          },
          {
            "date": "2022-04-30",
            "count": 1
          },
          {
            "date": "2022-05-11",
            "count": 1
          },
          {
            "date": "2022-05-19",
            "count": 1
          },
          {
            "date": "2022-05-23",
            "count": 1
          },
          {
            "date": "2022-05-30",
            "count": 1
          },
          {
            "date": "2022-06-07",
            "count": 1
          },
          {
            "date": "2022-06-11",
            "count": 1
          },
          {
            "date": "2022-06-14",
            "count": 1
          },
          {
            "date": "2022-06-17",
            "count": 1
          },
          {
            "date": "2022-06-22",
            "count": 1
          },
          {
            "date": "2022-06-23",
            "count": 1
          },
          {
            "date": "2022-08-11",
            "count": 1
          },
          {
            "date": "2022-08-15",
            "count": 1
          },
          {
            "date": "2022-08-26",
            "count": 1
          },
          {
            "date": "2022-08-30",
            "count": 1
          },
          {
            "date": "2022-09-22",
            "count": 1
          },
          {
            "date": "2022-09-28",
            "count": 1
          },
          {
            "date": "2022-10-24",
            "count": 1
          },
          {
            "date": "2022-10-25",
            "count": 1
          },
          {
            "date": "2022-11-03",
            "count": 1
          },
          {
            "date": "2022-11-21",
            "count": 1
          },
          {
            "date": "2022-11-24",
            "count": 1
          },
          {
            "date": "2022-12-08",
            "count": 1
          },
          {
            "date": "2022-12-15",
            "count": 1
          },
          {
            "date": "2022-12-27",
            "count": 1
          },
          {
            "date": "2023-01-06",
            "count": 1
          },
          {
            "date": "2023-01-29",
            "count": 1
          },
          {
            "date": "2023-01-30",
            "count": 1
          },
          {
            "date": "2023-02-03",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-03-08",
            "count": 1
          },
          {
            "date": "2023-03-09",
            "count": 1
          },
          {
            "date": "2023-03-24",
            "count": 1
          },
          {
            "date": "2023-04-03",
            "count": 1
          },
          {
            "date": "2023-04-11",
            "count": 1
          },
          {
            "date": "2023-04-19",
            "count": 1
          },
          {
            "date": "2023-04-23",
            "count": 2
          },
          {
            "date": "2023-04-24",
            "count": 1
          },
          {
            "date": "2023-05-03",
            "count": 1
          },
          {
            "date": "2023-05-26",
            "count": 1
          },
          {
            "date": "2023-06-01",
            "count": 1
          },
          {
            "date": "2023-06-07",
            "count": 1
          },
          {
            "date": "2023-06-16",
            "count": 1
          },
          {
            "date": "2023-06-24",
            "count": 1
          },
          {
            "date": "2023-07-13",
            "count": 1
          },
          {
            "date": "2023-07-29",
            "count": 1
          },
          {
            "date": "2023-08-03",
            "count": 1
          },
          {
            "date": "2023-08-23",
            "count": 1
          },
          {
            "date": "2023-08-30",
            "count": 1
          },
          {
            "date": "2023-09-08",
            "count": 1
          },
          {
            "date": "2023-09-10",
            "count": 1
          },
          {
            "date": "2023-09-16",
            "count": 1
          },
          {
            "date": "2023-09-20",
            "count": 1
          },
          {
            "date": "2023-09-22",
            "count": 1
          },
          {
            "date": "2023-09-23",
            "count": 1
          },
          {
            "date": "2023-10-19",
            "count": 1
          },
          {
            "date": "2023-10-31",
            "count": 1
          },
          {
            "date": "2023-11-11",
            "count": 1
          },
          {
            "date": "2024-01-18",
            "count": 1
          },
          {
            "date": "2024-01-19",
            "count": 1
          },
          {
            "date": "2024-01-26",
            "count": 1
          },
          {
            "date": "2024-01-30",
            "count": 1
          },
          {
            "date": "2024-02-07",
            "count": 1
          },
          {
            "date": "2024-02-18",
            "count": 1
          },
          {
            "date": "2024-02-20",
            "count": 1
          },
          {
            "date": "2024-02-28",
            "count": 1
          },
          {
            "date": "2024-03-06",
            "count": 1
          },
          {
            "date": "2024-04-10",
            "count": 1
          },
          {
            "date": "2024-05-17",
            "count": 1
          },
          {
            "date": "2024-05-31",
            "count": 1
          },
          {
            "date": "2024-06-06",
            "count": 1
          },
          {
            "date": "2024-06-19",
            "count": 1
          },
          {
            "date": "2024-07-20",
            "count": 1
          },
          {
            "date": "2024-08-21",
            "count": 1
          },
          {
            "date": "2024-09-02",
            "count": 1
          },
          {
            "date": "2024-09-11",
            "count": 1
          },
          {
            "date": "2024-09-17",
            "count": 1
          },
          {
            "date": "2024-09-26",
            "count": 1
          },
          {
            "date": "2024-11-14",
            "count": 1
          },
          {
            "date": "2025-01-14",
            "count": 1
          },
          {
            "date": "2025-01-21",
            "count": 1
          },
          {
            "date": "2025-02-04",
            "count": 1
          },
          {
            "date": "2025-03-03",
            "count": 1
          },
          {
            "date": "2025-03-04",
            "count": 1
          },
          {
            "date": "2025-03-05",
            "count": 1
          },
          {
            "date": "2025-03-24",
            "count": 1
          },
          {
            "date": "2025-03-28",
            "count": 1
          },
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-04-03",
            "count": 2
          },
          {
            "date": "2025-04-28",
            "count": 1
          },
          {
            "date": "2025-05-02",
            "count": 1
          },
          {
            "date": "2025-05-14",
            "count": 1
          },
          {
            "date": "2025-05-15",
            "count": 1
          },
          {
            "date": "2025-06-06",
            "count": 1
          },
          {
            "date": "2025-06-20",
            "count": 1
          },
          {
            "date": "2025-07-04",
            "count": 2
          },
          {
            "date": "2025-07-12",
            "count": 1
          },
          {
            "date": "2025-07-18",
            "count": 1
          },
          {
            "date": "2025-08-04",
            "count": 1
          },
          {
            "date": "2025-08-17",
            "count": 1
          },
          {
            "date": "2025-09-09",
            "count": 1
          },
          {
            "date": "2025-10-24",
            "count": 1
          },
          {
            "date": "2025-12-24",
            "count": 1
          },
          {
            "date": "2026-01-21",
            "count": 1
          },
          {
            "date": "2026-02-12",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-03-09",
            "count": 1
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-05-02",
            "count": 1
          },
          {
            "date": "2026-06-30",
            "count": 1
          },
          {
            "date": "2026-07-19",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 224,
        "total_forks": 229
      },
      "star_history": null,
      "open_issues_and_prs": 133
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "mise.toml"
      ],
      "api_schema_files": [
        "examples/proto/helloworld.proto",
        "sdk-tests/proto/methodinvokeservice.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "dapr-spring/dapr-spring-bom/pom.xml",
        "dapr-spring/dapr-spring-boot-autoconfigure/pom.xml",
        "dapr-spring/dapr-spring-boot-observation/pom.xml",
        "dapr-spring/dapr-spring-boot-properties/pom.xml",
        "dapr-spring/dapr-spring-boot-starters/dapr-spring-boot-starter-test/pom.xml",
        "dapr-spring/dapr-spring-boot-starters/dapr-spring-boot-starter/pom.xml",
        "dapr-spring/dapr-spring-boot-tests/pom.xml",
        "dapr-spring/dapr-spring-data/pom.xml",
        "dapr-spring/dapr-spring-messaging/pom.xml",
        "dapr-spring/dapr-spring-workflows/pom.xml",
        "dapr-spring/pom.xml",
        "durabletask-client/pom.xml",
        "examples/pom.xml",
        "pom.xml",
        "sdk-actors/pom.xml",
        "sdk-autogen/pom.xml",
        "sdk-bom/pom.xml",
        "sdk-springboot/pom.xml",
        "sdk-tests/pom.xml",
        "sdk-workflows/pom.xml",
        "sdk/pom.xml",
        "spring-boot-examples/consumer-app/pom.xml",
        "spring-boot-examples/pom.xml",
        "spring-boot-examples/producer-app/pom.xml",
        "spring-boot-examples/workflows/multi-app/orchestrator/pom.xml",
        "spring-boot-examples/workflows/multi-app/pom.xml",
        "spring-boot-examples/workflows/multi-app/worker-one/pom.xml",
        "spring-boot-examples/workflows/multi-app/worker-two/pom.xml",
        "spring-boot-examples/workflows/patterns/pom.xml",
        "spring-boot-examples/workflows/pom.xml",
        "spring-boot-examples/workflows/versioning/full-version-worker-one/pom.xml",
        "spring-boot-examples/workflows/versioning/full-version-worker-two/pom.xml",
        "spring-boot-examples/workflows/versioning/patch-version-worker-one/pom.xml",
        "spring-boot-examples/workflows/versioning/patch-version-worker-two/pom.xml",
        "spring-boot-examples/workflows/versioning/pom.xml",
        "spring-boot-examples/workflows/versioning/version-orchestrator/pom.xml",
        "spring-boot-sdk-tests/pom.xml",
        "testcontainers-dapr/pom.xml"
      ],
      "largest_source_bytes": 3725456,
      "source_files_sampled": 915,
      "oversized_source_files": 7,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "dapr-spring/pom.xml",
        "durabletask-client/pom.xml",
        "examples/pom.xml",
        "pom.xml",
        "sdk-actors/pom.xml",
        "sdk-autogen/pom.xml",
        "sdk-bom/pom.xml",
        "sdk-springboot/pom.xml",
        "sdk-tests/pom.xml",
        "sdk-workflows/pom.xml",
        "sdk/pom.xml",
        "spring-boot-examples/pom.xml",
        "spring-boot-sdk-tests/pom.xml",
        "testcontainers-dapr/pom.xml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "io.netty:netty-codec",
            "direct": false,
            "version": "4.1.135.Final",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-558v-64gr-wgg4"
            ],
            "fixed_version": "4.2.16.Final",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "io.netty:netty-codec-http",
            "direct": false,
            "version": "4.1.135.Final",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-4mp9-239f-g9hg",
              "GHSA-6cqp-g7gg-8hr5",
              "GHSA-6jqx-86gh-f27w",
              "GHSA-gcjf-9mgh-3p7g",
              "GHSA-jppx-w49h-x2qq",
              "GHSA-mvh2-crg5-v77c",
              "GHSA-q4f6-jm68-57ww"
            ],
            "fixed_version": "4.2.16.Final",
            "advisory_count": 7,
            "oldest_advisory_days": 1
          },
          {
            "name": "io.netty:netty-codec-http2",
            "direct": false,
            "version": "4.1.135.Final",
            "severity": "low",
            "ecosystem": "maven",
            "cvss_score": 0,
            "advisory_ids": [
              "GHSA-c69g-56f8-xwqj"
            ],
            "fixed_version": "4.2.16.Final",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 1,
          "high": 2
        },
        "advisory_count": 9,
        "affected_count": 3,
        "assessed_count": 40,
        "malicious_count": 0,
        "assessed_package": "maven:io.dapr:dapr-sdk@1.18.1",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "maven"
      ],
      "dependencies": [
        {
          "name": "io.dapr.spring:dapr-spring-data",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-messaging",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-workflows",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-autoconfigure",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-properties",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-observation",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-tests",
          "manifest": "dapr-spring/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.grpc:grpc-protobuf",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-stub",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-netty",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.google.protobuf:protobuf-java",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-core",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-databind",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-annotations",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.fasterxml.jackson.datatype:jackson-datatype-jsr310",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.commons:commons-lang3",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.micrometer:micrometer-observation",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-api",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-context",
          "manifest": "durabletask-client/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.netty:netty-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${netty.version}"
        },
        {
          "name": "io.grpc:grpc-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${grpc.version}"
        },
        {
          "name": "com.fasterxml.jackson:jackson-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jackson.version}"
        },
        {
          "name": "org.junit:junit-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${junit-bom.version}"
        },
        {
          "name": "org.springframework.boot:spring-boot-dependencies",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${springboot.version}"
        },
        {
          "name": "org.testcontainers:testcontainers-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers.version}"
        },
        {
          "name": "com.google.protobuf:protobuf-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${protobuf.version}"
        },
        {
          "name": "io.opentelemetry:opentelemetry-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${opentelemetry.version}"
        },
        {
          "name": "org.apache.commons:commons-compress",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${commons-compress.version}"
        },
        {
          "name": "commons-codec:commons-codec",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.17.2"
        },
        {
          "name": "org.testcontainers:testcontainers",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers.version}"
        },
        {
          "name": "org.testcontainers:testcontainers-junit-jupiter",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers.version}"
        },
        {
          "name": "org.testcontainers:testcontainers-kafka",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers.version}"
        },
        {
          "name": "org.testcontainers:testcontainers-postgresql",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers.version}"
        },
        {
          "name": "org.testcontainers:testcontainers-rabbitmq",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers.version}"
        },
        {
          "name": "org.slf4j:slf4j-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.mockito:mockito-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${mockito.version}"
        },
        {
          "name": "org.jetbrains.kotlin:kotlin-stdlib",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${kotlin.version}"
        },
        {
          "name": "org.yaml:snakeyaml",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${snakeyaml.version}"
        },
        {
          "name": "io.dapr:dapr-sdk",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.rest-assured:rest-assured",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${rest-assured.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-starter",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-starter-test",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:testcontainers-dapr",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "jakarta.annotation:jakarta.annotation-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jakarta.annotation.version}"
        },
        {
          "name": "javax.annotation:javax.annotation-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${javax.annotation.version}"
        },
        {
          "name": "org.apache.commons:commons-lang3",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${commons-lang.version}"
        },
        {
          "name": "commons-cli:commons-cli",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${commons-cli.version}"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${commons-io.version}"
        },
        {
          "name": "io.zipkin.reporter2:zipkin-reporter",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${zipkin.version}"
        },
        {
          "name": "io.zipkin.reporter2:zipkin-sender-urlconnection",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${zipkin.version}"
        },
        {
          "name": "io.dapr:dapr-sdk-actors",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:dapr-sdk-springboot",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:dapr-sdk-workflows",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "org.wiremock:wiremock-standalone",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${wiremock.version}"
        },
        {
          "name": "commons-validator:commons-validator",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${commons-validator.version}"
        },
        {
          "name": "com.jayway.jsonpath:json-path",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${json-path.version}"
        },
        {
          "name": "com.evanlennick:retry4j",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${retry4j.version}"
        },
        {
          "name": "com.github.stefanbirkner:system-rules",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${system-rules.version}"
        },
        {
          "name": "uk.org.webcompere:system-stubs-jupiter",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${system-stubs.version}"
        },
        {
          "name": "org.mockito:mockito-inline",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${mockito-inline.version}"
        },
        {
          "name": "org.junit.platform:junit-platform-console-standalone",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${junit-platform-console.version}"
        },
        {
          "name": "org.junit.jupiter:junit-jupiter",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${junit-bom.version}"
        },
        {
          "name": "org.junit.jupiter:junit-jupiter-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${junit-bom.version}"
        },
        {
          "name": "org.junit.jupiter:junit-jupiter-engine",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${junit-bom.version}"
        },
        {
          "name": "org.junit.jupiter:junit-jupiter-params",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${junit-bom.version}"
        },
        {
          "name": "io.projectreactor:reactor-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${reactor.version}"
        },
        {
          "name": "com.redis:testcontainers-redis",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${testcontainers-redis.version}"
        },
        {
          "name": "io.github.microcks:microcks-testcontainers",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${microcks.version}"
        },
        {
          "name": "org.assertj:assertj-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${assertj.version}"
        },
        {
          "name": "com.puppycrawl.tools:checkstyle",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${checkstyle.version}"
        },
        {
          "name": "io.dapr:dapr-sdk",
          "manifest": "sdk-actors/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "com.fasterxml.jackson.datatype:jackson-datatype-jsr310",
          "manifest": "sdk-actors/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-netty",
          "manifest": "sdk-autogen/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-protobuf",
          "manifest": "sdk-autogen/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-stub",
          "manifest": "sdk-autogen/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.dapr:dapr-sdk-autogen",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:dapr-sdk",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:dapr-sdk-actors",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:dapr-sdk-workflows",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:testcontainers-dapr",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.dapr:durabletask-client",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${dapr.sdk.version}"
        },
        {
          "name": "io.netty:netty-bom",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${netty.version}"
        },
        {
          "name": "com.fasterxml.jackson:jackson-bom",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jackson.version}"
        },
        {
          "name": "org.apache.commons:commons-compress",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${commons-compress.version}"
        },
        {
          "name": "commons-codec:commons-codec",
          "manifest": "sdk-bom/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.17.2"
        },
        {
          "name": "io.dapr:dapr-sdk",
          "manifest": "sdk-springboot/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.dapr:dapr-sdk-actors",
          "manifest": "sdk-springboot/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.springframework:spring-web",
          "manifest": "sdk-springboot/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.springframework:spring-context",
          "manifest": "sdk-springboot/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.springframework.boot:spring-boot-starter",
          "manifest": "sdk-springboot/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.springframework.boot:spring-boot-configuration-processor",
          "manifest": "sdk-springboot/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.netty:netty-bom",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${netty.version}"
        },
        {
          "name": "org.springframework.boot:spring-boot-dependencies",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${springboot4.version}"
        },
        {
          "name": "commons-cli:commons-cli",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-protobuf",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-stub",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-api",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-sdk",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-api",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-context",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-sdk-common",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-sdk-trace",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-sdk-metrics",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-exporter-common",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-exporter-logging",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.opentelemetry:opentelemetry-exporter-zipkin",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.zipkin.reporter2:zipkin-reporter",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.zipkin.reporter2:zipkin-sender-urlconnection",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.dapr.spring:dapr-spring-boot-starter",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.testcontainers:testcontainers-junit-jupiter",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.springframework.data:spring-data-keyvalue",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "jakarta.annotation:jakarta.annotation-api",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "javax.annotation:javax.annotation-api",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "jakarta.servlet:jakarta.servlet-api",
          "manifest": "sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.dapr:dapr-sdk",
          "manifest": "sdk-workflows/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.parent.version}"
        },
        {
          "name": "io.dapr:durabletask-client",
          "manifest": "sdk-workflows/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.parent.version}"
        },
        {
          "name": "io.opentelemetry:opentelemetry-api",
          "manifest": "sdk-workflows/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.slf4j:slf4j-api",
          "manifest": "sdk/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.dapr:dapr-sdk-autogen",
          "manifest": "sdk/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-databind",
          "manifest": "sdk/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.google.protobuf:protobuf-java-util",
          "manifest": "sdk/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.projectreactor:reactor-core",
          "manifest": "sdk/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.grpc:grpc-netty",
          "manifest": "sdk/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "tools.jackson:jackson-bom",
          "manifest": "spring-boot-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.1.1"
        },
        {
          "name": "io.netty:netty-bom",
          "manifest": "spring-boot-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${netty.version}"
        },
        {
          "name": "org.springframework.boot:spring-boot-dependencies",
          "manifest": "spring-boot-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${springboot4.version}"
        },
        {
          "name": "org.springframework.boot:spring-boot-starter-webmvc",
          "manifest": "spring-boot-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${springboot4.version}"
        },
        {
          "name": "org.springframework.boot:spring-boot-starter-restclient",
          "manifest": "spring-boot-examples/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${springboot4.version}"
        },
        {
          "name": "io.netty:netty-bom",
          "manifest": "spring-boot-sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${netty.version}"
        },
        {
          "name": "org.springframework.boot:spring-boot-dependencies",
          "manifest": "spring-boot-sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${springboot4.version}"
        },
        {
          "name": "org.testcontainers:testcontainers-junit-jupiter",
          "manifest": "spring-boot-sdk-tests/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.yaml:snakeyaml",
          "manifest": "testcontainers-dapr/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.testcontainers:testcontainers",
          "manifest": "testcontainers-dapr/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "commons-codec:commons-codec",
          "manifest": "testcontainers-dapr/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-databind",
          "manifest": "testcontainers-dapr/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "com.evanlennick:retry4j",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.evanlennick:retry4j",
            "direct": true,
            "version": "0.15.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-annotations",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.datatype:jackson-datatype-jsr310",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson:jackson-bom",
            "direct": true,
            "version": "2.21.2",
            "ecosystem": "maven"
          },
          {
            "name": "com.github.stefanbirkner:system-rules",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.github.stefanbirkner:system-rules",
            "direct": true,
            "version": "1.19.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.protobuf:protobuf-bom",
            "direct": true,
            "version": "3.25.5",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.protobuf:protobuf-java",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.google.protobuf:protobuf-java-util",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.jayway.jsonpath:json-path",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.jayway.jsonpath:json-path",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.puppycrawl.tools:checkstyle",
            "direct": true,
            "version": "10.17.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.redis:testcontainers-redis",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.redis:testcontainers-redis",
            "direct": true,
            "version": "2.2.4",
            "ecosystem": "maven"
          },
          {
            "name": "commons-cli:commons-cli",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-cli:commons-cli",
            "direct": true,
            "version": "1.9.0",
            "ecosystem": "maven"
          },
          {
            "name": "commons-codec:commons-codec",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-codec:commons-codec",
            "direct": true,
            "version": "1.17.2",
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": true,
            "version": "2.14.0",
            "ecosystem": "maven"
          },
          {
            "name": "commons-validator:commons-validator",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-validator:commons-validator",
            "direct": true,
            "version": "1.7",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-autoconfigure",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-autoconfigure",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-observation",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-observation",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-properties",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-properties",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-starter",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-starter",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-starter-test",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-starter-test",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-tests",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-boot-tests",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-data",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-data",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-messaging",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-messaging",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-workflows",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr.spring:dapr-spring-workflows",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-actors",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-actors",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-autogen",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-springboot",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-springboot",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-workflows",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-workflows",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:durabletask-client",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:durabletask-client",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:testcontainers-dapr",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:testcontainers-dapr",
            "direct": true,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.github.microcks:microcks-testcontainers",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.github.microcks:microcks-testcontainers",
            "direct": true,
            "version": "0.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-bom",
            "direct": true,
            "version": "1.79.0",
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-netty",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-protobuf",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-stub",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.micrometer:micrometer-observation",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.netty:netty-bom",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.netty:netty-bom",
            "direct": true,
            "version": "4.1.132",
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-bom",
            "direct": true,
            "version": "1.41.0",
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-context",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-exporter-common",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-exporter-logging",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-exporter-zipkin",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-sdk",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-sdk-common",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-sdk-metrics",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.opentelemetry:opentelemetry-sdk-trace",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.projectreactor:reactor-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.projectreactor:reactor-core",
            "direct": true,
            "version": "3.5.12",
            "ecosystem": "maven"
          },
          {
            "name": "io.rest-assured:rest-assured",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.rest-assured:rest-assured",
            "direct": true,
            "version": "5.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.zipkin.reporter2:zipkin-reporter",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.zipkin.reporter2:zipkin-reporter",
            "direct": true,
            "version": "3.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "io.zipkin.reporter2:zipkin-sender-urlconnection",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.zipkin.reporter2:zipkin-sender-urlconnection",
            "direct": true,
            "version": "3.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.annotation:jakarta.annotation-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.annotation:jakarta.annotation-api",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.servlet:jakarta.servlet-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "javax.annotation:javax.annotation-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "javax.annotation:javax.annotation-api",
            "direct": true,
            "version": "1.3.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-compress",
            "direct": true,
            "version": "1.26.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-lang3",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-lang3",
            "direct": true,
            "version": "3.18.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.assertj:assertj-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.assertj:assertj-core",
            "direct": true,
            "version": "3.27.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.jetbrains.kotlin:kotlin-stdlib",
            "direct": true,
            "version": "2.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter",
            "direct": true,
            "version": "5.11.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-api",
            "direct": true,
            "version": "5.11.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-engine",
            "direct": true,
            "version": "5.11.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-params",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-params",
            "direct": true,
            "version": "5.11.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.platform:junit-platform-console-standalone",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.platform:junit-platform-console-standalone",
            "direct": true,
            "version": "1.7.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit:junit-bom",
            "direct": true,
            "version": "5.11.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-core",
            "direct": true,
            "version": "3.11.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-inline",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-inline",
            "direct": true,
            "version": "4.2.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": "2.0.9",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-configuration-processor",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-dependencies",
            "direct": true,
            "version": "4.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-restclient",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-restclient",
            "direct": true,
            "version": "4.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-webmvc",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-webmvc",
            "direct": true,
            "version": "4.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.data:spring-data-keyvalue",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework:spring-context",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework:spring-web",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers",
            "direct": true,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-bom",
            "direct": true,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-junit-jupiter",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-junit-jupiter",
            "direct": true,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-kafka",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-kafka",
            "direct": true,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-postgresql",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-postgresql",
            "direct": true,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-rabbitmq",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-rabbitmq",
            "direct": true,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.wiremock:wiremock-standalone",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.wiremock:wiremock-standalone",
            "direct": true,
            "version": "3.9.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.yaml:snakeyaml",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.yaml:snakeyaml",
            "direct": true,
            "version": "2.0",
            "ecosystem": "maven"
          },
          {
            "name": "tools.jackson:jackson-bom",
            "direct": true,
            "version": "3.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "uk.org.webcompere:system-stubs-jupiter",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "uk.org.webcompere:system-stubs-jupiter",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.dataformat:jackson-dataformat-xml",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.github.spotbugs:spotbugs-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.github.spotbugs:spotbugs-maven-plugin",
            "direct": false,
            "version": "4.8.2.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.googlecode.maven-download-plugin:download-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.googlecode.maven-download-plugin:download-maven-plugin",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:dapr-sdk-bom",
            "direct": false,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:worker-one",
            "direct": false,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.dapr:worker-two",
            "direct": false,
            "version": "1.19.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-inprocess",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.grpc:grpc-testing",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.micrometer:micrometer-observation-test",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.projectreactor:reactor-test",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.projectreactor:reactor-test",
            "direct": false,
            "version": "3.5.12",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-checkstyle-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-checkstyle-plugin",
            "direct": false,
            "version": "3.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": "3.13.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-failsafe-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-failsafe-plugin",
            "direct": false,
            "version": "3.5.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-gpg-plugin",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jar-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": "3.7.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-project-info-reports-plugin",
            "direct": false,
            "version": "3.7.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-resources-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-resources-plugin",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-site-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-site-plugin",
            "direct": false,
            "version": "3.12.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-source-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-source-plugin",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.jacoco:jacoco-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.jacoco:jacoco-maven-plugin",
            "direct": false,
            "version": "0.8.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-migrationsupport",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.platform:junit-platform-commons",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.platform:junit-platform-engine",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-junit-jupiter",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.sonatype.plugins:nexus-staging-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.sonatype.plugins:nexus-staging-maven-plugin",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-autoconfigure",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-autoconfigure-processor",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-jackson",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-maven-plugin",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-actuator",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-test",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-web",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-webmvc-test",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-starter-webmvc-test",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.boot:spring-boot-testcontainers",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework.data:spring-data-commons",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.springframework:spring-beans",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-mysql",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-mysql",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-toxiproxy",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testcontainers:testcontainers-toxiproxy",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.xolstice.maven.plugins:protobuf-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.xolstice.maven.plugins:protobuf-maven-plugin",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "redis.clients:jedis",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "redis.clients:jedis",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "tools.jackson.core:jackson-databind",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 201,
        "direct_count": 139,
        "indirect_count": 62
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 18,
        "merged_prs": 919,
        "open_issues": 115,
        "closed_ratio": 0.825,
        "closed_issues": 543,
        "closed_unmerged_prs": 186
      },
      "bus_factor": 3,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "artursouza",
          "commits": 257,
          "avatar_url": "https://avatars.githubusercontent.com/u/130954?v=4"
        },
        {
          "type": "User",
          "login": "javier-aliaga",
          "commits": 56,
          "avatar_url": "https://avatars.githubusercontent.com/u/209620894?v=4"
        },
        {
          "type": "User",
          "login": "artur-ciocanu",
          "commits": 51,
          "avatar_url": "https://avatars.githubusercontent.com/u/743192?v=4"
        },
        {
          "type": "User",
          "login": "salaboy",
          "commits": 50,
          "avatar_url": "https://avatars.githubusercontent.com/u/271966?v=4"
        },
        {
          "type": "User",
          "login": "cicoyle",
          "commits": 38,
          "avatar_url": "https://avatars.githubusercontent.com/u/25733780?v=4"
        },
        {
          "type": "User",
          "login": "siri-varma",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/15071686?v=4"
        },
        {
          "type": "User",
          "login": "dapr-bot",
          "commits": 20,
          "avatar_url": "https://avatars.githubusercontent.com/u/56698301?v=4"
        },
        {
          "type": "User",
          "login": "mcruzdev",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/56329339?v=4"
        },
        {
          "type": "User",
          "login": "yaron2",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/16295283?v=4"
        },
        {
          "type": "User",
          "login": "wcs1only",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/7329298?v=4"
        }
      ],
      "contributors_sampled": 96,
      "top_contributor_share": 0.354
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "automerge-bot.yml",
        "backport.yaml",
        "build.yml",
        "create-release.yml",
        "dapr_bot.yml",
        "fossa.yml",
        "validate-docs.yml",
        "validate.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 7,
            "reason": "Found 18/24 approved changesets -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 26 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3258337c0bcec3ff1b21664b39ccd678fb7f5f28",
        "ran_at": "2026-07-24T11:44:41Z",
        "aggregate_score": 6.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T11:30:32Z",
      "oldest_open_prs": [
        {
          "number": 1230,
          "created_at": "2025-03-04T02:32:03Z",
          "last_comment_at": "2025-11-05T09:23:17Z",
          "last_comment_author": "salaboy"
        },
        {
          "number": 1294,
          "created_at": "2025-04-02T12:53:01Z",
          "last_comment_at": "2026-04-05T15:11:33Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1338,
          "created_at": "2025-05-08T19:24:38Z",
          "last_comment_at": "2026-03-31T12:23:20Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1396,
          "created_at": "2025-05-29T18:33:52Z",
          "last_comment_at": "2025-09-01T17:59:22Z",
          "last_comment_author": "artur-ciocanu"
        },
        {
          "number": 1423,
          "created_at": "2025-06-13T13:57:28Z",
          "last_comment_at": "2026-04-02T16:31:07Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1567,
          "created_at": "2025-09-30T13:00:02Z",
          "last_comment_at": "2026-07-13T20:44:36Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1585,
          "created_at": "2025-10-24T10:52:38Z",
          "last_comment_at": "2026-07-04T17:42:34Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1592,
          "created_at": "2025-11-18T11:37:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1611,
          "created_at": "2025-12-29T23:14:40Z",
          "last_comment_at": "2026-04-27T14:38:29Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1615,
          "created_at": "2026-01-07T00:55:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1632,
          "created_at": "2026-01-29T02:49:19Z",
          "last_comment_at": "2026-02-24T22:18:02Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1693,
          "created_at": "2026-03-10T14:48:28Z",
          "last_comment_at": "2026-06-17T07:37:01Z",
          "last_comment_author": "salaboy"
        },
        {
          "number": 1695,
          "created_at": "2026-03-11T18:01:29Z",
          "last_comment_at": "2026-03-16T09:34:21Z",
          "last_comment_author": "javier-aliaga"
        },
        {
          "number": 1697,
          "created_at": "2026-03-13T22:57:54Z",
          "last_comment_at": "2026-04-24T13:26:07Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1777,
          "created_at": "2026-07-01T13:43:24Z",
          "last_comment_at": "2026-07-01T13:49:39Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1786,
          "created_at": "2026-07-13T19:49:00Z",
          "last_comment_at": "2026-07-13T21:09:54Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1787,
          "created_at": "2026-07-17T05:44:40Z",
          "last_comment_at": "2026-07-17T05:50:16Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1790,
          "created_at": "2026-07-19T08:08:47Z",
          "last_comment_at": "2026-07-19T16:07:32Z",
          "last_comment_author": "codecov"
        }
      ],
      "last_merged_pr_at": "2026-07-22T11:08:50Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 201,
          "created_at": "2020-02-04T21:40:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 354,
          "created_at": "2020-10-12T19:09:05Z",
          "last_comment_at": "2023-09-22T08:42:24Z",
          "last_comment_author": "salaboy"
        },
        {
          "number": 368,
          "created_at": "2020-10-17T03:12:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 369,
          "created_at": "2020-10-17T03:24:02Z",
          "last_comment_at": "2026-07-19T08:07:59Z",
          "last_comment_author": "manduinca"
        },
        {
          "number": 447,
          "created_at": "2021-01-19T01:29:54Z",
          "last_comment_at": "2021-03-09T20:23:18Z",
          "last_comment_author": "artursouza"
        },
        {
          "number": 500,
          "created_at": "2021-02-25T10:48:29Z",
          "last_comment_at": "2021-04-27T05:51:02Z",
          "last_comment_author": "artursouza"
        },
        {
          "number": 503,
          "created_at": "2021-03-03T14:44:09Z",
          "last_comment_at": "2021-05-07T17:46:50Z",
          "last_comment_author": "artursouza"
        },
        {
          "number": 505,
          "created_at": "2021-03-10T20:35:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 506,
          "created_at": "2021-03-10T20:39:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 509,
          "created_at": "2021-03-11T18:44:58Z",
          "last_comment_at": "2021-12-07T14:05:06Z",
          "last_comment_author": "stliu"
        },
        {
          "number": 510,
          "created_at": "2021-03-11T21:39:32Z",
          "last_comment_at": "2021-12-03T06:29:25Z",
          "last_comment_author": "sahansera"
        },
        {
          "number": 531,
          "created_at": "2021-03-31T06:08:29Z",
          "last_comment_at": "2021-04-30T01:28:23Z",
          "last_comment_author": "LLLLimbo"
        },
        {
          "number": 533,
          "created_at": "2021-04-20T20:23:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 541,
          "created_at": "2021-05-07T00:11:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 542,
          "created_at": "2021-05-07T16:39:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 543,
          "created_at": "2021-05-10T16:22:08Z",
          "last_comment_at": "2021-08-21T01:27:18Z",
          "last_comment_author": "artursouza"
        },
        {
          "number": 544,
          "created_at": "2021-05-11T21:00:31Z",
          "last_comment_at": "2021-10-15T00:08:38Z",
          "last_comment_author": "artursouza"
        },
        {
          "number": 546,
          "created_at": "2021-05-14T16:17:11Z",
          "last_comment_at": "2021-11-10T17:16:40Z",
          "last_comment_author": "lullen"
        },
        {
          "number": 555,
          "created_at": "2021-05-26T22:37:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 558,
          "created_at": "2021-05-31T19:53:25Z",
          "last_comment_at": "2021-06-01T00:03:46Z",
          "last_comment_author": "artursouza"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/dapr/java-sdk",
    "host": "github.com",
    "name": "java-sdk",
    "owner": "dapr"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 78,
      "inputs": {
        "security": 65,
        "vitality": 96,
        "community": 72,
        "governance": 82,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 96,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "commits_last_year": 155,
              "human_commit_share": 0.85,
              "days_since_last_push": 2,
              "active_weeks_last_year": 42
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "42/52 weeks with commits",
                "points": 29.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 42
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "155 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 155
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 37,
              "latest_release_tag": "v1.18.1",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 34
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "37 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~34 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 34
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 2,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 2 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 72,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "forks": 229,
              "stars": 299,
              "watchers": 25,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "299 stars",
                "points": 40.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 299
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "229 forks",
                "points": 19.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 229
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "25 watchers",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 82,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 96,
              "top_contributor_share": 0.354
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 35% of commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 35
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "96 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 96
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 26 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 919,
              "open_issues": 115,
              "closed_issues": 543,
              "issue_closed_ratio": 0.825,
              "closed_unmerged_prs": 186
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "82% of issues closed",
                "points": 38.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 82
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "919/1105 decided PRs merged",
                "points": 31.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 919,
                      "decided": 1105
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 18/24 approved changesets -- score normalized to 7",
                "points": 10.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "followers": 1947,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "dapr",
              "public_repos": 45,
              "account_age_days": 2593
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,947 followers of dapr",
                "points": 23.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1947,
                      "login": "dapr"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "45 public repos, account ~7 yr old",
                "points": 24.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 45
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "io.dapr:dapr-sdk",
                "io.dapr:dapr-sdk-actors",
                "io.dapr:dapr-sdk-autogen",
                "io.dapr:dapr-sdk-workflows",
                "io.dapr:dapr-sdk-springboot",
                "io.dapr:durabletask-client",
                "io.dapr:testcontainers-dapr"
              ],
              "ecosystems": "maven",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "7 package(s) on maven",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 7,
                      "ecosystems": "maven"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "119 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 119
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 65,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "24 out of 24 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 18/24 approved changesets -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 26 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the maven:io.dapr:dapr-sdk@1.18.1 runtime dependency closure — what installing the published package pulls in — 40 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "maven:io.dapr:dapr-sdk@1.18.1",
                  "assessed": 40
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 83,
            "inputs": {
              "source": "osv",
              "advisories": 9,
              "affected_packages": 3,
              "assessed_packages": 40,
              "unassessed_packages": 0,
              "affected_by_severity": "high 2, low 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "3 affected: io.netty:netty-codec 4.1.135.Final (high 7.5), io.netty:netty-codec-http 4.1.135.Final (high 7.5), io.netty:netty-codec-http2 4.1.135.Final (low)",
                "points": 8.4,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 3,
                      "packages": "io.netty:netty-codec 4.1.135.Final (high 7.5), io.netty:netty-codec-http 4.1.135.Final (high 7.5), io.netty:netty-codec-http2 4.1.135.Final (low)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 40,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 66,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.871,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "74 of 85 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 74,
                      "sampled": 85
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 67,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "mise.toml"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.04,
              "toolchain_manifests": [
                "dapr-spring/dapr-spring-bom/pom.xml",
                "dapr-spring/dapr-spring-boot-autoconfigure/pom.xml",
                "dapr-spring/dapr-spring-boot-observation/pom.xml",
                "dapr-spring/dapr-spring-boot-properties/pom.xml",
                "dapr-spring/dapr-spring-boot-starters/dapr-spring-boot-starter-test/pom.xml",
                "dapr-spring/dapr-spring-boot-starters/dapr-spring-boot-starter/pom.xml",
                "dapr-spring/dapr-spring-boot-tests/pom.xml",
                "dapr-spring/dapr-spring-data/pom.xml",
                "dapr-spring/dapr-spring-messaging/pom.xml",
                "dapr-spring/dapr-spring-workflows/pom.xml",
                "dapr-spring/pom.xml",
                "durabletask-client/pom.xml",
                "examples/pom.xml",
                "pom.xml",
                "sdk-actors/pom.xml",
                "sdk-autogen/pom.xml",
                "sdk-bom/pom.xml",
                "sdk-springboot/pom.xml",
                "sdk-tests/pom.xml",
                "sdk-workflows/pom.xml",
                "sdk/pom.xml",
                "spring-boot-examples/consumer-app/pom.xml",
                "spring-boot-examples/pom.xml",
                "spring-boot-examples/producer-app/pom.xml",
                "spring-boot-examples/workflows/multi-app/orchestrator/pom.xml",
                "spring-boot-examples/workflows/multi-app/pom.xml",
                "spring-boot-examples/workflows/multi-app/worker-one/pom.xml",
                "spring-boot-examples/workflows/multi-app/worker-two/pom.xml",
                "spring-boot-examples/workflows/patterns/pom.xml",
                "spring-boot-examples/workflows/pom.xml",
                "spring-boot-examples/workflows/versioning/full-version-worker-one/pom.xml",
                "spring-boot-examples/workflows/versioning/full-version-worker-two/pom.xml",
                "spring-boot-examples/workflows/versioning/patch-version-worker-one/pom.xml",
                "spring-boot-examples/workflows/versioning/patch-version-worker-two/pom.xml",
                "spring-boot-examples/workflows/versioning/pom.xml",
                "spring-boot-examples/workflows/versioning/version-orchestrator/pom.xml",
                "spring-boot-sdk-tests/pom.xml",
                "testcontainers-dapr/pom.xml"
              ],
              "dependency_bot_commit_share": 0.15
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "mise.toml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "mise.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Java (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "4 of the last 100 commits agent-authored or agent-credited",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 4,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "15 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 15,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Java",
              "largest_source_bytes": 3725456,
              "source_files_sampled": 915,
              "oversized_source_files": 7
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Java (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "7/915 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 915,
                      "oversized": 7
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "examples/proto/helloworld.proto",
                "sdk-tests/proto/methodinvokeservice.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "examples/proto/helloworld.proto, sdk-tests/proto/methodinvokeservice.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/proto/helloworld.proto, sdk-tests/proto/methodinvokeservice.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch maven package 'io.dapr:dapr-sdk-tests' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T11:45:12.414467Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/dapr/java-sdk.svg",
  "full_name": "dapr/java-sdk",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsMaven.