Public record
Software health reportschema 0.25.0 · metrics 1.13.0 · 2026-07-21 22:40 UTC

hrodrig / pgwd

Go CLI that checks PostgreSQL connection counts and notifies via Slack and/or Loki when configured thresholds are exceeded. It can also alert on stale connections.

GoMIT★ 7 stars⑂ 0 forkssince Feb 2026View on GitHub ↗

hrodrig/pgwd holds a health index of 67 out of 100, placing it in the Moderate band. It scores highest on Vitality (83/100) and lowest on Community & Adoption (50/100). It was last updated 2 days ago. A single contributor accounts for most of its recent work.

67
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

67
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Hermes RodríguezPersonal account
52 followers313 public repossince Jul 2009

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/hrodrig/pgwdv1.0.0-233 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

83Good · 22% of overall
How it's scored
36/36Push recency — last push 2 days ago
12.5/36Commit cadence — 18/52 weeks with commits
18/18Commit volume — 214 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year214
human_commit_share1
days_since_last_push2
active_weeks_last_year18
How it's scored
27/27Ships releases — 23 releases published
36/36Release recency — latest release 3 days ago
27/27Release cadence — a release every ~7 days
4/10OpenSSF Scorecard: Signed-Releases — 3 out of the last 5 releases have a total of 3 signed artifacts.
Inputs used
releases_count23
latest_release_tagv1.0.0
releases_from_tagsno
days_since_latest_release3
mean_days_between_releases7

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

50Moderate · 18% of overall
How it's scored
12.6/60Stars — 7 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars7
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

56Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
38.2/38.3PR acceptance — 9/9 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/4 approved changesets -- score normalized to 0
Inputs used
merged_prs9
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
12.4/25Owner reach — 52 followers of hrodrig
25/25Track record — 313 public repos, account ~17 yr old
Inputs used
followers52
owner_typeUser
is_verified
owner_loginhrodrig
public_repos313
account_age_days6,215
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 3 days ago
20/20Version history — 23 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/hrodrig/pgwd
ecosystemsgo
any_deprecatedno
min_days_since_publish3

Engineering Quality

Are baseline engineering and documentation practices in place?

81Good · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://pgwd.hermesrodriguez.com
10/10Repository description
10/10Topics — 7 topics
10/10Wiki
Inputs used
topicscli, go, postgres, utility, loki, monitoring, slack
has_wikiyes
homepagehttps://pgwd.hermesrodriguez.com
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/4 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
3/7.5Signed-Releases — 3 out of the last 5 releases have a total of 3 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate5.2
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories2
affected_packages2
assessed_packages53
unassessed_packages0
affected_by_severityunknown 2
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 53 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

81Good · 0% of overall
How it's scored
45/45Agent instructions — .cursor/rules/changelog.mdc, .cursor/rules/commit-message-review.mdc, .cursor/rules/diagrams-mermaid.mdc, .cursor/rules/git-flow.mdc, .cursor/rules/gitignore-whitelist.mdc, .cursor/rules/language-english.mdc, .cursor/rules/man-page-sync.mdc, .cursor/rules/readme-badges-version.mdc, .cursor/rules/readme-deepwiki-badge.mdc, .cursor/rules/release-tests.mdc, AGENTS.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 85 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.85
agent_instruction_files.cursor/rules/changelog.mdc, .cursor/rules/commit-message-review.mdc, .cursor/rules/diagrams-mermaid.mdc, .cursor/rules/git-flow.mdc, .cursor/rules/gitignore-whitelist.mdc, .cursor/rules/language-english.mdc, .cursor/rules/man-page-sync.mdc, .cursor/rules/readme-badges-version.mdc, .cursor/rules/readme-deepwiki-badge.mdc, .cursor/rules/release-tests.mdc, AGENTS.md
agent_instruction_max_bytes10,408
How it's scored
18/18One-command bootstrap — GNUmakefile, Makefile, contrib/freebsd/Makefile, contrib/openbsd/port/Makefile
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 71 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_filesGNUmakefile, Makefile, contrib/freebsd/Makefile, contrib/openbsd/port/Makefile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.71
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
55/55Manageable file sizes — 0/68 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes27,332
source_files_sampled68
oversized_source_files0

Key facts

7GitHub stars
1contributors
214commits, last 12 months
2days since last push
23releases
1bus factor
0open issues
Gopackage ecosystems

More detail

Star and fork history 7 ★ / 0 ⇿
7Stars
20Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

1234567712026-022026-052026-07
Major 1Minor 6Patch 13
OpenSSF Scorecard 5.2 / 10
5.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-21 22:40 UTC

10Binary-Artifactsno binaries found in the repo
1Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests4 out of 4 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/4 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
4Signed-Releases3 out of the last 5 releases have a total of 3 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
Direct dependencies 9
RegistryPackageVersion constraintManifest
Gogithub.com/DATA-DOG/go-sqlmockv1.5.2go.mod
Gogithub.com/go-sql-driver/mysqlv1.8.1go.mod
Gogithub.com/jackc/pgx/v5v5.9.2go.mod
Gogithub.com/ncruces/go-sqlite3v0.32.0go.mod
Gogolang.org/x/sysv0.45.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gok8s.io/apiv0.35.0go.mod
Gok8s.io/apimachineryv0.35.0go.mod
Gok8s.io/client-gov0.35.0go.mod
All dependencies 53

Full resolved dependency set from the GitHub dependency graph: 9 direct and 44 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/data-dog/go-sqlmockv1.5.2direct
Gogithub.com/go-sql-driver/mysqlv1.8.1direct
Gogithub.com/jackc/pgx/v5v5.9.2direct
Gogithub.com/ncruces/go-sqlite3v0.32.0direct
Gogolang.org/x/sysv0.45.0direct
Gogopkg.in/yaml.v3v3.0.1direct
Gok8s.io/apiv0.35.0direct
Gok8s.io/apimachineryv0.35.0direct
Gok8s.io/client-gov0.35.0direct
Gofilippo.io/edwards25519v1.1.1indirect
Gogithub.com/davecgh/go-spewv1.1.1indirect
Gogithub.com/emicklei/go-restful/v3v3.12.2indirect
Gogithub.com/fxamacker/cbor/v2v2.9.0indirect
Gogithub.com/go-logr/logrv1.4.3indirect
Gogithub.com/go-openapi/jsonpointerv0.21.0indirect
Gogithub.com/go-openapi/jsonreferencev0.20.2indirect
Gogithub.com/go-openapi/swagv0.23.0indirect
Gogithub.com/google/gnostic-modelsv0.7.0indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/gorilla/websocketv1.5.4-0.20250319132907-e064f32e3674indirect
Gogithub.com/jackc/pgpassfilev1.0.0indirect
Gogithub.com/jackc/pgservicefilev0.0.0-20240606120523-5a60cdf6a761indirect
Gogithub.com/jackc/puddle/v2v2.2.2indirect
Gogithub.com/josharian/internv1.0.0indirect
Gogithub.com/json-iterator/gov1.1.12indirect
Gogithub.com/mailru/easyjsonv0.7.7indirect
Gogithub.com/moby/spdystreamv0.5.1indirect
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirect
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31eeindirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/mxk/go-flowratev0.0.0-20140419014527-cca7078d478findirect
Gogithub.com/ncruces/juliandayv1.0.0indirect
Gogithub.com/spf13/pflagv1.0.9indirect
Gogithub.com/tetratelabs/wazerov1.11.0indirect
Gogithub.com/x448/float16v0.8.4indirect
Gogo.yaml.in/yaml/v2v2.4.3indirect
Gogo.yaml.in/yaml/v3v3.0.4indirect
Gogolang.org/x/netv0.55.0indirect
Gogolang.org/x/oauth2v0.30.0indirect
Gogolang.org/x/syncv0.20.0indirect
Gogolang.org/x/termv0.43.0indirect
Gogolang.org/x/textv0.37.0indirect
Gogolang.org/x/timev0.9.0indirect
Gogoogle.golang.org/protobufv1.36.8indirect
Gogopkg.in/evanphx/json-patch.v4v4.13.0indirect
Gogopkg.in/inf.v0v0.9.1indirect
Gok8s.io/klog/v2v2.130.1indirect
Gok8s.io/kube-openapiv0.0.0-20250910181357-589584f1c912indirect
Gok8s.io/utilsv0.0.0-20251002143259-bc988d571ff4indirect
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730indirect
Gosigs.k8s.io/randfillv1.0.0indirect
Gosigs.k8s.io/structured-merge-diff/v6v6.3.0indirect
Gosigs.k8s.io/yamlv1.6.0indirect
Dependency advisories 2

This repository publishes no package the index resolves, so its own dependency graph was assessed — 53 packages, which also include development and test pins that never ship: 2 carry known advisories, of which 0 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
golang.org/x/netv0.55.0indirectunknown10.56.0
golang.org/x/textv0.37.0indirectunknown10.39.0

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "cli",
        "go",
        "postgres",
        "utility",
        "loki",
        "monitoring",
        "slack"
      ],
      "is_fork": false,
      "size_kb": 13751,
      "has_wiki": true,
      "homepage": "https://pgwd.hermesrodriguez.com",
      "languages": {
        "Go": 350197,
        "Roff": 9463,
        "Jinja": 697,
        "Shell": 20279,
        "Python": 1752,
        "Makefile": 26419,
        "Dockerfile": 1222
      },
      "pushed_at": "2026-07-19T00:05:54Z",
      "created_at": "2026-02-19T17:48:23Z",
      "owner_type": "User",
      "updated_at": "2026-07-21T06:40:28Z",
      "description": "Go CLI that checks PostgreSQL connection counts and notifies via Slack and/or Loki when configured thresholds are exceeded. It can also alert on stale connections.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://hermesrodriguez.com",
      "name": "Hermes Rodríguez",
      "type": "User",
      "login": "hrodrig",
      "company": null,
      "location": "Caracas, Venezuela",
      "followers": 52,
      "avatar_url": "https://avatars.githubusercontent.com/u/105245?v=4",
      "created_at": "2009-07-15T14:44:18Z",
      "is_verified": null,
      "public_repos": 313,
      "account_age_days": 6215
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-18T15:07:42Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-13T15:02:32Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-11T23:17:39Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-03T03:15:17Z"
        },
        {
          "tag": "v0.6.10",
          "kind": "patch",
          "published_at": "2026-06-17T18:08:55Z"
        },
        {
          "tag": "v0.6.9",
          "kind": "patch",
          "published_at": "2026-06-16T01:13:47Z"
        },
        {
          "tag": "v0.6.8",
          "kind": "patch",
          "published_at": "2026-06-10T14:22:42Z"
        },
        {
          "tag": "v0.6.7",
          "kind": "patch",
          "published_at": "2026-06-01T12:54:43Z"
        },
        {
          "tag": "v0.6.6",
          "kind": "patch",
          "published_at": "2026-05-25T04:12:14Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-05-17T01:43:44Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-05-03T16:36:08Z"
        },
        {
          "tag": "v0.5.10",
          "kind": "patch",
          "published_at": "2026-03-22T23:22:58Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-03-13T15:52:33Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-11T18:22:56Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2026-03-03T16:35:30Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-03-03T03:41:24Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-03T03:15:36Z"
        },
        {
          "tag": "v0.2.4",
          "kind": "patch",
          "published_at": "2026-03-02T20:01:36Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-02-28T20:00:09Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-02-26T02:36:50Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-02-24T19:11:29Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-02-20T14:10:18Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-02-20T13:12:09Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "48d4ce597ff2a266c1d8b6d1cfbfc212a70eee3d",
          "body": "docs: BSD port examples 1.0.0 + drop Go Report Card",
          "is_bot": false,
          "headline": "Merge pull request #10 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-19T00:05:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96101cafe8098cfa4e427aa0e727807e55718310",
          "body": "Align FreeBSD/OpenBSD port docs with v1.0.0\ntarballs and databases: (drop top-level db:).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(bsd): sync port examples to 1.0.0",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T23:59:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc602a6c0f3e4590ea65437e3d7501fcfb3b5d19",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(readme): drop retired Go Report Card badge",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T22:11:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "552354fd4d02838becbfbbb016ac6483380cac75",
          "body": "docs: drop star-history.com chart",
          "is_bot": false,
          "headline": "Merge pull request #9 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T16:20:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "513b1651c2df21fdf754cd9efbde176e8c37623f",
          "body": "Co-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: drop star-history.com chart (token wall)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T15:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a15d426f2999bd7e2923f96a5fea0a925b1a1a44",
          "body": "docs: v1.0.0 install examples and related-tools links",
          "is_bot": false,
          "headline": "Merge pull request #8 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T15:44:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4c405f994d68723c5e6debffa8c3cada233ffff",
          "body": "Point install/docker URLs at v1.0.0 and add cross-links to\ngghstats, kzero, and groot (plus selfhosted deploy repos).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: v1.0.0 install examples and related-tools family links",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T15:06:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1dafb2d09036f34087f2a70ffef7bbc9f06c1a3a",
          "body": "Release v1.0.0",
          "is_bot": false,
          "headline": "Merge pull request #7 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T14:44:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4fcb1783326478be3cb7d3a3520b2824a7d392a4",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T14:39:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "917fee25d66c7cafcf44aeecd328e2548c8dbe11",
          "body": "- preflight.yml: unique host:port, run_once, fail fast (~5s)\n- wire into ping + full-cycle; pin Linux ansible_python_interpreter\n- OpenRC command=/usr/local/bin/pgwd; drop threshold.total/active from j2/example\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test(platforms): Postgres preflight and Alpine/OpenRC 1.0 fixes",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T14:33:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "232f636d92407ff8f4b681bf157aa3742c42cd69",
          "body": "- archives/nfpms: formats + ids + maintainer; always v{{ .Version }}\n- checksum signing via --bundle (sigstore.json); snapshot --skip=sign\n- docs: verify-blob + CHANGELOG note\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: modernize GoReleaser (formats, Version names, Cosign v3)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T14:33:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6ec5e21815d0e94ce85bcbc3d100c2cc4e407f10",
          "body": "- Promote one databases: row to db URL before setupKube\n- Reject kube only when len(Databases) > 1\n- Migrate e2e fixture and kube-prod profile off removed db:\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Allow single databases: entry with kube-postgres",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T12:30:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e55179949581b1ae1b67daaa658c7a3624f8ab65",
          "body": "Extract assertion helpers so gocyclo stays ≤14 for release-check.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test(store): lower TestQueryAllMetrics cyclomatic complexity",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T12:03:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a9987e0dea41baf954ff4247045fe5675a48549a",
          "body": "Align contrib port Makefiles with VERSION after the release bump.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: bump FreeBSD/OpenBSD port versions to 1.0.0",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T11:50:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e2aa06aefee865d3f7470b1349a9051d01a2ebfd",
          "body": "Record vhs tape against binary reporting v1.0.0.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: regenerate demo.gif for v1.0.0",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T11:49:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f16bab2ebc9d2db36fadb70a5a7551fa65f277ba",
          "body": "Bump VERSION, README badge/roadmap, SPEC baseline, CHANGELOG [1.0.0],\nROADMAP status, man page .TH, and example config wording (db: removed).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: prepare v1.0.0 release metadata",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T11:49:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "53a024412addd29b23df4376b3329bc483abcee4",
          "body": "Link from docs/README Operations and Unreleased Documentation.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: index connection-limits guide and changelog entry",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:34:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fb1ad61414ecd1887d55d89802d1fcd9ab412e07",
          "body": "Practical DBA/developer sizing guide linked from the README blurb.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add PostgreSQL connection limits guide",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:34:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ba437b2a9b05ff7479e0f5de64849056e243c30c",
          "body": "Raise Why connection limits matter body to the 120–180 word range.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: expand connection-limits README blurb to word target",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:33:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b72802737bb8e368d4c2fd79c69c59aba9b9b9e4",
          "body": "Short problem presentation with link to the long sizing guide.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add README blurb for Postgres connection limits",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:32:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5fdee2e84adb9d182282288f0258ac4e93799845",
          "body": "Task breakdown for README blurb, long guide, index, and changelog.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: add connection-limits implementation plan",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:32:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1cdf37dba587a4ac4140b4132924d8705a7932e3",
          "body": "Capture README blurb + long-guide structure (DBA/dev, sizing heuristics)\nbefore implementation.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: design spec for connection-limits guide",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:30:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43a60736deab284a7343da7eb16a85dc3b9348d6",
          "body": "Extract queryAllMetrics from QueryAllMetricsFromDSN so export scan/query\npaths are unit-testable without a live SQL server.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test(store): cover queryAllMetrics export path with sqlmock",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:17:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3fea544bc4d2c0ab030b122c01051f1ca242e23b",
          "body": "Add sqlmock-backed tests for Insert/evict, LatestRecords, LastStates,\ncooldown (Postgres/MySQL), and schema helpers so internal/store hits ~80%.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "test(store): raise SQLStore unit coverage without Docker",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:14:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7c08f35afa6b826fc712637a5d50489986dce85f",
          "body": "Honest alternatives matrix, README Compare section, and\noperator migration guide for 1.0 breaking removals.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add compare and 0.9-to-1.0 upgrade docs",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:06:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c0b70c0ebc0357e17f33a95853a549adaeac9da8",
          "body": "Connect failure alerts stay always-on when notifiers exist.\nReject removed flag, env, and YAML key with migration hints.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Remove notify-on-connect-failure flag and config",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T05:00:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "37a512b431cbb61936873742f1324313e5fd90dd",
          "body": "Use -db-threshold-levels only. Reject removed flags, env vars,\nand YAML threshold.total/active with migration hints.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Remove legacy total/active connection thresholds",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T04:55:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc7bcc628057b2a8a3785b496e7d91d9cda53a12",
          "body": "Require databases: even for a single target. Files with db:\nfail at load with a migration hint. Docs and sample updated.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Remove legacy db: YAML config key",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T04:47:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9e09decc8d425c13fad1c5d27fee8c5fa60e897e",
          "body": "Ping after pool create so lazy pgx connect maps to exit 2;\none-shot stats/query failure exits 3; daemon continues.\nSPEC, README, CHANGELOG, and sequence docs updated.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Exit codes 2/3 for connect and query failures",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-18T04:37:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b81fc87c26b9a387755daefe7241498f3348af0d",
          "body": "Ship docs/logo.svg|png, use in README; note in CHANGELOG Unreleased.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add hybrid pgwd brand mark (pg + live status dot)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T17:34:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e2ff458469b2a2bc10da810d011e984a7443ac10",
          "body": "Note Debian/Ubuntu, Fedora, Alpine, FreeBSD, OpenBSD, NetBSD, DragonFly\nsubmissions (contrib seeds); not a hard v1.0.0 tag gate.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Plan 1.x: official distro packaging targets",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T16:07:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b81e4e281604c504fa07f60e05f7e25406f9b332",
          "body": "- ROADMAP: v0.9.0 shipped; 1.0 band adds docs/compare.md + README Compare\n- plan-1.0.x: marketing section, alternative matrix, checklist (gfire/groot pattern)\n- docs/README: 1.0.x band index entry\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Plan 1.0: transparent compare docs vs alternatives (marketing)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T15:10:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6df51bb52651759f8370afb3b176fa5692bfbe62",
          "body": "Release v0.9.0",
          "is_bot": false,
          "headline": "Merge pull request #6 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T14:40:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b22980347d65c61c8f1b603be4a4903f896d77d",
          "body": "Pre-1.0 security and operator polish: DISCOVER removal, metrics/CSV\nhardening, profiles, collector, operator use-case docs.\n\n- VERSION 0.9.0; README version badge; ROADMAP/plan-0.9.x updated\n- CHANGELOG [0.9.0] with summary; man .TH 2026-07-13\n- FreeBSD/OpenBSD port pins; platform test inventory\n- Regenerate docs/demo.gif (pgwd -version shows v0.9.0)\n- make release-check passed\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release v0.9.0: version bump, CHANGELOG, badges, man, BSD ports",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T14:22:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7193a92df291eadb09da38e3ce7e78386df89aa9",
          "body": "- Add docs/use-cases.md (UC-1..UC-7): single/multi DB, in/out of cluster,\n  different credentials per databases[] entry; what 0.9.x does not support\n- Rewrite docs/kubernetes-passwords.md as operator-first guide; link multi-DB\n- Expand contrib/k8s/README.md outside-cluster and multi-DB recipes\n- Improve DISCOVER removal startup error with concrete migration paths\n- Document make bench in SPEC §12, README Testing, AGENTS.md (non-blocking CI)\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Docs: operator use cases, DISCOVER migration, make bench in SPEC",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T14:11:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4d88ca955207b0c317c6e9fc37e0c53d35ddbf2b",
          "body": "- SPECIFICATIONS.md: baseline v0.9.0, DISCOVER removed, collector/TLS/CSV/kube\n- ROADMAP.md: 0.9.x band marked shipped; 0.9.0 pending tag\n- docs/plan-0.9.x.md: §11 audit checklist complete\n- docs/sequence/: startup diagram + AUDIT for 0.9.x behavior\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Complete 0.9 slice 4: SPEC audit, ROADMAP, sequence diagrams",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T13:52:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "199e387544a71a36ab2cab57847919b22f7346cd",
          "body": "- Opt-in anonymous collector + opt-out GitHub update check (daemon only)\n- POST https://collect.gghstats.com/a1b2c3d4e5f6a7b8; document payload example\n- Warn on non-loopback http:// notifier URLs at startup\n- make bench target and non-blocking CI job\n- Collector httptest coverage; cover-check back above 80%\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Complete 0.9 slice 3: collector, TLS warning, bench, docs",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T13:47:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "059f38e5324c80ad6353f58f5502e2ca63c86ad7",
          "body": "-strict exits 4 when all senders fail for a threshold event; legacy db: and\nnotify-on-connect-failure get clearer stderr migration hints.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add -strict notifier exit and stronger deprecation warnings",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:40:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5f640bdd160665e223cc6b8beed92e03a1fe4db3",
          "body": "Ship minimal-slack, daemon-loki, kube-prod, and multi-db YAML starters\nwith README linking to full config reference.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add contrib/profiles for common pgwd deployment patterns",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:38:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "845bfa0b9e3284e1f35c18577729c12ee7978007",
          "body": "Clarify default anonymous /metrics for Prometheus and Alloy; token/basic\nonly when operators enable them. SPEC §8, k8s README, pgwd.conf.example.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Docs: /metrics auth is opt-in for in-cluster scrape",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:33:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "99e84f762fd42c23159e00eba2ecfe6096248468",
          "body": "Bearer token (?token= or Authorization header) and optional basic auth\nprotect /metrics only; /healthz stays open for probes. Env:\nPGWD_HTTP_METRICS_TOKEN, PGWD_HTTP_METRICS_BASIC_*.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Add optional auth for HTTP /metrics endpoint",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:29:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43105222b8ae7188256576aeef0c020b97ab8a1e",
          "body": "Prefix client/cluster/database/state/threshold values that start with\nformula triggers so Excel and Sheets open exports as plain text.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Sanitize CSV string fields against spreadsheet formula injection",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:25:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4a1b7bd97541e85b7e94d1e313832091b45c6891",
          "body": "Escape backslash, quote, and newline per exposition format; replace other\ncontrol characters so scrapers do not break on hostile client/cluster names.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Harden Prometheus label escaping in /metrics exporter",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:25:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9119f6ecd2ed4ae7ca7f1d6ff7b852675d85e3a0",
          "body": "- Drop pods/exec password discovery, -kube-password-* flags, and legacy config keys\n- Read password or full DSN from Secret via client-go (ResolveKubeDBURL)\n- Ship contrib/k8s/pgwd-kube-run.sh and rbac-outside-cluster.yaml; migrate e2e kube tests\n- Colorized make help (gghstats-style GNUmakefile); ROADMAP 0.9.x active, v0.8.0 tagged\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "0.9 slice 1: remove DISCOVER_MY_PASSWORD, add kube.password_from_secret",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-13T12:16:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "268cf094145ef8036d88b8f43949d71d688ba471",
          "body": "Release 0.8.0",
          "is_bot": false,
          "headline": "Merge pull request #5 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-11T22:56:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f9a9613c397d5c2dbceabe2bf3a94a3a86b62d2",
          "body": "- Cosign + Syft SBOMs via GoReleaser; release workflow verify\n- Dockerfile/release: distroless/static-debian13 (client-go K8s, no kubectl)\n- Go 1.26.5 (CVE-2026-39822, CVE-2026-42505); VERSION, man, BSD ports, demo.gif\n- Audit docs: SPEC known limitations, ROADMAP 0.9.x checklist\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release 0.8.0: supply chain, distroless image, Go 1.26.5",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-11T22:51:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7120042e5ea6f939de030817fcb7934e6f1ff4dc",
          "body": "- SPECIFICATIONS: known limitations, HTTP/CSV corrections, TLS note\n- ROADMAP: 0.9.x hardening items and metrics privacy decision\n- plan-0.9.x: SPEC audit checklist\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: document v0.7.0 operator security gaps from audit review",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-11T22:11:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4ebdac66e0d9184e3fb54356eee0e5fd6fe978bb",
          "body": "…lete\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(plan-0.7.x): mark v0.7.0 band shipped and release checklist comp…",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T03:29:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12623a423ac76f9661302463b4e58c061da4cf4a",
          "body": "Release 0.7.0",
          "is_bot": false,
          "headline": "Merge pull request #4 from hrodrig/develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T02:52:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2353df9f46c876692aff85886831c5bb48c8bdc2",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'main' into develop",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T02:49:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "263584a207c86381ec40c77ea5f502a5ad6abac0",
          "body": "- Bump VERSION to 0.7.0; update CHANGELOG, man page, demo.gif, BSD ports\n- Thin cmd/pgwd/main.go; move orchestration to internal/cli and internal/run\n- Add unit/integration tests (postgres Querier, run, store, metricsstore, notify, kube, cli)\n- make cover-check (≥80% on library packages) in release-check and CI\n- Document coverage gate in ROADMAP, AGENTS, release-tests.mdc, testing/README\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Release 0.7.0: cover-check gate, CLI refactor, and test coverage",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T02:37:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5fb78ca3adeb5a1fb6d737d1eb7bcf956ac84657",
          "body": "- Update SPEC, README, pgwd.conf.example, man page, CHANGELOG, AGENTS\n- Mark plan-0.7.x documentation release gate items complete\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(0.7.x): document PagerDuty, Teams, generic webhook, and retry",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T01:36:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a538ed75ed1e1ca4ee337c85c99c3cc8dcf209ef",
          "body": "- Add PagerDuty Events v2, Teams, and generic webhook with HMAC/template support\n- Share SummaryText helper; migrate Slack and Loki to postJSONWithRetry\n- Wire new senders in buildSenders; unit tests for payloads and signing\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(notify): PagerDuty, Teams, generic webhook senders for 0.7.x",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T01:30:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a842e3f0ddacb1a2ec0c29b38a91514c973c4e8",
          "body": "- Add PagerDuty, Teams, generic webhook, and retry fields (YAML, env, CLI)\n- Wire notify.ApplyRetryConfig in buildSenders; extend HasAnyNotifier and validation\n- Tests for file/env loading and notifier channel validation\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(config): notifier scaffold and HTTP retry wiring for 0.7.x",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T01:20:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc1697a989c7f54742f6213651f2833324b19e07",
          "body": "- Add RetryConfig, ApplyRetryConfig, and postJSONWithRetry (30s client, exponential backoff)\n- Unit tests: 5xx retry, 4xx fast-fail, custom headers, context cancel, config defaults\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(notify): shared HTTP retry for 0.7.x notifiers",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T01:13:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "12c6ad42d3e1d4473f19d06d8d065fc33b171dd3",
          "body": "- ROADMAP: active band 0.7.x on develop\n- README roadmap table and plan-0.7.x status line aligned\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(roadmap): mark 0.7.x in progress",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T01:01:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "793ceef2005a6e1ec4df89796d5e148c2fb9367e",
          "body": "….10)\n\n- Add ROADMAP.md as canonical release index; wire README, SPEC, AGENTS, band plans\n- Add docs/kubernetes-passwords.md (DISCOVER_MY_PASSWORD decision record and migration)\n- Fix SPEC: config precedence, client-go kube, Prometheus /metrics, dry-run vs connect failure\n- Align README, man, contrib examples; CHANGELOG [Unreleased] only (no version bump)\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: ROADMAP, kubernetes-passwords, and alignment (VERSION stays 0.6…",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-03T00:51:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "25a76bb777b27ec2ecb3a53145fcd840bbd261fa",
          "body": "- Plan removal of pods/exec password discovery (security)\n- Document alternatives: in-cluster Secret, wrapper script, password_from_secret\n- Target kube.password_from_secret in 0.9.0; note DISCOVER removed before 1.0\n- Update roadmap index in docs/README.md\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(plan-0.9): remove DISCOVER_MY_PASSWORD, secure K8s password paths",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-02T11:06:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7d963c0afbe2709ff911e51c7bd74a2f5af06d92",
          "body": "- Add SPECIFICATIONS.md as behavior contract baseline (v0.6.10)\n- Split roadmap into plan-0.7.x through plan-1.0.x\n- Document 0.9.x daemon telemetry (opt-in collector, gghstats-style)\n- Index roadmap in docs/README.md\n- Whitelist SPECIFICATIONS.md in .gitignore\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: SPECIFICATIONS and release plans 0.7–1.0",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-07-01T03:51:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "26947a2fd660e2e1acd632290d2d736ee8076eae",
          "body": "Release v0.6.10 — Alpine 3.24.1 Docker runtime",
          "is_bot": false,
          "headline": "Merge pull request #3 from hrodrig/develop",
          "author_name": "Hermes Rodriguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-17T17:47:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "048d5b63a0f1765b21ef25f7d5783c3f1955dfdb",
          "body": "- Docker runtime alpine:3.24.1 (Snyk low cleared; OpenSSL/CVE-2026-2673)\n- VERSION, README badge, CHANGELOG, man page, demo.gif\n- FreeBSD/OpenBSD port sync (PORTVERSION, DISTNAME, PKGNAME, …)\n- Ansible inventory default pgwd_version\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): prepare v0.6.10",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-17T17:33:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5ecb663b0bc33ba6b10654e3620b1030568bfaa1",
          "body": "Release v0.6.9",
          "is_bot": false,
          "headline": "Merge pull request #2 from hrodrig/develop",
          "author_name": "Hermes Rodriguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-16T00:23:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a045dcc7b947e67833d14f3faeaf6ce86dfe6a44",
          "body": "Bump VERSION, README badge, CHANGELOG, and Homebrew cask caveats for\n--print-sample-config.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): prepare v0.6.9",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-16T00:17:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c7a2f5a1c5c5d97b51756080d26894c1ecb11e67",
          "body": "--print-sample-config embeds contrib/pgwd.conf.example; Docker builds\nmust copy contrib/ into the image build stage.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(docker): include contrib/ in build context",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-16T00:15:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "410d0b09739b61d315c1e5fe18ea6ad85774cefd",
          "body": "Print contrib/pgwd.conf.example to stdout before config load so operators\nwithout the example file on disk can bootstrap /etc/pgwd/pgwd.conf.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "feat(cli): add --print-sample-config flag",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-15T23:49:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "090267c59240afd4a93a8dc80804112ac61bbac9",
          "body": null,
          "is_bot": false,
          "headline": "Merge develop for release v0.6.8",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-10T14:02:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6f4c731342e9a8abe218d6d0a24f4d38d908aa6",
          "body": "Security patch: Go 1.26.4 (GO-2026-5037, GO-2026-5039).\nRoadmap/docs: Timescale via postgres metrics_store; 0.8.0 supply chain.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): v0.6.8",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-10T14:01:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8ee9ca0b548f6cab30fbe4cc2e60649b00d34c0e",
          "body": "Mitigate stdlib advisories GO-2026-5037 (crypto/x509) and\nGO-2026-5039 (net/textproto); keeps CI govulncheck clean.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore: bump Go toolchain to 1.26.4",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-10T13:33:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9efedb40ca143818e49f0d7d29a96f97556fb808",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' (release v0.6.7)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-01T12:33:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ba8343c660a0ca98f6fa83f41b7b33ded04e5c5",
          "body": "- Enriched Notification sent daemon log line\n- too_many_clients locale fix (SQLSTATE 53300)\n- Sync VERSION, CHANGELOG, README, man, BSD ports/docs, demo.gif\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): v0.6.7",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-06-01T12:32:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "272aa66924f8a9b196091c1809a3377b7a65e591",
          "body": "Add Go doc for all helpers and orchestration functions in cmd/pgwd/main.go.\nDetect Postgres SQLSTATE 53300 via pgconn.PgError so too_many_clients alerts\nwork regardless of server lc_messages locale; add unit tests.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "Document cmd/pgwd main.go and fix too_many_clients detection",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-29T04:26:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "40fcc28aeb11741b0494fb261b6ffef69dd3df23",
          "body": "- README: Supported architectures (release tarballs, no riscv64 yet)\n- PORT-RELEASE: arch table, release asset checklist, quick reference\n- Makefile: drop NO_ARCH, set ONLY_FOR_ARCHS amd64 aarch64; arch comment\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(freebsd): document amd64/aarch64-only port arches",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-26T11:47:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f0bc6c97d6598cf43797b0e29c06bde085294acd",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' (sync FreeBSD port to 0.6.6)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-26T02:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d09e784bbac0ac6ad24f51024b24969bace92ec2",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): bump pgwd version to 0.6.6 in FreeBSD Makefile",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-26T02:11:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7eead90fba09b8ee5d543ef9cbc465e8f082432",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' (OpenBSD port docs, platform tests)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-25T04:26:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ebceeffe484652dbfc3b34fdcc7162c1a3227dc",
          "body": "- Add BSD-PORTS-STEP-BY-STEP, PORT-RELEASE, DEBUG-VM; expand port/README\n- OpenBSD port: @rcscript ${RCDIR}/pgwd, pkg/pgwd.rc, port-openbsd-sync copies rc\n- Add test-install-from-dist.sh; sync port Makefile to VERSION 0.6.6\n- Ansible: tarball rc.d install, rcctl assert, stray cleanup, diagnose_rcd\n- Platform test defaults and docs for OpenBSD (gghstats-aligned)\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs(openbsd): port release guide, @rcscript PLIST, Ansible parity",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-25T04:25:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "24e9a62d96c563b6fd343e71fe1d47c100486753",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' (release v0.6.6)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-25T03:52:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f13fab25912e42be6ba62614e10feca8593af59",
          "body": "- Bump VERSION, CHANGELOG, README badge and roadmap\n- Sync man page and regenerate docs/demo.gif (VHS)\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): prepare v0.6.6",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-25T03:45:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9594ef61e01fe507055dd3a99aa249ea33e5b504",
          "body": "CI govulncheck failed on idna.ToASCII reached from notify.Loki.Send.\ngo mod tidy also updates golang.org/x/sys, x/term, and x/text.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(deps): bump golang.org/x/net to v0.55.0 (GO-2026-5026)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-25T03:38:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e96b516eb23d5c84cdf2f0544f3f7401434e37a2",
          "body": "Cross-pollinate deployment manifests and repo-traffic sibling tool for\noperators discovering pgwd from GitHub.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "docs: link pgwd-selfhosted and gghstats from README intro",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-25T00:54:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3d4ec2bafd88acfe43a7b33a59a5ac6b1735a30a",
          "body": "- Remove skip_upload; fail workflow if HOMEBREW_TAP_TOKEN is unset\n- commit_author Hermes Rodríguez <hrodrig@usb.ve>\n- README: document Actions secret for homebrew-pgwd\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(release): always publish Homebrew cask; require tap token in CI",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-17T03:00:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0865acc4a73644b8f1bd78ec53dd9ea49be86744",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' (fix GoReleaser Homebrew template)",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-17T01:22:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d66cf222ec9e3afa210d9ac5ea1d77bb71a8d57",
          "body": "GoReleaser has no empty() in templates; eq (index .Env HOMEBREW_TAP_TOKEN) \"\" skips cask publish when the secret is unset.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(release): use eq template for Homebrew skip_upload",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-17T01:22:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e34944879c6716da11307d9e6384175111c85992",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' for release v0.6.5",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T22:03:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c9db56622ad896cbb26246e5bc7fdad3b667c7b",
          "body": null,
          "is_bot": false,
          "headline": "docs: regenerate demo.gif for v0.6.5",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T22:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ec4d219e8d7ed17ee68fb6feb897078f98c7f25",
          "body": "- Updated Go to version 1.26.3 and `golang.org/x/net` to v0.53.0 to address security vulnerabilities.\n- Changed Docker runtime from Alpine 3.23 to 3.22 to avoid OpenSSL CVE-2026-2673.\n- Introduced `make security` target for running govulncheck and docker-scan, aligning with CI Security workflow.\n- Updated documentation in README and CHANGELOG to reflect these changes and added new sections for License and Star History.",
          "is_bot": false,
          "headline": "chore(release): bump version to 0.6.5 with security updates",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T21:53:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c87a6f9d021e4feaa1884e5588e079e93ff0e9f",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop'",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T17:48:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01aebe2b2124b050e7aa7aa9bde904c3d75f6713",
          "body": "- Changed the gghstats clones badge link to point directly to the project page for better visibility and tracking of project usage.",
          "is_bot": false,
          "headline": "docs(README): update gghstats clones badge link for improved tracking",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T17:48:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d794f3e7a728cda1278f38f2dc89c522ed16279c",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' for release",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T17:35:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "872f2addb6a9c38631b640f25c1a5346cfb42ba5",
          "body": "- Included a badge for tracking clones from gghstats to enhance visibility of project usage.",
          "is_bot": false,
          "headline": "docs(README): add gghstats clones badge to README",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-16T17:34:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9f74c363b5dc9670e3daac10c5060ca72ed285d",
          "body": "- skip_upload when HOMEBREW_TAP_TOKEN is unset; pass token from workflow\n- Document PAT requirement for hrodrig/homebrew-pgwd\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "ci(release): make Homebrew cask upload optional without tap token",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-06T17:18:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f8d9005e6acf27ef5053ad2cee6726586c6199c7",
          "body": "- Prefer discovery.k8s.io/v1 EndpointSlices (kubernetes.io/service-name)\n- Fall back to Service selector + pod list when slices are missing\n- Changelog: document fix for deprecated core/v1 Endpoints warnings\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(kube): resolve svc backend via EndpointSlice on Kubernetes 1.33+",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-06T17:18:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f77f092ed88bfd7519bf1e567f41dc32e742eda9",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' for v0.6.4 release",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T15:24:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9daca194fccac446b9ea1d0836d0d49f543d314c",
          "body": "Aligns Release workflow with gghstats: setup-qemu-action, setup-buildx-action, login to ghcr.io before GoReleaser so dockers_v2 multi-arch (linux/amd64,linux/arm64) does not fail on ubuntu-latest docker driver.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "ci(release): QEMU, buildx, GHCR login for GoReleaser docker",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T15:23:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "aa02f286dc529a73c047ad6b4ea627e0e183e283",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' for v0.6.4 release",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T14:28:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbeec2fb02f0ad35eab37f93b23ac48ef6db2fe5",
          "body": "Removes annotations: (OCI index) that became --annotation index:… and failed with single-platform export on the default docker driver. Labels unchanged.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(release): drop dockers_v2 index annotations for GHA buildx",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T14:28:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "132a07da52b9d0f1fdb5e3114318676dacd3a1f0",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' for v0.6.4 release",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T14:05:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b7205d4422038fd88c8b4476cc40047b42c2625",
          "body": "GoReleaser defaults sbom: true; GHA docker buildx driver rejects --attest=type=sbom. Document in CHANGELOG Unreleased.\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "fix(release): disable dockers_v2 SBOM for GitHub Actions buildx",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T14:05:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0b29abfe11302dc264ea70c2ad171ba1ca0f46de",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'develop' for v0.6.4 release",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T13:39:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62bbc31784570f36bff6e97f9ffc309085b88988",
          "body": "- CHANGELOG: consolidate [0.6.4], kind E2E trap fix, security indirect bumps (spdystream, edwards25519)\n\n- go.mod/go.sum: github.com/moby/spdystream v0.5.1, filippo.io/edwards25519 v1.1.1\n\n- testing/scripts/test-e2e-kube.sh: single EXIT cleanup + delete stale cluster before create\n\n- Man page + README roadmap date 2026-05-03; release workflow comment for v0.6.4\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
          "is_bot": false,
          "headline": "chore(release): v0.6.4 final notes, deps, and kind E2E cleanup",
          "author_name": "Hermes Rodríguez",
          "author_login": "hrodrig",
          "committed_at": "2026-05-03T13:39:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 23,
      "commits_last_year": 214,
      "latest_release_at": "2026-07-18T15:07:42Z",
      "latest_release_tag": "v1.0.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 18,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/hrodrig/pgwd",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/hrodrig/pgwd",
          "is_deprecated": false,
          "latest_version": "v1.0.0",
          "repository_url": "https://github.com/hrodrig/pgwd",
          "versions_count": 23,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-18T14:44:15Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 7,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-05",
            "count": 1
          },
          {
            "date": "2026-03-11",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 1
          },
          {
            "date": "2026-03-13",
            "count": 1
          },
          {
            "date": "2026-05-18",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 7,
        "total_stars": 7
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "GNUmakefile",
        "Makefile",
        "contrib/freebsd/Makefile",
        "contrib/openbsd/port/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 27332,
      "source_files_sampled": 68,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        ".cursor/rules/changelog.mdc",
        ".cursor/rules/commit-message-review.mdc",
        ".cursor/rules/diagrams-mermaid.mdc",
        ".cursor/rules/git-flow.mdc",
        ".cursor/rules/gitignore-whitelist.mdc",
        ".cursor/rules/language-english.mdc",
        ".cursor/rules/man-page-sync.mdc",
        ".cursor/rules/readme-badges-version.mdc",
        ".cursor/rules/readme-deepwiki-badge.mdc",
        ".cursor/rules/release-tests.mdc",
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 10408
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5942"
            ],
            "fixed_version": "0.56.0",
            "advisory_count": 1,
            "oldest_advisory_days": 7
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.37.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 7
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 2
        },
        "advisory_count": 2,
        "affected_count": 2,
        "assessed_count": 53,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/DATA-DOG/go-sqlmock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.2"
        },
        {
          "name": "github.com/go-sql-driver/mysql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.1"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.9.2"
        },
        {
          "name": "github.com/ncruces/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.32.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/data-dog/go-sqlmock",
            "direct": true,
            "version": "v1.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-sql-driver/mysql",
            "direct": true,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgx/v5",
            "direct": true,
            "version": "v5.9.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-sqlite3",
            "direct": true,
            "version": "v0.32.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "filippo.io/edwards25519",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.12.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.20.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/websocket",
            "direct": false,
            "version": "v1.5.4-0.20250319132907-e064f32e3674",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgpassfile",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgservicefile",
            "direct": false,
            "version": "v0.0.0-20240606120523-5a60cdf6a761",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/puddle/v2",
            "direct": false,
            "version": "v2.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.7.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/spdystream",
            "direct": false,
            "version": "v0.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mxk/go-flowrate",
            "direct": false,
            "version": "v0.0.0-20140419014527-cca7078d478f",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/julianday",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tetratelabs/wazero",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.3",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.30.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": false,
            "version": "v1.36.8",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": false,
            "version": "v2.130.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20250910181357-589584f1c912",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": false,
            "version": "v0.0.0-20251002143259-bc988d571ff4",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 53,
        "direct_count": 9,
        "indirect_count": 44
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 9,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "hrodrig",
          "commits": 214,
          "avatar_url": "https://avatars.githubusercontent.com/u/105245?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "release.yml",
        "security.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 1,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/4 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 4,
            "reason": "3 out of the last 5 releases have a total of 3 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "48d4ce597ff2a266c1d8b6d1cfbfc212a70eee3d",
        "ran_at": "2026-07-21T22:40:09Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T00:08:56Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-19T00:05:54Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/hrodrig/pgwd",
    "host": "github.com",
    "name": "pgwd",
    "owner": "hrodrig"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 67,
      "inputs": {
        "security": 62,
        "vitality": 83,
        "community": 50,
        "governance": 56,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "commits_last_year": 214,
              "human_commit_share": 1,
              "days_since_last_push": 2,
              "active_weeks_last_year": 18
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "18/52 weeks with commits",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 18
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "214 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 214
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "releases_count": 23,
              "latest_release_tag": "v1.0.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "23 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "3 out of the last 5 releases have a total of 3 signed artifacts.",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "forks": 0,
              "stars": 7,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "7 stars",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 9,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "9/9 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 9,
                      "decided": 9
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/4 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "followers": 52,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "hrodrig",
              "public_repos": 313,
              "account_age_days": 6215
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "52 followers of hrodrig",
                "points": 12.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 52,
                      "login": "hrodrig"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "313 public repos, account ~17 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 313
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 17
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/hrodrig/pgwd"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "23 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "cli",
                "go",
                "postgres",
                "utility",
                "loki",
                "monitoring",
                "slack"
              ],
              "has_wiki": true,
              "homepage": "https://pgwd.hermesrodriguez.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://pgwd.hermesrodriguez.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "4 out of 4 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/4 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "3 out of the last 5 releases have a total of 3 signed artifacts.",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 53 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 53
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 2,
              "affected_packages": 2,
              "assessed_packages": 53,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 53,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 81,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.85,
              "agent_instruction_files": [
                ".cursor/rules/changelog.mdc",
                ".cursor/rules/commit-message-review.mdc",
                ".cursor/rules/diagrams-mermaid.mdc",
                ".cursor/rules/git-flow.mdc",
                ".cursor/rules/gitignore-whitelist.mdc",
                ".cursor/rules/language-english.mdc",
                ".cursor/rules/man-page-sync.mdc",
                ".cursor/rules/readme-badges-version.mdc",
                ".cursor/rules/readme-deepwiki-badge.mdc",
                ".cursor/rules/release-tests.mdc",
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 10408
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".cursor/rules/changelog.mdc, .cursor/rules/commit-message-review.mdc, .cursor/rules/diagrams-mermaid.mdc, .cursor/rules/git-flow.mdc, .cursor/rules/gitignore-whitelist.mdc, .cursor/rules/language-english.mdc, .cursor/rules/man-page-sync.mdc, .cursor/rules/readme-badges-version.mdc, .cursor/rules/readme-deepwiki-badge.mdc, .cursor/rules/release-tests.mdc, AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".cursor/rules/changelog.mdc, .cursor/rules/commit-message-review.mdc, .cursor/rules/diagrams-mermaid.mdc, .cursor/rules/git-flow.mdc, .cursor/rules/gitignore-whitelist.mdc, .cursor/rules/language-english.mdc, .cursor/rules/man-page-sync.mdc, .cursor/rules/readme-badges-version.mdc, .cursor/rules/readme-deepwiki-badge.mdc, .cursor/rules/release-tests.mdc, AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "85 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 85,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "GNUmakefile",
                "Makefile",
                "contrib/freebsd/Makefile",
                "contrib/openbsd/port/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.71,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "GNUmakefile, Makefile, contrib/freebsd/Makefile, contrib/openbsd/port/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "GNUmakefile, Makefile, contrib/freebsd/Makefile, contrib/openbsd/port/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "71 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 71,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 27332,
              "source_files_sampled": 68,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/68 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 68,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [],
  "report_type": "repository",
  "generated_at": "2026-07-21T22:40:24.481719Z",
  "schema_version": "0.25.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/h/hrodrig/pgwd.svg",
  "full_name": "hrodrig/pgwd",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.25.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.