Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-28 14:18 UTC

jakartaee / servlet

Jakarta Servlet

Java · HTMLCustom license★ 325 stars⑂ 111 forkssince Jun 2018View on GitHub ↗

jakartaee/servlet holds a health index of 72 out of 100, placing it in the Good band. It scores highest on Vitality (84/100) and lowest on AI Readiness (51/100). It was last updated today. A single contributor accounts for most of its recent work.

72
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

72
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Jakarta EEOrganization
739 followers74 public repossince Feb 2018

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Mavenjakarta.servlet:jakarta.servlet-api6.2.0-M2-1271 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

84Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
22.2/36Commit cadence — 32/52 weeks with commits
17.7/18Commit volume — 93 commits in the last year
10/10OpenSSF Scorecard: Maintained — 21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year93
human_commit_share0.42
days_since_last_push0
active_weeks_last_year32
How it's scored
16.2/27Ships releases — 18 version tags (no GitHub releases)
36/36Release recency — latest release 63 days ago
19.8/27Release cadence — a release every ~102.4 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count18
latest_release_tag6.1.2-RELEASE-tck
releases_from_tagsyes
days_since_latest_release63
mean_days_between_releases102.4
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

72Good · 18% of overall
How it's scored
40.7/60Stars — 325 stars
17/25Forks — 111 forks
8.3/15Watchers — 32 watchers
Inputs used
forks111
stars325
watchers32
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
16.9/22.5License — license file present, not a recognized license
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

69Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
9.7/22.5Commit distribution — top contributor authored 57% of commits
13.5/13.5Contributor breadth — 34 contributors
10/10OpenSSF Scorecard: Contributors — project has 29 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled34
top_contributor_share0.567
How it's scored
35.6/46.8Issue resolution — 76% of issues closed
34.4/38.3PR acceptance — 593/659 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/7 approved changesets -- score normalized to 0
Inputs used
merged_prs593
open_issues97
closed_issues311
issue_closed_ratio0.762
closed_unmerged_prs66
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
20.6/25Owner reach — 739 followers of jakartaee
25/25Track record — 74 public repos, account ~8 yr old
Inputs used
followers739
owner_typeOrganization
is_verified
owner_loginjakartaee
public_repos74
account_age_days3,093
How it's scored
25/25Published & resolvable — 1 package(s) on maven
35/35Publish recency — latest publish 71 days ago
20/20Version history — 12 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesjakarta.servlet:jakarta.servlet-api
ecosystemsmaven
any_deprecatedno
min_days_since_publish71

Engineering Quality

Are baseline engineering and documentation practices in place?

67Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 26 out of 26 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://projects.eclipse.org/projects/ee4j.servlet
10/10Repository description
0/10Topics
10/10Wiki
Inputs used
topics
has_wikiyes
homepagehttps://projects.eclipse.org/projects/ee4j.servlet
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

69Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 26 out of 26 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/7 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 29 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5License — license file detected
7.5/7.5Maintained — 21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate6.1
Excluded from scoring (no data or not applicable): branch_protection, packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages47
unassessed_packages12
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 47 resolved dependencies against OSV. 12 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

51Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
22.9/40Legible commit history — 18 of 42 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.429
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — api/pom.xml, pom.xml, spec/pom.xml (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Java (statically typed)
0/10Reproducible environment
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 58 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifestsapi/pom.xml, pom.xml, spec/pom.xml, tck/pom.xml, tck/tck-dist/pom.xml, tck/tck-docs/userguide/pom.xml, tck/tck-runtime/pom.xml, tck/tck-util/pom.xml
dependency_bot_commit_share0.58
How it's scored
45/45Type-checkable code — Java (statically typed)
54.8/55Manageable file sizes — 4/923 source files over 60KB
Inputs used
primary_languageJava
largest_source_bytes85,073
source_files_sampled923
oversized_source_files4

Key facts

325GitHub stars
34contributors
93commits, last 12 months
0days since last push
18releases
1bus factor
97open issues
Mavenpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 111 ⇿
0Stars
111Forks
18Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

02040608010012011132018-072022-072026-07
Major 0Minor 0Patch 0

Each point covers 8 days.

OpenSSF Scorecard 6.1 / 10
6.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-28 14:18 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests26 out of 26 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/7 approved changesets -- score normalized to 0
10Contributorsproject has 29 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 9
RegistryPackageVersion constraintManifest
Mavenorg.junit:junit-bom6.1.2api/pom.xml
Mavenorg.jruby:jruby-complete${jruby.version}spec/pom.xml
Mavenorg.asciidoctor:asciidoctorj${asciidoctorj.version}spec/pom.xml
Mavenorg.asciidoctor:asciidoctorj-pdf${asciidoctorj.pdf.version}spec/pom.xml
Mavenorg.junit:junit-bom6.1.2tck/pom.xml
Mavenorg.jboss.arquillian:arquillian-bom1.10.2.Finaltck/pom.xml
Mavenorg.jboss.shrinkwrap:shrinkwrap-bom1.2.6tck/pom.xml
Mavenorg.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom3.3.7tck/pom.xml
Mavenorg.slf4j:slf4j-api2.0.18tck/pom.xml
All dependencies 59

Full resolved dependency set from the GitHub dependency graph: 11 direct and 48 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Mavenorg.asciidoctor:asciidoctorj2.4.2direct
Mavenorg.asciidoctor:asciidoctorj3.0.1direct
Mavenorg.asciidoctor:asciidoctorj-pdf1.5.3direct
Mavenorg.asciidoctor:asciidoctorj-pdf2.3.23direct
Mavenorg.jboss.arquillian:arquillian-bom1.10.2direct
Mavenorg.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom3.3.7direct
Mavenorg.jboss.shrinkwrap:shrinkwrap-bom1.2.6direct
Mavenorg.jruby:jruby-complete10.0.6.0direct
Mavenorg.junit:junit-bom6.1.2direct
Mavenorg.slf4j:slf4j-apidirect
Mavenorg.slf4j:slf4j-api2.0.18direct
Mavencommons-io:commons-io2.22.0indirect
Mavenjakarta.annotation:jakarta.annotation-api3.0.0indirect
Mavenjakarta.servlet:jakarta.servlet-api6.2.0-SNAPSHOTindirect
Mavenjakarta.tck:servlet-tck6.2.0-SNAPSHOTindirect
Mavenjakarta.tck:servlet-tck-runtime6.2.0-SNAPSHOTindirect
Mavenjakarta.tck:servlet-tck-util6.2.0-SNAPSHOTindirect
Mavenjakarta.tck:sigtest-maven-plugin2.6indirect
Mavennet.revelc.code.formatter:formatter-maven-pluginindirect
Mavennet.revelc.code.formatter:formatter-maven-plugin2.29.0indirect
Mavennet.revelc.code:impsort-maven-pluginindirect
Mavennet.revelc.code:impsort-maven-plugin1.13.0indirect
Mavenorg.apache.felix:maven-bundle-plugin6.0.2indirect
Mavenorg.apache.maven.plugins:maven-assembly-plugin3.3.0indirect
Mavenorg.apache.maven.plugins:maven-assembly-plugin3.8.0indirect
Mavenorg.apache.maven.plugins:maven-clean-pluginindirect
Mavenorg.apache.maven.plugins:maven-clean-plugin3.1.0indirect
Mavenorg.apache.maven.plugins:maven-clean-plugin3.5.0indirect
Mavenorg.apache.maven.plugins:maven-compiler-plugin3.15.0indirect
Mavenorg.apache.maven.plugins:maven-deploy-plugin3.1.4indirect
Mavenorg.apache.maven.plugins:maven-enforcer-pluginindirect
Mavenorg.apache.maven.plugins:maven-enforcer-plugin3.0.0-M3indirect
Mavenorg.apache.maven.plugins:maven-enforcer-plugin3.8.6indirect
Mavenorg.apache.maven.plugins:maven-install-plugin3.1.4indirect
Mavenorg.apache.maven.plugins:maven-jar-plugin3.5.0indirect
Mavenorg.apache.maven.plugins:maven-javadoc-plugin3.12.0indirect
Mavenorg.apache.maven.plugins:maven-resources-plugin3.5.0indirect
Mavenorg.apache.maven.plugins:maven-scm-publish-pluginindirect
Mavenorg.apache.maven.plugins:maven-scm-publish-plugin3.1.0indirect
Mavenorg.apache.maven.plugins:maven-source-plugin3.4.0indirect
Mavenorg.apache.maven.plugins:maven-surefire-plugin3.5.6indirect
Mavenorg.asciidoctor:asciidoctor-maven-pluginindirect
Mavenorg.asciidoctor:asciidoctor-maven-plugin2.1.0indirect
Mavenorg.asciidoctor:asciidoctor-maven-plugin3.2.0indirect
Mavenorg.asciidoctor:asciidoctorj-diagram2.1.0indirect
Mavenorg.codehaus.mojo:build-helper-maven-plugin3.6.1indirect
Mavenorg.freemarker:freemarker2.3.30indirect
Mavenorg.glassfish.copyright:glassfish-copyright-maven-plugin2.4indirect
Mavenorg.glassfish.doc:glassfish-doc-maven-pluginindirect
Mavenorg.glassfish.doc:glassfish-doc-maven-plugin1.3indirect
Mavenorg.hamcrest:hamcrest3.0indirect
Mavenorg.jbake:jbake-maven-pluginindirect
Mavenorg.jbake:jbake-maven-plugin0.3.3indirect
Mavenorg.jboss.arquillian.junit5:arquillian-junit5-containerindirect
Mavenorg.jboss.arquillian.junit:arquillian-junit-coreindirect
Mavenorg.jboss.shrinkwrap.resolver:shrinkwrap-resolver-api-maven3.3.7indirect
Mavenorg.jboss.shrinkwrap.resolver:shrinkwrap-resolver-impl-maven3.3.7indirect
Mavenorg.jboss.shrinkwrap.resolver:shrinkwrap-resolver-spi-maven3.3.7indirect
Mavenorg.junit.jupiter:junit-jupiterindirect
Dependency advisories 0

This repository publishes no package the index resolves, so its own dependency graph was assessed — 47 packages, which also include development and test pins that never ship: 0 carry known advisories, of which 0 are direct. 12 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 4354,
      "has_wiki": true,
      "homepage": "https://projects.eclipse.org/projects/ee4j.servlet",
      "languages": {
        "C++": 3377,
        "CSS": 11749,
        "HTML": 1482199,
        "Java": 4471598,
        "Pawn": 994,
        "Shell": 1558,
        "Pascal": 1191,
        "FreeMarker": 3069,
        "Grammatical Framework": 69
      },
      "pushed_at": "2026-07-27T18:04:21Z",
      "created_at": "2018-06-04T17:27:41Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-27T23:27:21Z",
      "description": "Jakarta Servlet",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "Java",
      "significant_languages": [
        "Java",
        "HTML"
      ]
    },
    "owner": {
      "blog": "https://jakarta.ee",
      "name": "Jakarta EE",
      "type": "Organization",
      "login": "jakartaee",
      "company": null,
      "location": null,
      "followers": 739,
      "avatar_url": "https://avatars.githubusercontent.com/u/36201228?v=4",
      "created_at": "2018-02-06T16:08:53Z",
      "is_verified": null,
      "public_repos": 74,
      "account_age_days": 3093
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "6.2.0-M2-RELEASE",
          "kind": "prerelease",
          "published_at": "2026-05-18T11:42:47Z"
        },
        {
          "tag": "6.2.0-M1-RELEASE-tck",
          "kind": "prerelease",
          "published_at": "2025-10-16T07:36:41Z"
        },
        {
          "tag": "6.2.0-M1",
          "kind": "prerelease",
          "published_at": "2025-10-15T16:58:26Z"
        },
        {
          "tag": "6.1.2-RELEASE-tck",
          "kind": "prerelease",
          "published_at": "2026-05-26T10:08:06Z"
        },
        {
          "tag": "6.1.1-RELEASE-tck",
          "kind": "prerelease",
          "published_at": "2024-12-20T15:45:41Z"
        },
        {
          "tag": "6.1.0-RELEASE-tck",
          "kind": "prerelease",
          "published_at": "2024-05-24T17:47:47Z"
        },
        {
          "tag": "6.1.0-RELEASE",
          "kind": "prerelease",
          "published_at": "2024-05-24T17:29:40Z"
        },
        {
          "tag": "6.1.0-M1-RELEASE-tck",
          "kind": "prerelease",
          "published_at": "2024-03-01T14:12:06Z"
        },
        {
          "tag": "6.1.0-M2-RELEASE",
          "kind": "prerelease",
          "published_at": "2024-02-27T12:11:59Z"
        },
        {
          "tag": "6.1.0-M1-RELEASE",
          "kind": "prerelease",
          "published_at": "2023-11-16T17:37:50Z"
        },
        {
          "tag": "6.0.0-RELEASE",
          "kind": "prerelease",
          "published_at": "2022-05-12T07:18:34Z"
        },
        {
          "tag": "6.0.0-M1-RELEASE",
          "kind": "prerelease",
          "published_at": "2021-11-05T20:58:10Z"
        },
        {
          "tag": "5.0.0-RELEASE",
          "kind": "prerelease",
          "published_at": "2020-09-07T11:40:22Z"
        },
        {
          "tag": "5.0.0-M2-RELEASE",
          "kind": "prerelease",
          "published_at": "2020-07-14T18:17:41Z"
        },
        {
          "tag": "5.0.0-M1-RELEASE",
          "kind": "prerelease",
          "published_at": "2020-01-10T21:15:11Z"
        },
        {
          "tag": "4.0.4-RELEASE",
          "kind": "prerelease",
          "published_at": "2020-06-18T13:56:27Z"
        },
        {
          "tag": "4.0.3-RELEASE",
          "kind": "prerelease",
          "published_at": "2019-08-21T14:44:47Z"
        },
        {
          "tag": "4.0.2-RELEASE",
          "kind": "prerelease",
          "published_at": "2019-01-14T15:22:00Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "0716658993beeed06b1487a8a6e446ed51c4ce06",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 6.1.1 to 6.1.2.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.1...r6.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: o\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 6.1.1 to 6.1.2 (#1073)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T22:51:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e913a972cad8aabdd98ce633fb616a3f29bf2ec",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 6.1.0 to 6.1.1.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.0...r6.1.1)\n\n---\nupdated-dependencies:\n- dependency-name: org.junit:junit-bom\n  dependency-version: 6.1.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 6.1.0 to 6.1.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-01T11:04:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ba63891e17b1efe8cdb1b5cda20ceb539006dea",
          "body": null,
          "is_bot": false,
          "headline": "Add TCK tests to mirror getParameterTest() and update signature file",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-07-01T11:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91bfc28d8d772641bed28fac781664e5c20f7c10",
          "body": null,
          "is_bot": false,
          "headline": "Fix formatting",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-07-01T11:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99960100a151584c8f64b46de0991f1e21388678",
          "body": null,
          "is_bot": false,
          "headline": "Add @since",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-07-01T11:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33154948ef781263de70db0562aaa39c2a6ff35a",
          "body": "With some elements taken from Mario Daniel Ruiz Saavedra's PR to add\nQUERY support to Tomcat",
          "is_bot": false,
          "headline": "First pass at adding HTTP QUERY (RFC 10008) support",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-07-01T11:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7bcb3ff8eac022ba49c6233976c031dde759d67",
          "body": "Bumps org.jruby:jruby-complete from 10.0.5.0 to 10.0.6.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.jruby:jruby-complete\n  dependency-version: 10.0.6.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jruby:jruby-complete from 10.0.5.0 to 10.0.6.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-25T15:05:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e9b9a35de31268dcbe07cdc62c93dc58e775bc4",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 6 to 7 (#1067)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-23T07:33:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44eab9244f6ba8c414020d262b0fa658578be13e",
          "body": null,
          "is_bot": true,
          "headline": "Bump shrinkwrap-resolver.version from 3.3.6 to 3.3.7 (#1060)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T07:52:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f08ada86d0ec205cd4937d25f6c5586b06ce235b",
          "body": "….6 (#1061)",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.5 to 3.5…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T07:51:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cb902939bd699bd3dbba8ab2b5310045981877e",
          "body": null,
          "is_bot": true,
          "headline": "Bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#1062)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T07:51:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6f0ea968c7d755cba6c1969bc3d0ea05165362d",
          "body": "Bumps [org.eclipse.ee4j:project](https://github.com/eclipse-ee4j/ee4j) from 2.0.3 to 2.0.4.\n- [Release notes](https://github.com/eclipse-ee4j/ee4j/releases)\n- [Commits](https://github.com/eclipse-ee4j/ee4j/compare/2.0.3...2.0.4)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.ee4j:project\n\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.eclipse.ee4j:project from 2.0.3 to 2.0.4 (#1052)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T09:06:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9181d33a2b98f394e8a94ab2c4c3df9ba03e050",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 6.0.3 to 6.1.0.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0)\n\n---\nupdated-dependencies:\n- dependency-name: o\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 6.0.3 to 6.1.0 (#1053)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T09:05:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b346c161ca5311637997625059299b10d5fdf80",
          "body": "Bumps [org.jboss.arquillian:arquillian-bom](https://github.com/arquillian/arquillian-core) from 1.10.1.Final to 1.10.2.Final.\n- [Release notes](https://github.com/arquillian/arquillian-core/releases)\n- [Commits](https://github.com/arquillian/arquillian-core/compare/1.10.1.Final...1.10.2.Final)\n\n---\n\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.jboss.arquillian:arquillian-bom (#1054)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T09:05:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7b8e63d8c4b1396e8d8ef2b886e002ba859a51a",
          "body": "Bumps [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) from 1.2.2 to 1.2.3.\n- [Release notes](https://github.com/apache/maven-build-cache-extension/releases)\n- [Commits](https://github.com/apache/maven-build-cache-extension/compare/mave\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.extensions:maven-build-cache-extension (#1055)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T09:03:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c4f59b5a8b44d0c75d7c7584416701b38c697da",
          "body": "Bumps org.slf4j:slf4j-api from 2.0.17 to 2.0.18.\n\n---\nupdated-dependencies:\n- dependency-name: org.slf4j:slf4j-api\n  dependency-version: 2.0.18\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 (#1045)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-19T10:30:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2dc9d2427383d82ed46ef428b4bbc40259a8c523",
          "body": "Bumps [org.eclipse.ee4j:project](https://github.com/eclipse-ee4j/ee4j) from 2.0.2 to 2.0.3.\n- [Release notes](https://github.com/eclipse-ee4j/ee4j/releases)\n- [Commits](https://github.com/eclipse-ee4j/ee4j/compare/2.0.2...2.0.3)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.ee4j:project\n\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.eclipse.ee4j:project from 2.0.2 to 2.0.3 (#1044)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-19T09:28:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a52f775c06f14414e39ea191ee9f5d0ba146497f",
          "body": "Signed-off-by: Olivier Lamy <olamy@apache.org>",
          "is_bot": false,
          "headline": "Fix thread safety of StaticLog class (#1038) (#1039)",
          "author_name": "Olivier Lamy",
          "author_login": "olamy",
          "committed_at": "2026-05-04T01:21:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "305eaabcbaa18c87332020a8022ccc1348dcb927",
          "body": "Bumps `shrinkwrap-resolver.version` from 3.3.5 to 3.3.6.\n\nUpdates `org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-api-maven` from 3.3.5 to 3.3.6\n- [Release notes](https://github.com/shrinkwrap/resolver/releases)\n- [Commits](https://github.com/shrinkwrap/resolver/compare/3.3.5...3.3.6)\n\nUpdates `o\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump shrinkwrap-resolver.version from 3.3.5 to 3.3.6 (#1034)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-03T12:08:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "736add2002b3ab117bfbd338774140ba5409606e",
          "body": "Bumps [org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom](https://github.com/shrinkwrap/resolver) from 3.3.5 to 3.3.6.\n- [Release notes](https://github.com/shrinkwrap/resolver/releases)\n- [Commits](https://github.com/shrinkwrap/resolver/compare/3.3.5...3.3.6)\n\n---\nupdated-dependencies:\n- depende\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#1036)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-03T12:08:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26f4102a4d59117d9806f252174a2ea82f95bb7b",
          "body": "Bumps commons-io:commons-io from 2.21.0 to 2.22.0.\n\n---\nupdated-dependencies:\n- dependency-name: commons-io:commons-io\n  dependency-version: 2.22.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump commons-io:commons-io from 2.21.0 to 2.22.0 (#1037)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-03T12:07:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9adfebcef1738c2806c2079c3e4c82678395616a",
          "body": "Bumps org.jruby:jruby-complete from 10.0.4.0 to 10.0.5.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.jruby:jruby-complete\n  dependency-version: 10.0.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jruby:jruby-complete from 10.0.4.0 to 10.0.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-10T16:32:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c26e1d319520e84d1c659e10493eabb37243b122",
          "body": "…#1022) (#1026)\n\nSigned-off-by: Olivier Lamy <olamy@apache.org>",
          "is_bot": false,
          "headline": "do not work offline as it can prevent project downloading artifacts (…",
          "author_name": "Olivier Lamy",
          "author_login": "olamy",
          "committed_at": "2026-03-30T08:13:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ce3a399858cf6e7cccc654fed470fdd8f1ac4b9",
          "body": null,
          "is_bot": false,
          "headline": "Add new status code constants to signature",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-25T10:41:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c503b6780a0b15798458f58c53e5e6c44453e6ff",
          "body": null,
          "is_bot": false,
          "headline": "Fix typo",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-18T17:40:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2afe8e4a648d76fd4ecefd988e2aef6945d4126d",
          "body": null,
          "is_bot": false,
          "headline": "Fix #981. Add status codes from RFC 6585.",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-18T17:29:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cddf142339dd8d8ede91502e05b926a5d4d3ece1",
          "body": "Fix issue #900 and improve ordering checks generally.\n\nUse a single expected response so that ordering of the individual\ncomponents is checked.\nAvoid a test hang if the expected response is not provided.\nRemove unused and/or unnecessary code\nTrack filter invocation order using a header (headers must\n[…]\ngraded message (\"world\") may be received with\n\"Hello\" or separately so don't look for \"onDataAvailable\" before it.\n\nFix some consistency issues in the log messages\nRemove unused (and unnecessary) code",
          "is_bot": false,
          "headline": "Ensure messages are received in the correct order",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-18T16:34:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b0819743c28b37d020bc1a8417c7642141b7f34",
          "body": "Fix IDE warnings\n- add missing @Override annotations\n- add missing serialVersionUID\n\nRemove old svn placeholders\nUpdate copyright date\nRefactor duplicate booleans",
          "is_bot": false,
          "headline": "Preparation for fixing #900",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-18T16:34:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9e700829e8800010d60f7baf296895d32060d8c",
          "body": "Bumps [org.jboss.arquillian:arquillian-bom](https://github.com/arquillian/arquillian-core) from 1.10.0.Final to 1.10.1.Final.\n- [Release notes](https://github.com/arquillian/arquillian-core/releases)\n- [Commits](https://github.com/arquillian/arquillian-core/compare/1.10.0.Final...1.10.1.Final)\n\n---\n\n[…]\nss.arquillian:arquillian-bom\n  dependency-version: 1.10.1.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jboss.arquillian:arquillian-bom",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-17T00:05:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7fb07ce96eaf9c59fa52119f995e29f50b6f667",
          "body": "Bumps [org.eclipse.ee4j:project](https://github.com/eclipse-ee4j/ee4j) from 2.0.1 to 2.0.2.\n- [Release notes](https://github.com/eclipse-ee4j/ee4j/releases)\n- [Commits](https://github.com/eclipse-ee4j/ee4j/compare/2.0.1...2.0.2)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.ee4j:project\n  dependency-version: 2.0.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.eclipse.ee4j:project from 2.0.1 to 2.0.2",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-17T00:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac0789dd1ecd798c4cca24974413cf696c66b2a8",
          "body": "…ming from the parent class",
          "is_bot": false,
          "headline": "Fix #1007: Change default user names and passwords to use the ones co…",
          "author_name": "Robert Patrick",
          "author_login": "robertpatrick",
          "committed_at": "2026-03-16T23:57:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22e149327e1bfd48699d1b3e0a853e2092151e68",
          "body": null,
          "is_bot": false,
          "headline": "Fix #1006: remove hard-coded user names and passwords",
          "author_name": "Robert Patrick",
          "author_login": "robertpatrick",
          "committed_at": "2026-03-16T23:53:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c07fa5d26a463647f8358cbe2475f8d3379c27d",
          "body": "URK patterns without a leading slash is a servlet 2.2 requirement if a\n2.2. descriptor is present. Supporting descriptors that old is optional\nso remove the tests.",
          "is_bot": false,
          "headline": "Remove tests for behaviour that is now optional.",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-16T23:50:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90efad940caad65c2c014215328b6f4c650db618",
          "body": null,
          "is_bot": false,
          "headline": "Align servlet spec with platform spec re support of old descriptors",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-16T23:50:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1b323ed46b36f37bc3b7bde6e8c81604c0368eb",
          "body": null,
          "is_bot": false,
          "headline": "Fix #994 - pathInfo does not include path parameters",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-03-16T23:11:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cc0907c3c8200342096ff19aa7c4f8d90b60272",
          "body": "Bumps org.jruby:jruby-complete from 10.0.3.0 to 10.0.4.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.jruby:jruby-complete\n  dependency-version: 10.0.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.jruby:jruby-complete from 10.0.3.0 to 10.0.4.0 (#999)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-12T11:33:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14203142fad69f05bab5e500d3964f1e7b937f8f",
          "body": "Bumps org.apache.felix:maven-bundle-plugin from 6.0.0 to 6.0.2.\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.felix:maven-bundle-plugin\n  dependency-version: 6.0.2\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.felix:maven-bundle-plugin from 6.0.0 to 6.0.2 (#1000)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-12T11:33:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd726652165d0f132f93b37897291faa170d0f48",
          "body": "Bumps [org.eclipse.ee4j:project](https://github.com/eclipse-ee4j/ee4j) from 2.0.0 to 2.0.1.\n- [Release notes](https://github.com/eclipse-ee4j/ee4j/releases)\n- [Commits](https://github.com/eclipse-ee4j/ee4j/compare/2.0.0...2.0.1)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.ee4j:project\n\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.eclipse.ee4j:project from 2.0.0 to 2.0.1 (#1001)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-12T11:32:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4100d965077010f5d5f652b84ed70c4f6bfb1c2c",
          "body": "…5.0 (#1002)\n\nBumps [org.apache.maven.plugins:maven-resources-plugin](https://github.com/apache/maven-resources-plugin) from 3.4.0 to 3.5.0.\n- [Release notes](https://github.com/apache/maven-resources-plugin/releases)\n- [Commits](https://github.com/apache/maven-resources-plugin/compare/v3.4.0...mave\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-resources-plugin from 3.4.0 to 3.…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-12T11:32:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4242c3e15043a0fa2ecd187d4f5524ea788fec0",
          "body": "Bumps [org.eclipse.ee4j:project](https://github.com/eclipse-ee4j/ee4j) from 2.0.0-M1 to 2.0.0.\n- [Release notes](https://github.com/eclipse-ee4j/ee4j/releases)\n- [Commits](https://github.com/eclipse-ee4j/ee4j/compare/2.0.0-M1...2.0.0)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.ee4j:project\n  dependency-version: 2.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.eclipse.ee4j:project from 2.0.0-M1 to 2.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-09T08:51:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60fec0ae58af5cb1d56f6b12848b7126c73c2307",
          "body": "Bumps `shrinkwrap-resolver.version` from 3.3.4 to 3.3.5.\n\nUpdates `org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-api-maven` from 3.3.4 to 3.3.5\n- [Release notes](https://github.com/shrinkwrap/resolver/releases)\n- [Commits](https://github.com/shrinkwrap/resolver/compare/3.3.4...3.3.5)\n\nUpdates `o\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump shrinkwrap-resolver.version from 3.3.4 to 3.3.5 (#988)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-03T04:52:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4fb6037ccb2cc97ae7f993d0c56df721bf450176",
          "body": "Bumps [org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom](https://github.com/shrinkwrap/resolver) from 3.3.4 to 3.3.5.\n- [Release notes](https://github.com/shrinkwrap/resolver/releases)\n- [Commits](https://github.com/shrinkwrap/resolver/compare/3.3.4...3.3.5)\n\n---\nupdated-dependencies:\n- depende\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#990)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-03T04:52:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "035981c8f4991ec9cdef218edf06ec3ad43084c5",
          "body": "….5 (#992)\n\nBumps [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) from 3.5.4 to 3.5.5.\n- [Release notes](https://github.com/apache/maven-surefire/releases)\n- [Commits](https://github.com/apache/maven-surefire/compare/surefire-3.5.4...surefire-3.5.5)\n\n---\nup\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.4 to 3.5…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-03T04:51:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07ad2711464c8df6820a0af516e9d87d65f132f2",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.0.2...r6.0.3)\n\n---\nupdated-dependencies:\n- dependency-name: o\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 6.0.2 to 6.0.3 (#989)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-03T04:42:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe4d13b593bc6808602e94a1f2d4b6c94e294550",
          "body": null,
          "is_bot": false,
          "headline": "Update year to fix copyright check",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2026-02-05T22:51:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e4b60160a1542f6e27c1729ee2399ec4ea4d25c",
          "body": "Set default delimiter to null and verify its initialization in\ngetDelimiter(). Also ensure consistency between the handler and the\nread listener to prevent early or missing calls to init().",
          "is_bot": false,
          "headline": "fix: #899 - Improve HttpUpgradeHandler initialization validation",
          "author_name": "Matheus Oliveira",
          "author_login": null,
          "committed_at": "2026-02-05T17:52:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a542ac3c9bababcd060cd0179c06cdb46b5f2a9",
          "body": "Ensure that HttpUpgradeHandler has been properly initialized before calling\ninit() by checking that the delimiter is not null in TCKReadListener.\nAdded getDelimiter() for verification.",
          "is_bot": false,
          "headline": "fix: #899 - Validate delimiter initialization in TCKReadListener",
          "author_name": "Matheus Oliveira",
          "author_login": null,
          "committed_at": "2026-02-05T17:52:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2af23a787daeb6248f9f5c42531c999e70d12607",
          "body": "Bumps org.jruby:jruby-complete from 10.0.2.0 to 10.0.3.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.jruby:jruby-complete\n  dependency-version: 10.0.3.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jruby:jruby-complete from 10.0.2.0 to 10.0.3.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-05T17:27:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aea0e5c92f247d2dda019728f4e063cad373cf2a",
          "body": "Bumps [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) from 1.2.1 to 1.2.2.\n- [Release notes](https://github.com/apache/maven-build-cache-extension/releases)\n- [Commits](https://github.com/apache/maven-build-cache-extension/compare/mave\n[…]\nensions:maven-build-cache-extension\n  dependency-version: 1.2.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.extensions:maven-build-cache-extension",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-05T17:27:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab4f8b19d0d5f90f4b85af1fe628168ede217d44",
          "body": "Bumps [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) from 3.14.1 to 3.15.0.\n- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)\n- [Commits](https://github.com/apache/maven-compiler-plugin/compare/maven-compiler-plugin-3.14.1.\n[…]\naven.plugins:maven-compiler-plugin\n  dependency-version: 3.15.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-compiler-plugin",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-05T17:26:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "564d52e3b9e357afc852a5b7e3be8be49fb28399",
          "body": "Bumps net.revelc.code:impsort-maven-plugin from 1.12.0 to 1.13.0.\n\n---\nupdated-dependencies:\n- dependency-name: net.revelc.code:impsort-maven-plugin\n  dependency-version: 1.13.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump net.revelc.code:impsort-maven-plugin from 1.12.0 to 1.13.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-01-30T09:26:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5c73deb9e9b01769d167046892eeb84c6b743a5",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 6.0.1 to 6.0.2.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.0.1...r6.0.2)\n\n---\nupdated-dependencies:\n- dependency-name: org.junit:junit-bom\n  dependency-version: 6.0.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 6.0.1 to 6.0.2",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-01-30T09:26:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f1f7c4b84c9ab8a1bffc168a982f4954d6510ad",
          "body": "Bumps [org.apache.maven.plugins:maven-resources-plugin](https://github.com/apache/maven-resources-plugin) from 3.3.1 to 3.4.0.\n- [Release notes](https://github.com/apache/maven-resources-plugin/releases)\n- [Commits](https://github.com/apache/maven-resources-plugin/compare/maven-resources-plugin-3.3.\n[…]\naven.plugins:maven-resources-plugin\n  dependency-version: 3.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-resources-plugin from 3.3.1 to 3.4.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-03T09:38:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "105aacf2983992665b98f48d2b9c571e58b1d9e6",
          "body": "Bumps [org.apache.maven.plugins:maven-source-plugin](https://github.com/apache/maven-source-plugin) from 3.3.1 to 3.4.0.\n- [Release notes](https://github.com/apache/maven-source-plugin/releases)\n- [Commits](https://github.com/apache/maven-source-plugin/compare/maven-source-plugin-3.3.1...maven-sourc\n[…]\ne.maven.plugins:maven-source-plugin\n  dependency-version: 3.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-source-plugin from 3.3.1 to 3.4.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-03T09:36:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dbd1c3a20ee900915d8e48d74c5a4c086061c85",
          "body": "Bumps [org.apache.maven.plugins:maven-assembly-plugin](https://github.com/apache/maven-assembly-plugin) from 3.7.1 to 3.8.0.\n- [Release notes](https://github.com/apache/maven-assembly-plugin/releases)\n- [Commits](https://github.com/apache/maven-assembly-plugin/compare/maven-assembly-plugin-3.7.1...v\n[…]\nmaven.plugins:maven-assembly-plugin\n  dependency-version: 3.8.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-assembly-plugin from 3.7.1 to 3.8.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-03T09:35:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25d602acc586fda9b4f42aec6e520f51b16cbf5d",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v5...v6)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n  dependency-version: '6'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 5 to 6",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-26T15:47:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43b3af2e33849403d24df2b404ce8bdb404a3ea8",
          "body": "Bumps [org.apache.maven.plugins:maven-jar-plugin](https://github.com/apache/maven-jar-plugin) from 3.4.2 to 3.5.0.\n- [Release notes](https://github.com/apache/maven-jar-plugin/releases)\n- [Commits](https://github.com/apache/maven-jar-plugin/compare/maven-jar-plugin-3.4.2...maven-jar-plugin-3.5.0)\n\n-\n[…]\nache.maven.plugins:maven-jar-plugin\n  dependency-version: 3.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-jar-plugin from 3.4.2 to 3.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-18T10:02:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d3bd34a249c658e322411c81c55bc718d4c3865",
          "body": "Bumps [org.asciidoctor:asciidoctorj](https://github.com/asciidoctor/asciidoctorj) from 3.0.0 to 3.0.1.\n- [Release notes](https://github.com/asciidoctor/asciidoctorj/releases)\n- [Changelog](https://github.com/asciidoctor/asciidoctorj/blob/main/CHANGELOG.adoc)\n- [Commits](https://github.com/asciidocto\n[…]\n-name: org.asciidoctor:asciidoctorj\n  dependency-version: 3.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.asciidoctor:asciidoctorj from 3.0.0 to 3.0.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-18T09:58:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "01ca3a9cb25defe0c13e6aa5027173ec6813b3c5",
          "body": "Bumps [commons-io:commons-io](https://github.com/apache/commons-io) from 2.20.0 to 2.21.0.\n- [Changelog](https://github.com/apache/commons-io/blob/master/RELEASE-NOTES.txt)\n- [Commits](https://github.com/apache/commons-io/compare/rel/commons-io-2.20.0...rel/commons-io-2.21.0)\n\n---\nupdated-dependenci\n[…]\nndency-name: commons-io:commons-io\n  dependency-version: 2.21.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump commons-io:commons-io from 2.20.0 to 2.21.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-18T09:44:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fffbc8582e9064928e08ba2276d13a93044a5b10",
          "body": "Bumps [org.asciidoctor:asciidoctorj-pdf](https://github.com/asciidoctor/asciidoctorj-pdf) from 2.3.21 to 2.3.23.\n- [Release notes](https://github.com/asciidoctor/asciidoctorj-pdf/releases)\n- [Changelog](https://github.com/asciidoctor/asciidoctorj-pdf/blob/main/CHANGELOG.adoc)\n- [Commits](https://git\n[…]\n: org.asciidoctor:asciidoctorj-pdf\n  dependency-version: 2.3.23\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.asciidoctor:asciidoctorj-pdf from 2.3.21 to 2.3.23",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-07T11:17:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a51e908b0c3997d81ccc4f7d32a0b99f375f54b0",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 6.0.0 to 6.0.1.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.0.1)\n\n---\nupdated-dependencies:\n- dependency-name: org.junit:junit-bom\n  dependency-version: 6.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 6.0.0 to 6.0.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-07T11:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0841f4ffe27ddbedc71dcf34535c12c1b55057f",
          "body": "Bumps [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) from 1.2.0 to 1.2.1.\n- [Release notes](https://github.com/apache/maven-build-cache-extension/releases)\n- [Commits](https://github.com/apache/maven-build-cache-extension/compare/mave\n[…]\nensions:maven-build-cache-extension\n  dependency-version: 1.2.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.extensions:maven-build-cache-extension",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-07T11:16:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c7c4779e959833bfeed69dadcb0d270f54bca4e",
          "body": null,
          "is_bot": false,
          "headline": "Fix copyright dates after spelling fixes",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-11-07T11:15:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ad63fe9d29b0703b44157e96e2ba98c60d0b53d",
          "body": "Fix spelling",
          "is_bot": false,
          "headline": "Fix spelling (#931)",
          "author_name": "Volodymyr Siedlecki",
          "author_login": "volosied",
          "committed_at": "2025-11-07T11:06:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24bb9444241bcf51f461f9e71f7557d641daeede",
          "body": "No substantive change.",
          "is_bot": false,
          "headline": "Align signature file with generated output",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-21T16:24:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f67ae3d735271f110fc9865424f66f0c381b16ae",
          "body": null,
          "is_bot": false,
          "headline": "Align signature generation with EL, Pages and WebSocket",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-21T16:24:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f24f9c46beb8b508160bb111d3312e996574004",
          "body": "Bumps [org.asciidoctor:asciidoctorj-pdf](https://github.com/asciidoctor/asciidoctorj-pdf) from 2.3.20 to 2.3.21.\n- [Release notes](https://github.com/asciidoctor/asciidoctorj-pdf/releases)\n- [Changelog](https://github.com/asciidoctor/asciidoctorj-pdf/blob/main/CHANGELOG.adoc)\n- [Commits](https://git\n[…]\n: org.asciidoctor:asciidoctorj-pdf\n  dependency-version: 2.3.21\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.asciidoctor:asciidoctorj-pdf from 2.3.20 to 2.3.21",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-21T12:47:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3116fb6b344af960fb35b3d3cb2ab5666f3f8b8f",
          "body": null,
          "is_bot": false,
          "headline": "Align with pages",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-21T10:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93794f91df14b211355f7b40d97b1c1b9a1ab681",
          "body": null,
          "is_bot": false,
          "headline": "Align with EL, Pages and WebSocket",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-21T10:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cfaf628109d628a93bdae6be45e155184920ad9",
          "body": null,
          "is_bot": false,
          "headline": "Remove unused/unnecessary elements",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-21T10:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3d7a6c5612d207c4cf79eca4ba0e11cb665e8f9",
          "body": null,
          "is_bot": false,
          "headline": "Update to EFSL 2.0",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-21T10:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6736b6b5a6b46688ab1c4f33c217f30ca3546b3",
          "body": "Minor changes only.\nIt is expected compatible implementations will still pass the TCK.",
          "is_bot": false,
          "headline": "Regenerate signatures from API",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-17T14:50:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2b2618775c8f65b3d94790ca88d70221d6c4960",
          "body": "- Update to latest parent POM\n- Remove sections that duplicate parent\n- Update/add mailing list URLs\n- Update/add SCM URLs\n- Update/add issue management URLs\n- Use a more recent time stamp for repeatable builds\n- Align with EL POMs where it makes sense to do so\n- Configure consistent minimum Java an\n[…]\nRemove Maven Central publishing configuration now it is available in\nparent\n- Revert to SNAPSHOT dependencies now M1 has been published\n- Remove invalid \"description\" configuration from Javadoc plugin",
          "is_bot": false,
          "headline": "Review POMs. Align (where it makes sense) with EL.",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-17T14:20:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a388e61aae195c2432e4f2961f7b2252b9ed3bbb",
          "body": null,
          "is_bot": false,
          "headline": "Update Servlet API dependency to M1 for TCK M1 build",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-15T19:41:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a81e24b36447128286fe53e9a63d9745d4b7e1f8",
          "body": null,
          "is_bot": false,
          "headline": "Update TCK to use central SNAPSHOT repo",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-15T14:49:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c15a26e7624356b1d61b2bda4a50ab686da1fa7",
          "body": "Bumps org.jruby:jruby-complete from 9.4.14.0 to 10.0.2.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.jruby:jruby-complete\n  dependency-version: 10.0.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jruby:jruby-complete from 9.4.14.0 to 10.0.2.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-15T13:58:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2738f9e62ad77c12eee3e9c955e869810559d340",
          "body": null,
          "is_bot": false,
          "headline": "Use Java 21 for CI build",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-15T13:48:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfb4d4141a4d2238c8f1aa5cb8d0443e95b36485",
          "body": null,
          "is_bot": false,
          "headline": "Update default branch master -> main",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-10-15T13:12:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae43c069dff3f36ae616933cfb86a0dc3d86a700",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 5.13.4 to 6.0.0.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r5.13.4...r6.0.0)\n\n---\nupdated-dependencies:\n- dependency-name: org.junit:junit-bom\n  dependency-version: 6.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 5.13.4 to 6.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-15T09:28:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd01531a1c408600033c2bd162b460c5103b6536",
          "body": "Bumps [org.asciidoctor:asciidoctorj-pdf](https://github.com/asciidoctor/asciidoctorj-pdf) from 2.3.19 to 2.3.20.\n- [Release notes](https://github.com/asciidoctor/asciidoctorj-pdf/releases)\n- [Changelog](https://github.com/asciidoctor/asciidoctorj-pdf/blob/main/CHANGELOG.adoc)\n- [Commits](https://git\n[…]\n: org.asciidoctor:asciidoctorj-pdf\n  dependency-version: 2.3.20\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.asciidoctor:asciidoctorj-pdf from 2.3.19 to 2.3.20",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-15T09:26:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "435d17fe23adb56a16382a48630523b9d3d22583",
          "body": null,
          "is_bot": false,
          "headline": "Update parent POM to 2.0.0-SNAPSHOT and switch to Central for SNAPSHOTs",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-09-26T07:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0f5a9268d68c0198f241b776bfa651d470427e5",
          "body": "Bumps net.revelc.code.formatter:formatter-maven-plugin from 2.27.0 to 2.29.0.\n\n---\nupdated-dependencies:\n- dependency-name: net.revelc.code.formatter:formatter-maven-plugin\n  dependency-version: 2.29.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump net.revelc.code.formatter:formatter-maven-plugin",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-25T16:55:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c46a96bfa8aef84097381138e082c7d591ddcf5",
          "body": "Bumps [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) from 3.5.3 to 3.5.4.\n- [Release notes](https://github.com/apache/maven-surefire/releases)\n- [Commits](https://github.com/apache/maven-surefire/compare/surefire-3.5.3...surefire-3.5.4)\n\n---\nupdated-depend\n[…]\nmaven.plugins:maven-surefire-plugin\n  dependency-version: 3.5.4\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.3 to 3.5.4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-25T16:45:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8f5ede0713e06b02ba50f9052516f0e79737f9c",
          "body": null,
          "is_bot": false,
          "headline": "Apply SEO fix as per jakartaee/platform#1108",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-09-25T16:44:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2ab5eefce5e7352ee31527ff963cc6ed3d97d45",
          "body": "Bumps [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) from 3.14.0 to 3.14.1.\n- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)\n- [Commits](https://github.com/apache/maven-compiler-plugin/compare/maven-compiler-plugin-3.14.0.\n[…]\naven.plugins:maven-compiler-plugin\n  dependency-version: 3.14.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.apache.maven.plugins:maven-compiler-plugin",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-25T16:31:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f0838ba7634a141968ffae2db938f9deac49f5e",
          "body": null,
          "is_bot": false,
          "headline": "Clean-up",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-09-24T17:14:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "079ceb29cbc5171985603f2e473a600c93c4f3e5",
          "body": "The test only uses one request so no need to use keep-alive. That just\ncauses the test to wait for the keep-alive timeout before the container\ncloses the connection.",
          "is_bot": false,
          "headline": "Speed up this TCK test.",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-09-24T17:14:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4586034ce9cd63778e404bf6f97567ee229b04b6",
          "body": "Bumps org.jruby:jruby-complete from 9.4.13.0 to 9.4.14.0.\n\n---\nupdated-dependencies:\n- dependency-name: org.jruby:jruby-complete\n  dependency-version: 9.4.14.0\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jruby:jruby-complete from 9.4.13.0 to 9.4.14.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-08T09:25:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89d3fd690f72a81e7707a4868d9615fc7155e014",
          "body": "Bumps [actions/setup-java](https://github.com/actions/setup-java) from 4 to 5.\n- [Release notes](https://github.com/actions/setup-java/releases)\n- [Commits](https://github.com/actions/setup-java/compare/v4...v5)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-java\n  dependency-version: '5'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/setup-java from 4 to 5",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-08T09:24:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a931723b23b2a2b07f22de349f486e5681e44d8",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v5)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n  dependency-version: '5'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 4 to 5",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-08-13T07:01:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e27d918cb26a2771321fe8d689eb791cdc35a99b",
          "body": "These tests are essentially a copy of the programmatic tests with\nmodifications to allow for the SessionCookieConfig to be provided from\nthe web.xml file.\n\nThe existing programmatic test code is re-used where possible.",
          "is_bot": false,
          "headline": "Fix #681 - add tests for web.xml configuration of SessionCookieConfig",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-08-05T16:41:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6d6b4e68d56de9aa7929bb6846d441f84e65d7d",
          "body": "Clean-up includes:\n- remove old subversion placeholder comment\n- fix IDE warnings",
          "is_bot": false,
          "headline": "Fix typo in log message plus additional clean-up",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-08-05T16:41:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb70b641f3fb6bac0dff17fab5f7474e5e08d8fb",
          "body": "Port of @olamy's fix from 6.1.x",
          "is_bot": false,
          "headline": "Remove @test annotation from non test method to avoid junit warning",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-07-31T09:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1134b4877f9bd5ce23e604a8e1d65ec48ec9de81",
          "body": "---\nupdated-dependencies:\n- dependency-name: org.junit:junit-bom\n  dependency-version: 5.13.4\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 5.13.2 to 5.13.4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-07-25T14:55:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d50ac0a2a7f97b6bd2565ef72755f7a535122f48",
          "body": "---\nupdated-dependencies:\n- dependency-name: commons-io:commons-io\n  dependency-version: 2.20.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump commons-io:commons-io from 2.19.0 to 2.20.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-07-25T14:54:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e6a0b43f3c3b8bb77bb505c11c3cd154e5deaa1",
          "body": null,
          "is_bot": false,
          "headline": "Fix copyright year after re-format",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-07-03T08:09:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "515485d3d06d0347a476a8b270e2d65fcd637ad6",
          "body": null,
          "is_bot": false,
          "headline": "Formatting updates after plug-in update",
          "author_name": "Mark Thomas",
          "author_login": "markt-asf",
          "committed_at": "2025-07-02T13:10:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd7fa62a57f4b1142762ebcba8f5ab31e6e9ca24",
          "body": "Bumps net.revelc.code.formatter:formatter-maven-plugin from 2.26.0 to 2.27.0.\n\n---\nupdated-dependencies:\n- dependency-name: net.revelc.code.formatter:formatter-maven-plugin\n  dependency-version: 2.27.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump net.revelc.code.formatter:formatter-maven-plugin",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-07-02T13:01:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cde0377bf42d54fbc7f1543094ba6f7bd508820b",
          "body": "Bumps [org.jboss.arquillian:arquillian-bom](https://github.com/arquillian/arquillian-core) from 1.9.5.Final to 1.10.0.Final.\n- [Release notes](https://github.com/arquillian/arquillian-core/releases)\n- [Commits](https://github.com/arquillian/arquillian-core/compare/1.9.5.Final...1.10.0.Final)\n\n---\nup\n[…]\nss.arquillian:arquillian-bom\n  dependency-version: 1.10.0.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.jboss.arquillian:arquillian-bom",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-07-02T12:54:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4593c9f0f9a3bf0403e2ce574b51e01f62d823d9",
          "body": "Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework) from 5.13.1 to 5.13.2.\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r5.13.1...r5.13.2)\n\n---\nupdated-dependencies:\n- dependency-name: org.junit:junit-bom\n  dependency-version: 5.13.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.junit:junit-bom from 5.13.1 to 5.13.2",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-07-02T12:52:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 18,
      "commits_last_year": 93,
      "latest_release_at": "2026-05-26T10:08:06Z",
      "latest_release_tag": "6.1.2-RELEASE-tck",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 32,
      "days_since_latest_release": 63,
      "mean_days_between_releases": 102.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "jakarta.servlet:jakarta.servlet-api",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": true,
          "registry_url": "https://central.sonatype.com/artifact/jakarta.servlet/jakarta.servlet-api",
          "is_deprecated": false,
          "latest_version": "6.2.0-M2",
          "repository_url": "https://github.com/jakartaee/servlet",
          "versions_count": 12,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-05-18T11:49:37Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 71
        }
      ]
    },
    "popularity": {
      "forks": 111,
      "stars": 325,
      "watchers": 32,
      "fork_history": {
        "days": [
          {
            "date": "2018-07-12",
            "count": 1
          },
          {
            "date": "2018-09-05",
            "count": 1
          },
          {
            "date": "2018-09-06",
            "count": 1
          },
          {
            "date": "2018-09-19",
            "count": 1
          },
          {
            "date": "2018-10-06",
            "count": 1
          },
          {
            "date": "2018-11-09",
            "count": 1
          },
          {
            "date": "2018-11-12",
            "count": 1
          },
          {
            "date": "2018-11-13",
            "count": 1
          },
          {
            "date": "2018-11-24",
            "count": 1
          },
          {
            "date": "2018-12-30",
            "count": 1
          },
          {
            "date": "2019-03-04",
            "count": 1
          },
          {
            "date": "2019-03-07",
            "count": 1
          },
          {
            "date": "2019-05-29",
            "count": 1
          },
          {
            "date": "2019-06-04",
            "count": 1
          },
          {
            "date": "2019-06-30",
            "count": 1
          },
          {
            "date": "2019-07-12",
            "count": 1
          },
          {
            "date": "2019-07-22",
            "count": 1
          },
          {
            "date": "2019-08-20",
            "count": 1
          },
          {
            "date": "2019-09-06",
            "count": 1
          },
          {
            "date": "2019-09-07",
            "count": 1
          },
          {
            "date": "2019-10-06",
            "count": 1
          },
          {
            "date": "2019-12-06",
            "count": 1
          },
          {
            "date": "2019-12-11",
            "count": 2
          },
          {
            "date": "2020-01-06",
            "count": 1
          },
          {
            "date": "2020-01-12",
            "count": 1
          },
          {
            "date": "2020-01-27",
            "count": 1
          },
          {
            "date": "2020-01-30",
            "count": 1
          },
          {
            "date": "2020-03-21",
            "count": 1
          },
          {
            "date": "2020-04-11",
            "count": 1
          },
          {
            "date": "2020-04-14",
            "count": 1
          },
          {
            "date": "2020-05-21",
            "count": 1
          },
          {
            "date": "2020-06-04",
            "count": 1
          },
          {
            "date": "2020-06-18",
            "count": 1
          },
          {
            "date": "2020-06-27",
            "count": 1
          },
          {
            "date": "2020-07-24",
            "count": 1
          },
          {
            "date": "2020-08-19",
            "count": 1
          },
          {
            "date": "2020-08-20",
            "count": 1
          },
          {
            "date": "2020-08-28",
            "count": 1
          },
          {
            "date": "2020-11-10",
            "count": 1
          },
          {
            "date": "2020-12-16",
            "count": 1
          },
          {
            "date": "2020-12-19",
            "count": 1
          },
          {
            "date": "2021-04-15",
            "count": 1
          },
          {
            "date": "2021-06-30",
            "count": 1
          },
          {
            "date": "2021-07-01",
            "count": 1
          },
          {
            "date": "2021-07-08",
            "count": 1
          },
          {
            "date": "2021-11-08",
            "count": 1
          },
          {
            "date": "2021-11-19",
            "count": 1
          },
          {
            "date": "2022-03-02",
            "count": 1
          },
          {
            "date": "2022-07-18",
            "count": 1
          },
          {
            "date": "2022-07-26",
            "count": 1
          },
          {
            "date": "2022-09-05",
            "count": 1
          },
          {
            "date": "2022-09-23",
            "count": 1
          },
          {
            "date": "2022-11-19",
            "count": 1
          },
          {
            "date": "2023-01-05",
            "count": 1
          },
          {
            "date": "2023-02-22",
            "count": 1
          },
          {
            "date": "2023-02-24",
            "count": 2
          },
          {
            "date": "2023-03-22",
            "count": 1
          },
          {
            "date": "2023-05-19",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-06",
            "count": 1
          },
          {
            "date": "2023-08-08",
            "count": 1
          },
          {
            "date": "2023-08-20",
            "count": 1
          },
          {
            "date": "2023-08-31",
            "count": 1
          },
          {
            "date": "2023-09-16",
            "count": 1
          },
          {
            "date": "2023-10-05",
            "count": 1
          },
          {
            "date": "2023-10-21",
            "count": 1
          },
          {
            "date": "2023-11-09",
            "count": 1
          },
          {
            "date": "2023-12-31",
            "count": 1
          },
          {
            "date": "2024-03-02",
            "count": 1
          },
          {
            "date": "2024-03-12",
            "count": 1
          },
          {
            "date": "2024-04-15",
            "count": 1
          },
          {
            "date": "2024-05-21",
            "count": 1
          },
          {
            "date": "2024-06-03",
            "count": 1
          },
          {
            "date": "2024-06-13",
            "count": 1
          },
          {
            "date": "2024-07-09",
            "count": 1
          },
          {
            "date": "2024-07-15",
            "count": 1
          },
          {
            "date": "2024-08-13",
            "count": 1
          },
          {
            "date": "2024-09-04",
            "count": 1
          },
          {
            "date": "2024-09-17",
            "count": 1
          },
          {
            "date": "2024-09-19",
            "count": 1
          },
          {
            "date": "2024-10-23",
            "count": 1
          },
          {
            "date": "2024-10-24",
            "count": 1
          },
          {
            "date": "2024-12-19",
            "count": 1
          },
          {
            "date": "2025-01-19",
            "count": 1
          },
          {
            "date": "2025-01-28",
            "count": 1
          },
          {
            "date": "2025-03-02",
            "count": 1
          },
          {
            "date": "2025-03-07",
            "count": 1
          },
          {
            "date": "2025-03-09",
            "count": 1
          },
          {
            "date": "2025-03-14",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-04-24",
            "count": 2
          },
          {
            "date": "2025-05-21",
            "count": 1
          },
          {
            "date": "2025-07-06",
            "count": 1
          },
          {
            "date": "2025-07-23",
            "count": 1
          },
          {
            "date": "2025-09-08",
            "count": 1
          },
          {
            "date": "2025-09-17",
            "count": 1
          },
          {
            "date": "2025-09-21",
            "count": 1
          },
          {
            "date": "2025-09-22",
            "count": 1
          },
          {
            "date": "2025-10-08",
            "count": 1
          },
          {
            "date": "2025-11-07",
            "count": 1
          },
          {
            "date": "2025-11-22",
            "count": 1
          },
          {
            "date": "2025-12-10",
            "count": 1
          },
          {
            "date": "2026-02-01",
            "count": 1
          },
          {
            "date": "2026-03-14",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          },
          {
            "date": "2026-07-28",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 111,
        "total_forks": 111
      },
      "star_history": null,
      "open_issues_and_prs": 111
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "api/pom.xml",
        "pom.xml",
        "spec/pom.xml",
        "tck/pom.xml",
        "tck/tck-dist/pom.xml",
        "tck/tck-docs/userguide/pom.xml",
        "tck/tck-runtime/pom.xml",
        "tck/tck-util/pom.xml"
      ],
      "largest_source_bytes": 85073,
      "source_files_sampled": 923,
      "oversized_source_files": 4,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "api/pom.xml",
        "pom.xml",
        "spec/pom.xml",
        "tck/pom.xml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 47,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 12,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "maven"
      ],
      "dependencies": [
        {
          "name": "org.junit:junit-bom",
          "manifest": "api/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.1.2"
        },
        {
          "name": "org.jruby:jruby-complete",
          "manifest": "spec/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jruby.version}"
        },
        {
          "name": "org.asciidoctor:asciidoctorj",
          "manifest": "spec/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${asciidoctorj.version}"
        },
        {
          "name": "org.asciidoctor:asciidoctorj-pdf",
          "manifest": "spec/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${asciidoctorj.pdf.version}"
        },
        {
          "name": "org.junit:junit-bom",
          "manifest": "tck/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.1.2"
        },
        {
          "name": "org.jboss.arquillian:arquillian-bom",
          "manifest": "tck/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.10.2.Final"
        },
        {
          "name": "org.jboss.shrinkwrap:shrinkwrap-bom",
          "manifest": "tck/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.2.6"
        },
        {
          "name": "org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom",
          "manifest": "tck/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.3.7"
        },
        {
          "name": "org.slf4j:slf4j-api",
          "manifest": "tck/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.18"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "org.asciidoctor:asciidoctorj",
            "direct": true,
            "version": "2.4.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctorj",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctorj-pdf",
            "direct": true,
            "version": "1.5.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctorj-pdf",
            "direct": true,
            "version": "2.3.23",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.arquillian:arquillian-bom",
            "direct": true,
            "version": "1.10.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom",
            "direct": true,
            "version": "3.3.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.shrinkwrap:shrinkwrap-bom",
            "direct": true,
            "version": "1.2.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.jruby:jruby-complete",
            "direct": true,
            "version": "10.0.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit:junit-bom",
            "direct": true,
            "version": "6.1.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": "2.0.18",
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": false,
            "version": "2.22.0",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.annotation:jakarta.annotation-api",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.servlet:jakarta.servlet-api",
            "direct": false,
            "version": "6.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.tck:servlet-tck",
            "direct": false,
            "version": "6.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.tck:servlet-tck-runtime",
            "direct": false,
            "version": "6.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.tck:servlet-tck-util",
            "direct": false,
            "version": "6.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.tck:sigtest-maven-plugin",
            "direct": false,
            "version": "2.6",
            "ecosystem": "maven"
          },
          {
            "name": "net.revelc.code.formatter:formatter-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "net.revelc.code.formatter:formatter-maven-plugin",
            "direct": false,
            "version": "2.29.0",
            "ecosystem": "maven"
          },
          {
            "name": "net.revelc.code:impsort-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "net.revelc.code:impsort-maven-plugin",
            "direct": false,
            "version": "1.13.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:maven-bundle-plugin",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-assembly-plugin",
            "direct": false,
            "version": "3.3.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-assembly-plugin",
            "direct": false,
            "version": "3.8.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-clean-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-clean-plugin",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-clean-plugin",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": "3.15.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-deploy-plugin",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-enforcer-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-enforcer-plugin",
            "direct": false,
            "version": "3.0.0-M3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-enforcer-plugin",
            "direct": false,
            "version": "3.8.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-install-plugin",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jar-plugin",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": "3.12.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-resources-plugin",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-scm-publish-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-scm-publish-plugin",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-source-plugin",
            "direct": false,
            "version": "3.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": "3.5.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctor-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctor-maven-plugin",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctor-maven-plugin",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctorj-diagram",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:build-helper-maven-plugin",
            "direct": false,
            "version": "3.6.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.freemarker:freemarker",
            "direct": false,
            "version": "2.3.30",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.copyright:glassfish-copyright-maven-plugin",
            "direct": false,
            "version": "2.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.doc:glassfish-doc-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.doc:glassfish-doc-maven-plugin",
            "direct": false,
            "version": "1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.hamcrest:hamcrest",
            "direct": false,
            "version": "3.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.jbake:jbake-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.jbake:jbake-maven-plugin",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.arquillian.junit5:arquillian-junit5-container",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.arquillian.junit:arquillian-junit-core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-api-maven",
            "direct": false,
            "version": "3.3.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-impl-maven",
            "direct": false,
            "version": "3.3.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-spi-maven",
            "direct": false,
            "version": "3.3.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 59,
        "direct_count": 11,
        "indirect_count": 48
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 14,
        "merged_prs": 593,
        "open_issues": 97,
        "closed_ratio": 0.762,
        "closed_issues": 311,
        "closed_unmerged_prs": 66
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "markt-asf",
          "commits": 315,
          "avatar_url": "https://avatars.githubusercontent.com/u/4690029?v=4"
        },
        {
          "type": "User",
          "login": "stuartwdouglas",
          "commits": 66,
          "avatar_url": "https://avatars.githubusercontent.com/u/328571?v=4"
        },
        {
          "type": "User",
          "login": "arjantijms",
          "commits": 44,
          "avatar_url": "https://avatars.githubusercontent.com/u/3037006?v=4"
        },
        {
          "type": "User",
          "login": "olamy",
          "commits": 38,
          "avatar_url": "https://avatars.githubusercontent.com/u/19728?v=4"
        },
        {
          "type": "User",
          "login": "gregw",
          "commits": 28,
          "avatar_url": "https://avatars.githubusercontent.com/u/70829?v=4"
        },
        {
          "type": "User",
          "login": "pzygielo",
          "commits": 11,
          "avatar_url": "https://avatars.githubusercontent.com/u/11896137?v=4"
        },
        {
          "type": "User",
          "login": "OnlyWick",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/53461157?v=4"
        },
        {
          "type": "User",
          "login": "dblevins",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/94926?v=4"
        },
        {
          "type": "User",
          "login": "thadumi",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/19282590?v=4"
        },
        {
          "type": "User",
          "login": "servlet-bot",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/43731440?v=4"
        }
      ],
      "contributors_sampled": 34,
      "top_contributor_share": 0.567
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "maven.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "26 out of 26 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/7 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 29 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "0716658993beeed06b1487a8a6e446ed51c4ce06",
        "ran_at": "2026-07-28T14:18:20Z",
        "aggregate_score": 6.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T18:04:14Z",
      "oldest_open_prs": [
        {
          "number": 285,
          "created_at": "2020-01-07T08:03:04Z",
          "last_comment_at": "2020-01-08T09:29:18Z",
          "last_comment_author": "senivam"
        },
        {
          "number": 434,
          "created_at": "2021-11-03T01:12:51Z",
          "last_comment_at": "2024-01-17T02:56:45Z",
          "last_comment_author": "stuartwdouglas"
        },
        {
          "number": 435,
          "created_at": "2021-11-03T04:10:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 637,
          "created_at": "2024-05-21T16:40:19Z",
          "last_comment_at": "2024-11-07T15:59:14Z",
          "last_comment_author": "markt-asf"
        },
        {
          "number": 881,
          "created_at": "2025-06-12T15:06:01Z",
          "last_comment_at": "2025-09-08T09:22:31Z",
          "last_comment_author": "markt-asf"
        },
        {
          "number": 885,
          "created_at": "2025-06-27T15:15:38Z",
          "last_comment_at": "2025-08-04T11:01:47Z",
          "last_comment_author": "markt-asf"
        },
        {
          "number": 914,
          "created_at": "2025-09-08T09:23:56Z",
          "last_comment_at": "2025-09-30T09:12:47Z",
          "last_comment_author": "markt-asf"
        },
        {
          "number": 1074,
          "created_at": "2026-07-20T00:46:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1076,
          "created_at": "2026-07-27T18:03:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1077,
          "created_at": "2026-07-27T18:03:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1078,
          "created_at": "2026-07-27T18:03:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1079,
          "created_at": "2026-07-27T18:04:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1080,
          "created_at": "2026-07-27T18:04:17Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1081,
          "created_at": "2026-07-27T18:04:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-13T22:51:44Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 193,
          "created_at": "2011-05-31T18:39:36Z",
          "last_comment_at": "2021-06-05T17:16:29Z",
          "last_comment_author": null
        },
        {
          "number": 20,
          "created_at": "2011-10-07T01:34:14Z",
          "last_comment_at": "2025-06-12T15:07:03Z",
          "last_comment_author": "markt-asf"
        },
        {
          "number": 21,
          "created_at": "2011-10-07T01:36:29Z",
          "last_comment_at": "2025-06-13T10:09:14Z",
          "last_comment_author": "markt-asf"
        },
        {
          "number": 26,
          "created_at": "2011-10-07T01:58:39Z",
          "last_comment_at": "2018-10-04T23:46:21Z",
          "last_comment_author": "gregw"
        },
        {
          "number": 31,
          "created_at": "2012-02-27T01:06:20Z",
          "last_comment_at": "2019-12-12T04:18:05Z",
          "last_comment_author": "gregw"
        },
        {
          "number": 39,
          "created_at": "2012-05-22T10:38:42Z",
          "last_comment_at": "2017-04-26T06:06:52Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 40,
          "created_at": "2012-05-30T10:02:05Z",
          "last_comment_at": "2017-04-26T06:06:54Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 41,
          "created_at": "2012-06-04T20:59:47Z",
          "last_comment_at": "2017-04-26T06:06:56Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 44,
          "created_at": "2012-08-21T17:48:28Z",
          "last_comment_at": "2020-09-08T09:26:51Z",
          "last_comment_author": "gregw"
        },
        {
          "number": 50,
          "created_at": "2012-11-01T19:01:14Z",
          "last_comment_at": "2017-04-26T06:07:19Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 52,
          "created_at": "2013-01-07T03:34:17Z",
          "last_comment_at": "2020-05-21T10:44:06Z",
          "last_comment_author": "gregw"
        },
        {
          "number": 58,
          "created_at": "2013-02-19T15:53:40Z",
          "last_comment_at": "2017-04-26T06:07:38Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 61,
          "created_at": "2013-02-20T19:36:12Z",
          "last_comment_at": "2017-04-26T06:07:45Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 62,
          "created_at": "2013-02-20T20:23:43Z",
          "last_comment_at": "2017-04-26T06:07:47Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 63,
          "created_at": "2013-02-21T02:15:55Z",
          "last_comment_at": "2020-09-19T14:51:38Z",
          "last_comment_author": "chkal"
        },
        {
          "number": 65,
          "created_at": "2013-03-05T19:26:37Z",
          "last_comment_at": "2017-04-26T06:07:56Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 66,
          "created_at": "2013-03-10T04:06:58Z",
          "last_comment_at": "2025-05-19T13:30:05Z",
          "last_comment_author": "reiern70"
        },
        {
          "number": 67,
          "created_at": "2013-03-11T01:06:03Z",
          "last_comment_at": "2017-04-26T06:08:00Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 78,
          "created_at": "2013-08-20T01:35:35Z",
          "last_comment_at": "2017-04-26T06:08:28Z",
          "last_comment_author": "glassfishrobot"
        },
        {
          "number": 79,
          "created_at": "2013-08-31T22:30:39Z",
          "last_comment_at": "2017-09-28T15:12:57Z",
          "last_comment_author": "glassfishrobot"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/jakartaee/servlet",
    "host": "github.com",
    "name": "servlet",
    "owner": "jakartaee"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 72,
      "inputs": {
        "security": 69,
        "vitality": 84,
        "community": 72,
        "governance": 69,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "commits_last_year": 93,
              "human_commit_share": 0.42,
              "days_since_last_push": 0,
              "active_weeks_last_year": 32
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "32/52 weeks with commits",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 32
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "93 commits in the last year",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 93
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "releases_count": 18,
              "latest_release_tag": "6.1.2-RELEASE-tck",
              "releases_from_tags": true,
              "days_since_latest_release": 63,
              "mean_days_between_releases": 102.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "18 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 18
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 63 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 63
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~102.4 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 102.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 27,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 27 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 27
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 72,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "forks": 111,
              "stars": 325,
              "watchers": 32,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "325 stars",
                "points": 40.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 325
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "111 forks",
                "points": 17,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 111
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "32 watchers",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 32
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 69,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 34,
              "top_contributor_share": 0.567
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 57% of commits",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 57
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "34 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 29 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "merged_prs": 593,
              "open_issues": 97,
              "closed_issues": 311,
              "issue_closed_ratio": 0.762,
              "closed_unmerged_prs": 66
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "76% of issues closed",
                "points": 35.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 76
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "593/659 decided PRs merged",
                "points": 34.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 593,
                      "decided": 659
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/7 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "followers": 739,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "jakartaee",
              "public_repos": 74,
              "account_age_days": 3093
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "739 followers of jakartaee",
                "points": 20.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 739,
                      "login": "jakartaee"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "74 public repos, account ~8 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 74
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 8
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "jakarta.servlet:jakarta.servlet-api"
              ],
              "ecosystems": "maven",
              "any_deprecated": false,
              "min_days_since_publish": 71
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on maven",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "maven"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 71 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 71
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "12 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "26 out of 26 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://projects.eclipse.org/projects/ee4j.servlet",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://projects.eclipse.org/projects/ee4j.servlet",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 69,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 6.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "26 out of 26 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/7 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 29 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "21 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 47 resolved dependencies against OSV; 12 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 47
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 12
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 47,
              "unassessed_packages": 12,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 47,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 11
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 51,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.429,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "18 of 42 human commits state their intent (structured subject or explanatory body)",
                "points": 22.9,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 18,
                      "sampled": 42
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "api/pom.xml",
                "pom.xml",
                "spec/pom.xml",
                "tck/pom.xml",
                "tck/tck-dist/pom.xml",
                "tck/tck-docs/userguide/pom.xml",
                "tck/tck-runtime/pom.xml",
                "tck/tck-util/pom.xml"
              ],
              "dependency_bot_commit_share": 0.58
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "api/pom.xml, pom.xml, spec/pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "api/pom.xml, pom.xml, spec/pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Java (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "58 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 58,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Java",
              "largest_source_bytes": 85073,
              "source_files_sampled": 923,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Java (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/923 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 923,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T14:18:51.386534Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/jakartaee/servlet.svg",
  "full_name": "jakartaee/servlet",
  "license_state": "custom",
  "license_spdx": null
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsMaven.