Public record
Software health reportschema 0.23.0 · metrics 1.13.0 · 2026-07-21 19:59 UTC

kivra / oauth2

Erlang Oauth2 implementation

ErlangMIT★ 221 stars⑂ 69 forkssince Feb 2012View on GitHub ↗

kivra/oauth2 holds a health index of 62 out of 100, placing it in the Moderate band. It scores highest on Vitality (73/100) and lowest on AI Readiness (37/100). It was last updated 22 days ago. A single contributor accounts for most of its recent work.

62
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

62
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

KivraOrganization
33 followers63 public repossince Jan 2012

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Hexoauth2points to another repo — not scored2.1.1220,8132848 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

73Good · 22% of overall
How it's scored
28.8/36Push recency — last push 22 days ago
9.7/36Commit cadence — 14/52 weeks with commits
11.9/18Commit volume — 20 commits in the last year
5/10OpenSSF Scorecard: Maintained — 7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
Inputs used
commits_last_year20
human_commit_share0.82
days_since_last_push22
active_weeks_last_year14

Release discipline

100Excellent
How it's scored
27/27Ships releases — 12 releases published
36/36Release recency — latest release 22 days ago
27/27Release cadence — a release every ~35.8 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count12
latest_release_tagv1.0.3
releases_from_tagsno
days_since_latest_release22
mean_days_between_releases35.8
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

55Moderate · 18% of overall
How it's scored
38/60Stars — 221 stars
15.3/25Forks — 69 forks
7.2/15Watchers — 21 watchers
Inputs used
forks69
stars221
watchers21
growth_stateorganic
growth_factor_pct100
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

60Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
7/22.5Commit distribution — top contributor authored 69% of commits
13.5/13.5Contributor breadth — 12 contributors
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Inputs used
bus_factor1
contributors_sampled12
top_contributor_share0.689
How it's scored
45.2/46.8Issue resolution — 97% of issues closed
28.7/38.3PR acceptance — 63/84 decided PRs merged
3/15OpenSSF Scorecard: Code-Review — Found 3/12 approved changesets -- score normalized to 2
Inputs used
merged_prs63
open_issues1
closed_issues28
issue_closed_ratio0.966
closed_unmerged_prs21
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
11/25Owner reach — 33 followers of kivra
25/25Track record — 63 public repos, account ~14 yr old
Inputs used
followers33
owner_typeOrganization
is_verified
owner_loginkivra
public_repos63
account_age_days5,304

Engineering Quality

Are baseline engineering and documentation practices in place?

57Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
14/20OpenSSF Scorecard: CI-Tests — 23 out of 30 merged PRs checked by a CI test -- score normalized to 7
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

50Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 1 topics
0/10Wiki
Inputs used
topicskivra-platform-engineering
has_wikino
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
1.8/2.5CI-Tests — 23 out of 30 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
1.5/7.5Code-Review — Found 3/12 approved changesets -- score normalized to 2
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5License — license file detected
3.8/7.5Maintained — 7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
0/5Packaging — no data
3/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
3.5/5SAST — SAST tool is not run on all commits -- score normalized to 7
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.1
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

37At risk · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
29.3/40Legible commit history — 45 of 82 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.549
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
0/11Lint / format config
0/11Static type checking
0/10Reproducible environment
2/10Demonstrated agent practice — 1 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 18 of the last 100 commits are automated dependency updates
6/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 6
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageno
bootstrap_filesMakefile
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.01
toolchain_manifests
dependency_bot_commit_share0.18
How it's scored
0/45Type-checkable code — Erlang without a type-check config
0/55Manageable file sizes — no source files detected
Inputs used
primary_languageErlang
largest_source_bytes
source_files_sampled0
oversized_source_files0
Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.

Key facts

221GitHub stars
12contributors
20commits, last 12 months
22days since last push
12releases
1bus factor
1open issues
package ecosystems

Data collection warnings

  • hex package 'oauth2' points at a different repository (https://github.com/scrogson/oauth2); excluded from ecosystem scoring

More detail

Star and fork history 221 ★ / 69 ⇿
221Stars
69Forks
7Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0408012016020024022157282012-022019-032026-03
Major 0Minor 2Patch 5

Each point covers 13 days.

OpenSSF Scorecard 6.1 / 10
6.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-21 19:59 UTC

10Binary-Artifactsno binaries found in the repo
1Branch-Protectionbranch protection is not maximal on development and all release branches
7CI-Tests23 out of 30 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
2Code-ReviewFound 3/12 approved changesets -- score normalized to 2
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
5Maintained7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5
n/aPackagingpackaging workflow not detected
6Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 6
7SASTSAST tool is not run on all commits -- score normalized to 7
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
All dependencies 0

Full resolved dependency set from the GitHub dependency graph: 0 direct and 0 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Dependency advisories not assessed

Advisory matching could not run for this report: No resolved dependencies to assess

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "kivra-platform-engineering"
      ],
      "is_fork": false,
      "size_kb": 1131,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Erlang": 98913,
        "Makefile": 222
      },
      "pushed_at": "2026-06-29T13:50:26Z",
      "created_at": "2012-02-29T16:03:07Z",
      "owner_type": "Organization",
      "updated_at": "2026-06-29T13:50:35Z",
      "description": "Erlang Oauth2 implementation",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "Erlang",
      "significant_languages": [
        "Erlang"
      ]
    },
    "owner": {
      "blog": "https://kivra.com",
      "name": "Kivra",
      "type": "Organization",
      "login": "kivra",
      "company": null,
      "location": "Stockholm, Sweden",
      "followers": 33,
      "avatar_url": "https://avatars.githubusercontent.com/u/1324180?v=4",
      "created_at": "2012-01-12T08:54:45Z",
      "is_verified": null,
      "public_repos": 63,
      "account_age_days": 5304
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.3",
          "kind": "patch",
          "published_at": "2026-06-29T13:50:26Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-06-29T13:43:15Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-06-18T14:32:13Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-06-18T10:52:14Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2026-03-25T13:57:27Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2025-11-21T16:49:30Z"
        },
        {
          "tag": "v0.9.4",
          "kind": "patch",
          "published_at": "2025-11-18T06:19:16Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2025-10-13T06:27:08Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2025-08-12T09:24:18Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2025-08-11T11:57:58Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2025-07-16T12:40:22Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2021-08-17T10:39:02Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "06b4b4c90c6b21d9c2054d8d5f74d7d0dcc5083b",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "fix(deps): update erlef/setup-beam action to v1.24.1 (#112)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-29T13:50:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85839e50a218ce960c35d4b0479a308645093374",
          "body": "…erge, ...) schedule (#113)\n\n* Ease auto-merging via Renovate\n\n* Tweak it post self-review\n\n* Fix per Copilot finding",
          "is_bot": false,
          "headline": "fix: [PE-7464] Renovate config. as `json5`, with (PR creation, auto-m…",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2026-06-29T13:43:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73ec972a8686dba542ebeaec82fa15b392c8f445",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/checkout action to v7 (#111)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-18T14:31:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4541b58a5f22c54b85a40ca0da29828e77caff9c",
          "body": "… (from `platform-ci`)\" (#110)\n\nRevert \"no-release: [PTF-1954] use shared Renovate config (from `platform-ci`) (#108)\"\n\nThis reverts commit 11d06cf8f122095828aa64c7efdc4c2ce677bb02.",
          "is_bot": false,
          "headline": "no-release: Revert \"no-release: [PTF-1954] use shared Renovate config…",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2026-06-08T23:16:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11d06cf8f122095828aa64c7efdc4c2ce677bb02",
          "body": "…) (#108)",
          "is_bot": false,
          "headline": "no-release: [PTF-1954] use shared Renovate config (from `platform-ci`…",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2026-06-08T22:39:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7ca7cf1551083b58f0df2411870b503df9e9f75",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release: Update actions/checkout action to v6.0.3 (#107)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-04T02:23:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e23b7857bfa6e0f530c429c9b32f2a011b0fb29",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release: Update dependency meck to v1.2.0 (#106)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-05-27T16:04:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5af228dc223155916d084d00ddcf3bcdefcf3411",
          "body": "chore(deps): update dependency meck to v1.1.1\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release: Update dependency meck to v1.1.1 (#104)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-17T09:28:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb9b6c6cf99cd504475ffeea927eea5dfa138c0d",
          "body": "chore(deps): update erlef/setup-beam action to v1.24.0\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release: Update erlef/setup-beam action to v1.24.0 (#105)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-04-17T09:28:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2d6ef71f85cc8b9ef4a8b9689d83af05cf98e58",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update erlef/setup-beam action to v1.23.0 (#102)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-25T13:57:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e43330ef73f1cc3a647afd178f899699cf7e6db",
          "body": "Adapt to team name change",
          "is_bot": false,
          "headline": "no-release(fix/codeowners): adapt to team name change (#103)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2026-03-18T12:41:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a86623899db77825fb10111c0f3bd32d813bcc0f",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update erlef/setup-beam action to v1.21.0 (#101)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-03-02T11:05:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd73b69a91705f727324395207f555cd8a1645db",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update actions/checkout action to v6.0.2 (#100)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-01-22T20:53:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d6a13579224f0fd6aa8f745147de37cdd631c57",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release: update actions/checkout action to v6.0.1 (#99)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-12-03T07:27:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5c0f51e5ce7e42226189432ac09cc2922534a1e",
          "body": "Be more relaxed",
          "is_bot": false,
          "headline": "no-release(fix): be more relaxed for `no-release` (#98)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2025-12-02T21:10:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84dcdfee39122122557815d1319f93bd8099f52b",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update actions/checkout action to v6 (#97)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-11-21T16:49:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5200b1a21e9187d08373a2c3e9e39718288e6125",
          "body": "chore(deps): update actions/checkout action to v5.0.1\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update actions/checkout action to v5.0.1 (#96)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-11-18T06:19:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8128c0c98d817b24aa0fc839215c9d47a1ba86b",
          "body": "chore(deps): update dependency meck to v1.1.0\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update dependency meck to v1.1.0 (#95)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-10-13T06:26:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6fdc7cfcf668d7eab16ec7ca99efcf60f5e9248",
          "body": "chore(deps): update actions/checkout action to v5\n\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update actions/checkout action to v5 (#94)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-08-12T09:24:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b112835862cb343d2d5593412f6589c70b49902c",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release(deps): update actions/checkout action to v4.3.0 (#93)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-08-11T11:57:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ac66a147c5b9cef7e422aee8e441758b73dd7a9",
          "body": "* Potential fix for code scanning alert no. 1: Workflow does not contain permissions\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>\n\n* Act on our current needs\n\n---------\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "no-release: Fix \"Workflow does not contain permissions\" (#92)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2025-07-16T16:26:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c063f122933bcb6db388ce71c0c6b06d6e79326e",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "no-release: update dependency meck to v1 (#91)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-07-16T12:43:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65b5a8b47fd747cb2749576303bc7bc9bed0ec09",
          "body": "* CI on GitHub Actions, not Travis\n\n* Drop local rebar (stop pushing to repo, also)\n\n* Stop trying to build the docs\n\n* Accept change with confidence\n\n* Add auto-release to CI\n\n* Simplify Makefile (add xref, remove non-essential targets)\n\n* Ease versioning\n\n* Tweak Makefile: we're using eunit, not ct\n\n* Allow for `rebar3 as test dialyzer` to be taken further\n\n* Ignore proper results\n\n* Fix per `rebar3 as test dialyzer`\n\n* Act on CI results",
          "is_bot": false,
          "headline": "feat: CI (#90)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2025-07-16T12:40:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6f4d07f3718bfcda35564b1da0e5b48aaacc314",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update dependency meck to v0.9.2 (#87)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-07-16T11:13:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a568d39612b7423807cad2467da9344a709f36f7",
          "body": "Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): update dependency proper to v1.5.0 (#88)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2025-07-16T11:13:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b06e2da2480b4d3a1204f5525f512df857df8115",
          "body": "Start Renovate'ing",
          "is_bot": false,
          "headline": "no-release: Start Renovate'ing (#86)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2025-07-16T11:07:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44b5728f8dc60fd16bf40caf7511cb5b2c52c903",
          "body": "Don't blame on recent formatting change",
          "is_bot": false,
          "headline": "no-release: Don't blame on recent formatting change (#85)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2024-12-12T11:44:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34665ce22d9439993b10bec853680176fe1835ff",
          "body": "This reverts commit 4a9ce4ca05a052a2f81239694ff49b407d29bd8e.",
          "is_bot": false,
          "headline": "Revert \"no-release: Format it! (#82)\" (#84)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2024-12-11T15:37:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85d9a52b0027b3560d79d2dd28c3ab28aa8f449c",
          "body": "Don't blame on recent formatting change",
          "is_bot": false,
          "headline": "no-release: Don't blame on recent formatting change (#83)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2024-12-10T12:02:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a9ce4ca05a052a2f81239694ff49b407d29bd8e",
          "body": "Format it!",
          "is_bot": false,
          "headline": "no-release: Format it! (#82)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2024-12-09T08:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98de355bbfa77bfad6b70c18407bedd3cc5ed550",
          "body": "* Ease booting application for development\r\n\r\n* Ease moving toward rebar3\r\n\r\nCheck\r\nhttps://erlangforums.com/t/what-is-the-best-way-to-deal-with-rebar-lock-files-of-dependencies/2826/15\r\non a discussion of the benefits of rebar.lock\r\n\r\n* Remove useless warning: warn_export_all\r\n\r\nBy default we alrea\n[…]\ns\"\r\n\r\nIt's either this or flagging all \"interface API\" functions\r\nas -ignore_xref, which is potentially more difficult to\r\nmaintain. Choices (?)\r\n\r\n* Tweak test coverage\r\n\r\n* Ease owner identification",
          "is_bot": false,
          "headline": "chore: modernise the repository a bit (#81)",
          "author_name": "Paulo F. Oliveira",
          "author_login": "kivra-pauoli",
          "committed_at": "2024-09-04T08:10:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8e77e0830bc39ff44740f9f5df4a722e3573091",
          "body": null,
          "is_bot": false,
          "headline": "feat: add authorize_directly (#77)",
          "author_name": "Yifan Yu",
          "author_login": "kampiliira",
          "committed_at": "2020-05-25T07:03:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c2f95e496429a09be11e880e33165b3d28bb0f5",
          "body": null,
          "is_bot": false,
          "headline": "fix: compute refresh_token scope correctly (#76)",
          "author_name": "Yifan Yu",
          "author_login": "kampiliira",
          "committed_at": "2020-01-23T11:44:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41b345a3eb18bbc0f4e4eb7cda8c86696781eca2",
          "body": null,
          "is_bot": false,
          "headline": "feat: associate JWT refresh_token with device_id (#75)",
          "author_name": "Yifan Yu",
          "author_login": "kampiliira",
          "committed_at": "2019-06-25T08:03:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5559bc8c037a1358768526255334c92a98d836e",
          "body": null,
          "is_bot": false,
          "headline": "feat: JWT support (#74)",
          "author_name": "Yifan Yu",
          "author_login": "kampiliira",
          "committed_at": "2019-06-17T18:32:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f5b9f17ec689c472c3704583c2cacfb2a3cca82",
          "body": "Remove usage of crypto:rand_bytes/1",
          "is_bot": false,
          "headline": "Merge pull request #72 from kivra/remove-usage-of-crypto-rand-bytes",
          "author_name": "Onno Vos",
          "author_login": "onno-vos-kivra",
          "committed_at": "2019-03-28T08:11:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "187786b8116f93cbe1710977acaebce06b23038d",
          "body": null,
          "is_bot": false,
          "headline": "Remove usage of crypto:rand_bytes/1",
          "author_name": "Onno Vos",
          "author_login": "onno-vos-kivra",
          "committed_at": "2019-03-01T13:16:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b91ccc6bc48cceb19d93c2feedfd5ee297f35e00",
          "body": "Pass on error from authenticate_user",
          "is_bot": false,
          "headline": "Merge pull request #71 from kivra/hn-otp",
          "author_name": "Håkan Nilsson",
          "author_login": "plux",
          "committed_at": "2018-01-17T14:53:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ee5b1814f1d4671765e22c6c38d351bc545baeb",
          "body": null,
          "is_bot": false,
          "headline": "Update specs",
          "author_name": "Hakan Nilsson",
          "author_login": "plux-kivra",
          "committed_at": "2018-01-16T11:35:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96a1969238a45d3ea23d73f7611a9b33535eaaac",
          "body": null,
          "is_bot": false,
          "headline": "Pass on error from authenticate_user",
          "author_name": "Hakan Nilsson",
          "author_login": "plux-kivra",
          "committed_at": "2018-01-12T09:35:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14ce8e774d7310797d2e9ece733641f243359243",
          "body": null,
          "is_bot": false,
          "headline": "Tag 0.7.0",
          "author_name": "Hakan Nilsson",
          "author_login": "plux-kivra",
          "committed_at": "2017-11-07T15:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ceef3dcf4eed161171153f4ef8d39b08a417e9c",
          "body": "Response record fields can be undefined",
          "is_bot": false,
          "headline": "Merge pull request #70 from kivra/fix-response-record-types",
          "author_name": "Håkan Nilsson",
          "author_login": "plux",
          "committed_at": "2017-11-07T15:04:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e0c7e47f5e4dccff104d2e4ca87e0d2255a4d2a",
          "body": null,
          "is_bot": false,
          "headline": "Response record fields can be undefined",
          "author_name": "Hakan Nilsson",
          "author_login": "plux-kivra",
          "committed_at": "2017-11-06T21:06:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "218c963d387fafa16495bd50d62089b18fd28662",
          "body": "Relation refresh and access token via access token context",
          "is_bot": false,
          "headline": "Merge pull request #65 from mdaguete/relation_refresh_and_access",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2016-04-20T12:38:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a15827ddd17be3ae93fdb36361b9f2ac803531af",
          "body": "Implicit Grant doesn't need client secret",
          "is_bot": false,
          "headline": "Merge pull request #64 from mdaguete/implicit_grant",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2016-04-20T12:36:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f74c2d39d145c24bc7f6869cf8eee92c1d4dc889",
          "body": null,
          "is_bot": false,
          "headline": "Add refresh_token to access_token context",
          "author_name": "Manuel Durán Aguete",
          "author_login": "mdaguete",
          "committed_at": "2016-03-11T17:13:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bd0a6df0809e8dc4a72d996315881a197d714bc",
          "body": "As RFC mentions:\n\n> The implicit grant type does not include client authentication, and\n   relies on the presence of the resource owner and the registration of\n   the redirection URI.\n\nClient secret is not needed.",
          "is_bot": false,
          "headline": "Implicit Grant doesn't  need client secret",
          "author_name": "Manuel Durán Aguete",
          "author_login": "mdaguete",
          "committed_at": "2016-02-25T09:02:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a8f1431d002f33dd0bba7850e5257a2277be526",
          "body": "Hex",
          "is_bot": false,
          "headline": "Merge pull request #63 from project-fifo/hex",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2016-02-18T07:45:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40cf5d42443ecc61c506a1cb4e7b3442f40d741f",
          "body": null,
          "is_bot": false,
          "headline": "Change package name to oauth2_erlang to prevent conflicts",
          "author_name": "Heinz N. Gies",
          "author_login": "Licenser",
          "committed_at": "2016-02-17T18:48:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6ce6920deb0ee373297b5c7cbb0acb97e1bc314",
          "body": null,
          "is_bot": false,
          "headline": "Added hex related fields to app.src",
          "author_name": "Heinz N. Gies",
          "author_login": "Licenser",
          "committed_at": "2016-02-17T18:41:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75f62a64efcee7b7c818a6db7b9a5ab2a97f6cca",
          "body": null,
          "is_bot": false,
          "headline": "Tag 0.6.1",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2016-02-08T07:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d129fbf8866930b4ffa6dd84e65bd2b32b9acb8",
          "body": "Tweaks for OTP 18.0 support and dependency updates",
          "is_bot": false,
          "headline": "Merge pull request #60 from synlay/feature/otp_18.0_tweaks",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2015-09-11T12:51:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1e0cb05a98a134c19076a35fde4adef50d9efa0",
          "body": "…lds with OTP >= 18\n\nThe rebar option 'require_otp_vsn' was removed and replaced through\n'require_min_otp_vsn' in order to support future OTP releases right\naway.",
          "is_bot": false,
          "headline": "Update dependencies and introduce a compiler directive for proper bui…",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2015-09-09T14:21:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "598540a992f8ecfa08eaf71f98aefdf7fe684405",
          "body": null,
          "is_bot": false,
          "headline": "Update rebar to version v2.6.0",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2015-09-09T14:20:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dcabbbc9d749df5f78f41f1dc0ffbd711f10bf8",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'IvanMartinez-master'",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2015-04-01T14:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46c95a1081370ca2abd69956ffd42b256d46e652",
          "body": "auth_client/3 likely takes the client's credentials, performs a database\nquery, and returns the client's identity. verify_client_scope/3 should\ntake this identity and not the credentials again, so a repeated query\ncan be avoided. This is consistent with how\noauth2:authorize_code_grant/4, oauth2:authorize_code_request/5 and\noauth2_mock_backend:verify_redirection_uri/3 are already implemented.",
          "is_bot": false,
          "headline": "oauth2_backend:verify_redirection_uri/3 should take client's identity",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2015-04-01T14:00:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "624392a3825a7169b504ad463c2b4a55c46a4d43",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'bt-6.0'",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-18T10:59:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8209c2f8185a4d2d1be3d76e3b7e7a28a4c6aa30",
          "body": null,
          "is_bot": false,
          "headline": "Change types",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-18T10:20:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e063c5d2e8496f4c2b8fe1f0a9325e2ae5ecada2",
          "body": null,
          "is_bot": false,
          "headline": "Typo in map-tests",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-14T08:30:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f263cec82614f9ac5f747dada209449a68c0c2e",
          "body": null,
          "is_bot": false,
          "headline": "Add RefreshTokenExpiresIn",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-13T14:01:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe84c85f0f7dba142b4198c96a7819f5e6334481",
          "body": null,
          "is_bot": false,
          "headline": "Typo",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-13T11:19:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "253ee44b30db8accb3dc47e1337b80557f2b33d8",
          "body": null,
          "is_bot": false,
          "headline": "Add config for refresh_token TTL",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-13T11:16:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7a4abc2e3aa86734822404854b47e5e9f502a1a",
          "body": null,
          "is_bot": false,
          "headline": "Pass around the right context",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-13T10:08:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6cfa9e6e4cbedbed2123cf8265f58530bec15c35",
          "body": null,
          "is_bot": false,
          "headline": "Change verify_resowner_scope",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-13T10:04:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bd5a32d749990cb3d0ce417dc5cdce7f7c5573a",
          "body": null,
          "is_bot": false,
          "headline": "Refactor for 0.6",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-12T19:33:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e10ef57a3fdc15c4ed9b6e43c8dc133a26571a5f",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'IvanMartinez-test' into bt-6.0",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-12T10:56:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df1ecf3dcb1b0f0ac57bc3aba0946cd321d5f795",
          "body": "WARNING: Breaks the compatibility with any code using the library\nThe specification of Authorization Code Grant and Implicit Grant\nrequires that unsupported_response_type errors are sent to the redirect\nURI if this is valid (see 4.1.2.1 and 4.2.2.1). In order to facilitate\nthis, authorize_code_reque\n[…]\nt_type parameters have been added to every other\nAPI function for the shake of consistency.\nSee an example of how this API could be used in\n\nhttps://github.com/IvanMartinez/oauth2_webmachine/tree/test",
          "is_bot": false,
          "headline": "Adds response_type/grant_type parameter to API",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-11-12T10:55:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e588d3a503fb9a44ab61f3db6f9eafdfd4564d52",
          "body": null,
          "is_bot": false,
          "headline": "Pass around the right AppCtx",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-20T14:00:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6511dfbf00bdf574d528eca53e15b9ab48ef778a",
          "body": null,
          "is_bot": false,
          "headline": "Roll a new tag",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-20T07:43:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1210f189d06fc87921e043dcf7254d073ff7c69d",
          "body": "Added `authorize_password/7` to aid in implementing `implicit_grant`(4.2)\nTo validate a public client(just validate the redirection_uri) and a\nauthenticate a user and issue a token use:\n\n```erlang\n{ok, {Ctx, Auth}} =\n    oauth2:authorize_password( CLIENT_ID\n                             , CLIENT_SECR\n[…]\n                  , UNAME\n                             , UPWD\n                             , USCOPE\n                             , CONTEXT ),\n{ok, {Ctx, Response}} = oauth2:issue_token(Auth, Ctx),\n```",
          "is_bot": false,
          "headline": "Add functions for implicit grant",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-19T11:50:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50e0b41e748e937a251344eaba30b806c528740d",
          "body": null,
          "is_bot": false,
          "headline": "Prepare 0.5.1",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-18T11:18:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c70be75e4500d0f2d7af6abfd23a9388bd08ffe8",
          "body": "…venience_function\n\nIntroduce new convenience function oauth2_response:to_map/1",
          "is_bot": false,
          "headline": "Merge pull request #42 from synlay/feature/oauth2_response_to_map_con…",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-18T11:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e1807421ac600a39cfe950ed70f9cc429aa52e6",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'IvanMartinez-api_docs'",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-11T08:56:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddbecfeee4788cbac6d52a1b0fd35796cf0f2e96",
          "body": null,
          "is_bot": false,
          "headline": "Merge of IvanMartinez work, PR #47",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-11T08:56:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0173355033208cbe6855183a3e831f9fbcb39ef",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'IvanMartinez-only_confidential_client_refresh_token2'",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-04T09:37:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f666d5f349535797d6403adea2638aebd1668d9a",
          "body": null,
          "is_bot": false,
          "headline": "Fixes #44 by not issuing refresh tokens to public clients.",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-08-04T09:36:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bc62052f78940b35ca6c09340f57cae19c2a2b8",
          "body": "…Er test",
          "is_bot": false,
          "headline": "Refactor oauth2_response_tests:to_map_test/0 to a property-based Prop…",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-06-11T10:56:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "767ea7b38d5eea6567d3b98513658358d904efba",
          "body": "…_map/1",
          "is_bot": false,
          "headline": "Introduce new Erlang/OTP 17.0 convenience function oauth2_response:to…",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-06-11T10:36:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b25a4410801f92c42bb74619424552812858b90",
          "body": "Fix oauth2_response:to_proplist/1 for correct scoping according to RFC6749 section 3.3",
          "is_bot": false,
          "headline": "Merge pull request #41 from synlay/feature/scope_to_proplist_fix",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-06-11T08:06:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef1b7b244675a5f4f9ca6f30d0e3a1f9a944172f",
          "body": null,
          "is_bot": false,
          "headline": "Tweak binary comprehension for oauth2_response:to_proplist/1",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-06-03T07:49:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8602e2bc4dbc31c89d8f36431fd4958903a3b3a1",
          "body": "…C6749 section 3.3\n\nScopes should be expressed as a list of space-delimited, case-sensitive strings.\nAlso refactored oauth2_response_tests:to_proplist_test/0 to a property-based PropEr test.",
          "is_bot": false,
          "headline": "Fix oauth2_response:to_proplist/1 for correct scoping according to RF…",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-05-30T11:12:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6f519bcff2e136dfa3ede0d302d32daf6d7b466",
          "body": "…in_authorize_password\n\nAdd additional oauth2:authorize_password/6 with previous client authentication and fix for #38",
          "is_bot": false,
          "headline": "Merge pull request #39 from synlay/feature/client_authentication_with…",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-05-07T06:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2bac4e7eb96321c77568dba4ff61d38e9052729",
          "body": "Add Erlang/OTP 17.0 to the Travis CI test matrix and update meck dependency",
          "is_bot": false,
          "headline": "Merge pull request #40 from synlay/feature/otp_17.0_dependency_update",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-05-06T12:00:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57b8d4d4170e58d6eb77e08d4c6a7a7fa6e7ac93",
          "body": "…ndency\n\nMissing Erlang/OTP R16B01 - R16B03-01 are also added to the test matrix.",
          "is_bot": false,
          "headline": "Add Erlang/OTP 17.0 to the Travis CI test matrix and update meck depe…",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-05-06T08:51:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "511fc9c270a2b8b6286eded8fa3a3e56f3b59816",
          "body": "…ntication and fix for #38\n\nWARNING: Breaks the compatibility with existing backend implementations\n\nThe client can now be authenticated before the resource owner's\ncredentials. See RFC6749 / Section 4.3.2 for more details.\nIn addition to AppCtx and Scope, oauth2_backend:verify_resowner_scope/3\nnow returns the ClientIdentity so that oauth2:authorize_resource_owner/3\ncan set the client for the #authorization{} record and\noauth2:refresh_access_token/5 can be successfully executed.",
          "is_bot": false,
          "headline": "Add additional oauth2:authorize_password/6 with previous client authe…",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-05-05T16:42:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de40018686a6e9289e8f7d20efc44379cf437e8a",
          "body": "Export types auth/0 and priv_set/0 for a better analyzing of backend implementations",
          "is_bot": false,
          "headline": "Merge pull request #36 from synlay/feature/dialyzer_tweaks",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-01-27T16:30:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff59c3389063ad47ff0b8928a1d4724bacd73b98",
          "body": "Allow authorization with a previously authenticated resource owner",
          "is_bot": false,
          "headline": "Merge pull request #35 from danielwhite/authorize-resource-owner",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-01-23T14:34:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f97f22b69c9f2bd3ae20636e75adbbb586dc79b",
          "body": "This adds a new function `authorize_resource_owner/3` for establishing\nauthorization where the resource owner has already been authenticated.\nUseful in the case where the Authentication Server is separate to the\nAuthorization Server.",
          "is_bot": false,
          "headline": "Allow authorization with a previously authenticated resource owner",
          "author_name": "Daniel White",
          "author_login": "danielwhite",
          "committed_at": "2014-01-23T09:39:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cdf4d29d5db79af9da1aa98913722923f032959",
          "body": "implementations",
          "is_bot": false,
          "headline": "Export types auth/0 and priv_set/0 for a better analyzing of backend",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-01-22T14:47:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b9bf3219deeee8552d0edbe5ac5563810dee078",
          "body": null,
          "is_bot": false,
          "headline": "Bump version 0.5.0",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-01-20T23:18:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73a0313394fa2283e9a72cbe560008d686bdecf4",
          "body": "Fix binary encoded expiration values",
          "is_bot": false,
          "headline": "Merge pull request #34 from danielwhite/fix-binary-expiration-values",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-01-20T23:11:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b695236e04f6adc47274304e3f6d4551f687663",
          "body": "This number was being encoded as a binary, and later compared to an\ninteger.  Erlang term comparison rules mean that the time of\nexpiration was always greater than the current time.\n\nThe 'expiry_time' parameter in a grant context is now an integer\nrather than a binary.  This may be a breaking change for anyone\nrelying on this value.\n\nA side issue here was that the mocks in the TTL tests were returning\nbad results that would trigger the expected results.",
          "is_bot": false,
          "headline": "Fix never expiring access tokens and codes",
          "author_name": "Daniel White",
          "author_login": "danielwhite",
          "committed_at": "2014-01-17T16:19:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e644f87f8d2c8dc8d40a5e1474483d6024b55a7",
          "body": "…plist\n\nThis was intended as a convenience function for encoding the response\nto JSON.  The specification indicates that the parameter should be a\nnumber, and not a string.  Translating it to binary in to_proplist/1\nmakes it more difficult for the encoder.",
          "is_bot": false,
          "headline": "Preserve expires_in as an integer when converting a response to a pro…",
          "author_name": "Daniel White",
          "author_login": "danielwhite",
          "committed_at": "2014-01-17T16:19:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7052b70224e06bd4a2fd1665de7bdf69c8e4f422",
          "body": "Dialyzer tweaks for the new usage of the AppCtx",
          "is_bot": false,
          "headline": "Merge pull request #32 from synlay/feature/appctx_dialyzer_tweaks",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2014-01-08T15:20:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8987f1eaf2f1ac1c7bf8d43cdfb66b9ad91db4f2",
          "body": null,
          "is_bot": false,
          "headline": "Dialyzer tweaks for the new usage of the AppCtx",
          "author_name": "David Robakowski",
          "author_login": "drobakowski",
          "committed_at": "2014-01-08T12:12:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8f7c5b3ed45f340bedc4755847ac2631eb58e7c",
          "body": "Try to harmonize the use of AppCtx in which all functions require a\ncontext that get's passed to the underlying backend functions. They in\nreturn respond with a updated context that get's handed back to the\ncaller.",
          "is_bot": false,
          "headline": "Changes to how AppCtx is used",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2013-12-06T14:28:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28dea15a06fc373627af143f1f2182d66ec1b6c3",
          "body": null,
          "is_bot": false,
          "headline": "Change now() to os:timestamp().",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2013-11-26T09:50:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae95595d5ef7f77b05ea68e4b6a16ba0c8b3422c",
          "body": null,
          "is_bot": false,
          "headline": "add tuple case to oauth_response, roll 0.4.1",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2013-08-21T10:21:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b64f19eef0c360408885cc6850f7aa88a860fc1",
          "body": null,
          "is_bot": false,
          "headline": "Update deps and prepare 0.4.0",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2013-08-19T19:53:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f1fef240e62ddecfe954c98390f1e518a89c15e",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'IvanMartinez-context'",
          "author_name": "Bip Thelin",
          "author_login": "bipthelin",
          "committed_at": "2013-08-19T19:26:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 12,
      "commits_last_year": 20,
      "latest_release_at": "2026-06-29T13:50:26Z",
      "latest_release_tag": "v1.0.3",
      "releases_from_tags": false,
      "days_since_last_push": 22,
      "active_weeks_last_year": 14,
      "days_since_latest_release": 22,
      "mean_days_between_releases": 35.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "oauth2",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "hex",
          "matches_repo": false,
          "registry_url": "https://hex.pm/packages/oauth2",
          "is_deprecated": false,
          "latest_version": "2.1.1",
          "repository_url": "https://github.com/scrogson/oauth2",
          "versions_count": 28,
          "total_downloads": 14166729,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 220813,
          "first_published_at": "2014-12-17T07:22:47Z",
          "latest_published_at": "2026-06-03T17:52:17.432766Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 48
        }
      ]
    },
    "popularity": {
      "forks": 69,
      "stars": 221,
      "watchers": 21,
      "fork_history": {
        "days": [
          {
            "date": "2012-03-22",
            "count": 1
          },
          {
            "date": "2012-03-30",
            "count": 1
          },
          {
            "date": "2012-05-13",
            "count": 1
          },
          {
            "date": "2012-05-22",
            "count": 1
          },
          {
            "date": "2012-11-26",
            "count": 1
          },
          {
            "date": "2012-12-16",
            "count": 1
          },
          {
            "date": "2013-01-24",
            "count": 1
          },
          {
            "date": "2013-03-19",
            "count": 1
          },
          {
            "date": "2013-03-20",
            "count": 1
          },
          {
            "date": "2013-04-11",
            "count": 1
          },
          {
            "date": "2013-11-22",
            "count": 1
          },
          {
            "date": "2014-01-07",
            "count": 1
          },
          {
            "date": "2014-01-16",
            "count": 1
          },
          {
            "date": "2014-02-17",
            "count": 1
          },
          {
            "date": "2014-04-12",
            "count": 1
          },
          {
            "date": "2014-04-23",
            "count": 1
          },
          {
            "date": "2014-04-25",
            "count": 1
          },
          {
            "date": "2014-05-05",
            "count": 1
          },
          {
            "date": "2014-05-18",
            "count": 1
          },
          {
            "date": "2014-09-27",
            "count": 1
          },
          {
            "date": "2014-10-01",
            "count": 1
          },
          {
            "date": "2014-12-28",
            "count": 1
          },
          {
            "date": "2014-12-30",
            "count": 1
          },
          {
            "date": "2015-01-15",
            "count": 1
          },
          {
            "date": "2015-04-14",
            "count": 1
          },
          {
            "date": "2015-04-30",
            "count": 1
          },
          {
            "date": "2015-05-29",
            "count": 1
          },
          {
            "date": "2015-06-25",
            "count": 1
          },
          {
            "date": "2015-07-27",
            "count": 1
          },
          {
            "date": "2015-10-19",
            "count": 1
          },
          {
            "date": "2015-10-26",
            "count": 1
          },
          {
            "date": "2015-11-24",
            "count": 1
          },
          {
            "date": "2016-01-09",
            "count": 1
          },
          {
            "date": "2016-01-23",
            "count": 1
          },
          {
            "date": "2016-02-14",
            "count": 1
          },
          {
            "date": "2016-05-12",
            "count": 1
          },
          {
            "date": "2016-08-16",
            "count": 2
          },
          {
            "date": "2016-08-22",
            "count": 1
          },
          {
            "date": "2016-12-01",
            "count": 1
          },
          {
            "date": "2016-12-02",
            "count": 1
          },
          {
            "date": "2016-12-07",
            "count": 1
          },
          {
            "date": "2016-12-23",
            "count": 1
          },
          {
            "date": "2017-05-19",
            "count": 1
          },
          {
            "date": "2017-06-04",
            "count": 1
          },
          {
            "date": "2017-07-05",
            "count": 1
          },
          {
            "date": "2017-07-19",
            "count": 1
          },
          {
            "date": "2017-09-19",
            "count": 1
          },
          {
            "date": "2018-05-08",
            "count": 1
          },
          {
            "date": "2018-06-26",
            "count": 1
          },
          {
            "date": "2018-07-05",
            "count": 1
          },
          {
            "date": "2018-12-19",
            "count": 1
          },
          {
            "date": "2019-01-04",
            "count": 1
          },
          {
            "date": "2020-08-19",
            "count": 1
          },
          {
            "date": "2021-08-23",
            "count": 1
          },
          {
            "date": "2022-10-11",
            "count": 1
          },
          {
            "date": "2023-04-28",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 57,
        "total_forks": 69
      },
      "star_history": {
        "days": [
          {
            "date": "2012-02-29",
            "count": 28
          },
          {
            "date": "2013-02-18",
            "count": 1
          },
          {
            "date": "2013-03-15",
            "count": 1
          },
          {
            "date": "2013-04-23",
            "count": 1
          },
          {
            "date": "2013-05-04",
            "count": 1
          },
          {
            "date": "2013-05-29",
            "count": 1
          },
          {
            "date": "2013-06-07",
            "count": 1
          },
          {
            "date": "2013-08-06",
            "count": 1
          },
          {
            "date": "2013-08-14",
            "count": 1
          },
          {
            "date": "2013-08-30",
            "count": 1
          },
          {
            "date": "2013-10-01",
            "count": 1
          },
          {
            "date": "2013-10-08",
            "count": 1
          },
          {
            "date": "2013-11-17",
            "count": 1
          },
          {
            "date": "2013-11-18",
            "count": 1
          },
          {
            "date": "2013-11-30",
            "count": 1
          },
          {
            "date": "2013-12-01",
            "count": 1
          },
          {
            "date": "2014-01-09",
            "count": 1
          },
          {
            "date": "2014-01-20",
            "count": 1
          },
          {
            "date": "2014-02-11",
            "count": 1
          },
          {
            "date": "2014-03-20",
            "count": 1
          },
          {
            "date": "2014-03-27",
            "count": 1
          },
          {
            "date": "2014-03-31",
            "count": 1
          },
          {
            "date": "2014-04-23",
            "count": 1
          },
          {
            "date": "2014-04-28",
            "count": 2
          },
          {
            "date": "2014-05-07",
            "count": 1
          },
          {
            "date": "2014-05-29",
            "count": 1
          },
          {
            "date": "2014-06-04",
            "count": 1
          },
          {
            "date": "2014-06-12",
            "count": 1
          },
          {
            "date": "2014-06-15",
            "count": 1
          },
          {
            "date": "2014-06-18",
            "count": 1
          },
          {
            "date": "2014-06-23",
            "count": 1
          },
          {
            "date": "2014-06-29",
            "count": 1
          },
          {
            "date": "2014-07-26",
            "count": 1
          },
          {
            "date": "2014-07-29",
            "count": 1
          },
          {
            "date": "2014-08-03",
            "count": 1
          },
          {
            "date": "2014-09-06",
            "count": 1
          },
          {
            "date": "2014-09-24",
            "count": 1
          },
          {
            "date": "2014-09-25",
            "count": 1
          },
          {
            "date": "2014-10-01",
            "count": 2
          },
          {
            "date": "2014-10-02",
            "count": 1
          },
          {
            "date": "2014-10-10",
            "count": 1
          },
          {
            "date": "2014-10-19",
            "count": 1
          },
          {
            "date": "2014-10-23",
            "count": 1
          },
          {
            "date": "2014-10-24",
            "count": 1
          },
          {
            "date": "2014-10-30",
            "count": 1
          },
          {
            "date": "2014-11-01",
            "count": 1
          },
          {
            "date": "2014-11-06",
            "count": 2
          },
          {
            "date": "2014-11-17",
            "count": 1
          },
          {
            "date": "2014-11-20",
            "count": 1
          },
          {
            "date": "2014-11-25",
            "count": 1
          },
          {
            "date": "2014-12-05",
            "count": 1
          },
          {
            "date": "2014-12-09",
            "count": 1
          },
          {
            "date": "2014-12-19",
            "count": 1
          },
          {
            "date": "2014-12-20",
            "count": 1
          },
          {
            "date": "2014-12-25",
            "count": 1
          },
          {
            "date": "2015-01-03",
            "count": 1
          },
          {
            "date": "2015-01-05",
            "count": 1
          },
          {
            "date": "2015-01-12",
            "count": 1
          },
          {
            "date": "2015-01-14",
            "count": 1
          },
          {
            "date": "2015-01-29",
            "count": 1
          },
          {
            "date": "2015-01-30",
            "count": 1
          },
          {
            "date": "2015-02-05",
            "count": 1
          },
          {
            "date": "2015-02-22",
            "count": 1
          },
          {
            "date": "2015-02-27",
            "count": 1
          },
          {
            "date": "2015-03-11",
            "count": 2
          },
          {
            "date": "2015-03-21",
            "count": 1
          },
          {
            "date": "2015-04-08",
            "count": 1
          },
          {
            "date": "2015-04-10",
            "count": 1
          },
          {
            "date": "2015-04-14",
            "count": 3
          },
          {
            "date": "2015-05-04",
            "count": 1
          },
          {
            "date": "2015-05-06",
            "count": 1
          },
          {
            "date": "2015-05-10",
            "count": 1
          },
          {
            "date": "2015-05-21",
            "count": 1
          },
          {
            "date": "2015-06-07",
            "count": 1
          },
          {
            "date": "2015-06-15",
            "count": 1
          },
          {
            "date": "2015-07-12",
            "count": 1
          },
          {
            "date": "2015-07-15",
            "count": 1
          },
          {
            "date": "2015-07-27",
            "count": 1
          },
          {
            "date": "2015-08-05",
            "count": 1
          },
          {
            "date": "2015-08-06",
            "count": 1
          },
          {
            "date": "2015-08-19",
            "count": 1
          },
          {
            "date": "2015-09-12",
            "count": 1
          },
          {
            "date": "2015-09-15",
            "count": 1
          },
          {
            "date": "2015-09-23",
            "count": 1
          },
          {
            "date": "2015-10-06",
            "count": 1
          },
          {
            "date": "2015-10-07",
            "count": 1
          },
          {
            "date": "2015-10-26",
            "count": 1
          },
          {
            "date": "2015-11-14",
            "count": 1
          },
          {
            "date": "2015-11-25",
            "count": 1
          },
          {
            "date": "2015-12-04",
            "count": 1
          },
          {
            "date": "2015-12-15",
            "count": 1
          },
          {
            "date": "2015-12-22",
            "count": 1
          },
          {
            "date": "2015-12-25",
            "count": 1
          },
          {
            "date": "2015-12-28",
            "count": 1
          },
          {
            "date": "2016-01-07",
            "count": 2
          },
          {
            "date": "2016-01-09",
            "count": 1
          },
          {
            "date": "2016-01-25",
            "count": 2
          },
          {
            "date": "2016-02-04",
            "count": 1
          },
          {
            "date": "2016-02-05",
            "count": 1
          },
          {
            "date": "2016-02-22",
            "count": 2
          },
          {
            "date": "2016-03-15",
            "count": 1
          },
          {
            "date": "2016-04-25",
            "count": 1
          },
          {
            "date": "2016-05-19",
            "count": 2
          },
          {
            "date": "2016-05-22",
            "count": 1
          },
          {
            "date": "2016-05-23",
            "count": 2
          },
          {
            "date": "2016-06-10",
            "count": 1
          },
          {
            "date": "2016-06-17",
            "count": 1
          },
          {
            "date": "2016-07-08",
            "count": 1
          },
          {
            "date": "2016-07-20",
            "count": 1
          },
          {
            "date": "2016-08-17",
            "count": 1
          },
          {
            "date": "2016-08-26",
            "count": 1
          },
          {
            "date": "2016-08-27",
            "count": 1
          },
          {
            "date": "2016-09-13",
            "count": 1
          },
          {
            "date": "2016-09-26",
            "count": 1
          },
          {
            "date": "2016-10-30",
            "count": 1
          },
          {
            "date": "2016-11-23",
            "count": 1
          },
          {
            "date": "2016-12-23",
            "count": 1
          },
          {
            "date": "2017-01-08",
            "count": 1
          },
          {
            "date": "2017-01-10",
            "count": 1
          },
          {
            "date": "2017-01-14",
            "count": 1
          },
          {
            "date": "2017-01-16",
            "count": 1
          },
          {
            "date": "2017-01-25",
            "count": 1
          },
          {
            "date": "2017-02-17",
            "count": 1
          },
          {
            "date": "2017-03-10",
            "count": 1
          },
          {
            "date": "2017-05-26",
            "count": 1
          },
          {
            "date": "2017-06-02",
            "count": 1
          },
          {
            "date": "2017-06-05",
            "count": 1
          },
          {
            "date": "2017-06-22",
            "count": 1
          },
          {
            "date": "2017-07-02",
            "count": 1
          },
          {
            "date": "2017-08-11",
            "count": 1
          },
          {
            "date": "2017-08-28",
            "count": 1
          },
          {
            "date": "2017-09-15",
            "count": 1
          },
          {
            "date": "2017-09-18",
            "count": 1
          },
          {
            "date": "2017-10-13",
            "count": 1
          },
          {
            "date": "2017-11-06",
            "count": 1
          },
          {
            "date": "2017-11-15",
            "count": 1
          },
          {
            "date": "2017-11-20",
            "count": 1
          },
          {
            "date": "2017-11-22",
            "count": 1
          },
          {
            "date": "2018-01-19",
            "count": 1
          },
          {
            "date": "2018-04-02",
            "count": 1
          },
          {
            "date": "2018-04-11",
            "count": 1
          },
          {
            "date": "2018-06-14",
            "count": 1
          },
          {
            "date": "2018-07-05",
            "count": 1
          },
          {
            "date": "2018-08-09",
            "count": 1
          },
          {
            "date": "2018-09-11",
            "count": 1
          },
          {
            "date": "2018-10-02",
            "count": 1
          },
          {
            "date": "2018-10-12",
            "count": 1
          },
          {
            "date": "2018-10-22",
            "count": 1
          },
          {
            "date": "2019-02-05",
            "count": 1
          },
          {
            "date": "2019-02-07",
            "count": 1
          },
          {
            "date": "2019-02-12",
            "count": 1
          },
          {
            "date": "2019-02-16",
            "count": 1
          },
          {
            "date": "2019-03-06",
            "count": 1
          },
          {
            "date": "2019-03-22",
            "count": 1
          },
          {
            "date": "2019-04-21",
            "count": 1
          },
          {
            "date": "2019-04-30",
            "count": 1
          },
          {
            "date": "2019-09-13",
            "count": 1
          },
          {
            "date": "2019-11-14",
            "count": 1
          },
          {
            "date": "2019-12-11",
            "count": 1
          },
          {
            "date": "2020-01-09",
            "count": 1
          },
          {
            "date": "2020-04-13",
            "count": 1
          },
          {
            "date": "2020-08-08",
            "count": 1
          },
          {
            "date": "2020-08-19",
            "count": 1
          },
          {
            "date": "2021-03-09",
            "count": 1
          },
          {
            "date": "2021-05-27",
            "count": 1
          },
          {
            "date": "2021-12-05",
            "count": 1
          },
          {
            "date": "2022-01-22",
            "count": 1
          },
          {
            "date": "2022-05-13",
            "count": 2
          },
          {
            "date": "2022-06-08",
            "count": 1
          },
          {
            "date": "2022-09-13",
            "count": 1
          },
          {
            "date": "2022-10-23",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-06-16",
            "count": 1
          },
          {
            "date": "2023-11-13",
            "count": 1
          },
          {
            "date": "2023-11-21",
            "count": 1
          },
          {
            "date": "2024-01-05",
            "count": 1
          },
          {
            "date": "2024-04-02",
            "count": 1
          },
          {
            "date": "2024-04-19",
            "count": 1
          },
          {
            "date": "2024-12-07",
            "count": 1
          },
          {
            "date": "2025-10-16",
            "count": 1
          },
          {
            "date": "2025-11-25",
            "count": 1
          },
          {
            "date": "2026-03-17",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 221,
        "total_stars": 221
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": null,
      "source_files_sampled": 0,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": "No resolved dependencies to assess",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [],
        "collected": true,
        "truncated": false,
        "total_count": 0,
        "direct_count": 0,
        "indirect_count": 0
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 63,
        "open_issues": 1,
        "closed_ratio": 0.966,
        "closed_issues": 28,
        "closed_unmerged_prs": 21
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "bipthelin",
          "commits": 104,
          "avatar_url": "https://avatars.githubusercontent.com/u/1185571?v=4"
        },
        {
          "type": "User",
          "login": "kivra-pauoli",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/142223309?v=4"
        },
        {
          "type": "User",
          "login": "drobakowski",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/81381?v=4"
        },
        {
          "type": "User",
          "login": "plux-kivra",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/48825574?v=4"
        },
        {
          "type": "User",
          "login": "kampiliira",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/48207660?v=4"
        },
        {
          "type": "User",
          "login": "danielwhite",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/481511?v=4"
        },
        {
          "type": "User",
          "login": "kivraDawi",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/92713372?v=4"
        },
        {
          "type": "User",
          "login": "Licenser",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/119093?v=4"
        },
        {
          "type": "User",
          "login": "plux",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/56249?v=4"
        },
        {
          "type": "User",
          "login": "mtornwall",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/1321973?v=4"
        }
      ],
      "contributors_sampled": 12,
      "top_contributor_share": 0.689
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 1,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "23 out of 30 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 2,
            "reason": "Found 3/12 approved changesets -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 5,
            "reason": "7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 6,
            "reason": "dependency not pinned by hash detected -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 7,
            "reason": "SAST tool is not run on all commits -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "06b4b4c90c6b21d9c2054d8d5f74d7d0dcc5083b",
        "ran_at": "2026-07-21T19:59:25Z",
        "aggregate_score": 6.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kivra/oauth2",
    "host": "github.com",
    "name": "oauth2",
    "owner": "kivra"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 62,
        "vitality": 73,
        "community": 55,
        "governance": 60,
        "engineering": 57
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 73,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "commits_last_year": 20,
              "human_commit_share": 0.82,
              "days_since_last_push": 22,
              "active_weeks_last_year": 14
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 22 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "14/52 weeks with commits",
                "points": 9.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 14
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "20 commits in the last year",
                "points": 11.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5",
                "points": 5,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 12,
              "latest_release_tag": "v1.0.3",
              "releases_from_tags": false,
              "days_since_latest_release": 22,
              "mean_days_between_releases": 35.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "12 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 22 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~35.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 35.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 22,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 22 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 22
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 55,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "forks": 69,
              "stars": 221,
              "watchers": 21,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "221 stars",
                "points": 38,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 221
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "69 forks",
                "points": 15.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 69
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "21 watchers",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 12,
              "top_contributor_share": 0.689
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 69% of commits",
                "points": 7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 69
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "12 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "merged_prs": 63,
              "open_issues": 1,
              "closed_issues": 28,
              "issue_closed_ratio": 0.966,
              "closed_unmerged_prs": 21
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "97% of issues closed",
                "points": 45.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "63/84 decided PRs merged",
                "points": 28.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 63,
                      "decided": 84
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 3/12 approved changesets -- score normalized to 2",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "followers": 33,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "kivra",
              "public_repos": 63,
              "account_age_days": 5304
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "33 followers of kivra",
                "points": 11,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 33,
                      "login": "kivra"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "63 public repos, account ~14 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 63
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 57,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "23 out of 30 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [
                "kivra-platform-engineering"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "1 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "23 out of 30 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 3/12 approved changesets -- score normalized to 2",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "7 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 5",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 13
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 37,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 29,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.549,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "45 of 82 human commits state their intent (structured subject or explanatory body)",
                "points": 29.3,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 45,
                      "sampled": 82
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.18
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "18 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 18,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "critical",
            "name": "Code legibility for models",
            "note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "manageable_file_sizes"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "primary_language": "Erlang",
              "largest_source_bytes": null,
              "source_files_sampled": 0,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Erlang without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Erlang"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "no source files detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_source_files",
                    "params": {}
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "hex package 'oauth2' points at a different repository (https://github.com/scrogson/oauth2); excluded from ecosystem scoring"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T19:59:46.659867Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kivra/oauth2.svg",
  "full_name": "kivra/oauth2",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.23.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsHex.