Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-26 01:32 UTC

imneeteeshyadav98 / kubepreflight

Kubernetes upgrade-readiness CLI and Console for detecting deprecated APIs, webhook blockers, PDB risks, unhealthy workloads, node skew, and upgrade action plans.

Go · TypeScriptApache-2.0★ 0 stars⑂ 0 forkssince Jul 2026View on GitHub ↗

imneeteeshyadav98/kubepreflight holds a health index of 59 out of 100, placing it in the Moderate band. It scores highest on Engineering Quality (81/100) and lowest on Community & Adoption (24/100). It was last updated today. A single contributor accounts for most of its recent work.

59
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

59
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Neetesh YadavPersonal account
2 followers44 public repossince Mar 2019

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/imneeteeshyadav98/kubepreflightv1.2.1-430 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

70Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
2.8/36Commit cadence — 4/52 weeks with commits
18/18Commit volume — 233 commits in the last year
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Inputs used
commits_last_year233
human_commit_share1
days_since_last_push0
active_weeks_last_year4
How it's scored
27/27Ships releases — 27 releases published
36/36Release recency — latest release 0 days ago
27/27Release cadence — a release every ~0.7 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count27
latest_release_tagv1.2.1
releases_from_tagsno
days_since_latest_release0
mean_days_between_releases0.7

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

24Critical · 18% of overall
How it's scored
0/60Stars — 0 stars
0/25Forks — 0 forks
0/15Watchers — 0 watchers
Inputs used
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

57Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
4.9/22.5Commit distribution — top contributor authored 78% of commits
2.7/13.5Contributor breadth — 2 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.782
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
33.8/38.3PR acceptance — 183/207 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Inputs used
merged_prs183
open_issues0
closed_issues2
issue_closed_ratio1
closed_unmerged_prs24
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
3.4/25Owner reach — 2 followers of imneeteeshyadav98
24/25Track record — 44 public repos, account ~7 yr old
Inputs used
followers2
owner_typeUser
is_verified
owner_loginimneeteeshyadav98
public_repos44
account_age_days2,689
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 0 days ago
20/20Version history — 43 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/imneeteeshyadav98/kubepreflight
ecosystemsgo
any_deprecatedno
min_days_since_publish0

Engineering Quality

Are baseline engineering and documentation practices in place?

81Good · 20% of overall
How it's scored
24/24CI workflows — 9 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://devopsofworld.com/
10/10Repository description
10/10Topics — 14 topics
10/10Wiki
Inputs used
topicscli, devops, golang, kubernetes, observability, platform-engineering, react, sre, upgrade-readiness, eks, kubernetes-upgrade, pdb, webhooks, kuberntes-api
has_wikiyes
homepagehttps://devopsofworld.com/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

60Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3/7.5Vulnerabilities — 6 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate5
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories2
affected_packages2
assessed_packages254
unassessed_packages0
affected_by_severityhigh 1, unknown 1
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 254 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

62Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — web/tsconfig.json
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 19 of the last 100 commits agent-authored or agent-credited
5/8Automated maintenance — dependency automation configured, none observed in the sampled commits
3/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum, package-lock.json
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configsweb/tsconfig.json
agent_commit_share0.19
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
54.3/55Manageable file sizes — 3/224 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes124,040
source_files_sampled224
oversized_source_files3
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

0GitHub stars
2contributors
233commits, last 12 months
0days since last push
27releases
1bus factor
0open issues
Go, npmpackage ecosystems

More detail

OpenSSF Scorecard 5.0 / 10
5.0aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-26 01:32 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests29 out of 29 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
4Vulnerabilities6 existing vulnerabilities detected
Direct dependencies 15
RegistryPackageVersion constraintManifest
Gogithub.com/aws/aws-sdk-go-v2v1.42.1go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.27go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/ec2v1.311.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/eksv1.88.1go.mod
Gogithub.com/aws/smithy-gov1.27.3go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/pflagv1.0.9go.mod
Gogolang.org/x/termv0.43.0go.mod
Gok8s.io/apiv0.31.3go.mod
Gok8s.io/apiextensions-apiserverv0.31.3go.mod
Gok8s.io/apimachineryv0.31.3go.mod
Gok8s.io/client-gov0.31.3go.mod
Gosigs.k8s.io/yamlv1.4.0go.mod
npmreact^18.3.1web/package.json
npmreact-dom^18.3.1web/package.json
All dependencies 254

Full resolved dependency set from the GitHub dependency graph: 15 direct and 239 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/aws/aws-sdk-go-v2v1.42.1direct
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.27direct
Gogithub.com/aws/aws-sdk-go-v2/service/ec2v1.311.0direct
Gogithub.com/aws/aws-sdk-go-v2/service/eksv1.88.1direct
Gogithub.com/aws/smithy-gov1.27.3direct
Gogithub.com/spf13/cobrav1.10.2direct
Gogithub.com/spf13/pflagv1.0.9direct
Gogolang.org/x/termv0.43.0direct
Gok8s.io/apiv0.31.3direct
Gok8s.io/apiextensions-apiserverv0.31.3direct
Gok8s.io/apimachineryv0.31.3direct
Gok8s.io/client-gov0.31.3direct
Gosigs.k8s.io/yamlv1.4.0direct
npmreact18.3.1direct
npmreact-dom18.3.1direct
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.26indirect
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.30indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.30indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.30indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.31indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.13indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.30indirect
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.2.2indirect
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.31.5indirect
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.36.8indirect
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.43.5indirect
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirect
Gogithub.com/emicklei/go-restful/v3v3.11.0indirect
Gogithub.com/fxamacker/cbor/v2v2.7.0indirect
Gogithub.com/go-logr/logrv1.4.2indirect
Gogithub.com/go-openapi/jsonpointerv0.19.6indirect
Gogithub.com/go-openapi/jsonreferencev0.20.2indirect
Gogithub.com/go-openapi/swagv0.22.4indirect
Gogithub.com/gogo/protobufv1.3.2indirect
Gogithub.com/golang/protobufv1.5.4indirect
Gogithub.com/google/gnostic-modelsv0.6.8indirect
Gogithub.com/google/go-cmpv0.6.0indirect
Gogithub.com/google/gofuzzv1.2.0indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/imdario/mergov0.3.6indirect
Gogithub.com/inconshreveable/mousetrapv1.1.0indirect
Gogithub.com/josharian/internv1.0.0indirect
Gogithub.com/json-iterator/gov1.1.12indirect
Gogithub.com/mailru/easyjsonv0.7.7indirect
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirect
Gogithub.com/modern-go/reflect2v1.0.2indirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/onsi/gomegav1.33.1indirect
Gogithub.com/pkg/errorsv0.9.1indirect
Gogithub.com/x448/float16v0.8.4indirect
Gogolang.org/x/netv0.55.0indirect
Gogolang.org/x/oauth2v0.27.0indirect
Gogolang.org/x/sysv0.45.0indirect
Gogolang.org/x/textv0.39.0indirect
Gogolang.org/x/timev0.3.0indirect
Gogoogle.golang.org/protobufv1.34.2indirect
Gogopkg.in/evanphx/json-patch.v4v4.12.0indirect
Gogopkg.in/inf.v0v0.9.1indirect
Gogopkg.in/yaml.v2v2.4.0indirect
Gogopkg.in/yaml.v3v3.0.1indirect
Gok8s.io/klog/v2v2.130.1indirect
Gok8s.io/kube-openapiv0.0.0-20240228011516-70dd3763d340indirect
Gok8s.io/utilsv0.0.0-20240711033017-18e509b52bc8indirect
Gosigs.k8s.io/jsonv0.0.0-20221116044647-bc3834ca7abdindirect
Gosigs.k8s.io/structured-merge-diff/v4v4.4.1indirect
npm@adobe/css-tools4.5.0indirect
npm@asamuzakjp/css-color5.1.11indirect
npm@asamuzakjp/dom-selector7.1.1indirect
npm@asamuzakjp/generational-cache1.0.1indirect
npm@asamuzakjp/nwsapi2.3.9indirect
npm@babel/code-frame7.29.7indirect
npm@babel/compat-data7.29.7indirect
npm@babel/core7.29.7indirect
npm@babel/generator7.29.7indirect
npm@babel/helper-compilation-targets7.29.7indirect
npm@babel/helper-globals7.29.7indirect
npm@babel/helper-module-imports7.29.7indirect
npm@babel/helper-module-transforms7.29.7indirect
npm@babel/helper-plugin-utils7.29.7indirect
npm@babel/helper-string-parser7.29.7indirect
npm@babel/helper-validator-identifier7.29.7indirect
npm@babel/helper-validator-option7.29.7indirect
npm@babel/helpers7.29.7indirect
npm@babel/parser7.29.7indirect
npm@babel/plugin-transform-react-jsx-self7.29.7indirect
npm@babel/plugin-transform-react-jsx-source7.29.7indirect
npm@babel/runtime7.29.7indirect
npm@babel/template7.29.7indirect
npm@babel/traverse7.29.7indirect
npm@babel/types7.29.7indirect
npm@bramus/specificity2.4.2indirect
npm@csstools/color-helpers6.1.0indirect
npm@csstools/css-calc3.2.1indirect
npm@csstools/css-color-parser4.1.9indirect
npm@csstools/css-parser-algorithms4.0.0indirect
npm@csstools/css-syntax-patches-for-csstree1.1.6indirect
npm@csstools/css-tokenizer4.0.0indirect
npm@esbuild/aix-ppc640.25.12indirect
npm@esbuild/android-arm0.25.12indirect
npm@esbuild/android-arm640.25.12indirect
npm@esbuild/android-x640.25.12indirect
npm@esbuild/darwin-arm640.25.12indirect
npm@esbuild/darwin-x640.25.12indirect
npm@esbuild/freebsd-arm640.25.12indirect
npm@esbuild/freebsd-x640.25.12indirect
npm@esbuild/linux-arm0.25.12indirect
npm@esbuild/linux-arm640.25.12indirect
npm@esbuild/linux-ia320.25.12indirect
npm@esbuild/linux-loong640.25.12indirect
npm@esbuild/linux-mips64el0.25.12indirect
npm@esbuild/linux-ppc640.25.12indirect
npm@esbuild/linux-riscv640.25.12indirect
npm@esbuild/linux-s390x0.25.12indirect
npm@esbuild/linux-x640.25.12indirect
npm@esbuild/netbsd-arm640.25.12indirect
npm@esbuild/netbsd-x640.25.12indirect
npm@esbuild/openbsd-arm640.25.12indirect
npm@esbuild/openbsd-x640.25.12indirect
npm@esbuild/openharmony-arm640.25.12indirect
npm@esbuild/sunos-x640.25.12indirect
npm@esbuild/win32-arm640.25.12indirect
npm@esbuild/win32-ia320.25.12indirect
npm@esbuild/win32-x640.25.12indirect
npm@exodus/bytes1.15.1indirect
npm@jridgewell/gen-mapping0.3.13indirect
npm@jridgewell/remapping2.3.5indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@rolldown/pluginutils1.0.0-beta.27indirect
npm@rollup/rollup-linux-x64-gnu4.62.2indirect
npm@rollup/rollup-linux-x64-musl4.62.2indirect
npm@testing-library/dom10.4.1indirect
npm@testing-library/jest-dom6.9.1indirect
npm@testing-library/react16.3.2indirect
npm@testing-library/user-event14.6.1indirect
npm@types/aria-query5.0.4indirect
npm@types/babel__core7.20.5indirect
npm@types/babel__generator7.27.0indirect
npm@types/babel__template7.4.4indirect
npm@types/babel__traverse7.28.0indirect
npm@types/chai5.2.3indirect
npm@types/deep-eql4.0.2indirect
npm@types/estree1.0.9indirect
npm@types/prop-types15.7.15indirect
npm@types/react18.3.31indirect
npm@types/react-dom18.3.7indirect
npm@vitejs/plugin-react4.7.0indirect
npm@vitest/expect3.2.7indirect
npm@vitest/mocker3.2.7indirect
npm@vitest/pretty-format3.2.7indirect
npm@vitest/runner3.2.7indirect
npm@vitest/snapshot3.2.7indirect
npm@vitest/spy3.2.7indirect
npm@vitest/utils3.2.7indirect
npmansi-regex5.0.1indirect
npmansi-styles5.2.0indirect
npmaria-query5.3.0indirect
npmassertion-error2.0.1indirect
npmbaseline-browser-mapping2.10.41indirect
npmbidi-js1.0.3indirect
npmbrowserslist4.28.4indirect
npmcac6.7.14indirect
npmcaniuse-lite1.0.30001800indirect
npmchai5.3.3indirect
npmcheck-error2.1.3indirect
npmconvert-source-map2.0.0indirect
npmcss-tree3.2.1indirect
npmcss.escape1.5.1indirect
npmcsstype3.2.3indirect
npmdata-urls7.0.0indirect
npmdebug4.4.3indirect
npmdecimal.js10.6.0indirect
npmdeep-eql5.0.2indirect
npmdequal2.0.3indirect
npmdom-accessibility-api0.5.16indirect
npmdom-accessibility-api0.6.3indirect
npmelectron-to-chromium1.5.385indirect
npmentities8.0.0indirect
npmes-module-lexer1.7.0indirect
npmesbuild0.25.12indirect
npmescalade3.2.0indirect
npmestree-walker3.0.3indirect
npmexpect-type1.4.0indirect
npmfdir6.5.0indirect
npmfsevents2.3.3indirect
npmgensync1.0.0-beta.2indirect
npmhtml-encoding-sniffer6.0.0indirect
npmindent-string4.0.0indirect
npmis-potential-custom-element-name1.0.1indirect
npmjs-tokens4.0.0indirect
npmjs-tokens9.0.1indirect
npmjsdom29.1.1indirect
npmjsesc3.1.0indirect
npmjson52.2.3indirect
npmloose-envify1.4.0indirect
npmloupe3.2.1indirect
npmlru-cache11.5.1indirect
npmlru-cache5.1.1indirect
npmlz-string1.5.0indirect
npmmagic-string0.30.21indirect
npmmdn-data2.27.1indirect
npmmin-indent1.0.1indirect
npmms2.1.3indirect
npmnanoid3.3.15indirect
npmnode-releases2.0.50indirect
npmparse58.0.1indirect
npmpathe2.0.3indirect
npmpathval2.0.1indirect
npmpicocolors1.1.1indirect
npmpicomatch4.0.5indirect
npmpostcss8.5.16indirect
npmpretty-format27.5.1indirect
npmpunycode2.3.1indirect
npmreact-is17.0.2indirect
npmreact-refresh0.17.0indirect
npmredent3.0.0indirect
npmrequire-from-string2.0.2indirect
npmrollup4.62.2indirect
npmsaxes6.0.0indirect
npmscheduler0.23.2indirect
npmsemver6.3.1indirect
npmsiginfo2.0.0indirect
npmsource-map-js1.2.1indirect
npmstackback0.0.2indirect
npmstd-env3.10.0indirect
npmstrip-indent3.0.0indirect
npmstrip-literal3.1.0indirect
npmsymbol-tree3.2.4indirect
npmtinybench2.9.0indirect
npmtinyexec0.3.2indirect
npmtinyglobby0.2.17indirect
npmtinypool1.1.1indirect
npmtinyrainbow2.0.0indirect
npmtinyspy4.0.4indirect
npmtldts7.4.6indirect
npmtldts-core7.4.6indirect
npmtough-cookie6.0.1indirect
npmtr466.0.0indirect
npmtypescript5.9.3indirect
npmundici7.28.0indirect
npmupdate-browserslist-db1.2.3indirect
npmvite6.4.3indirect
npmvite-node3.2.4indirect
npmvitest3.2.7indirect
npmw3c-xmlserializer5.0.0indirect
npmwebidl-conversions8.0.1indirect
npmwhatwg-mimetype5.0.0indirect
npmwhatwg-url16.0.1indirect
npmwhy-is-node-running2.3.0indirect
npmxml-name-validator5.0.0indirect
npmxmlchars2.2.0indirect
npmyallist3.1.1indirect
PyPIselenium4.34.2indirect
Dependency advisories 2

This repository publishes no package the index resolves, so its own dependency graph was assessed — 254 packages, which also include development and test pins that never ship: 2 carry known advisories, of which 0 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
postcss8.5.16indirecthigh18.5.18
golang.org/x/netv0.55.0indirectunknown10.56.0

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "cli",
        "devops",
        "golang",
        "kubernetes",
        "observability",
        "platform-engineering",
        "react",
        "sre",
        "upgrade-readiness",
        "eks",
        "kubernetes-upgrade",
        "pdb",
        "webhooks",
        "kuberntes-api"
      ],
      "is_fork": false,
      "size_kb": 7281,
      "has_wiki": true,
      "homepage": "https://devopsofworld.com/",
      "languages": {
        "Go": 1989740,
        "CSS": 40584,
        "HTML": 329,
        "Shell": 77478,
        "Python": 33343,
        "Dockerfile": 1534,
        "PowerShell": 4695,
        "TypeScript": 297251
      },
      "pushed_at": "2026-07-25T17:45:14Z",
      "created_at": "2026-07-04T10:02:56Z",
      "owner_type": "User",
      "updated_at": "2026-07-25T17:45:22Z",
      "description": "Kubernetes upgrade-readiness CLI and Console for detecting deprecated APIs, webhook blockers, PDB risks, unhealthy workloads, node skew, and upgrade action plans.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "master",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://devopsofworld.com/",
      "name": "Neetesh Yadav",
      "type": "User",
      "login": "imneeteeshyadav98",
      "company": null,
      "location": "Noida",
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/48591606?v=4",
      "created_at": "2019-03-15T12:23:15Z",
      "is_verified": null,
      "public_repos": 44,
      "account_age_days": 2689
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-07-25T17:22:43Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-07-25T03:35:42Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-07-22T08:34:30Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-07-20T08:59:58Z"
        },
        {
          "tag": "v1.0.0-rc.3",
          "kind": "prerelease",
          "published_at": "2026-07-20T07:26:37Z"
        },
        {
          "tag": "v1.0.0-rc.2",
          "kind": "prerelease",
          "published_at": "2026-07-19T17:23:22Z"
        },
        {
          "tag": "v1.0.0-rc.1",
          "kind": "prerelease",
          "published_at": "2026-07-19T15:22:01Z"
        },
        {
          "tag": "v0.17.1-install-matrix",
          "kind": "prerelease",
          "published_at": "2026-07-19T11:01:25Z"
        },
        {
          "tag": "v0.17.0-install-matrix",
          "kind": "prerelease",
          "published_at": "2026-07-19T09:38:28Z"
        },
        {
          "tag": "v0.16.2-security-trust",
          "kind": "prerelease",
          "published_at": "2026-07-19T06:24:04Z"
        },
        {
          "tag": "v0.16.1-security-trust",
          "kind": "prerelease",
          "published_at": "2026-07-19T05:14:51Z"
        },
        {
          "tag": "v0.15.0-redaction",
          "kind": "prerelease",
          "published_at": "2026-07-18T13:44:41Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-17T18:10:05Z"
        },
        {
          "tag": "v0.14.0-real-eks-case-study",
          "kind": "prerelease",
          "published_at": "2026-07-17T04:17:42Z"
        },
        {
          "tag": "v0.13.0-github-action-comparison",
          "kind": "prerelease",
          "published_at": "2026-07-16T08:09:01Z"
        },
        {
          "tag": "v0.13.0-github-action-comparison-rc.1",
          "kind": "prerelease",
          "published_at": "2026-07-16T07:46:05Z"
        },
        {
          "tag": "v0.12.0-eks-rollback-readiness",
          "kind": "prerelease",
          "published_at": "2026-07-15T11:27:20Z"
        },
        {
          "tag": "v0.11.1-console-responsive-fix",
          "kind": "prerelease",
          "published_at": "2026-07-15T07:29:39Z"
        },
        {
          "tag": "v0.11.0-api-version-catalog",
          "kind": "prerelease",
          "published_at": "2026-07-15T06:51:38Z"
        },
        {
          "tag": "v0.10.0-compatibility-catalog",
          "kind": "prerelease",
          "published_at": "2026-07-14T11:02:17Z"
        },
        {
          "tag": "v0.9.1-version-direction-ux",
          "kind": "prerelease",
          "published_at": "2026-07-14T08:42:09Z"
        },
        {
          "tag": "v0.9.0-scale-resilience",
          "kind": "prerelease",
          "published_at": "2026-07-13T11:32:32Z"
        },
        {
          "tag": "v0.8.0-drain-readiness",
          "kind": "prerelease",
          "published_at": "2026-07-12T17:11:55Z"
        },
        {
          "tag": "v0.7.0-addon-compatibility",
          "kind": "prerelease",
          "published_at": "2026-07-12T10:42:31Z"
        },
        {
          "tag": "v0.6.0-admission-webhook-safety",
          "kind": "prerelease",
          "published_at": "2026-07-12T08:11:44Z"
        },
        {
          "tag": "v0.5.0-scan-comparison",
          "kind": "prerelease",
          "published_at": "2026-07-12T05:25:42Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-07-11T17:53:48Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "4bd2ea8db9b63dd3dc30ced83c9ffd8c84ea3aa1",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: refresh hardcoded version references to v1.2.1 (#219)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-25T17:45:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "365260f829b91e433e2941a0d9f61bb8916fe335",
          "body": "Records tag/commit identity, published release assets, GitHub Actions\nrun links, the external `go install` consumer-path verification, the\ntransient sum.golang.org propagation delay (and its retry) classified\nas infrastructure, not a product defect, and the full focused patch\nvalidation run against \n[…]\nre tagging.\n\nMatches this repo's existing evidence-archive convention (e.g.\ndocs/phase-0-release-security-verification.md, docs/case-studies/).\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: archive v1.2.1 release evidence (#218)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-25T17:38:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6cba978e73941be5669038a71a543a542bfdf0ac",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: document EKS exec-auth requirements for container usage (#217)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-25T17:06:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8609e4e1e9c3f2e331b437795bba9cfc8370912e",
          "body": "Found live during a real-EKS v1.2.0 certification against AWS's own\nvpc-resource-validating-webhook: the high-risk-resource-scope finding's\nmessage unconditionally claimed \"this fail-closed webhook\" regardless of\nthe webhook's actual failurePolicy, contradicting its own Evidence entry\n(failurePolicy\n[…]\npgradeGate, Fingerprint\ninputs, and every other finding field are unchanged -- only Message text\nand the two stale comments/docs are corrected.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: correct WH-005 fail-open webhook wording (#216)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-25T16:44:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "98303465430d5c1f45186a5c5582fc23a0587fd8",
          "body": "A requested persistent report/artifact that cannot be created or fully\nwritten (bad --output-dir, an unwritable target path, a partial\n--output all write) is an infrastructure/output-delivery failure, not\nan ordinary command error -- it must exit 4, not 1, so CI gates\nchecking \"exit code <= 1 is saf\n[…]\nvior, or successful-run\nexit code changes. Assessment.Validate() and other generic pre-report\nerrors keep their existing exit-1 classification.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: return infrastructure exit code for report write failures (#213)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-25T13:11:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1309f5b5e210f5b477cdb217002c315bc44bf729",
          "body": "Adds the missing v1.1.0 release-history entry and marks v1.2.0 current;\ncorrects rollback-readiness.md's stale \"planned for v0.12.0\" status line,\nwhich was never updated after that feature shipped.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: update release history and rollback status for v1.2.0 (#212)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-25T03:28:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a847321cc3391f422d6977039b54cf54ae66acdb",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: preserve blocker exit code for hard rollback ineligibility (#211)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-24T10:58:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c1975952aa70c70b3bf6de7005b95168266ff1b",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: validate rollback findings input document (#210)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-24T09:11:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8976fb78f058e880763ed93144d82afdd5225eef",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: validate findings freshness for rollback (#209)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-24T07:02:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39619bbdde2f891f19ef4f0ef8aafef033530dd3",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: validate findings cluster identity for rollback (#208)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-24T03:21:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d63bc41532472bbf6b016bf0f09886c65fef830",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: validate API evidence target for rollback (#207)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T09:50:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97700d40425716cefd27c295ef5e94e2b4772bb8",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix(deps): update x/text to address GO-2026-5970 (#206)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T08:43:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a1195d64a464bdb548e5221920597fb9c7bd740",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: require disruption evidence for rollback blockers (#205)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T08:13:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc3c858ce29aead4c87b932bf40965433f4aa6fc",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: document current rollback finding semantics (#204)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T07:25:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54b284fc76dad079bffffa7d29a713aa482920eb",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add explicit impact scopes to non-blocking findings (#203)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T07:00:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b0de4ccfe1de7b065573871a888903af03b515e",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: gate add-on incompatibilities by operational impact (#202)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T04:11:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6cef33f9b943b898fba69e9ce2a0b8fc26506a6",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add add-on operational impact metadata (#201)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-23T03:35:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffb706a0c62038c33f7428b0b0cdb65dd5f52edd",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: gate EKS provider preconditions by upgrade context (#200)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T11:21:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fa96aafca2c8cfe2c557e1240b8a72545ffa283",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: add v1.1.0 context-aware gating demo (#199)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T10:40:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdfad7eb897c348c8a61af3b811caa5d3d7e9fa4",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: add v1.1.0 context-aware gating demo (#198)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T10:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee08a1d857baa353afe0a5a13964ac53a405743b",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: make upgrade gating context-aware (#196)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T07:33:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5b75104a454aa437829de2b6cf5a184d6ed1bb7",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: downgrade deprecated master label finding to warning (#195)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T06:13:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffccd7f3ccfe17310e99832a337b20cbd57ff087",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: add five-minute KubePreflight testing guide (#193)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T05:42:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e36fd965beb114fd81c24171e495ef4cbe3766d",
          "body": "* demo: enlarge LinkedIn v2 opening title card for mobile legibility\n\nThe title group (\"KubePreflight v1.0.0\", \"Kubernetes & EKS upgrade\nreadiness\") was sized for the 1920x1080 recording canvas, but the\n1080x1080 LinkedIn export scales that down by ~0.56x -- what read fine\nat native resolution becam\n[…]\n reverified via ffprobe and demo/v1-launch/verify.sh after\nre-recording and re-rendering.\n\n* docs: add external tester feedback form\n\n---------\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "Demo/linkedin v2 title legibility (#191)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-22T03:44:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b57dd22ae8d47ebab3f2d40c2d4d5875559ecd6",
          "body": "Adds the v1.0.0 launch demo GIF (docs/assets/kubepreflight-v1-launch.gif)\nas a hero visual near the top of the README, linking to the EKS\n1.31-to-1.32 case study. Built from real, sanitized SEC-TRUST-002\nevidence -- see demo/v1-launch/README.md for the full pipeline,\nprovenance, and the cosmetic cluster-name redaction applied for public\ndistribution.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: add v1.0.0 launch demo to README (#189)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-21T07:27:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "920b042054b219402a5b161af37d92132e0f7b99",
          "body": "…) (#190)\n\nThe 13s GIF-derived teaser opens directly on the terminal and ends\ndirectly on the report -- fine riding a LinkedIn post's caption for\ncontext, but it doesn't stand on its own with no caption. Adds a second,\nindependent recording mode (VARIANT=linkedin) that brackets the same\nreal termina\n[…]\nx1.mp4 (1080x1080),\n-v2-poster.png -- all verified via ffprobe + demo/v1-launch/verify.sh\nand by extracting/inspecting a frame from every beat.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "demo: add standalone LinkedIn v2 teaser (15.8s, opening/closing cards…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-21T07:13:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "372af900ec83d2417e717dff2921432ee9a7afb0",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: redact cluster name in public launch media (#188)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-21T06:21:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ba03147193d9205ffc3feda7c0f79e05fb8b52b",
          "body": "…ling) (#187)\n\nUpgrades web/'s dev-only build/test tooling to clear all 5 open Dependabot\nalerts (1 critical: vitest arbitrary file read via its UI server; 1 high\nand 2 medium: vite path-traversal/fs-deny bypass; 1 medium: esbuild dev-server\nCORS): vite ^5.4.10 -> ^6.4.3, vitest ^2.1.4 -> ^3.2.6 (es\n[…]\nlready a real, if\npreviously mislabeled, dependency of spf13/cobra) -- unrelated to this\nsecurity fix, no version or checksum change in go.sum.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "security: resolve open Dependabot alerts (vite/vitest/esbuild dev too…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-21T03:39:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b8c1a79bece4cb3f375a81ec31e3c1160630b72",
          "body": "Self-contained pipeline under demo/v1-launch/ that produces a 25-30s\nlaunch demo from real, already-sanitized SEC-TRUST-002 evidence: a\nPlaywright recorder that navigates real title/finding cards, the real\nreport.html, and the real embedded Console (loaded with real evidence\nfixtures), plus an ffmpe\n[…]\nion\"). The one exception is\nthe README-ready GIF, committed at docs/assets/kubepreflight-v1-launch.gif\nalongside the repo's other product GIFs.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "demo: add v1.0.0 launch video pipeline (#186)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-20T16:57:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e714950e9ecb98de156c7643bbb65e7943f637b5",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: prepare README for v1.0.0 (#185)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-20T08:47:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87c8bfb884d3df4210def4cc102ac6ba868e15f4",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "chore: pin published Action validation to v1.0.0 (#184)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-20T08:01:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc568ea74810efa334f8785479eac26bbbc63f07",
          "body": "Same convention every prior bump used -- uses: can't take a dynamic\n${{ env.X }} ref, so REF and every uses: line's hardcoded tag move\ntogether by hand.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: pin validate-published-action.yml to v1.0.0-rc.3 (#182)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-20T07:37:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "966b944dc86e1f89a340a2d7f286ce7ad243946d",
          "body": "Full Playwright + axe-core audit against real captured data (live BLOCKED\nreport, plan, rollback assessment, a real compare diff) across all four\nlaunch breakpoints, plus a synthetic 1,247-finding dataset for load\nbehavior. Started at ~13 violation groups across every scanned view, ends\nat zero.\n\nFi\n[…]\nby reverting these\nchanges) -- unrelated to any fix here and out of this audit's scope.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: resolve Console v1 accessibility audit findings (#181)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-20T07:11:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2757bc5ef43afb46c315b5f894299ff053bbd7c8",
          "body": "None of these are reachable from a mocked cluster or a manifests-only\nfixture -- they only surfaced once the harness ran for real against a\ndisposable EKS cluster and the v1.0.0-rc.2 release artifacts.\n\n- lib.sh: write_ephemeral_eks_kubeconfig returned a relative path,\n  which `docker run -v` silent\n[…]\nmarked complete\nagainst v1.0.0-rc.2, with a short account of what this run alone found.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: five bugs found by the real SEC-TRUST-002 live EKS execution (#180)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T18:24:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2222ccd2038931c31990075921a5ac1c167fc963",
          "body": "…t-dir (#179)\n\nrollbackReportTargets only checked filepath.IsAbs before joining\nassessmentOut onto outputDir, unlike scan's resolveOutputPath (which\nalso treats a relative path with an existing directory component as\nalready-resolved). Any caller passing --assessment-out as\n<output-dir>/<file> -- th\n[…]\nilter is invalid jq syntax --\nsingle quotes don't need escaping) found by the same run.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: rollback plan/assess double-prefix --assessment-out with --outpu…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T17:12:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "93d14b978cb73b481b02da814cf297d6c600ba7a",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: accept release version metadata in live EKS smoke (#178)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T15:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cd105fd1e7222ba0f96857c938ceaab5d25f225",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: add released-artifact live EKS smoke (#177)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T15:06:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c46c1801009b18295a0d0ca311dd5c57ca103b4f",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "perf: harden v1 scale and responsiveness (#176)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T14:45:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "510477c548b069dde5f29d05c66ba270d3ff2f89",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: define v1 compatibility contract (#175)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T14:27:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2ee88a460647b49112bb4ff6572d79de228ad24",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: finalize false-positive governance (#174)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T13:59:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "109bae1b90d628dd534bb9ef53759cccbe53dde5",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "ci: enforce false-positive exemption governance (#173)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T13:42:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd2225e4df934a4ca5cdf7454bce10c0f4cee2cb",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "ci: enforce false-positive exemption governance (#172)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T13:37:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "daad4045773edaf9329308f05a41a8acd7ddd16b",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: add exemption spoofing regression suite (#171)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T13:27:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3518f90aa1dd99078f7e60d1c544d26e0d97911",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: add exemption spoofing regression suite (#170)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T13:22:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce04913804995cfbd6b474aad7c1c09b712ccc80",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "refactor: govern existing false-positive exemptions (#169)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T13:08:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19667430e7b48167a6470096cdd3486a6fa48bdc",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "refactor: govern existing false-positive exemptions (#168)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T12:58:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1879b5253e467e8f5875d744a141d42b04d5bad4",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add false-positive exemption governance (#167)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T12:43:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a0f87a285e2a7bc0d02ffb1e507e64499f339cc",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add false-positive exemption governance (#166)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T12:30:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f5c789b0298bcf5682f0ed954c4878397348f77",
          "body": "…d-action.yml (#165)\n\nThe BLOCKED fixture makes entrypoint.sh correctly exit 1 (fail-closed\nbehavior for real callers), which stopped the job before the next step\ncould assert on the scan step's outputs. Same convention\nvalidate-comparison-rc.yml already uses for its own\nintentionally-failing steps.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: continue-on-error on scan Action smoke step in validate-publishe…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T11:36:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "19c7bb89452c0bbee72dccb143c575afd1dd96bc",
          "body": "…eal run (#164)\n\nv0.17.0-install-matrix published successfully -- core build/image/\nsecurity jobs all green, but four of the five new KP-V1-INSTALL-001\nverification jobs failed on their first real run against hosted\nrunners. Not a product defect: the harness itself had bugs that only a\nreal tagged r\n[…]\n every scripts/release/*.sh,\nactionlint, check-github-action-security.sh, go build/vet/test,\ngovulncheck, gofmt, git diff --check -- all clean.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: cross-platform install-matrix verifier bugs found by v0.17.0's r…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T10:38:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aaf859463c4f97bb39582e431f6a723df26e86d4",
          "body": "…163)\n\nBumps the workflow's hardcoded tag reference (job name, env.REF, and\nboth `uses:` lines -- uses: does not support dynamic ${{ env.X }}\nsubstitution, so these have to be kept in sync by hand) from\nv0.16.2-security-trust to the release that will actually contain the\ngo install fix this release \n[…]\nspatch-only, never auto-triggered, so a\nbrief window where it points at a tag that doesn't exist yet is\nharmless -- nobody runs it by accident.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "chore: pin validate-published-action.yml to v0.17.0-install-matrix (#…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T09:13:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d5b296f33514df02f8a444f0f55680b08fb9768",
          "body": "go.mod declared this module's path as plain \"kubepreflight\" since the\nproject's inception -- fine for a binary nobody imports as a library,\nbut it meant `go install github.com/imneeteeshyadav98/kubepreflight/\ncmd/kubepreflight@<tag>` could never work, failing with:\n\n  module declares its path as: ku\n[…]\nng the existing verify job's smoke step) confirming the\nsafe dev/unknown/unknown default still works when no build-args are\ngiven -- all clean.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: publish this module under its real GitHub import path (#162)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T08:18:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0f58648deef636aa65081ed861099745c5251f5",
          "body": "Extends REL-TRUST-004's single Linux-only verify-published-release job\ninto a full matrix proving every documented install path against the\nactual published artifacts, not a repo-local rebuild:\n\n  verify-published-release-linux   deep smoke (unchanged behavior,\n                                    re\n[…]\nnot externally-referenced\nscript files), check-github-action-security.sh, go build/vet/test,\ngovulncheck, gofmt, git diff --check -- all clean.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "ci: add published installation matrix (KP-V1-INSTALL-001) (#161)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T07:16:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9ac65ab222a913bafd40cae057e8863b854cef6",
          "body": "REL-TRUST-002/003's type=semver,pattern=v{{version}} line has never\nactually worked, for every release this project has ever published\n(0.15.0-redaction, 0.16.0-security-trust, 0.16.1-security-trust) --\nconfirmed by checking GHCR directly: only the bare tag exists on any\nof them, never the v-prefixe\n[…]\nal verification.\n\nValidated: actionlint, check-github-action-security.sh, go\nbuild/vet/test, govulncheck, gofmt, git diff --check -- all clean.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: publish the v-prefixed GHCR alias correctly (#160)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T06:10:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f15989de17a7a914e601573f75e3ead14399e27",
          "body": "Scorecard's own workflow-verification step rejects a calling workflow\nthat declares id-token or security-events write scope at the\nworkflow level, since that would grant that scope to every job the\nworkflow could ever run, not just the analysis job that actually\nneeds it -- confirmed as the real cau\n[…]\nocal-validation\nenvironment), plus the existing check-github-action-security.sh\nguard, go build/vet/test, govulncheck, gofmt, git diff --check.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: scope Scorecard publishing permissions (#159)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T04:54:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "38c120b6855cf5f4376758e9d2004f28781a2149",
          "body": "Root cause of ci #298 failing on master (the run right after #156\nmerged): actionlint's shellcheck integration silently no-ops when\nshellcheck isn't on PATH -- true in my earlier local validation, but\nGitHub-hosted ubuntu-latest runners have shellcheck pre-installed, so\nCI's actionlint step (added i\n[…]\nclean both with\nand without shellcheck on PATH, matching both the CI environment and\nthe environment my prior local validation actually ran in.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: resolve shellcheck findings actionlint now surfaces in CI (#158)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T04:06:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6cf83aaf477a4bb0fe48e8e4096bf47f132ca4c",
          "body": "Follow-up to #155, which fixed the invalid @0.33.1 reference but\npinned to that tag's own (safe, post-remediation) commit rather than\nmoving past the version threshold GHSA-69fq-xp46-6x23 /\nCVE-2026-33634 actually recommends. That advisory documents a real\nsupply-chain compromise of aquasecurity/tri\n[…]\ne pre-existing, unrelated,\ntag-pinned references this script deliberately leaves alone; a\nblanket SHA-pin mandate would break CI for all three.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: upgrade Trivy action to a safe version, add regression guard (#156)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T03:50:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25a9c046aba69dd46dcc160b9482d4d467b4f7f7",
          "body": "aquasecurity/trivy-action@0.33.1 does not exist -- confirmed via the\nGitHub API (git/refs/tags/0.33.1 returns 404). The real upstream tag\nis v-prefixed: v0.33.1, resolving to commit\nb6643a29fecd7f34b3597bc6acb0a98b03d33ff8. This broke the\nv0.16.0-security-trust release run (scan-release-image job) a\n[…]\n-action was even\nintroduced) -- not addressed here, flagged separately since GitHub's\njob-log API needs admin rights this session doesn't have.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: use valid Trivy action release reference (#155)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-19T03:29:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3bb167a59af953033134a4f0467e16d1bb33a5d2",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "security: add container scanning and scorecard hardening (#153)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T18:12:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31374cab87b5598dc52fcb59a25e604330a8d972",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "security: add GitHub-native security baseline (#147)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T17:53:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd60de01d5bbb8f45ee59e130e13a009243d9387",
          "body": "…-004) (#146)\n\nNew verify-published-release job in release.yml, running after\ngithub-release so every asset is live. Downloads the actual GitHub\nRelease assets via `gh release download` -- never a `go build` of\nthis checkout -- and:\n\n- verifies the linux_amd64 archive's checksum\n- confirms the SBOM \n[…]\nch one passes (and would fail loudly if any single\npiece regressed -- e.g. version stuck on \"unknown\", a missing flag,\nor the wrong exit code).\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "ci: verify published release artifacts, not the repo build (REL-TRUST…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T14:42:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b83b837033c0c3cb622f6c9cd8f42f1ffd1b3d4",
          "body": "…EC-TRUST-001) (#145)\n\ninternal/redact.Text() now also redacts bare 12-digit AWS account IDs\nin free text (\\b\\d{12}\\b), not just IDs embedded in a full ARN --\narnPattern alone can't catch e.g. \"AccessDenied for account\n164761934067\" with no arn:aws: prefix. Applied after arnPattern, so\nan account ID\n[…]\n output, instead of only the\ntwo it started with, so a regression in any one leaks the same way\nregardless of which writer produced the output.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: add standalone-account-ID redaction and exhaustive leak gate (S…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T14:37:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5420d9d540fe5dc40b85f4a68792f05f82c32696",
          "body": "… (REL-TRUST-002/003) (#143)\n\nBoth the binaries job and the docker job now compute the same\nversion (tag with leading \"v\" stripped), commit (short SHA), and\nUTC build date, and thread them into internal/buildinfo via -X\nldflags / Docker build-args, so `kubepreflight version` and\n`docker run <image> \n[…]\nnner. A build with no\nbuild-args (matching the existing verify job's release-smoke build)\nstill falls back cleanly to the dev/unknown defaults.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: inject release provenance via ldflags, add v-prefixed GHCR alias…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T14:29:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "83d4d87ee4a1f1a45e927641076c9faaf2ddfdae",
          "body": "Adds `kubepreflight version` and `kubepreflight --version`/`-v`, both\nprinting the same three-line banner from a new internal/buildinfo\npackage. Version/Commit/BuildDate default to dev/unknown for local and\ntest builds; wiring them via release-workflow ldflags is left to a\nfollow-up PR (REL-TRUST-002/003) to keep this change isolated.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add version command and build provenance (REL-TRUST-001) (#142)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T14:07:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f590e9365722b09362035df9f7a335974ebd17a",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: redact API compatibility summary resources (#141)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T13:35:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27fe42ae00644e626aad93bffbdbb6bc5c2dca10",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: lock redaction release verification (#140)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T13:28:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03f8aad635967f5d74b735a89b95c4c9acc5a6b0",
          "body": "…ive flag (#139)\n\nPre-merge review of the redaction feature found a real gap: comparison.Entry\nembeds the full findings.Finding verbatim (\"the full finding, not a\nsummary\" per its own doc comment), so kubepreflight compare could silently\nforward every unredacted identifier into comparison.json even \n[…]\nheck it always was, now confirming the native flag rather than rescuing\nafter the fact.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: extend redaction to compare output, migrate live-eks demo to nat…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T12:52:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2e966ac6e7af498f4be86d5ee5789404ad3c3e84",
          "body": "Generated evidence (findings.json, report.md/html, rollback-assessment\nJSON, upgrade-plan.json) embeds real AWS account IDs (inside cluster ARNs)\nand real EC2-style internal node hostnames verbatim, with no way to avoid\nit. This was found the hard way while building the live EKS demo\n(demo/live-eks/\n[…]\nernal form -- exactly\nthe shape every finding in this session's own demo evidence used.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add --redact-sensitive-identifiers flag (SEC-ARTIFACT-001) (#138)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T12:35:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "17ade3d7d6ca1199cc0451282c2798604702f18d",
          "body": "* docs: add live disposable-EKS demo GIFs\n\nAdds a reproducible demo/live-eks/ script suite (create/apply-before/scan/\nremediate/compare/redact-evidence/verify-expected-output/destroy), modeled\non scripts/case-study/'s pattern, reusing the already-proven demo/eks and\ndemo/eks-case-study fixtures rath\n[…]\nuster name remains.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Docs/add live eks demo (#137)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T11:33:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f9d7e93bae9c91de93781dca5e5b35e5f6896d1f",
          "body": "* docs: add real cluster workflow demo\n\nAdds a GIF near the top of the README showing kubepreflight compare run\nlive against the already-published, sanitized EKS 1.31-to-1.32 case-study\nevidence (demo/eks-case-study/evidence/), followed by the same evidence in\nthe real embedded Console (via cmd/cons\n[…]\ne PR's merge order.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Docs/add real cluster demo gif (#136)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-18T09:04:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d66bc5b77238f60d6e9793e09884e217fc72d8f1",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: redact EKS case study evidence identifiers (#135)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-17T04:08:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90721fe7ae902a4652dbc26c0771c10ce210361d",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: publish real EKS upgrade and rollback case study (#134)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-17T03:51:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9eba4e3197d15dd3d6eda92b31e9c17e79a0b212",
          "body": "Two follow-ups from PR3 review, both addressed rather than deferred:\n\nEvidence sanitization: demo/eks-case-study/evidence/ and this PR's own\nnarrative in docs/case-studies/eks-1.31-to-1.32.md embedded the real\nAWS account ID (in cluster ARNs) and the real node's private-IP-derived\nhostname across ev\n[…]\nhe same class of limitation the\nprior annotation-only check already had, not a new one.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: narrow eks-internal field-manager tests, sanitize evidence (#133)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T17:44:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3281712c99dacb3d1947dcc118bb4affc43de713",
          "body": "…(#132)\n\nPR3 of v0.14.0-real-eks-case-study: ran the full documented walkthrough\nagainst a real EKS cluster (kubepreflight-case-study, us-east-1,\naccount 164761934067), start to finish -- clean baseline, seed\nfixtures, before/after-remediation/after-upgrade scans, remediation,\na real `eksctl upgrade\n[…]\n these real findings\nneeds `gh` auth this sandbox doesn't have -- carried to PR4/Final.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: execute real EKS 1.31->1.32 case study, fix a real Blocker bug …",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T17:34:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a82d995e01b5bfc78b43a2a86e338cde68168706",
          "body": "PR2 of v0.14.0-real-eks-case-study: reproducible automation only,\nnothing executed against a real cluster yet -- PR3 does that.\n\nscripts/case-study/ -- numbered scripts matching the design doc's\nmethodology: seed the (mostly reused) fixtures, scan a phase into\ndemo/eks-case-study/evidence/<phase>/, \n[…]\nroof the constructed command is well-formed, not proof it\nworks against a live cluster.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add reproducible case-study scripts and evidence capture (#131)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T10:30:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1e5e48d122cb82be42bb53c3659598b82741780b",
          "body": "PR1 of v0.14.0-real-eks-case-study: environment and fixture design\nonly, nothing executed against a real cluster yet.\n\ndocs/case-studies/eks-1.31-to-1.32.md is the committed methodology —\nenvironment, the five fixture categories and which rule each\ndemonstrates, the PR split, the case-study-vs-featu\n[…]\nmo.yaml (a single-version worst-case scan demo, not an\nupgrade walkthrough) never does.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: define real EKS case study validation plan (#130)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T10:21:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "70fb561bfa01477f99a9f5301808225de7fe1da3",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: isolate hosted comparison warning-policy validation (#129)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T09:54:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5db0b0cbd9a158125bdfb22a9d4d67d7fc295e2",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "test: add hosted comparison RC validation workflow (#128)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T07:59:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f600dd6283e3b7e9df4099d74399a3799e457b02",
          "body": "…(#127)\n\nAdds a full \"Comparing two scans\" section to docs/ci-integration.md\n(quick start, inputs, outputs, exit policy, what you get in the UI)\nplus a short pointer from README.md's GitHub Action section, using a\nreal PR-gate example (scan base ref, scan head ref, compare) that was\nactually run end\n[…]\nnket check that entrypoint.sh\nnever logs a jq error, so both stay caught going forward.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: document the compare Action; fix two chaining bugs it surfaced …",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T07:33:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ee796abdb858a6e9cfefb4cb9a1028878ce36fa",
          "body": "… (#125)\n\nAdds an actions/upload-artifact step to compare/action.yml uploading\ncomparison.json/gate.json, mirroring the root action's own always-run\nartifact upload. Adds three committed findings.json fixture pairs\n(compare/testdata/fixtures/pass, fail-new-blocker,\nneutral-incomplete) covering the g\n[…]\nopulated, stays reserved for the\nmilestone's Final real-GitHub-Actions-validation step.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add artifact upload, fixtures, and e2e tests for compare Action…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T07:03:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bc7743e370b4284095ba2bf2276306ec76bd4137",
          "body": "compare/entrypoint.sh now writes a Markdown job summary (gate\ndecision/reasons, verdict and readiness-score movement, and tables of\nnew/resolved findings by rule ID) to GITHUB_STEP_SUMMARY, and emits one\n::error:: annotation per newly-introduced Blocker-severity finding\n(with file= set from the find\n[…]\n summary\ntable only, keeping annotations reserved for what's actually gating\nthe merge.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add job summary and blocker annotations to compare Action (#124)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T06:19:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d4aad4271ed8f38092d46679b341b546028567a3",
          "body": "…123)\n\nExtends `kubepreflight compare` with --gate-out and granular\n--fail-on-new-blockers/--warning-policy/--fail-on-verdict-regression/\n--minimum-score-delta flags that invoke internal/gate and write a\npass/fail/neutral decision as JSON, then adds a new compare/action.yml\ncomposite Action (with it\n[…]\nainst\ntwo pre-produced findings.json files and surfaces the decision as\nAction outputs.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: wire compare command to gate policy and add composite Action (#…",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T06:02:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3d18e8140d52f1e397910fde98c944022bb2ad28",
          "body": "Adds internal/gate, a pure decision layer on top of comparison.Comparison\n-- the existing compare engine's fingerprint-diffed facts stay untouched;\nthis package only judges them against a configurable Policy (new-blocker/\nwarning/verdict-regression/score-delta thresholds) into a deterministic\npass/f\n[…]\n.\n\nNo CLI or GitHub Action wiring in this PR -- internal/gate is a library\nonly, exercised entirely through its own decision-matrix test suite.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add comparison regression gate policy (#122)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-16T05:33:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c850ee31fcc82213add24e4ac588b8071031745",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: make rollback eligibility work against real EKS (#121)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T11:14:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbc8bb071eb60581b0a968593ad15cb7e3c82a00",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: expose rollback readiness surfaces (#120)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T09:34:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2b15626ff571bc263214c4a511b27d36e003edf",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add rollback recommendation engine (#119)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T09:18:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4da299965c5da858dd57e79db799490725e8626",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: evaluate rollback operational readiness (#118)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T09:09:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82d5005267dc0c0ef996854b6374d3915274f317",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: collect EKS rollback readiness insights (#117)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T09:00:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a050553e18c1259c86992b05a58f5ebf5ac0a60a",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: collect EKS rollback eligibility evidence (#116)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T08:50:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96e65539e629bbbabd1e11a42ae6804739c47ec5",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add rollback assessment domain model (#115)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T07:38:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e75972a37cff268a0cadbd05fa0b02e6c2ca0578",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: prevent Console findings list from collapsing (#114)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T07:16:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf322e332488874369dda73519be49bacd8cac6",
          "body": "The \"API version catalog foundation\" row still described the PR1-only\nstate (\"no rule behavior change yet\"), stale since PR2 wired API-001/002\ninto it and PR4 made it the sole source of truth. Also adds a row for\nthe unsupported-target-version rejection behavior (PR3), which had no\nREADME coverage at all. Found during the pre-tag audit for\nv0.11.0-api-version-catalog.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "docs: refresh README for the completed API version catalog (#113)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T06:34:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16de751f51cafb8edd0632b5c0a601dfe46f5d86",
          "body": "Adds cmd/apicatalogcheck (mirroring cmd/compatcatalogcheck's pattern) and\nits thin wrapper scripts/check-api-version-catalog.sh, which:\n\n- loads and validates the embedded versioned catalog (schema, ranges,\n  dates, confidence -- all via existing load-time validation)\n- checks frozen legacy inventor\n[…]\nRange.max raise policy, the\nsource-of-truth JSON / generated Go view relationship, and the no-\nunreviewed-scraping and tests-required policies.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "chore: add API catalog maintenance checks (#112)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T05:55:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "107dfd419e194581ed41037314600a70f55cdbe7",
          "body": "Migrates the complete legacy apicatalog.Deprecated inventory (35\npreviously-uncatalogued GVKs, spanning the 1.16/1.22/1.25/1.26/1.27\nKubernetes removal waves) into the versioned catalog, sourced and\ncross-checked against kubernetes.io deprecation-guide/blog content and\nthe upstream kubernetes/api pr\n[…]\ngrated\ncatalog against a frozen pre-migration snapshot, guarding against a\nsilently dropped or altered entry during migration or a future edit.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: make API catalog the lifecycle source of truth (#111)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T05:17:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4da5ea73245ee65bf076647566bbc04c4f4006d8",
          "body": "…(#110)\n\nAdds a top-level buildSupportedTargetRange to the API version catalog\ndocument -- the Kubernetes target-version range this build's maintainer\nhas explicitly verified the embedded data against, independent of any\nsingle entry's own supportedTargetRange (VersionedCatalog.TargetSupported).\n\nsc\n[…]\nror naming the supported range, rather than silently\nfalling through to collectors and rules whose underlying facts were\nnever reviewed for it.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "fix: reject unsupported target Kubernetes versions before collection …",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-15T03:55:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "150575ff4f3ab4ee735aa39d813dc3769cca942e",
          "body": "API-001/API-002 now resolve each object's removed-version fact through\napicatalog.DefaultVersioned() first, falling back to the existing static\napicatalog.Deprecated-sourced value whenever the versioned catalog has no\nentry for that group/version/kind, or the target version falls outside\nits verifie\n[…]\nce\" evidence lines. Collectors, Events exclusion, APF\nauto-managed noise handling, and controller-managed EndpointSlice\nhandling are untouched.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: evaluate deprecated APIs with the version catalog (#109)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-14T11:41:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "144ee6b982e6c2dc8ef38e58ffabb9db5cfc32a9",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: add API version catalog foundation (#108)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-14T11:15:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62aeb922209c02f7d31fd848e157fdd2c6c2dc0e",
          "body": "Adds scripts/check-compatibility-catalog.sh (wrapping a small standalone\ncmd/compatcatalogcheck, not part of the public CLI, same pattern as\ncmd/consoledevserver) wired into CI's verify job -- a broken or\nincomplete catalog entry now fails CI before merge instead of silently\ndegrading every affected\n[…]\ns never silently overwritten,\nchanging a minimum version is a product behavior change).\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: add compatibility catalog maintenance checks (#107)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-14T10:49:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a3ec9558de34bb06e6a64ee68a92e79b96d13456",
          "body": "Live workload add-ons (metrics-server, ingress-nginx, AWS Load Balancer\nController, cert-manager, external-dns) previously always produced an\n\"unverifiable\" ADDON-002 warning regardless of installed version -- PR\n#105 built the discovery mechanism but explicitly deferred wiring it into\nthe catalog. \n[…]\n catalog data is never applied to a cluster the scan\nhasn't confirmed is that provider.\n\nCo-authored-by: devopsofworld <devopsofworld@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: apply compatibility catalog to workload add-ons (#106)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-14T10:20:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "026b24256222964864373ed85bced600e1ae3a75",
          "body": "Co-authored-by: devopsofworld <devopsofworld@gmail.com>",
          "is_bot": false,
          "headline": "feat: use compatibility catalog for EKS managed add-ons (#105)",
          "author_name": "Neetesh Yadav",
          "author_login": "imneeteeshyadav98",
          "committed_at": "2026-07-14T09:49:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 27,
      "commits_last_year": 233,
      "latest_release_at": "2026-07-25T17:22:43Z",
      "latest_release_tag": "v1.2.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 4,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/imneeteeshyadav98/kubepreflight",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/imneeteeshyadav98/kubepreflight",
          "is_deprecated": false,
          "latest_version": "v1.2.1",
          "repository_url": "https://github.com/imneeteeshyadav98/kubepreflight",
          "versions_count": 43,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-25T17:06:49Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 10
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "web/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 124040,
      "source_files_sampled": 224,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "web/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.16",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-r28c-9q8g-f849"
            ],
            "fixed_version": "8.5.18",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5942"
            ],
            "fixed_version": "0.56.0",
            "advisory_count": 1,
            "oldest_advisory_days": 11
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1,
          "unknown": 1
        },
        "advisory_count": 2,
        "affected_count": 2,
        "assessed_count": 254,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.1"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.27"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/ec2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.311.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/eks",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.88.1"
        },
        {
          "name": "github.com/aws/smithy-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.3"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/pflag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.9"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.31.3"
        },
        {
          "name": "k8s.io/apiextensions-apiserver",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.31.3"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.31.3"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.31.3"
        },
        {
          "name": "sigs.k8s.io/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "react",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        },
        {
          "name": "react-dom",
          "manifest": "web/package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.3.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": true,
            "version": "v1.42.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": true,
            "version": "v1.32.27",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ec2",
            "direct": true,
            "version": "v1.311.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/eks",
            "direct": true,
            "version": "v1.88.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": true,
            "version": "v1.27.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": true,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.31.3",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": true,
            "version": "v0.31.3",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.31.3",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.31.3",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": true,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "react",
            "direct": true,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": false,
            "version": "v1.19.26",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.31.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.36.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": false,
            "version": "v1.43.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.19.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.20.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.22.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gogo/protobuf",
            "direct": false,
            "version": "v1.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/protobuf",
            "direct": false,
            "version": "v1.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.6.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gofuzz",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/imdario/mergo",
            "direct": false,
            "version": "v0.3.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.7.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/onsi/gomega",
            "direct": false,
            "version": "v1.33.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.27.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.39.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": false,
            "version": "v1.34.2",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.12.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": false,
            "version": "v2.130.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20240228011516-70dd3763d340",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": false,
            "version": "v0.0.0-20240711033017-18e509b52bc8",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20221116044647-bc3834ca7abd",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v4",
            "direct": false,
            "version": "v4.4.1",
            "ecosystem": "go"
          },
          {
            "name": "@adobe/css-tools",
            "direct": false,
            "version": "4.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/css-color",
            "direct": false,
            "version": "5.1.11",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/dom-selector",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/generational-cache",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/nwsapi",
            "direct": false,
            "version": "2.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-react-jsx-self",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-react-jsx-source",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bramus/specificity",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/color-helpers",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-calc",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-color-parser",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-parser-algorithms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-syntax-patches-for-csstree",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-tokenizer",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@exodus/bytes",
            "direct": false,
            "version": "1.15.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/pluginutils",
            "direct": false,
            "version": "1.0.0-beta.27",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-musl",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/dom",
            "direct": false,
            "version": "10.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/jest-dom",
            "direct": false,
            "version": "6.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/react",
            "direct": false,
            "version": "16.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/user-event",
            "direct": false,
            "version": "14.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/aria-query",
            "direct": false,
            "version": "5.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__core",
            "direct": false,
            "version": "7.20.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__generator",
            "direct": false,
            "version": "7.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__template",
            "direct": false,
            "version": "7.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__traverse",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/prop-types",
            "direct": false,
            "version": "15.7.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "18.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "18.3.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitejs/plugin-react",
            "direct": false,
            "version": "4.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "aria-query",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.10.41",
            "ecosystem": "npm"
          },
          {
            "name": "bidi-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.4",
            "ecosystem": "npm"
          },
          {
            "name": "cac",
            "direct": false,
            "version": "6.7.14",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001800",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "5.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "check-error",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "css-tree",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "css.escape",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "data-urls",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decimal.js",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-eql",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "dequal",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "dom-accessibility-api",
            "direct": false,
            "version": "0.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "dom-accessibility-api",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.385",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "html-encoding-sniffer",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "indent-string",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-potential-custom-element-name",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsdom",
            "direct": false,
            "version": "29.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "loose-envify",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "loupe",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "lz-string",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "mdn-data",
            "direct": false,
            "version": "2.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "min-indent",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.15",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.50",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "pathval",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "27.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "17.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "react-refresh",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "redent",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rollup",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "saxes",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "3.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-indent",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-literal",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "symbol-tree",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinypool",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyspy",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "tldts",
            "direct": false,
            "version": "7.4.6",
            "ecosystem": "npm"
          },
          {
            "name": "tldts-core",
            "direct": false,
            "version": "7.4.6",
            "ecosystem": "npm"
          },
          {
            "name": "tough-cookie",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tr46",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "6.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "vite-node",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "w3c-xmlserializer",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "webidl-conversions",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-mimetype",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-url",
            "direct": false,
            "version": "16.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "xml-name-validator",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "xmlchars",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "selenium",
            "direct": false,
            "version": "4.34.2",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 254,
        "direct_count": 15,
        "indirect_count": 239
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 183,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 2,
        "closed_unmerged_prs": 24
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "imneeteeshyadav98",
          "commits": 179,
          "avatar_url": "https://avatars.githubusercontent.com/u/48591606?v=4"
        },
        {
          "type": "User",
          "login": "devopsofworld",
          "commits": 50,
          "avatar_url": "https://avatars.githubusercontent.com/u/145892752?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.782
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "container-image-scan.yml",
        "dependency-review.yml",
        "release.yml",
        "scorecard.yml",
        "validate-comparison-rc.yml",
        "validate-eks-case-study.yml",
        "validate-published-action.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 4,
            "reason": "6 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "4bd2ea8db9b63dd3dc30ced83c9ffd8c84ea3aa1",
        "ran_at": "2026-07-26T01:32:24Z",
        "aggregate_score": 5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T17:47:14Z",
      "oldest_open_prs": [
        {
          "number": 18,
          "created_at": "2026-07-06T09:13:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 19,
          "created_at": "2026-07-06T09:14:01Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 20,
          "created_at": "2026-07-06T09:14:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 69,
          "created_at": "2026-07-11T15:16:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 150,
          "created_at": "2026-07-18T17:55:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 151,
          "created_at": "2026-07-18T17:57:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 152,
          "created_at": "2026-07-18T17:58:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 197,
          "created_at": "2026-07-22T07:36:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 214,
          "created_at": "2026-07-25T15:12:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 215,
          "created_at": "2026-07-25T15:12:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-25T17:45:11Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/imneeteeshyadav98/kubepreflight",
    "host": "github.com",
    "name": "kubepreflight",
    "owner": "imneeteeshyadav98"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 60,
        "vitality": 70,
        "community": 24,
        "governance": 57,
        "engineering": 81
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 70,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "commits_last_year": 233,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 4
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "4/52 weeks with commits",
                "points": 2.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "233 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 233
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 27,
              "latest_release_tag": "v1.2.1",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "27 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 27
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 17,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.782
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 78% of commits",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 78
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 183,
              "open_issues": 0,
              "closed_issues": 2,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 24
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "183/207 decided PRs merged",
                "points": 33.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 183,
                      "decided": 207
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 47,
            "inputs": {
              "followers": 2,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "imneeteeshyadav98",
              "public_repos": 44,
              "account_age_days": 2689
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of imneeteeshyadav98",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "imneeteeshyadav98"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "44 public repos, account ~7 yr old",
                "points": 24,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 44
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/imneeteeshyadav98/kubepreflight"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "43 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 43
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 81,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "cli",
                "devops",
                "golang",
                "kubernetes",
                "observability",
                "platform-engineering",
                "react",
                "sre",
                "upgrade-readiness",
                "eks",
                "kubernetes-upgrade",
                "pdb",
                "webhooks",
                "kuberntes-api"
              ],
              "has_wiki": true,
              "homepage": "https://devopsofworld.com/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://devopsofworld.com/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "14 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 60,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "29 out of 29 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "6 existing vulnerabilities detected",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 254 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 254
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 2,
              "affected_packages": 2,
              "assessed_packages": 254,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1, unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 254,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 62,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "web/tsconfig.json"
              ],
              "agent_commit_share": 0.19,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "web/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "web/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "19 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 19,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 124040,
              "source_files_sampled": 224,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/224 source files over 60KB",
                "points": 54.3,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 224,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [],
  "report_type": "repository",
  "generated_at": "2026-07-26T01:32:40.233432Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/imneeteeshyadav98/kubepreflight.svg",
  "full_name": "imneeteeshyadav98/kubepreflight",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.