Public record
Software health reportschema 0.23.0 · metrics 1.13.0 · 2026-07-21 20:37 UTC

linux-credentials / libwebauthn

FIDO2 (WebAuthn) and FIDO U2F platform library for Linux written in Rust

RustLGPL-2.1★ 567 stars⑂ 25 forkssince Apr 2020View on GitHub ↗

linux-credentials/libwebauthn holds a health index of 69 out of 100, placing it in the Moderate band. It scores highest on Vitality (87/100) and lowest on AI Readiness (55/100). It was last updated 7 days ago. A single contributor accounts for most of its recent work.

69
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

69
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

226 followers5 public repossince Feb 2025

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
crates.iolibwebauthn0.10.02,324117 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

87Excellent · 22% of overall
How it's scored
36/36Push recency — last push 7 days ago
15.2/36Commit cadence — 22/52 weeks with commits
18/18Commit volume — 142 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year142
human_commit_share1
days_since_last_push7
active_weeks_last_year22

Release discipline

100Excellent
How it's scored
27/27Ships releases — 10 releases published
36/36Release recency — latest release 7 days ago
27/27Release cadence — a release every ~39.1 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count10
latest_release_taglibwebauthn-v0.10.0
releases_from_tagsno
days_since_latest_release7
mean_days_between_releases39.1
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

57Moderate · 18% of overall
How it's scored
44.7/60Stars — 567 stars
11.5/25Forks — 25 forks
7.5/15Watchers — 23 watchers
Inputs used
forks25
stars567
watchers23
growth_stateorganic
growth_factor_pct100
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (LGPL-2.1)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno
How it's scored
44.9/80Monthly downloads — 2,324 downloads/month across crates
0/20Registry dependents — not reported by this ecosystem
Inputs used
packageslibwebauthn
dependents
ecosystemscrates
total_downloads8,290
monthly_downloads2,324
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

63Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
4/22.5Commit distribution — top contributor authored 82% of commits
12.2/13.5Contributor breadth — 9 contributors
10/10OpenSSF Scorecard: Contributors — project has 12 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled9
top_contributor_share0.824
How it's scored
38/46.8Issue resolution — 81% of issues closed
36.6/38.3PR acceptance — 194/203 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 2/30 approved changesets -- score normalized to 0
Inputs used
merged_prs194
open_issues18
closed_issues78
issue_closed_ratio0.812
closed_unmerged_prs9
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
16.9/25Owner reach — 226 followers of linux-credentials
8.6/25Track record — 5 public repos, account ~1 yr old
Inputs used
followers226
owner_typeOrganization
is_verified
owner_loginlinux-credentials
public_repos5
account_age_days527
How it's scored
25/25Published & resolvable — 1 package(s) on crates
35/35Publish recency — latest publish 7 days ago
20/20Version history — 11 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packageslibwebauthn
ecosystemscrates
any_deprecatedno
min_days_since_publish7

Engineering Quality

Are baseline engineering and documentation practices in place?

65Moderate · 20% of overall
How it's scored
24/24CI workflows — 3 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

60Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 5 topics
10/10Wiki
Inputs used
topicsfido2, webauthn, xdg-portal, linux, u2f
has_wikiyes
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

73Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 2/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 12 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
4.5/5SAST — SAST tool is not run on all commits -- score normalized to 9
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
5.2/7.5Vulnerabilities — 3 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.6
Excluded from scoring (no data or not applicable): branch_protection, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories3
affected_packages3
assessed_packages478
unassessed_packages71
affected_by_severityhigh 1, unknown 2
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 478 resolved dependencies against OSV. 71 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

55Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — Cargo.toml, libwebauthn-tests/Cargo.toml, libwebauthn/Cargo.toml (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Rust (statically typed)
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesCargo.lock
has_dockerfileno
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0
toolchain_manifestsCargo.toml, libwebauthn-tests/Cargo.toml, libwebauthn/Cargo.toml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Rust (statically typed)
53.5/55Manageable file sizes — 4/142 source files over 60KB
Inputs used
primary_languageRust
largest_source_bytes102,029
source_files_sampled142
oversized_source_files4
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

567GitHub stars
9contributors
142commits, last 12 months
7days since last push
10releases
1bus factor
18open issues
crates.iopackage ecosystems

Data collection warnings

  • Could not fetch crates package 'libwebauthn-tests' from its registry
  • deps.dev does not index crates:libwebauthn@0.10.0; advisories assessed against the repository dependency graph instead

More detail

Star and fork history 567 ★ / 25 ⇿
567Stars
25Forks
10Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0100200300400500600567251452020-042023-052026-07
Major 0Minor 0Patch 0

Each point covers 6 days.

OpenSSF Scorecard 6.6 / 10
6.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-21 20:37 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 2/30 approved changesets -- score normalized to 0
10Contributorsproject has 12 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
9SASTSAST tool is not run on all commits -- score normalized to 9
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
7Vulnerabilities3 existing vulnerabilities detected
Direct dependencies 74
RegistryPackageVersion constraintManifest
crates.iolibwebauthnlibwebauthn-tests/Cargo.toml
crates.iocosey0.3.2libwebauthn-tests/Cargo.toml
crates.ioctaphid0.3.1libwebauthn-tests/Cargo.toml
crates.ioctaphid-dispatch0.3libwebauthn-tests/Cargo.toml
crates.iodelog0.1libwebauthn-tests/Cargo.toml
crates.iofido-authenticatorlibwebauthn-tests/Cargo.toml
crates.iointerchange0.3.0libwebauthn-tests/Cargo.toml
crates.iolittlefs20.6.0libwebauthn-tests/Cargo.toml
crates.ionum_enum0.7.1libwebauthn-tests/Cargo.toml
crates.iorand0.8.5libwebauthn-tests/Cargo.toml
crates.iotracing0.1.29libwebauthn-tests/Cargo.toml
crates.iotrussed0.1libwebauthn-tests/Cargo.toml
crates.iotrussed-staging0.3.0libwebauthn-tests/Cargo.toml
crates.iobase64-url3.0.0libwebauthn/Cargo.toml
crates.iodbus0.9.5libwebauthn/Cargo.toml
crates.iotracing0.1.29libwebauthn/Cargo.toml
crates.ioidna1.0.3libwebauthn/Cargo.toml
crates.ioicu_normalizer2libwebauthn/Cargo.toml
crates.iopublicsuffix2.3libwebauthn/Cargo.toml
crates.iourl2.5libwebauthn/Cargo.toml
crates.iohttp1libwebauthn/Cargo.toml
crates.iomaplit1.0.2libwebauthn/Cargo.toml
crates.iosha20.10.2libwebauthn/Cargo.toml
crates.iouuid1.5.0libwebauthn/Cargo.toml
crates.ioasync-trait0.1.36libwebauthn/Cargo.toml
crates.iofutures0.3.5libwebauthn/Cargo.toml
crates.iotokio1.45libwebauthn/Cargo.toml
crates.ioserde1.0.110libwebauthn/Cargo.toml
crates.ioserde_cbor_20.13libwebauthn/Cargo.toml
crates.ioserde-indexed0.2.0libwebauthn/Cargo.toml
crates.ioserde_derive1.0.123libwebauthn/Cargo.toml
crates.ioserde_repr0.1.6libwebauthn/Cargo.toml
crates.ioserde_bytes0.11.5libwebauthn/Cargo.toml
crates.ionum-traits0.2libwebauthn/Cargo.toml
crates.ionum-derive0.4.1libwebauthn/Cargo.toml
crates.iobyteorder1.3.4libwebauthn/Cargo.toml
crates.ionum_enum0.7.1libwebauthn/Cargo.toml
crates.iox509-parser0.17.0libwebauthn/Cargo.toml
crates.iotime0.3.35libwebauthn/Cargo.toml
crates.iocurve25519-dalek4.1.3libwebauthn/Cargo.toml
crates.iohex0.4.3libwebauthn/Cargo.toml
crates.iomockall0.13.1libwebauthn/Cargo.toml
crates.iohidapi2.4.1libwebauthn/Cargo.toml
crates.iobitflags2.4.1libwebauthn/Cargo.toml
crates.iorand0.8.5libwebauthn/Cargo.toml
crates.iop2560.13.2libwebauthn/Cargo.toml
crates.ioheapless0.7libwebauthn/Cargo.toml
crates.iocosey0.3.2libwebauthn/Cargo.toml
crates.iospki0.7libwebauthn/Cargo.toml
crates.ioder0.7libwebauthn/Cargo.toml
crates.ioaes0.8.2libwebauthn/Cargo.toml
crates.ioaes-gcm0.10libwebauthn/Cargo.toml
crates.ioflate21.0libwebauthn/Cargo.toml
crates.iohmac0.12.1libwebauthn/Cargo.toml
crates.iocbc0.1libwebauthn/Cargo.toml
crates.iohkdf0.12libwebauthn/Cargo.toml
crates.iozeroize1.8libwebauthn/Cargo.toml
crates.iotext_io0.1libwebauthn/Cargo.toml
crates.iotungstenite0.26.2libwebauthn/Cargo.toml
crates.iotokio-tungstenite0.26libwebauthn/Cargo.toml
crates.iorustls0.23.27libwebauthn/Cargo.toml
crates.iotokio-stream0.1libwebauthn/Cargo.toml
crates.iosnow0.10libwebauthn/Cargo.toml
crates.ioctap-types0.4.0libwebauthn/Cargo.toml
crates.iobtleplug0.11.7libwebauthn/Cargo.toml
crates.iobluer0.17libwebauthn/Cargo.toml
crates.iothiserror2.0.12libwebauthn/Cargo.toml
crates.ioserde_json1.0.141libwebauthn/Cargo.toml
crates.ioapdu-core0.4.0libwebauthn/Cargo.toml
crates.ioapdu0.4.0libwebauthn/Cargo.toml
crates.iopcsc2.9.0libwebauthn/Cargo.toml
crates.ionfc1=0.6.0libwebauthn/Cargo.toml
crates.ionfc1-sys0.3.9libwebauthn/Cargo.toml
crates.ioreqwest0.12libwebauthn/Cargo.toml
All dependencies 549

Full resolved dependency set from the GitHub dependency graph: 144 direct and 405 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
crates.ioaesdirect
crates.ioaes0.8.4direct
crates.ioaes-gcmdirect
crates.ioaes-gcm0.10.3direct
crates.ioapdudirect
crates.ioapdu0.4.0direct
crates.ioapdu-coredirect
crates.ioapdu-core0.4.0direct
crates.ioasync-traitdirect
crates.ioasync-trait0.1.89direct
crates.iobase64-urldirect
crates.iobase64-url3.0.3direct
crates.iobitflagsdirect
crates.iobitflags1.3.2direct
crates.iobitflags2.11.1direct
crates.iobluerdirect
crates.iobluer0.17.4direct
crates.iobtleplugdirect
crates.iobtleplug0.11.8direct
crates.iobyteorderdirect
crates.iobyteorder1.5.0direct
crates.iocbcdirect
crates.iocbc0.1.2direct
crates.iocoseydirect
crates.iocosey0.3.2direct
crates.ioctap-typesdirect
crates.ioctap-types0.4.0direct
crates.ioctaphiddirect
crates.ioctaphid0.3.1direct
crates.ioctaphid-dispatchdirect
crates.ioctaphid-dispatch0.3.0direct
crates.iocurve25519-dalekdirect
crates.iocurve25519-dalek4.1.3direct
crates.iodbusdirect
crates.iodbus0.9.11direct
crates.iodelogdirect
crates.iodelog0.1.8direct
crates.ioderdirect
crates.ioder0.4.5direct
crates.ioder0.7.10direct
crates.iofido-authenticator0.1.1direct
crates.ioflate2direct
crates.ioflate21.1.9direct
crates.iofuturesdirect
crates.iofutures0.3.32direct
crates.ioheaplessdirect
crates.ioheapless0.7.17direct
crates.iohexdirect
crates.iohex0.4.3direct
crates.iohidapidirect
crates.iohidapi2.6.5direct
crates.iohkdfdirect
crates.iohkdf0.12.4direct
crates.iohmacdirect
crates.iohmac0.11.0direct
crates.iohmac0.12.1direct
crates.iohttpdirect
crates.iohttp1.4.0direct
crates.ioicu_normalizerdirect
crates.ioicu_normalizer2.2.0direct
crates.ioidnadirect
crates.ioidna1.1.0direct
crates.iointerchangedirect
crates.iointerchange0.3.2direct
crates.iolittlefs2direct
crates.iolittlefs20.6.1direct
crates.iomaplitdirect
crates.iomaplit1.0.2direct
crates.iomockalldirect
crates.iomockall0.13.1direct
crates.ionfc10.6.0direct
crates.ionfc1-sysdirect
crates.ionfc1-sys0.3.13direct
crates.ionum-derivedirect
crates.ionum-derive0.4.2direct
crates.ionum-traitsdirect
crates.ionum-traits0.2.19direct
crates.ionum_enumdirect
crates.ionum_enum0.7.6direct
crates.iop256direct
crates.iop2560.13.2direct
crates.iop2560.9.0direct
crates.iopcscdirect
crates.iopcsc2.9.0direct
crates.iopublicsuffixdirect
crates.iopublicsuffix2.3.0direct
crates.ioranddirect
crates.iorand0.8.6direct
crates.iorand0.9.4direct
crates.ioreqwestdirect
crates.ioreqwest0.12.28direct
crates.iorustlsdirect
crates.iorustls0.23.40direct
crates.ioserdedirect
crates.ioserde1.0.228direct
crates.ioserde-indexeddirect
crates.ioserde-indexed0.1.1direct
crates.ioserde-indexed0.2.0direct
crates.ioserde_bytesdirect
crates.ioserde_bytes0.11.19direct
crates.ioserde_cbor_2direct
crates.ioserde_cbor_20.13.0direct
crates.ioserde_derivedirect
crates.ioserde_derive1.0.228direct
crates.ioserde_jsondirect
crates.ioserde_json1.0.149direct
crates.ioserde_reprdirect
crates.ioserde_repr0.1.20direct
crates.iosha2direct
crates.iosha20.10.9direct
crates.iosha20.9.9direct
crates.iosnowdirect
crates.iosnow0.10.0direct
crates.iospkidirect
crates.iospki0.7.3direct
crates.iotext_iodirect
crates.iotext_io0.1.13direct
crates.iothiserrordirect
crates.iothiserror1.0.69direct
crates.iothiserror2.0.18direct
crates.iotimedirect
crates.iotime0.3.47direct
crates.iotokiodirect
crates.iotokio1.52.3direct
crates.iotokio-streamdirect
crates.iotokio-stream0.1.18direct
crates.iotokio-tungstenitedirect
crates.iotokio-tungstenite0.26.2direct
crates.iotracingdirect
crates.iotracing0.1.44direct
crates.iotrusseddirect
crates.iotrussed0.1.0direct
crates.iotrussed-stagingdirect
crates.iotrussed-staging0.3.2direct
crates.iotungstenitedirect
crates.iotungstenite0.26.2direct
crates.iourldirect
crates.iourl2.5.8direct
crates.iouuiddirect
crates.iouuid1.23.1direct
crates.iox509-parserdirect
crates.iox509-parser0.17.0direct
crates.iozeroizedirect
crates.iozeroize1.8.2direct
crates.ioadler22.0.1indirect
crates.ioaead0.5.2indirect
crates.ioaho-corasick1.1.4indirect
crates.ioanstream1.0.0indirect
crates.ioanstyle1.0.14indirect
crates.ioanstyle-parse1.0.0indirect
crates.ioanstyle-query1.1.5indirect
crates.ioanstyle-wincon3.0.11indirect
crates.ioanyhow1.0.102indirect
crates.ioapdu-app0.1.0indirect
crates.ioapdu-derive0.4.0indirect
crates.ioasn1-rs0.7.1indirect
crates.ioasn1-rs-derive0.6.0indirect
crates.ioasn1-rs-impl0.2.0indirect
crates.ioatomic-polyfill1.0.3indirect
crates.ioatomic-waker1.1.2indirect
crates.ioautocfg1.5.0indirect
crates.iobase16ct0.2.0indirect
crates.iobase640.22.1indirect
crates.iobase64ct1.8.3indirect
crates.iobindgen0.70.1indirect
crates.iobindgen0.72.1indirect
crates.ioblake20.10.6indirect
crates.ioblock-buffer0.10.4indirect
crates.ioblock-buffer0.9.0indirect
crates.ioblock-padding0.3.3indirect
crates.ioblock20.5.1indirect
crates.iobluez-async0.8.2indirect
crates.iobluez-generated0.4.0indirect
crates.iobumpalo3.20.2indirect
crates.iobytemuck1.25.0indirect
crates.iobyteorder-lite0.1.0indirect
crates.iobytes1.11.1indirect
crates.iocbor-smol0.5.1indirect
crates.iocc1.2.62indirect
crates.iocesu81.1.0indirect
crates.iocexpr0.6.0indirect
crates.iocfg-if1.0.4indirect
crates.iocfg_aliases0.2.1indirect
crates.iochacha200.9.1indirect
crates.iochacha20poly13050.10.1indirect
crates.iocipher0.4.4indirect
crates.ioclang-sys1.8.1indirect
crates.iocolorchoice1.0.5indirect
crates.iocombine4.6.7indirect
crates.ioconst-oid0.9.6indirect
crates.iocore-foundation0.10.1indirect
crates.iocore-foundation-sys0.8.7indirect
crates.iocpufeatures0.2.17indirect
crates.iocrc32fast1.5.0indirect
crates.iocritical-section1.2.0indirect
crates.iocrossbeam-utils0.8.21indirect
crates.iocrunchy0.2.4indirect
crates.iocrypto-bigint0.2.5indirect
crates.iocrypto-bigint0.5.5indirect
crates.iocrypto-common0.1.7indirect
crates.iocrypto-mac0.11.0indirect
crates.ioctaphid-app0.1.0indirect
crates.ioctaphid-types0.2.0indirect
crates.ioctr0.9.2indirect
crates.iocty0.2.2indirect
crates.iocurve25519-dalek-derive0.1.1indirect
crates.iodashmap5.5.3indirect
crates.iodashmap6.1.0indirect
crates.iodata-encoding2.11.0indirect
crates.iodbus-tokio0.7.6indirect
crates.ioder-parser10.0.0indirect
crates.ioder_derive0.4.1indirect
crates.ioder_derive0.7.3indirect
crates.ioderanged0.5.8indirect
crates.iodes0.8.1indirect
crates.iodigest0.10.7indirect
crates.iodigest0.9.0indirect
crates.iodisplaydoc0.2.5indirect
crates.iodowncast0.11.0indirect
crates.ioecdsa0.12.4indirect
crates.ioecdsa0.16.9indirect
crates.ioed255192.2.3indirect
crates.ioeither1.15.0indirect
crates.ioelliptic-curve0.10.4indirect
crates.ioelliptic-curve0.13.8indirect
crates.ioencoding_rs0.8.35indirect
crates.ioenv_filter1.0.1indirect
crates.ioenv_logger0.11.10indirect
crates.ioequivalent1.0.2indirect
crates.ioerrno0.3.14indirect
crates.iofastrand2.4.1indirect
crates.ioff0.10.1indirect
crates.ioff0.13.1indirect
crates.iofiat-crypto0.2.9indirect
crates.iofind-msvc-tools0.1.9indirect
crates.iofind-winsdk0.2.0indirect
crates.ioflexiber0.1.3indirect
crates.ioflexiber_derive0.1.3indirect
crates.iofnv1.0.7indirect
crates.iofoldhash0.1.5indirect
crates.ioform_urlencoded1.2.2indirect
crates.iofragile2.1.0indirect
crates.iofutures-channel0.3.32indirect
crates.iofutures-core0.3.32indirect
crates.iofutures-executor0.3.32indirect
crates.iofutures-io0.3.32indirect
crates.iofutures-macro0.3.32indirect
crates.iofutures-sink0.3.32indirect
crates.iofutures-task0.3.32indirect
crates.iofutures-util0.3.32indirect
crates.iogenerator0.7.5indirect
crates.iogeneric-array0.14.7indirect
crates.iogetrandom0.2.17indirect
crates.iogetrandom0.3.4indirect
crates.iogetrandom0.4.2indirect
crates.ioghash0.5.1indirect
crates.ioglob0.3.3indirect
crates.iogroup0.10.0indirect
crates.iogroup0.13.0indirect
crates.ioh20.4.14indirect
crates.iohalf2.7.1indirect
crates.iohash320.2.1indirect
crates.iohashbrown0.14.5indirect
crates.iohashbrown0.15.5indirect
crates.iohashbrown0.17.0indirect
crates.ioheapless-bytes0.3.0indirect
crates.ioheck0.5.0indirect
crates.iohex-literal0.4.1indirect
crates.iohttp-body1.0.1indirect
crates.iohttp-body-util0.1.3indirect
crates.iohttparse1.10.1indirect
crates.iohyper1.9.0indirect
crates.iohyper-rustls0.27.9indirect
crates.iohyper-util0.1.20indirect
crates.ioicu_collections2.2.0indirect
crates.ioicu_locale_core2.2.0indirect
crates.ioicu_normalizer_data2.2.0indirect
crates.ioicu_properties2.2.0indirect
crates.ioicu_properties_data2.2.0indirect
crates.ioicu_provider2.2.0indirect
crates.ioid-arena2.3.0indirect
crates.ioidna_adapter1.2.2indirect
crates.ioimage0.25.10indirect
crates.ioindexmap2.14.0indirect
crates.ioinout0.1.4indirect
crates.ioipnet2.12.0indirect
crates.iois_terminal_polyfill1.70.2indirect
crates.ioiso78160.1.4indirect
crates.ioitertools0.13.0indirect
crates.ioitertools0.14.0indirect
crates.ioitoa1.0.18indirect
crates.iojni0.19.0indirect
crates.iojni-sys0.3.1indirect
crates.iojni-sys0.4.1indirect
crates.iojni-sys-macros0.4.1indirect
crates.iojni-utils0.1.1indirect
crates.iojs-sys0.3.98indirect
crates.iolazy_static1.5.0indirect
crates.ioleb128fmt0.1.0indirect
crates.iolibc0.2.186indirect
crates.iolibdbus-sys0.2.7indirect
crates.iolibloading0.8.9indirect
crates.iolinux-raw-sys0.12.1indirect
crates.iolitemap0.8.2indirect
crates.iolittlefs2-core0.1.2indirect
crates.iolittlefs2-sys0.3.2indirect
crates.iolock_api0.4.14indirect
crates.iolog0.4.29indirect
crates.ioloom0.5.6indirect
crates.iolru-slab0.1.2indirect
crates.iomacaddr1.0.1indirect
crates.iomatchers0.2.0indirect
crates.iomemchr2.8.0indirect
crates.iomime0.3.17indirect
crates.iominimal-lexical0.2.1indirect
crates.iominiz_oxide0.8.9indirect
crates.iomio1.2.0indirect
crates.iomockall_derive0.13.1indirect
crates.iomoxcms0.8.1indirect
crates.ionb1.1.0indirect
crates.ionix0.29.0indirect
crates.ionom7.1.3indirect
crates.ionu-ansi-term0.50.3indirect
crates.ionum-bigint0.4.6indirect
crates.ionum-conv0.2.1indirect
crates.ionum-integer0.1.46indirect
crates.ionum_enum_derive0.7.6indirect
crates.ioobjc-sys0.3.5indirect
crates.ioobjc20.5.2indirect
crates.ioobjc2-core-bluetooth0.2.2indirect
crates.ioobjc2-encode4.1.0indirect
crates.ioobjc2-foundation0.2.2indirect
crates.iooid-registry0.8.1indirect
crates.ioonce_cell1.21.4indirect
crates.ioonce_cell_polyfill1.70.2indirect
crates.ioopaque-debug0.3.1indirect
crates.ioopenssl-probe0.2.1indirect
crates.iop256-cortex-m40.1.0-alpha.6indirect
crates.iop256-cortex-m4-sys0.1.0indirect
crates.ioparking_lot0.12.5indirect
crates.ioparking_lot_core0.9.12indirect
crates.iopcsc-sys1.3.0indirect
crates.iopem-rfc74680.7.0indirect
crates.iopercent-encoding2.3.2indirect
crates.iopin-project-lite0.2.17indirect
crates.iopkcs80.10.2indirect
crates.iopkg-config0.3.33indirect
crates.iopoly13050.8.0indirect
crates.iopolyval0.6.2indirect
crates.iopostcard0.7.3indirect
crates.iopostcard-cobs0.1.5-preindirect
crates.iopotential_utf0.1.5indirect
crates.iopowerfmt0.2.0indirect
crates.ioppv-lite860.2.21indirect
crates.iopredicates3.1.4indirect
crates.iopredicates-core1.0.10indirect
crates.iopredicates-tree1.0.13indirect
crates.ioprettyplease0.2.37indirect
crates.ioprimeorder0.13.6indirect
crates.ioproc-macro-crate3.5.0indirect
crates.ioproc-macro21.0.106indirect
crates.iopsl-types2.0.11indirect
crates.iopxfm0.1.29indirect
crates.ioqrcodeindirect
crates.ioqrcode0.14.1indirect
crates.ioquinn0.11.9indirect
crates.ioquinn-proto0.11.14indirect
crates.ioquinn-udp0.5.14indirect
crates.ioquote1.0.45indirect
crates.ior-efi5.3.0indirect
crates.ior-efi6.0.0indirect
crates.iorand_chacha0.3.1indirect
crates.iorand_chacha0.9.0indirect
crates.iorand_core0.6.4indirect
crates.iorand_core0.9.5indirect
crates.ioredox_syscall0.5.18indirect
crates.ioref-swap0.1.2indirect
crates.ioregex1.12.3indirect
crates.ioregex-automata0.4.14indirect
crates.ioregex-syntax0.8.10indirect
crates.iorfc69790.4.0indirect
crates.ioring0.17.14indirect
crates.iorustc-hash1.1.0indirect
crates.iorustc-hash2.1.2indirect
crates.iorustc_version0.4.1indirect
crates.iorusticata-macros4.1.0indirect
crates.iorustix1.1.4indirect
crates.iorustls-native-certs0.8.3indirect
crates.iorustls-pki-types1.14.1indirect
crates.iorustls-webpki0.103.13indirect
crates.iorustversion1.0.22indirect
crates.ioryu1.0.23indirect
crates.iosalty0.3.0indirect
crates.iosame-file1.0.6indirect
crates.ioschannel0.1.29indirect
crates.ioscoped-tls1.0.1indirect
crates.ioscopeguard1.2.0indirect
crates.iosec10.7.3indirect
crates.iosecurity-framework3.7.0indirect
crates.iosecurity-framework-sys2.17.0indirect
crates.iosemver1.0.28indirect
crates.ioserde-byte-array0.1.2indirect
crates.ioserde-xml-rs0.8.2indirect
crates.ioserde_core1.0.228indirect
crates.ioserde_urlencoded0.7.1indirect
crates.ioserdect0.2.0indirect
crates.iosha-10.10.1indirect
crates.iosha10.10.6indirect
crates.iosharded-slab0.1.7indirect
crates.ioshlex1.3.0indirect
crates.iosignal-hook-registry1.4.8indirect
crates.iosignature1.3.2indirect
crates.iosignature2.2.0indirect
crates.iosimd-adler320.3.9indirect
crates.ioslab0.4.12indirect
crates.iosmallvec1.15.1indirect
crates.iosocket20.6.3indirect
crates.iospin0.9.8indirect
crates.iostable_deref_trait1.2.1indirect
crates.iostatic_assertions1.1.0indirect
crates.iostrum0.26.3indirect
crates.iostrum_macros0.26.4indirect
crates.iosubtle2.6.1indirect
crates.iosyn1.0.109indirect
crates.iosyn2.0.117indirect
crates.iosync_wrapper1.0.2indirect
crates.iosynstructure0.12.6indirect
crates.iosynstructure0.13.2indirect
crates.iotap1.0.1indirect
crates.iotempfileindirect
crates.iotempfile3.27.0indirect
crates.iotermtree0.5.1indirect
crates.iotest-logindirect
crates.iotest-log0.2.20indirect
crates.iotest-log-core0.2.20indirect
crates.iotest-log-macros0.2.20indirect
crates.iothiserror-impl1.0.69indirect
crates.iothiserror-impl2.0.18indirect
crates.iothread_local1.1.9indirect
crates.iotime-core0.1.8indirect
crates.iotime-macros0.2.27indirect
crates.iotinystr0.8.3indirect
crates.iotinyvec1.11.0indirect
crates.iotinyvec_macros0.1.1indirect
crates.iotokio-macros2.7.0indirect
crates.iotokio-rustls0.26.4indirect
crates.iotokio-util0.7.18indirect
crates.iotoml_datetime1.1.1+spec-1.1.0indirect
crates.iotoml_edit0.25.11+spec-1.1.0indirect
crates.iotoml_parser1.1.2+spec-1.1.0indirect
crates.iotower0.5.3indirect
crates.iotower-http0.6.10indirect
crates.iotower-layer0.3.3indirect
crates.iotower-service0.3.3indirect
crates.iotracing-attributes0.1.31indirect
crates.iotracing-core0.1.36indirect
crates.iotracing-log0.2.0indirect
crates.iotracing-subscriberindirect
crates.iotracing-subscriber0.3.23indirect
crates.iotrussed-chunked0.2.0indirect
crates.iotrussed-core0.1.0indirect
crates.iotrussed-fs-info0.2.0indirect
crates.iotrussed-hkdf0.3.0indirect
crates.iotry-lock0.2.5indirect
crates.iotypenum1.20.0indirect
crates.iounicode-ident1.0.24indirect
crates.iounicode-xid0.2.6indirect
crates.iouniversal-hash0.5.1indirect
crates.iountrusted0.9.0indirect
crates.ioutf-80.7.6indirect
crates.ioutf8_iter1.0.4indirect
crates.ioutf8parse0.2.2indirect
crates.iovaluable0.1.1indirect
crates.iovcpkg0.2.15indirect
crates.ioversion_check0.9.5indirect
crates.iowalkdir2.5.0indirect
crates.iowant0.3.1indirect
crates.iowasi0.11.1+wasi-snapshot-preview1indirect
crates.iowasip21.0.3+wasi-0.2.9indirect
crates.iowasip30.4.0+wasi-0.3.0-rc-2026-01-06indirect
crates.iowasm-bindgen0.2.121indirect
crates.iowasm-bindgen-futures0.4.71indirect
crates.iowasm-bindgen-macro0.2.121indirect
crates.iowasm-bindgen-macro-support0.2.121indirect
crates.iowasm-bindgen-shared0.2.121indirect
crates.iowasm-encoder0.244.0indirect
crates.iowasm-metadata0.244.0indirect
crates.iowasm-streams0.4.2indirect
crates.iowasmparser0.244.0indirect
crates.ioweb-sys0.3.98indirect
crates.ioweb-time1.1.0indirect
crates.iowinapi0.3.9indirect
crates.iowinapi-i686-pc-windows-gnu0.4.0indirect
crates.iowinapi-util0.1.11indirect
crates.iowinapi-x86_64-pc-windows-gnu0.4.0indirect
crates.iowindows0.48.0indirect
crates.iowindows0.61.3indirect
crates.iowindows-collections0.2.0indirect
crates.iowindows-core0.61.2indirect
crates.iowindows-future0.2.1indirect
crates.iowindows-implement0.60.2indirect
crates.iowindows-interface0.59.3indirect
crates.iowindows-link0.1.3indirect
crates.iowindows-link0.2.1indirect
crates.iowindows-numerics0.2.0indirect
crates.iowindows-result0.3.4indirect
crates.iowindows-strings0.4.2indirect
crates.iowindows-sys0.52.0indirect
crates.iowindows-sys0.61.2indirect
crates.iowindows-targets0.48.5indirect
crates.iowindows-targets0.52.6indirect
crates.iowindows-threading0.1.0indirect
crates.iowindows_aarch64_gnullvm0.48.5indirect
crates.iowindows_aarch64_gnullvm0.52.6indirect
crates.iowindows_aarch64_msvc0.48.5indirect
crates.iowindows_aarch64_msvc0.52.6indirect
crates.iowindows_i686_gnu0.48.5indirect
crates.iowindows_i686_gnu0.52.6indirect
crates.iowindows_i686_gnullvm0.52.6indirect
crates.iowindows_i686_msvc0.48.5indirect
crates.iowindows_i686_msvc0.52.6indirect
crates.iowindows_x86_64_gnu0.48.5indirect
crates.iowindows_x86_64_gnu0.52.6indirect
crates.iowindows_x86_64_gnullvm0.48.5indirect
crates.iowindows_x86_64_gnullvm0.52.6indirect
crates.iowindows_x86_64_msvc0.48.5indirect
crates.iowindows_x86_64_msvc0.52.6indirect
crates.iowinnow1.0.2indirect
crates.iowinreg0.5.1indirect
crates.iowit-bindgen0.51.0indirect
crates.iowit-bindgen0.57.1indirect
crates.iowit-bindgen-core0.51.0indirect
crates.iowit-bindgen-rust0.51.0indirect
crates.iowit-bindgen-rust-macro0.51.0indirect
crates.iowit-component0.244.0indirect
crates.iowit-parser0.244.0indirect
crates.iowriteable0.6.3indirect
crates.ioxml1.3.0indirect
crates.ioyoke0.8.2indirect
crates.ioyoke-derive0.8.2indirect
crates.iozerocopy0.8.48indirect
crates.iozerocopy-derive0.8.48indirect
crates.iozerofrom0.1.7indirect
crates.iozerofrom-derive0.1.7indirect
crates.iozeroize_derive1.4.3indirect
crates.iozerotrie0.2.4indirect
crates.iozerovec0.11.6indirect
crates.iozerovec-derive0.11.3indirect
crates.iozmij1.0.21indirect
Dependency advisories 3

This repository publishes no package the index resolves, so its own dependency graph was assessed — 478 packages, which also include development and test pins that never ship: 3 carry known advisories, of which 0 are direct. 71 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
quinn-proto0.11.14indirecthigh10.11.15
anyhow1.0.102indirectunknown11.0.103
atomic-polyfill1.0.3indirectunknown1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "fido2",
        "webauthn",
        "xdg-portal",
        "linux",
        "u2f"
      ],
      "is_fork": false,
      "size_kb": 2119,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Rust": 1449990,
        "Shell": 607,
        "RenderScript": 1
      },
      "pushed_at": "2026-07-14T19:24:00Z",
      "created_at": "2020-04-13T14:52:12Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T15:08:24Z",
      "description": "FIDO2 (WebAuthn) and FIDO U2F platform library for Linux written in Rust",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "LGPL-2.1",
      "default_branch": "master",
      "license_spdx_raw": "LGPL-2.1",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Credentials for Linux",
      "type": "Organization",
      "login": "linux-credentials",
      "company": null,
      "location": null,
      "followers": 226,
      "avatar_url": "https://avatars.githubusercontent.com/u/198482973?v=4",
      "created_at": "2025-02-09T17:36:44Z",
      "is_verified": null,
      "public_repos": 5,
      "account_age_days": 527
    },
    "license": {
      "state": "standard",
      "spdx_id": "LGPL-2.1",
      "raw_spdx": "LGPL-2.1",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "libwebauthn-v0.10.0",
          "kind": "other",
          "published_at": "2026-07-14T18:31:27Z"
        },
        {
          "tag": "libwebauthn-v0.9.0",
          "kind": "other",
          "published_at": "2026-07-01T21:22:43Z"
        },
        {
          "tag": "libwebauthn-v0.8.0",
          "kind": "other",
          "published_at": "2026-06-15T20:54:43Z"
        },
        {
          "tag": "libwebauthn-v0.7.1",
          "kind": "other",
          "published_at": "2026-06-10T22:36:57Z"
        },
        {
          "tag": "libwebauthn-v0.7.0",
          "kind": "other",
          "published_at": "2026-06-07T21:42:45Z"
        },
        {
          "tag": "libwebauthn-v0.6.0",
          "kind": "other",
          "published_at": "2026-05-30T17:28:38Z"
        },
        {
          "tag": "libwebauthn-v0.5.1",
          "kind": "other",
          "published_at": "2026-05-26T19:14:24Z"
        },
        {
          "tag": "libwebauthn-v0.5.0",
          "kind": "other",
          "published_at": "2026-05-18T19:22:34Z"
        },
        {
          "tag": "libwebauthn-v0.3.0",
          "kind": "other",
          "published_at": "2026-05-08T21:32:04Z"
        },
        {
          "tag": "libwebauthn-v0.2.2",
          "kind": "other",
          "published_at": "2025-07-27T16:03:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "5bd5f49cbf868b90e99edb5c0471949622992c79",
          "body": "Stacked on #302.\n\nNow the toolchain is pinned we can move it on purpose. Bump to 1.97.0\nand fix the 13 clippy warnings it brings. They are all the same one: a\nredundant & in a println! or write! argument. Formatting takes its\narguments by reference anyway, so nothing changes at runtime.\n\nPinning kee\n[…]\n as the pinned build job. It\nruns on master and weekly, never on pull requests, so it warns us early\nwithout putting a red X on everyone's PR.\n\nIt also deletes rust-clippy.yml, which has never worked.",
          "is_bot": false,
          "headline": "chore(ci): bump pinned toolchain to rust 1.97.0 (#303)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-14T19:23:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39ac69965f6cf4b0f40763b47c012ea0d3c1cbf4",
          "body": "Our build job doesn't install a toolchain, so it runs on whatever Rust\nthe runner image happens to ship. Clippy is gated with -D warnings, so\nthe day that image moves to a newer compiler, master and every open PR\ngo red at once.\n\nPin the job to 1.96.1, which is green today. CI config only, no code\nchanges.",
          "is_bot": false,
          "headline": "chore(ci): pin build job to rust 1.96.1 (#302)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-14T19:23:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b5e8c767a79239163ebae0d4a9b10ab19aa3076",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.10.0 (#301)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-14T18:31:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c09266b8438d97e8728049415a29cb51bb5023b",
          "body": null,
          "is_bot": false,
          "headline": "feat(webauthn): parse hints & merge into a transport preference (#300)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-14T18:28:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd5b6c2c6dce2b8466ff8f186e5b330d8f881513",
          "body": "…299)",
          "is_bot": false,
          "headline": "feat(webauthn): populate authenticatorAttachment in JSON responses (#…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-14T18:28:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6bdb700918f4c8c06c52d41f4d2d9e79888c5ad",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.9.0 (#298)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-01T21:22:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6c726eac7a143e7d6a6437cab63511d4e5265e2",
          "body": "The appid and appidExclude extensions were accepted without checking the\nsupplied AppID against the caller, so a site could drive a query under\nan unrelated AppID. This authorizes the AppID against the caller origin\nand rejects a mismatch with a security error. The appidExclude result is\nnow reported back when an exclusion is acted on.\n\nCloses #252.",
          "is_bot": false,
          "headline": "fix(webauthn): authorize appid against caller origin (#275)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-01T21:04:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "511dc4059cd7839da27204323a9612a557abe1ec",
          "body": "Implements the CTAP2 authenticatorReset command so callers can\nfactory-reset an authenticator. The command carries no parameters and no\nPIN or UV auth, and a successful reset evicts any matching persistent\ntoken from the store.",
          "is_bot": false,
          "headline": "feat(ctap2): implement authenticatorReset command (#296)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-01T20:59:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af594c3eed128b1d37c7e0685182cf71333c7816",
          "body": "…ror (#297)\n\nToday every transport failure collapses into one catch-all transport\nerror, and the underlying cause from the OS, Bluetooth, USB, or tunnel\nlayer is discarded. That makes diagnostics weak and leaves the error\nsurface unsettled ahead of a 1.0 freeze.\n\nThis reworks the error model so the \n[…]\ndistinct phase and is not representable as a\nceremony error.\n\nThe ceremony error:\n\n```rust\npub enum Error<TE> {\n    Ctap(CtapError),\n    Transport(TE),\n    Platform(PlatformError),\n}\n```\n\nCloses #130.",
          "is_bot": false,
          "headline": "refactor(error): per-transport TransportError and generic ceremony Er…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-07-01T20:51:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffa421cefe79a64440ee909d075bbe18d532a7cd",
          "body": "…ve (#293)\n\nMarks the public types that model device responses and protocol data as non-exhaustive, so adding fields or variants after 1.0 does not break downstream code. Types that callers construct directly are left exhaustive to keep them ergonomic to build. This is groundwork for committing to a stable API.",
          "is_bot": false,
          "headline": "chore(api): mark growable public response and spec types non_exhausti…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "537aca14ede7f09bf9f2e140af3ba6cb1601c0e5",
          "body": "The multi-assertion loop trusted the device-reported credential count with no limit, so a misbehaving device could drive unbounded iteration. The loop is now bounded and each returned assertion is checked for consistency with the request. This hardens the client against a hostile authenticator.",
          "is_bot": false,
          "headline": "fix(webauthn): bound and validate getNextAssertion iteration (#290)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:08:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e050904f78cff29367bdbb52f1b64a59d2cbeeac",
          "body": "Credential preflight treated every error as credential not present, so a transient transport error looked like a missing credential. It now treats only the explicit no-credentials response as absence and propagates other errors. This stops the client from silently skipping a credential that is actually present.",
          "is_bot": false,
          "headline": "fix(preflight): treat only no-credentials as credential absence (#287)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:08:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c666b45b1acae1fa83120253aacd66acfbcf6b4e",
          "body": "When a relying party requests no attestation, the client now removes the attestation statement and zeroes the AAGUID before returning the credential, rather than forwarding the authenticator attestation verbatim. This honors the requested conveyance and avoids disclosing identifying device information for a privacy-preferring registration. Requests that ask for direct or indirect attestation are unchanged.",
          "is_bot": false,
          "headline": "feat(webauthn): scrub attestation for attestation=none conveyance (#284)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:07:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3f8597bd0d62e65a54242c627b0f5a32dbcb8c5",
          "body": "…l rp ids (#285)\n\nRegistration now defaults a missing RP ID to the caller effective domain, matching the assertion ceremony and the spec, instead of failing. Origins whose host is an IP address are rejected rather than used as an RP ID. This removes an inconsistency between the create and get paths and closes a malformed RP ID case.",
          "is_bot": false,
          "headline": "fix(webauthn): default rp.id to effective domain and reject ip-litera…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:07:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac426c2012bb77eb072f079878d2ceb8116fecd8",
          "body": "…#291)\n\nAuthenticator configuration subcommands were sent without first confirming the device advertises support, and the minimum PIN length RP list was sent without a bound. Each subcommand now checks the relevant getInfo capability before being sent, and the RP list is bounded to the device limit. This avoids predictable rejections and respects the authenticator declared limits.",
          "is_bot": false,
          "headline": "fix(authnr-config): gate config subcommands on getInfo capabilities (…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:06:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6b9dcb16fe474fbf9da68bc2812911f360f035a",
          "body": "…(#289)\n\nParsing a credential descriptor that listed an unrecognized transport value failed the whole request. Unknown transport values are now ignored, as the spec requires, so a forward-compatible relying party request still succeeds. Recognized transports are handled as before.",
          "is_bot": false,
          "headline": "fix(ctap2): tolerate unknown authenticator transports in descriptors …",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:06:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a71bc2d6a4d48fb086d906c952e1d9269f0f3b90",
          "body": "Unknown and vendor CTAP status codes were reported as wire framing errors, which masked the real device response. The client now preserves any unrecognized status byte and surfaces it to the caller, and it adds the two defined codes for a full fingerprint store and a full large-blob store. Error reporting for real device conditions is now accurate instead of looking like corruption.",
          "is_bot": false,
          "headline": "fix(ctap2): preserve unknown ctap status codes and add 0x17/0x18 (#286)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:05:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9d03dc25156f2addb3770efcfa539f37085021a",
          "body": "A hybrid linking update carrying an invalid signature could delete the stored entry for the device it named, which let a connected device evict another link. Malformed or unauthenticated updates are now dropped without touching the store, and only a fully validated update modifies it. Forgetting a dead link still happens through the normal contact-time path.",
          "is_bot": false,
          "headline": "fix(cable): do not evict known device on invalid linking update (#288)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:05:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d72d92a32ff70942dd0820e415ba7de202b39c0e",
          "body": "BLE FIDO authenticator traffic must run over a bonded LE Secure Connections link. When the bonding state could not be confirmed through bluez, for example when the DBus query fails in a sandboxed deployment, the client proceeded anyway and exchanged sensitive traffic over an unverified link. It now refuses the connection on Linux when bonding cannot be confirmed, unless an explicit opt-in is set. Platforms where the OS enforces bonding at the GATT layer are unaffected.",
          "is_bot": false,
          "headline": "fix(ble): fail closed when bluez bonding state is unknown (#283)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:04:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a4252c32ee2d0362b3a2331907a172d238bd658",
          "body": "Documents the PIN and user-verification update channel that every consumer must wire to complete a ceremony, which had no documentation before. Adds a license section, an MSRV note, a crate-level overview for the docs landing page, and the missing cloud-assisted hybrid transport row, and removes a stale setup step. Documentation only.",
          "is_bot": false,
          "headline": "docs: document UV update wiring and add license, msrv, cable rows (#294)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:04:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "856097d9110edbdadb7b367353e6e00adfe5e50c",
          "body": "Adds coverage for the U2F downgrade exclude-list preflight path, which had no tests. This is a focused first step toward broader coverage of the U2F downgrade flow. Tests only.",
          "is_bot": false,
          "headline": "test(ctap1): cover u2f downgrade exclude-list preflight (#295)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:03:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6cb9147d02dc685b34e89b959659321db337170",
          "body": "Declares a minimum supported Rust version and verifies it in CI, so the crate makes an explicit toolchain commitment ahead of a stable release. The value was derived from the current dependency tree and can be relaxed if we want broader compatibility.",
          "is_bot": false,
          "headline": "chore(ci): declare and gate msrv at 1.88 (#292)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-21T15:03:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dca2054c261c0b688bb1d5914091af0bd8c389c1",
          "body": "The PIN flow ignored authenticator policy and measured PINs in bytes.\nThis routes operations away from a PIN token when the device forbids it,\ndrives a required PIN change first, and normalizes PINs to NFC with the\nminimum length checked in code points.\n\nCloses #256.",
          "is_bot": false,
          "headline": "fix(pin): honor PIN policy and normalize PINs (#281)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T22:04:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf2b40b83342c7c60bb403289a7e596ede73431d",
          "body": "Some security keys appear twice when we go looking for authenticators.\nThe same key shows up once as a USB device over HID, and again as a\nPC/SC reader for its built-in smart-card interface. Both entries are the\nsame physical key, but until now nothing connected them, so a single key\nplugged into US\n[…]\ned as a separate NFC device.\n\nReading real NFC keys is unchanged. A key held to a contactless reader\nhas no matching USB device, so it stays in the list and is read exactly\nas before.\n\nRelates to #182",
          "is_bot": false,
          "headline": "feat(nfc): dedupe USB-HID authenticators (#270)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T21:38:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d351aabd8b24aede3b9c04923ef1833bebe2c370",
          "body": "The end-to-end tests drove full ceremonies but never verified a\nsignature, so a regression in the emitted bytes could pass unnoticed.\nThis adds a round-trip test against the virtual authenticator that\nverifies an assertion signature and a packed attestation signature,\nincluding an extension that writes into the signed data.\n\nPart of #259.",
          "is_bot": false,
          "headline": "test(ctap2): verify signature round-trip (#280)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T21:35:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32869220918a93374661205bfe1978403cd8a1c5",
          "body": "There was no test pinning the exact wire bytes the stack emits, so a\nchange in CBOR ordering or a serialization dependency could break\ninteroperability silently. This pins golden vectors for a\nmake-credential and a get-assertion request and for a COSE public key.\n\nPart of #259.",
          "is_bot": false,
          "headline": "test(ctap2): pin canonical CBOR and COSE vectors (#279)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T21:33:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee077e7801847c37d39abb22c790c5334200e812",
          "body": "Authenticators report size and credential-list limits that the client\ndid not act on, so oversized requests failed at the device with opaque\nerrors. This keeps requests within the reported message size, drops\ncredential ids too long to belong to the device, and reports an\nover-count list clearly. The checks run on both the preflight and direct\npaths.\n\nCloses #254.",
          "is_bot": false,
          "headline": "feat(ctap2): enforce getInfo request limits (#278)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T21:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9187409b442a6cdabaad51ecb71e269b5e52a8a6",
          "body": "JSON callers scope PRF salts per credential under the member name\nevalByCredential, but the deserializer only accepted a snake_case key,\nso the per-credential map was dropped before it could be used. This\naccepts the spec member name so those salts reach the assertion request.\n\nCloses #251.",
          "is_bot": false,
          "headline": "fix(webauthn): accept PRF evalByCredential JSON key (#277)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T21:32:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "958894a94c42c04d358ce59fedd57ae809d6bd40",
          "body": "When a relying party requires a credential protection policy, the client\nmust refuse an authenticator that cannot honor it. The check looked at\nuser verification state, which says nothing about credProtect support.\nThis feature-detects credProtect from the authenticator getInfo and\nenforces the policy against that.\n\nCloses #253.",
          "is_bot": false,
          "headline": "fix(ctap2): feature-detect credProtect from getInfo (#273)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-19T21:31:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6749f917e707645ee6ffee17ccfc4029e9dbd3d0",
          "body": "The library implements four transports but advertised only USB and BLE,\nand registration responses always returned an empty transports list.\nThis adds NFC and hybrid to the public transport list, with NFC shown\nonly when a backend is compiled in, and fills the registration\ntransports from the transport actually used, ordered and deduplicated\nper the WebAuthn rules.\n\nCloses #258.",
          "is_bot": false,
          "headline": "feat(transport): advertise NFC and hybrid transports (#282)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-17T22:07:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4eb06652dde437d8cfb0e7e42d577c348c9881e",
          "body": "Two authenticator-data flag bits carry backup eligibility and backup\nstate but were modeled as reserved. This names them and adds read-only\naccessors derived from the parsed flags. The signed bytes are still\nreturned verbatim, so signed output is unchanged.\n\nCloses #255.",
          "is_bot": false,
          "headline": "feat(fido): model backup eligibility and state flags (#272)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-17T22:06:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9d6b77558af5c40f8e1846032292dd28394cf9e",
          "body": "The hybrid tunnel did not follow HTTP redirects, so a redirecting tunnel\nserver could not be reached, and a permanently gone link kept being\nretried. This follows redirects with the required headers reattached,\nand treats a gone response as permanent by forgetting the stored link.\n\nPart of #257.",
          "is_bot": false,
          "headline": "fix(cable): follow tunnel redirects and forget gone links (#274)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-17T22:06:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d593d6b4953dd945ebfc30a778cfc5a33ca70de2",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.8.0 (#271)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-15T20:54:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1441ce1d9537ae309d4aee04bb238c562f19eecb",
          "body": "…(#269)\n\nCloses #266. Closes #168.\n\nWebAuthn L3 defines prf as a client extension. Security keys do not implement it directly. The client maps the PRF inputs onto the CTAP hmac-secret extension, encrypting the salts with a shared secret negotiated over the PIN/UV protocol, and the outputs come back \n[…]\ntion and assertion. Verified end to end against a Google Password Manager phone over caBLE: registration returns enabled true together with create-time results, and assertion returns both PRF outputs.",
          "is_bot": false,
          "headline": "feat(webauthn): PRF with hybrid authenticators via the prf extension …",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-15T20:44:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c05be0090cd3dd699d4bd202dff1cfad06ab4c5",
          "body": "…nt extension results (#260)\n\nFollow-up to #244.\n\nThat change fixed decoding of the unsigned extension outputs returned at\nthe getAssertion response, but stopped short of surfacing them to\ncallers. The decoded map stayed on the protocol response and never\nreached the client extension results.\n\nThis \n[…]\nrdPartyPayment sits alongside the\nexisting typed outputs. Binary values are encoded as base64url to stay\nconsistent with the rest of the JSON output. An empty or absent map adds\nnothing.\n\nCloses #250.",
          "is_bot": false,
          "headline": "feat(webauthn): surface getAssertion unsignedExtensionOutputs to clie…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-15T20:35:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69ca216d3b0c0a49c0a25191138faffb08173db2",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.7.1 (#268)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-10T22:36:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5294ac76604c20fe1525f76248b0a60c90bdb870",
          "body": "…(#264)\n\nI have a Token2 and a Yubikey \"Security Key C NFC\".\nThe Yubikey is more strict than the Token2 and causes errors.\n\n`cargo run --example cred_management_hid` with option 2: \"(2) Enumerate\ncredentials\"\ncauses `Error: Ctap(NotAllowed)` on the Yubikey after the PIN have been\ninput.\nI think this is due to enumerateCredentialsGetNextCredential and\nenumerateRPsGetNextRP being statefull in the fido v2.1 spec.\n\n---------\n\nCo-authored-by: Alfie Fresta <alfie.fresta@gmail.com>",
          "is_bot": false,
          "headline": "fix(credmgmt): Yubikey error when NextCred is not handled statefully …",
          "author_name": "Nisker",
          "author_login": "Nisker",
          "committed_at": "2026-06-10T22:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c466fbf3aaa10cee683aa0422e360f6f52c44a81",
          "body": "This was tested with libwebauthn 0.5.1 in credentialsd master branch\n([7c13749](https://github.com/linux-credentials/credentialsd/commit/7c137495b0fe1651171cc21a830feb0bfb7ff69c))\nin a modified Teams for linux (FIDO2 passkey login login).\nToken2 version 3.1 logins without problems.\nYubikey triggers \n[…]\ne treated as being present with the value false.\"\nSo having UV=true and pinUvAuthParam will cause errors on a strict key\nlike Yubikey.\n\n---------\n\nCo-authored-by: Alfie Fresta <alfie.fresta@gmail.com>",
          "is_bot": false,
          "headline": "fix(ctap2): do not send uv option together with pinUvAuthParam (#265)",
          "author_name": "Nisker",
          "author_login": "Nisker",
          "committed_at": "2026-06-10T21:47:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68ea5db4eddf96294b5e17cd9f77b48866772afa",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.7.0 (#262)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T21:36:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60d8d956ff05e131deda39928bc416e62f262681",
          "body": "Adds the WebAuthn L3 largeBlob write extension and a libwebauthn-side delete operation on top of CTAP 2.2 authenticatorLargeBlobs. After an assertion yields the per-credential key, the platform fetches the on-authenticator array, replaces or erases the credential's own entry, and re-uploads it in chunks while preserving other credentials' blobs. Write and delete failures are non-fatal and surface as written=false.",
          "is_bot": false,
          "headline": "feat(webauthn): largeBlob write and delete (#261)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T21:21:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14895c17c548192120e2bc8231f3e1df47c70135",
          "body": "Implements the read half of the WebAuthn L3 `largeBlob` extension end to\nend. Until now the library could request a per-credential key from the\nauthenticator but had no way to actually fetch and decrypt the stored\nblob, so the read output was never populated.\n\nAfter an assertion succeeds and yields \n[…]\n0:\nhttps://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-20210615.html#authenticatorLargeBlobs\n- RFC 1951 (DEFLATE): https://www.rfc-editor.org/rfc/rfc1951",
          "is_bot": false,
          "headline": "feat(webauthn): largeBlob read via authenticatorLargeBlobs (#206)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T21:18:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14afd1f00bd50ea67898b6619aaa9af2cee80c73",
          "body": "The client rebuilt the authenticator data from a parsed structure\ninstead of keeping the exact bytes the authenticator produced. An\nauthenticator signature covers those exact bytes, so re-encoding could\ndrop extension entries the client did not model or reorder map keys,\nwhich would make a relying p\n[…]\nr data verbatim and returns it unchanged.\nPlatform-synthesized data is still built from fields.\n\nIncludes a regression test confirming the bytes round-trip unchanged,\nincluding an unmodeled extension.",
          "is_bot": false,
          "headline": "fix(ctap2): preserve raw authenticatorData bytes (#249)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:48:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "76512c49f66fec865ba464fa39aed4019eaa435f",
          "body": "The assertion response mapped entry 0x08 to a value it should not have,\nwhile the protocol defines 0x08 as the unsigned extension outputs map.\nAn authenticator that returns that map caused the whole assertion\nresponse to fail to decode, breaking the ceremony. This becomes more\nlikely as newer authen\n[…]\nThe change also drops two\nunused fields from the public assertion type, a minor change for a\npre-1.0 crate.\n\nIncludes a regression test that decodes a response carrying the map and\nconfirms it parses.",
          "is_bot": false,
          "headline": "fix(ctap2): decode unsignedExtensionOutputs at GetAssertion 0x08 (#244)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:48:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba35dde7714674f6948b48afb6c9d151b0504061",
          "body": "During registration the excludeCredentials ids were stored as the raw\ntext of the base64url string rather than the decoded bytes. The ids in\nthe request never matched the credentials an authenticator already held,\nso duplicate-credential prevention was silently bypassed and a second\ncredential could\n[…]\ndecodes the ids the same way the authentication path already does,\nand treats an omitted excludeCredentials as an empty list.\n\nIncludes regression tests asserting the ids decode to the expected\nbytes.",
          "is_bot": false,
          "headline": "fix(webauthn): base64url-decode excludeCredentials ids (#242)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:47:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a440ade19e5a7091aa04a3912dff99771558652",
          "body": "… path (#248)\n\nWhen a ceremony also needed a shared secret, for example any request\nusing the PRF extension, the check that enforces required user\nverification was skipped. On a device that can verify the user but is\nnot yet enrolled, a registration requested with required user\nverification could co\n[…]\nser, the request\nnow fails clearly instead of proceeding. Requests that prefer or\ndiscourage user verification are unaffected.\n\nIncludes a regression test covering the required, not-yet-enrolled case.",
          "is_bot": false,
          "headline": "fix(webauthn): enforce userVerification=required on the shared-secret…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:47:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09623aca78d995edeabe04ec687cf3aad58db5ea",
          "body": "On the U2F-over-NFC path the channel discarded the card status word and\nreported every non-success as a framing error. The U2F layer relies on\nthe status word to tell whether a credential was absent, whether user\npresence is needed, or whether U2F is disabled, so authentication with\nseveral allowed \n[…]\nenabled, so a\nseparate commit adds a CI step that runs the NFC backend tests, ensuring\nthe new guard is exercised.\n\nIncludes a regression test confirming a not-registered status is\nsurfaced correctly.",
          "is_bot": false,
          "headline": "fix(nfc): preserve APDU status words on the U2F path (#247)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:46:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15b555953cd26dbc1d859fdc4076eddfc65d841a",
          "body": "A U2F registration over the downgrade path requested at most 256\nresponse bytes. A registration response is larger than that, so over USB\nand Bluetooth, which do not chain partial responses, the response was\ntruncated and registration failed.\n\nThis requests the full response length for registration.\n\nIncludes a regression test asserting the encoded request uses the\nextended wildcard length.",
          "is_bot": false,
          "headline": "fix(ctap1): request full-length response for U2F_REGISTER (#246)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:44:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19b6b9d025884c026451d29d4707dbee3fc6e5c1",
          "body": "Two management calls returned an identifier wrapped in an extra layer of\nCBOR framing. The relying-party hash from enumerate and the template id\nfrom fingerprint enrollment came back a couple of bytes longer than the\nraw value, so the follow-up call never matched and enumerate-credentials\nand multi-\n[…]\nenrollment could not complete.\n\nThis returns the raw bytes, matching how the neighbouring calls already\nwork.\n\nIncludes regression tests asserting the returned values are the raw hash\nand template id.",
          "is_bot": false,
          "headline": "fix(ctap2): return raw rpIDHash and templateId from management (#245)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:43:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0996d978d785629744e9d0d08185bd28c612af21",
          "body": "…243)\n\nThe extensions map sent with a registration was encoded in\nfield-declaration order, which is not the canonical key order the\nprotocol requires. Some authenticators reject a non-canonical map, so\nregistrations that combined certain extensions could fail.\n\nThis orders the extension keys canonically, shortest key first and then\nby byte value.\n\nIncludes a regression test that encodes several extensions together and\nasserts the key order.",
          "is_bot": false,
          "headline": "fix(ctap2): emit makeCredential extensions in canonical CBOR order (#…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:43:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81ff12cbc3ac84154942d9d39dda77ee6d4e4c20",
          "body": "…#241)\n\nFor cross-origin ceremonies the client data JSON serialized topOrigin\nbefore crossOrigin. The fixed order is type, challenge, origin,\ncrossOrigin, then topOrigin. Relying parties that verify the client data\nbytes positionally would reject otherwise-valid cross-origin\nregistrations and assertions.\n\nThis emits crossOrigin before topOrigin. Same-origin output is\nunchanged.\n\nIncludes a regression test asserting the field order.",
          "is_bot": false,
          "headline": "fix(webauthn): order crossOrigin before topOrigin in clientDataJSON (…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:42:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5adb90df7e65534b34feaeac08fadab0e2b2cb5",
          "body": "…l suffixes (#240)\n\nWhen a relying party ID is validated against the caller origin, the\ncheck approximated the registrable-domain rule with a public-suffix\nheuristic. That heuristic only holds for single-label effective\ntop-level domains. Under a multi-label suffix it accepted relying party\nIDs that\n[…]\n/localhost`, but is now rejected for a sub-domain\nsuch as `sub.localhost`, which matches browser behavior.\n\nIncludes a regression test covering a multi-label suffix and the\nstandard example.com cases.",
          "is_bot": false,
          "headline": "fix(webauthn): scope rp.id to the registrable domain under multi-labe…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T15:41:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3367ea0da0c2a7c1d7e671a4fd23baf51a249f66",
          "body": null,
          "is_bot": false,
          "headline": "docs(credmgmt): document persistent token usage and add example (#235)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T14:56:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "518b97a3d7a1e5a7bfeb124e56ed43e5a1ff1d30",
          "body": "…#234)",
          "is_bot": false,
          "headline": "feat(pin): invalidate persistent tokens on rejection and PIN change (…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T14:56:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bba9008ebf8c48c5fa963b332c7750a1860d7e6",
          "body": "…gnition (#233)",
          "is_bot": false,
          "headline": "feat(pin): acquire and reuse persistent tokens via encIdentifier reco…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T14:56:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ed48b96576372c4b7cb60ff338db3b7c9dc00f8",
          "body": null,
          "is_bot": false,
          "headline": "feat(pin): add persistent token store trait and channel plumbing (#232)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T14:55:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52c407bdfc0e495643b71e6e3e322ffbd916d780",
          "body": null,
          "is_bot": false,
          "headline": "feat(pin): add pcmr permission and rename ephemeral token source (#231)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-06-07T14:55:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4151e172b74a82d1450b40c3d53aa428d8756ae8",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.6.0 (#239)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-30T17:28:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d26b983b46b673f8db2cd5530cc175559e50550",
          "body": "Implements WebAuthn L3 §5.11 \"Related Origins\". When a request's rp.id\nis not a registrable suffix of the caller's effective domain,\nlibwebauthn resolves the relying party's allowed origins and accepts the\nrequest if one matches the caller.\n\nOrigin resolution is pluggable and the matching always run\n[…]\nvalue rather than positional parameters,\nwhich keeps the API manageable as options grow. Existing call sites need\na small update for the new signature.\n\nCloses #160. Based on #173 by @HarveyOrourke15.",
          "is_bot": false,
          "headline": "feat(webauthn): related-origins validation (WebAuthn L3 §5.11) (#219)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-30T17:16:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e104a65d1b5e2fc377be7ee57b5a7b36ad6cb260",
          "body": "The crate enables a set of strict clippy denies (no panic, unwrap,\nexpect, or unchecked indexing in production code) but gates them on\nbuilds without the test or virt features. Every CI job builds with\n`--all-features`, which always enables virt, so the denies were switched\noff across the whole crat\n[…]\ne\nlint runs for real, in the WebAuthn client-data and assertion paths and\nthe HID framing parser. There are no functional changes, and every\nfeature combination builds clean under the enforced denies.",
          "is_bot": false,
          "headline": "chore(clippy): enforce production denies in CI (#238)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-30T16:33:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e062e5b057a8c9a0f37b3c79a672ce5cc500db33",
          "body": "docs.rs builds a crate with its default features only, which left the\nNFC transport out of the published documentation. This adds docs.rs\nmetadata so the NFC transport is documented through the pcsc backend.\nlibnfc is not available in the docs.rs build environment, so the libnfc\nbackend is intention\n[…]\na CI job that builds the documentation the same way docs.rs\ndoes, inside the same container image. A broken docs build now fails a\npull request instead of only showing up as a red badge after release.",
          "is_bot": false,
          "headline": "docs: document full API on docs.rs and guard the build in CI (#236)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-30T16:13:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70cb6a663e07c759f5269f00be481d179d0ec181",
          "body": "WebAuthn L3 §5.2.1.1 says\n`AuthenticatorAttestationResponse.getPublicKey()` returns DER-encoded\nSubjectPublicKeyInfo for credentials using ES256, EdDSA Ed25519 and\nRS256, and null for any algorithm the user agent does not implement.\nlibwebauthn was emitting raw COSE bytes there instead, which relyin\n[…]\nrypto, both\nalready in the transitive dependency tree via `p256`, so no new external\nruntime crates land. Adding new algorithm support later is a small\nper-algorithm addition.\n\nStacked on top of #229.",
          "is_bot": false,
          "headline": "feat(webauthn): emit SubjectPublicKeyInfo from getPublicKey() (#230)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-28T22:33:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e484455686176388ac356fbe5183ac134b1ccd8",
          "body": "The credential public key returned by an authenticator was being stored\nin a closed Rust enum that only handled P-256 and Ed25519. Any\ncredential using RSA, P-384, secp256k1 or a post-quantum algorithm\nfailed to deserialise, so the whole registration response was rejected.\n\nCredential public keys ar\n[…]\nallback was hiding real protocol violations.\n\nThe closed enum is still used for the ECDH-ES P-256 key agreement during\nPIN/UV protocols, where the COSE shape is fixed by spec.\n\nStacked on top of #228.",
          "is_bot": false,
          "headline": "fix(ctap2): store credential public keys as opaque COSE bytes (#229)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-28T18:49:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "48387f24dbd7a6de0c8cb2779ef41c2a57bd4db9",
          "body": "The COSE algorithm identifier type was a closed enum with a sentinel for\nunknown values. Any algorithm a relying party requested that wasn't one\nof three known values got silently rewritten to the sentinel before\nreaching the authenticator. Authenticators that supported RS256, ES384,\nPS256, secp256k\n[…]\n. The `-9` codepoint was historically misnamed for an internal use\nand is now aligned with RFC 9864 ESP256, the actual IANA assignment.\n\nThis is a breaking change on the public Rust API.\n\nCloses #148.",
          "is_bot": false,
          "headline": "fix(ctap2): pass through arbitrary COSE algorithm identifiers (#228)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-28T17:37:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7aa0cbf623b5c8bfc7ae34e4ad6a1b951315e511",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.5.1 (#227)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-26T19:13:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3b9b1cb65139ffb170632d5abbf340adfe6fa2c",
          "body": "Hybrid currently fails immediately with `Transport(Timeout)` (issue\n#225) because the protocol layer wraps each CTAP2 exchange in a 250ms\nwall-clock timeout, but the cable transport legitimately blocks for the\nBLE handshake before that timeout window even applies.\n\nRemoving the outer wrap is safe. H\n[…]\nion shape of the protocol\nlayer and adds a unit test that pins the behaviour by sleeping the mock\nchannel's send past the GetInfo timeout and asserting the call still\nreaches the response.\n\nFixes #225",
          "is_bot": false,
          "headline": "fix(cable): GetInfo timing out before BLE handshake completes (#226)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-26T19:08:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "86c7c5151d70b7a30474e560f7697940cdeef861",
          "body": "## Summary\n`wait_for_connection` returned `ConnectionLost` on an entry-time\n`Terminated` but `ConnectionFailed` on a transition-time `Terminated`.\nThe caller can't observe which path it took, so the two variants are an\naccidental asymmetry that makes downstream `match`es fragile. Both paths\nnow return `ConnectionFailed`.\n\n## Test plan\n- [ ] `cargo build -p libwebauthn`\n- [ ] `cargo test -p libwebauthn`",
          "is_bot": false,
          "headline": "fix(cable): return ConnectionFailed for both Terminated paths (#222)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-19T18:34:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c71a77c3faf5a24ac5854ca66a55e62d55cc204",
          "body": "A handful of Cargo metadata fixes so the crates.io listing renders\nproperly on the next publish:\n\n- Add `license = \"LGPL-2.1-or-later\"`. Fixes the \"nonstandard license\"\nlabel on crates.io.\n- Add `readme = \"../README.md\"` so the crate page renders the README.\nVerified via `cargo package --list`.\n- Updating my email address.\n- Credit @msirringhaus and @iinuwa as authors.",
          "is_bot": false,
          "headline": "chore(cargo): tidy package metadata (#221)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-19T17:58:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a0e737029e2954a9c60cd59c6e4707b405f1770",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): 0.5.0 (#220)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T19:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24d874aeea218d7e29cf3e1e52ea9daa8cf0a172",
          "body": "Map tungstenite::Error::Io to TransportError::IoError(kind), matching the L2capDataChannel variant so the CableDataChannel trait differentiates failure modes regardless of transport. Treat Error::ConnectionClosed as a clean close in recv.",
          "is_bot": false,
          "headline": "fix(cable): preserve I/O error kind on the WebSocket data channel (#218)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T19:09:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "700e262faee44150ad5d2e07dfca99c2ce7f0db6",
          "body": "… (#217)\n\n- Add EncryptionFailed transport error variant\n- Surface decode/encrypt failures out of the cable connection task instead of swallowing them\n- Forward tunnel-connection errors via send_error so callers see the real cause\n- Hoist CableTunnelMessage::from_slice and CableKnownDeviceInfo::new to return TransportError directly",
          "is_bot": false,
          "headline": "fix(cable): propagate post-handshake errors from protocol::connection…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T19:04:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "073406725f6c1aafa455c5a858c608896ba3d430",
          "body": "Implements the CTAP 2.3 hybrid transport over a direct BLE L2CAP channel, QR-initiated. The library now establishes the cable tunnel by connecting to the authenticator's advertised L2CAP PSM (bluez via the `bluer` crate, L2CAP-only) instead of the WebSocket relay.\n\n- New cable channel backend dialin\n[…]\nP socket\n- Noise handshake and post-handshake framing reused across BLE / WebSocket\n- QR pairing extended to surface BLE-capable authenticators\n- Examples and README updated for the new transport name",
          "is_bot": false,
          "headline": "feat(cable): hybrid transport over a direct BLE L2CAP channel (#216)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T18:55:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16be38adbb3bbe41fb2730ec62bbdc98904c7e7f",
          "body": "- Split psl.rs into psl/{mod,dat,dafsa,system}\n- DafsaFilePublicSuffixList: native libpsl .dafsa reader with BadMagic / BadHeader / Truncated / UnsupportedVersion errors\n- SystemPublicSuffixList::auto() probes DAFSA then DAT, picking whichever the distro ships\n- Hoist registrable_domain to a default trait method derived from public_suffix\n- CI installs publicsuffix and exercises the gated system-file PSL test",
          "is_bot": false,
          "headline": "feat(psl): add DAFSA-format Public Suffix List reader (#215)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T18:42:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b677e6eb6b63224ad7a75c2a5396719c17afc7d",
          "body": "- Validate CID, SEQ, and init bit on every continuation packet\n- Enforce a wall-clock timeout on HID receive and CTAP2 exchanges",
          "is_bot": false,
          "headline": "fix(hid): wall-clock timeout and continuation-packet validation (#205)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T18:23:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e00499c00040bbf2c763e3e139178757650564cd",
          "body": "- Add appid and appidExclude inputs to the IDL types\n- Plumb appid through GetAssertionRequest and the U2F downgrade path\n- Preflight excludeList against appidExclude; signal appid in U2F output",
          "is_bot": false,
          "headline": "feat(webauthn): support appid and appidExclude extensions (#204)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T18:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "201d527f52aee3e2d62d47999e448937c108345f",
          "body": "…heck (#202)\n\n- Consume fidoStatus notifications instead of GATT Read\n- Use Write Request for spec-declared Write characteristics\n- Refuse unbonded LE links per CTAP 2.2 §11.4.3\n- Enumerate undiscovered peripherals\n- Add webauthn_ble example",
          "is_bot": false,
          "headline": "fix(ble): notifications, write-with-response, LE secure connections c…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-18T18:13:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95db65c8f296e1e719d4cd8f9ddeefa565b43aa1",
          "body": "Enables PRF evaluation at MakeCredential time on authenticators that\nadvertise hmac-secret-mc. Falls back gracefully to hmac-secret: true\n(PRF via GetAssertion) when the extension is unsupported.\n\nWire format and processing reuse the existing GA hmac-secret path.",
          "is_bot": false,
          "headline": "feat(webauthn): support hmac-secret-mc CTAP 2.2 extension (fix #147)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T19:21:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1c3d485a220088de04208c36644570363db021e",
          "body": "…x #183)\n\nWebAuthn PRF outputs are sensitive key material. Per the spec direction\nin w3c/webauthn#2337, callers requesting the PRF extension must have\nuserVerification upgraded to \"required\" before the request reaches the\nauthenticator. This applies regardless of whether PRF eval values are\npopulate\n[…]\ned or Preferred + PRF now triggers UV (PIN setup if no PIN).\n- U2F-only devices were already incapable of PRF; PRF-bearing requests\n  now error with NegotiationFailed instead of silently dropping PRF.",
          "is_bot": false,
          "headline": "feat(webauthn): force UV=required when PRF extension is requested (fi…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:56:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8556676020fa16428e9b5e18c5ef3c4fcb461991",
          "body": "publicsuffix 1.5 transitively pulls idna 0.2.3, which is affected by\nCVE-2024-12224 (GHSA-h97m-ww89-6jmq). publicsuffix 2.3 depends on\nidna 1.0+, which is patched. Closes Dependabot alert #25.\n\nThe 2.x API replaces List::from_str / parse_domain / Domain::root with\nstr::parse and the Psl trait's suff\n[…]\n also applies an implicit wildcard so unlisted TLDs (like\n\"localhost\") report themselves as a suffix; filter on Suffix::is_known()\nto preserve v1 semantics and keep bare \"localhost\" valid as an rp.id.",
          "is_bot": false,
          "headline": "fix(deps): bump publicsuffix to 2.3 to drop vulnerable idna 0.2.3",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:29:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc1734ed7013475a7a11838be9a33350a7e5d87d",
          "body": null,
          "is_bot": false,
          "headline": "test(webauthn): add explicit short-input JSON parse test for PRF",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:15:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d7236eb2bc1f55c23a9927775325f835d4f0a16",
          "body": "Split PRFValue into PrfInputValue (Vec<u8>) for variable-length salt\ninputs and PrfOutputValue ([u8; 32]) for the fixed-size hmac-secret\noutput. Per W3C WebAuthn L3 §10.1.4, PRF salt inputs are BufferSources\nof any length; the existing SHA-256 prefix-hashing already produces a\n32-byte salt for CTAP2 hmac-secret regardless of input length.\n\nAdds unit tests for variable-length and empty inputs, and a virtual-\ndevice test exercising 0-byte, 7-byte, and 100-byte salts.",
          "is_bot": false,
          "headline": "fix(webauthn): allow PRF inputs of any length (fix #209)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:15:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f0267f9186cefe02ba982cc1b2f4454deb4e1f9",
          "body": "The NFC backend (gated behind the `nfc`/`pcsc`/`libnfc` features) was\nnot exercised by the default `cargo build`, so the lint enabled in\nthe previous commits did not surface there. CI's\n`cargo clippy --all-targets --all-features` flags 5 sites:\n\n- `channel::NfcChannel::handle`: replace `&buf[..len]`\n[…]\nis panic-safe.\n- `libnfc::Channel::connect_to_target`: replace\n  `&modulations[modulations.len() - 1]` with `.last()`, returning\n  `TransportUnavailable` if the device reports no supported baud rates.",
          "is_bot": false,
          "headline": "fix(nfc): bounds-check slicing flagged by clippy::indexing_slicing",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39bfa519a2a269ebfdbc87c396cac85b6919d02f",
          "body": "In `transport::ble::framing` and `transport::hid::framing`, rewrite\n`frame()` / `message()`, `expected_bytes()`, and length helpers to use\n`split_first`, `.get()`, and `saturating_sub` instead of direct\nindexing. The behaviour is preserved (verified by the existing unit\ntests).\n\nIn `transport::hid::\n[…]\nesponse.payload.get(..INIT_NONCE_LEN)` rather than the previously\npanic-prone slice index; the explicit length check on the line above\nmakes this safe in practice but the lint requires bounded access.",
          "is_bot": false,
          "headline": "fix(transport): bounds-check slicing in BLE and HID framing",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41750cb0390d116f595c7a35634e7350b9df0351",
          "body": "- `crypto::trial_decrypt_advert`: switch to `.get()` for all EID-key\n  and candidate-advert subslices, returning `None` on length mismatch\n  (the up-front length checks make this dead in practice, but the\n  lint requires explicit bounded access).\n- `crypto::reserved_bits_are_zero`: use `.first().cop\n[…]\nuse\n  `BASE32_CHARS.get()` / `TLDS.get()`.\n- `tunnel::connect` (initial msg buffer) and the trace log: bound the\n  buffer slice via `.get()`.\n- `tunnel::send_cbor` padding-length byte: use `last_mut`.",
          "is_bot": false,
          "headline": "fix(cable): bounds-check slicing flagged by clippy::indexing_slicing",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5fb96b19a9d0524399a8e4980891d0f4aaeb36a",
          "body": "Replace direct slice / index access with `.get()`, `split_first`,\n`split_at`, or iterator-based equivalents in CTAP message parsing and\nPIN/UV helpers. Functions affected:\n\n- `fido::AuthenticatorData::deserialize`: bound the trailing-data check.\n- `pin::PinUvAuthProtocolOne::authenticate`: handle th\n[…]\nponse::try_from`: rewrite using\n  `split_first`.\n- `proto::ctap2::model::get_assertion`: convert SHA-256 outputs to\n  `[u8; 32]` via `GenericArray::into` and use `first()` on the\n  allowList shortcut.",
          "is_bot": false,
          "headline": "fix(proto): bounds-check slicing flagged by clippy::indexing_slicing",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "48b05b053e11cfd570942f31f8674ed53a5759dd",
          "body": "`clippy::indexing_slicing` flags any `&v[i]` / `&v[a..b]` that could\npanic at runtime, complementing the existing `deny(clippy::panic)`\nwhich does not see slice-index panics from transitive crates.\n`clippy::unwrap_in_result` flags `.unwrap()` / `.expect()` inside\nfunctions that return `Result`, wher\n[…]\n tests retain the latitude they already\nhave via the existing cfg_attr pattern.\n\nThis commit is intentionally lint-failing: subsequent commits in this\nPR fix the call sites that the new lints surface.",
          "is_bot": false,
          "headline": "chore(clippy): enable indexing_slicing and unwrap_in_result lints",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6a59395bcd0a0a5eca2b1f5587ee7352ba7c45b",
          "body": "The boundary check accepted any token of at least min_token_len bytes,\nso protocol one accepted e.g. a 20-byte token and protocol two a\n33-byte one. CTAP 2.1 requires the decrypted pinUvAuthToken to be\nexactly 16 or 32 bytes for protocol one and exactly 32 bytes for\nprotocol two. Replace the minimum-length check with an exact-length\nhelper and unit-test it.",
          "is_bot": false,
          "headline": "fix(pin): require exact pinUvAuthToken length per protocol",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:04:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f53fbad2859eca9fad8c2a3569d1785371ff8b0",
          "body": "`RegisterResponse::try_upgrade` asserts that the canonical CBOR\nencoding of the synthesized COSE P-256 key is exactly 77 bytes. The\n77-byte assumption holds for current `cosey 0.3` output, but is\nimplementation-defined: a future `cosey` revision adding an optional\nfield (e.g., `kid`) would round-tri\n[…]\n5df814b)\nmissed this site because `clippy::panic` does not lint `assert!`.\n\nReplace the assertion with a typed length check that returns\n`Error::Platform(PlatformError::CryptoError(...))` on mismatch.",
          "is_bot": false,
          "headline": "fix(u2f): replace production assert! in U2F register response upgrade",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:04:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6f0dcacf7ce34b625379b92c8e377187ae3b036",
          "body": "After Noise transport decryption, the last byte of the plaintext is\nread as a 0..=255 padding length and the frame is truncated by\n`padding_len + 1`. Two crash inputs are reachable from any\nlegitimate-but-malicious paired peer:\n\n1. Empty plaintext (Noise transport accepts a 16-byte AEAD-tag-only\n   \n[…]\n `.last()` and `.checked_sub`, returning\n`Error::Transport(TransportError::InvalidFraming)` on either edge\ncase. Add regression tests for the empty and overlong-padding inputs\nplus a happy-path check.",
          "is_bot": false,
          "headline": "fix(cable): bound decrypt_frame indexing on malformed Noise plaintext",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:04:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6a562185f35d402df5fd8fdb46ba56cd5e14ad0b",
          "body": "…ation\n\nA malicious or buggy authenticator can advertise `pinUvAuthToken=true`\nwithout `clientPin` set (or supported). CTAP 2.2 §6.4 makes these\noptions independent and the platform must tolerate any combination.\nThe current `assert!(self.option_enabled(\"clientPin\"))` panics on this\npath, taking dow\n[…]\nken supported but PIN not set\".\nThe caller can still establish a shared secret (e.g., for hmac-secret),\nwhile not attempting a PIN-token ceremony that the device cannot\nservice. Add a regression test.",
          "is_bot": false,
          "headline": "fix(get_info): graceful early-return in Ctap2GetInfoResponse::uv_oper…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:04:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99fa2658179940647d0260a3fe6d06600d0805fb",
          "body": "`PinUvAuthProtocolTwo::{encrypt, decrypt}` use `&key[32..]` to discard\nthe HMAC-key portion of the shared secret, and `authenticate` uses\n`&key[..32]`. Both panic with an out-of-bounds slice index if the key\nis shorter than 32 bytes.\n\nThis is reachable from device-controlled data: in `user_verificat\n[…]\nlength at the boundary\n(16 bytes for PUAP1 per CTAP 2.2 §6.5.5.7 step 3.7, 32 bytes for\nPUAP2). Update PUAP1 mocks to use a spec-correct 16-byte token. Add\nregression tests for empty and 16-byte keys.",
          "is_bot": false,
          "headline": "fix(pin): bounds-checked slicing in PIN/UV protocol 2 primitives",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:04:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "234fdbcc32c30c3a93e634bbacd766444d02372f",
          "body": "A malicious or buggy authenticator can return an `EcdhEsHkdf256PublicKey`\nwhose x or y coordinate is shorter than 32 bytes. `cosey` accepts any\nlength up to 32, but `EncodedPoint::from_affine_coordinates` requires\nexactly 32 bytes per coordinate; the `.into()` calls invoke\n`GenericArray::from_slice`\n[…]\ns x and y to be 32 bytes (P-256 field-element\nsize). Validate explicitly via `try_into` and return\n`Error::Ctap(CtapError::Other)` on mismatch. Add regression tests for\nshort and empty x, and short y.",
          "is_bot": false,
          "headline": "fix(pin): validate peer COSE EC2 key x/y length in PIN/UV ECDH",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T18:04:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36cfe412ec6c720eeae4f4225d3203dc21cfb856",
          "body": "…lacks largeBlobs\n\nPreviously the FIDO2 path emitted a warn! when extensions.largeBlob.support\n== Required and the device did not advertise the largeBlobs option, then\nforwarded the request as if largeBlob were preferred. The device returned\nsuccess but ignored the extension, leaving the caller with\n[…]\nsionInput from ops::webauthn so\nthe type required to construct MakeCredentialsRequestExtensions::large_blob\nis part of the public API surface.\n\nRefs: WebAuthn L3 section 10.1.5; CTAP 2.1 section 12.1.",
          "is_bot": false,
          "headline": "fix(webauthn): enforce largeBlob: required on FIDO2 path when device …",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:57:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee2f984f0bf534f9341d0f61783d28a05be09423",
          "body": "…eBlob required\n\nMakeCredentialRequest::is_downgradable() previously rejected only when ES256\nwas unsupported, resident_key was Required, or user_verification was Required.\nRequests carrying credProtect with enforce_policy or largeBlob: required were\nsilently downgraded into U2F credentials that cou\n[…]\nRequired.\n\nBoth checks mirror the FIDO2 path's existing enforcement in\nCtap2MakeCredentialsRequestExtensions::from_webauthn_request.\n\nRefs: WebAuthn L3 section 10.1.5; CTAP 2.1 sections 10.2 and 12.1.",
          "is_bot": false,
          "headline": "fix(webauthn): refuse U2F downgrade when credProtect enforced or larg…",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:57:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04fa23336d096739d04aaa3457b1e7c2ecdfadce",
          "body": "The From<&ApduRequest> for Command impl was calling\nCommand::new_with_payload, which produced a Case 3 APDU and dropped\nthe response_max_length field. U2F REGISTER and AUTHENTICATE require\na Case 4 APDU per FIDO U2F NFC section 3.1.\n\nSwitch to new_with_payload_le so Le is included when the request asks\nfor a response. For the typical short-form request (le=256), apdu-core\nencodes Le as a single 0x00 byte.",
          "is_bot": false,
          "headline": "fix(nfc): propagate response_max_length as Le on CTAP1 APDUs",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:52:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6847f02d8d984eafc1854f5a1c27eecccc5f24de",
          "body": "U2F REGISTER and AUTHENTICATE are Case 4 APDUs per FIDO U2F Raw\nMessage Formats v1.2 sections 3 and 4. The encoder previously stopped\nafter the Lc + data field, silently dropping the response_max_length\nthat callers were setting. Strict authenticators reject these as\nCase 3 (no response expected) requests.\n\nAppend a 2-byte big-endian Le when response_max_length is Some, with\nvalues >= 65536 encoded as the 0x0000 wildcard.",
          "is_bot": false,
          "headline": "fix(ctap1): emit extended-length Le in ApduRequest::raw_long",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:52:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "41a8a7a4d4837bf07a1033c510d912a6571567aa",
          "body": null,
          "is_bot": false,
          "headline": "test(ctap2): cover status-code propagation across CTAP2 methods",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:47:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2db6b8be5a76998990b107938d95fd2ecc7f0b63",
          "body": "ctap2_get_next_assertion was the only CTAP2 method that did not match\nthe response's status byte before parsing data. A non-OK status (e.g.\nCTAP2_ERR_NOT_ALLOWED when the 30-second window expires) was masked as\nPlatformError::InvalidDeviceResponse, and undefined trailing bytes\nafter a non-OK status could be parsed as a valid assertion.\n\nAdd the standard status_code match block and a regression test that\nasserts a non-OK status surfaces the correct CtapError variant.",
          "is_bot": false,
          "headline": "fix(ctap2): check status code in getNextAssertion",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:47:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f90f86aa3e2e2460baa58b5f7f1f1616e65e181",
          "body": "ClientData::to_json hand-rolled a JSON object with format!(), concatenating\nthe origin and topOrigin strings unescaped. An origin containing a double\nquote, backslash, or U+0000-U+001F produced malformed JSON, and a hostile\norigin like 'https://example.com\",\"origin\":\"https://attacker.com'\nyielded a \n[…]\n escapes.\n\nAdd regression tests covering hostile origins and topOrigins (double\nquote, backslash, control characters), spec-conformant field ordering\nwith and without topOrigin, and a full round-trip.",
          "is_bot": false,
          "headline": "fix(webauthn): escape clientDataJSON strings per CCDToString",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-14T17:41:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "927b548781afdc4396784ca084b618d1d6d9141b",
          "body": "Refactor: move internal `_`-prefixed methods out of the public\n`WebAuthn` trait, and into module-private free functions. Keeping only\n`webauthn_make_credential` and `webauthn_get_assertion` in the public\nWebAuthn API surface.\n\nNo behaviour changes.",
          "is_bot": false,
          "headline": "refactor(webauthn): remove private methods with underscore prefix (#179)",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-12T18:38:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9099de3b947d421c5ff99ec1534f48df22d86082",
          "body": "…(#197)\n\nStricter CTAP 2.1+ NFC authenticators advertise the version string\n`FIDO_2_1`, `FIDO_2_1_PRE`, or `FIDO_2_2` from the FIDO AID SELECT\nresponse without shadowing as `U2F_V2`. The current code only matches\n`FIDO_2_0` and `U2F_V2`, so those devices are reported as supporting\nneither protocol.\n\n[…]\ns in `select_fido2`.\n- Add a unit test for the version-string classifier.\n\nOther NFC items (CTAP2 keepalive, SELECT Le, SW preservation) are\ntracked separately in #195.\n\nRefs: CTAP 2.2 section 11.3.1.",
          "is_bot": false,
          "headline": "fix(nfc): recognise FIDO_2_1, FIDO_2_1_PRE, FIDO_2_2 in select_fido2 …",
          "author_name": "Alfie Fresta",
          "author_login": "AlfioEmanueleFresta",
          "committed_at": "2026-05-12T18:23:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 10,
      "commits_last_year": 142,
      "latest_release_at": "2026-07-14T18:31:27Z",
      "latest_release_tag": "libwebauthn-v0.10.0",
      "releases_from_tags": false,
      "days_since_last_push": 7,
      "active_weeks_last_year": 22,
      "days_since_latest_release": 7,
      "mean_days_between_releases": 39.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "libwebauthn",
          "exists": true,
          "license": "LGPL-2.1-or-later",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": true,
          "registry_url": "https://crates.io/crates/libwebauthn",
          "is_deprecated": false,
          "latest_version": "0.10.0",
          "repository_url": "https://github.com/linux-credentials/libwebauthn",
          "versions_count": 11,
          "total_downloads": 8290,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 2324,
          "first_published_at": "2025-04-06T20:26:36.055793Z",
          "latest_published_at": "2026-07-14T18:31:35.476992Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 7
        }
      ]
    },
    "popularity": {
      "forks": 25,
      "stars": 567,
      "watchers": 23,
      "fork_history": {
        "days": [
          {
            "date": "2020-04-13",
            "count": 1
          },
          {
            "date": "2022-10-23",
            "count": 2
          },
          {
            "date": "2022-10-24",
            "count": 1
          },
          {
            "date": "2022-10-27",
            "count": 1
          },
          {
            "date": "2022-10-30",
            "count": 1
          },
          {
            "date": "2023-05-20",
            "count": 1
          },
          {
            "date": "2023-10-18",
            "count": 1
          },
          {
            "date": "2024-05-18",
            "count": 1
          },
          {
            "date": "2024-06-02",
            "count": 1
          },
          {
            "date": "2024-06-19",
            "count": 1
          },
          {
            "date": "2024-06-27",
            "count": 1
          },
          {
            "date": "2024-09-14",
            "count": 1
          },
          {
            "date": "2025-01-03",
            "count": 1
          },
          {
            "date": "2025-02-15",
            "count": 1
          },
          {
            "date": "2025-05-02",
            "count": 1
          },
          {
            "date": "2025-07-06",
            "count": 1
          },
          {
            "date": "2025-07-27",
            "count": 1
          },
          {
            "date": "2025-08-19",
            "count": 1
          },
          {
            "date": "2026-02-04",
            "count": 1
          },
          {
            "date": "2026-03-31",
            "count": 1
          },
          {
            "date": "2026-05-04",
            "count": 1
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-06-09",
            "count": 1
          },
          {
            "date": "2026-06-11",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 25,
        "total_forks": 25
      },
      "star_history": {
        "days": [
          {
            "date": "2020-07-25",
            "count": 1
          },
          {
            "date": "2020-11-07",
            "count": 1
          },
          {
            "date": "2021-03-21",
            "count": 1
          },
          {
            "date": "2021-06-07",
            "count": 2
          },
          {
            "date": "2021-06-15",
            "count": 1
          },
          {
            "date": "2021-06-25",
            "count": 1
          },
          {
            "date": "2021-10-22",
            "count": 1
          },
          {
            "date": "2021-12-10",
            "count": 1
          },
          {
            "date": "2022-02-20",
            "count": 1
          },
          {
            "date": "2022-03-03",
            "count": 1
          },
          {
            "date": "2022-04-09",
            "count": 1
          },
          {
            "date": "2022-04-26",
            "count": 1
          },
          {
            "date": "2022-05-30",
            "count": 1
          },
          {
            "date": "2022-06-01",
            "count": 1
          },
          {
            "date": "2022-06-30",
            "count": 1
          },
          {
            "date": "2022-07-25",
            "count": 1
          },
          {
            "date": "2022-08-01",
            "count": 1
          },
          {
            "date": "2022-08-20",
            "count": 1
          },
          {
            "date": "2022-10-22",
            "count": 4
          },
          {
            "date": "2022-10-23",
            "count": 33
          },
          {
            "date": "2022-10-24",
            "count": 105
          },
          {
            "date": "2022-10-25",
            "count": 15
          },
          {
            "date": "2022-10-26",
            "count": 13
          },
          {
            "date": "2022-10-27",
            "count": 5
          },
          {
            "date": "2022-10-28",
            "count": 3
          },
          {
            "date": "2022-10-29",
            "count": 4
          },
          {
            "date": "2022-10-30",
            "count": 1
          },
          {
            "date": "2022-11-01",
            "count": 4
          },
          {
            "date": "2022-11-02",
            "count": 2
          },
          {
            "date": "2022-11-04",
            "count": 1
          },
          {
            "date": "2022-11-07",
            "count": 1
          },
          {
            "date": "2022-11-08",
            "count": 2
          },
          {
            "date": "2022-11-16",
            "count": 1
          },
          {
            "date": "2022-11-17",
            "count": 1
          },
          {
            "date": "2022-11-19",
            "count": 1
          },
          {
            "date": "2022-11-27",
            "count": 1
          },
          {
            "date": "2022-11-30",
            "count": 2
          },
          {
            "date": "2022-12-06",
            "count": 1
          },
          {
            "date": "2022-12-11",
            "count": 1
          },
          {
            "date": "2022-12-13",
            "count": 2
          },
          {
            "date": "2022-12-23",
            "count": 1
          },
          {
            "date": "2023-01-08",
            "count": 1
          },
          {
            "date": "2023-01-16",
            "count": 1
          },
          {
            "date": "2023-01-17",
            "count": 1
          },
          {
            "date": "2023-01-22",
            "count": 1
          },
          {
            "date": "2023-01-23",
            "count": 2
          },
          {
            "date": "2023-02-02",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-02-14",
            "count": 1
          },
          {
            "date": "2023-03-11",
            "count": 1
          },
          {
            "date": "2023-03-12",
            "count": 1
          },
          {
            "date": "2023-03-21",
            "count": 1
          },
          {
            "date": "2023-03-23",
            "count": 1
          },
          {
            "date": "2023-03-28",
            "count": 1
          },
          {
            "date": "2023-03-30",
            "count": 1
          },
          {
            "date": "2023-03-31",
            "count": 1
          },
          {
            "date": "2023-04-11",
            "count": 1
          },
          {
            "date": "2023-04-18",
            "count": 1
          },
          {
            "date": "2023-04-19",
            "count": 1
          },
          {
            "date": "2023-04-27",
            "count": 1
          },
          {
            "date": "2023-05-01",
            "count": 1
          },
          {
            "date": "2023-05-05",
            "count": 1
          },
          {
            "date": "2023-05-07",
            "count": 1
          },
          {
            "date": "2023-05-13",
            "count": 1
          },
          {
            "date": "2023-05-17",
            "count": 3
          },
          {
            "date": "2023-05-18",
            "count": 1
          },
          {
            "date": "2023-05-19",
            "count": 1
          },
          {
            "date": "2023-05-21",
            "count": 1
          },
          {
            "date": "2023-05-25",
            "count": 1
          },
          {
            "date": "2023-05-26",
            "count": 2
          },
          {
            "date": "2023-05-28",
            "count": 1
          },
          {
            "date": "2023-06-07",
            "count": 1
          },
          {
            "date": "2023-06-24",
            "count": 1
          },
          {
            "date": "2023-06-25",
            "count": 1
          },
          {
            "date": "2023-06-26",
            "count": 1
          },
          {
            "date": "2023-07-02",
            "count": 1
          },
          {
            "date": "2023-07-12",
            "count": 2
          },
          {
            "date": "2023-07-13",
            "count": 1
          },
          {
            "date": "2023-07-28",
            "count": 1
          },
          {
            "date": "2023-08-02",
            "count": 1
          },
          {
            "date": "2023-08-07",
            "count": 1
          },
          {
            "date": "2023-08-25",
            "count": 1
          },
          {
            "date": "2023-09-08",
            "count": 1
          },
          {
            "date": "2023-09-10",
            "count": 1
          },
          {
            "date": "2023-09-18",
            "count": 1
          },
          {
            "date": "2023-09-19",
            "count": 1
          },
          {
            "date": "2023-09-27",
            "count": 1
          },
          {
            "date": "2023-09-30",
            "count": 1
          },
          {
            "date": "2023-10-10",
            "count": 1
          },
          {
            "date": "2023-10-11",
            "count": 1
          },
          {
            "date": "2023-10-17",
            "count": 1
          },
          {
            "date": "2023-10-18",
            "count": 3
          },
          {
            "date": "2023-10-25",
            "count": 1
          },
          {
            "date": "2023-10-26",
            "count": 1
          },
          {
            "date": "2023-10-27",
            "count": 1
          },
          {
            "date": "2023-10-31",
            "count": 1
          },
          {
            "date": "2023-11-02",
            "count": 1
          },
          {
            "date": "2023-11-03",
            "count": 1
          },
          {
            "date": "2023-11-29",
            "count": 1
          },
          {
            "date": "2023-12-03",
            "count": 1
          },
          {
            "date": "2023-12-12",
            "count": 1
          },
          {
            "date": "2023-12-13",
            "count": 2
          },
          {
            "date": "2023-12-14",
            "count": 1
          },
          {
            "date": "2023-12-20",
            "count": 1
          },
          {
            "date": "2024-01-03",
            "count": 1
          },
          {
            "date": "2024-01-15",
            "count": 1
          },
          {
            "date": "2024-01-28",
            "count": 1
          },
          {
            "date": "2024-01-31",
            "count": 1
          },
          {
            "date": "2024-02-03",
            "count": 2
          },
          {
            "date": "2024-02-15",
            "count": 1
          },
          {
            "date": "2024-02-18",
            "count": 1
          },
          {
            "date": "2024-02-20",
            "count": 1
          },
          {
            "date": "2024-02-27",
            "count": 1
          },
          {
            "date": "2024-03-07",
            "count": 1
          },
          {
            "date": "2024-03-11",
            "count": 1
          },
          {
            "date": "2024-03-19",
            "count": 1
          },
          {
            "date": "2024-03-27",
            "count": 1
          },
          {
            "date": "2024-04-02",
            "count": 1
          },
          {
            "date": "2024-04-08",
            "count": 1
          },
          {
            "date": "2024-04-10",
            "count": 1
          },
          {
            "date": "2024-04-14",
            "count": 3
          },
          {
            "date": "2024-04-16",
            "count": 1
          },
          {
            "date": "2024-05-01",
            "count": 2
          },
          {
            "date": "2024-05-12",
            "count": 1
          },
          {
            "date": "2024-05-13",
            "count": 1
          },
          {
            "date": "2024-05-24",
            "count": 1
          },
          {
            "date": "2024-06-03",
            "count": 1
          },
          {
            "date": "2024-06-13",
            "count": 1
          },
          {
            "date": "2024-06-27",
            "count": 1
          },
          {
            "date": "2024-07-01",
            "count": 1
          },
          {
            "date": "2024-07-20",
            "count": 1
          },
          {
            "date": "2024-07-21",
            "count": 1
          },
          {
            "date": "2024-07-23",
            "count": 1
          },
          {
            "date": "2024-07-24",
            "count": 1
          },
          {
            "date": "2024-08-02",
            "count": 1
          },
          {
            "date": "2024-08-06",
            "count": 1
          },
          {
            "date": "2024-08-08",
            "count": 1
          },
          {
            "date": "2024-08-13",
            "count": 1
          },
          {
            "date": "2024-08-15",
            "count": 1
          },
          {
            "date": "2024-08-16",
            "count": 1
          },
          {
            "date": "2024-08-18",
            "count": 1
          },
          {
            "date": "2024-08-21",
            "count": 2
          },
          {
            "date": "2024-08-30",
            "count": 1
          },
          {
            "date": "2024-09-04",
            "count": 1
          },
          {
            "date": "2024-09-14",
            "count": 1
          },
          {
            "date": "2024-09-16",
            "count": 1
          },
          {
            "date": "2024-09-19",
            "count": 1
          },
          {
            "date": "2024-09-20",
            "count": 1
          },
          {
            "date": "2024-09-21",
            "count": 1
          },
          {
            "date": "2024-09-27",
            "count": 2
          },
          {
            "date": "2024-09-30",
            "count": 1
          },
          {
            "date": "2024-10-11",
            "count": 1
          },
          {
            "date": "2024-10-31",
            "count": 1
          },
          {
            "date": "2024-11-02",
            "count": 1
          },
          {
            "date": "2024-11-08",
            "count": 1
          },
          {
            "date": "2024-11-09",
            "count": 3
          },
          {
            "date": "2024-11-10",
            "count": 1
          },
          {
            "date": "2024-11-20",
            "count": 1
          },
          {
            "date": "2024-12-07",
            "count": 1
          },
          {
            "date": "2024-12-08",
            "count": 1
          },
          {
            "date": "2024-12-09",
            "count": 1
          },
          {
            "date": "2024-12-19",
            "count": 1
          },
          {
            "date": "2024-12-23",
            "count": 1
          },
          {
            "date": "2024-12-27",
            "count": 1
          },
          {
            "date": "2024-12-28",
            "count": 1
          },
          {
            "date": "2025-01-05",
            "count": 1
          },
          {
            "date": "2025-01-09",
            "count": 1
          },
          {
            "date": "2025-01-10",
            "count": 1
          },
          {
            "date": "2025-01-11",
            "count": 1
          },
          {
            "date": "2025-01-15",
            "count": 1
          },
          {
            "date": "2025-01-21",
            "count": 1
          },
          {
            "date": "2025-01-23",
            "count": 1
          },
          {
            "date": "2025-01-25",
            "count": 1
          },
          {
            "date": "2025-01-31",
            "count": 1
          },
          {
            "date": "2025-02-13",
            "count": 3
          },
          {
            "date": "2025-02-16",
            "count": 1
          },
          {
            "date": "2025-02-19",
            "count": 2
          },
          {
            "date": "2025-02-20",
            "count": 1
          },
          {
            "date": "2025-02-21",
            "count": 1
          },
          {
            "date": "2025-02-25",
            "count": 1
          },
          {
            "date": "2025-02-27",
            "count": 1
          },
          {
            "date": "2025-03-02",
            "count": 1
          },
          {
            "date": "2025-03-07",
            "count": 1
          },
          {
            "date": "2025-03-08",
            "count": 3
          },
          {
            "date": "2025-03-09",
            "count": 3
          },
          {
            "date": "2025-03-10",
            "count": 2
          },
          {
            "date": "2025-03-18",
            "count": 1
          },
          {
            "date": "2025-03-27",
            "count": 1
          },
          {
            "date": "2025-04-10",
            "count": 1
          },
          {
            "date": "2025-04-11",
            "count": 2
          },
          {
            "date": "2025-04-15",
            "count": 2
          },
          {
            "date": "2025-04-18",
            "count": 1
          },
          {
            "date": "2025-04-19",
            "count": 1
          },
          {
            "date": "2025-05-03",
            "count": 2
          },
          {
            "date": "2025-05-05",
            "count": 1
          },
          {
            "date": "2025-05-14",
            "count": 1
          },
          {
            "date": "2025-05-21",
            "count": 1
          },
          {
            "date": "2025-05-24",
            "count": 1
          },
          {
            "date": "2025-05-29",
            "count": 2
          },
          {
            "date": "2025-06-02",
            "count": 1
          },
          {
            "date": "2025-06-06",
            "count": 1
          },
          {
            "date": "2025-06-24",
            "count": 1
          },
          {
            "date": "2025-06-27",
            "count": 1
          },
          {
            "date": "2025-06-30",
            "count": 1
          },
          {
            "date": "2025-07-01",
            "count": 3
          },
          {
            "date": "2025-07-04",
            "count": 1
          },
          {
            "date": "2025-07-06",
            "count": 1
          },
          {
            "date": "2025-07-17",
            "count": 1
          },
          {
            "date": "2025-07-19",
            "count": 1
          },
          {
            "date": "2025-07-22",
            "count": 1
          },
          {
            "date": "2025-07-25",
            "count": 1
          },
          {
            "date": "2025-07-28",
            "count": 1
          },
          {
            "date": "2025-07-29",
            "count": 1
          },
          {
            "date": "2025-08-01",
            "count": 1
          },
          {
            "date": "2025-08-04",
            "count": 1
          },
          {
            "date": "2025-08-13",
            "count": 1
          },
          {
            "date": "2025-08-15",
            "count": 1
          },
          {
            "date": "2025-08-19",
            "count": 1
          },
          {
            "date": "2025-08-27",
            "count": 2
          },
          {
            "date": "2025-09-02",
            "count": 3
          },
          {
            "date": "2025-09-09",
            "count": 1
          },
          {
            "date": "2025-09-20",
            "count": 1
          },
          {
            "date": "2025-09-25",
            "count": 2
          },
          {
            "date": "2025-09-30",
            "count": 1
          },
          {
            "date": "2025-10-04",
            "count": 1
          },
          {
            "date": "2025-10-09",
            "count": 1
          },
          {
            "date": "2025-10-10",
            "count": 2
          },
          {
            "date": "2025-10-13",
            "count": 2
          },
          {
            "date": "2025-10-20",
            "count": 1
          },
          {
            "date": "2025-10-30",
            "count": 1
          },
          {
            "date": "2025-11-06",
            "count": 1
          },
          {
            "date": "2025-11-08",
            "count": 1
          },
          {
            "date": "2025-11-09",
            "count": 1
          },
          {
            "date": "2025-11-13",
            "count": 1
          },
          {
            "date": "2025-11-30",
            "count": 1
          },
          {
            "date": "2025-12-03",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 1
          },
          {
            "date": "2025-12-09",
            "count": 1
          },
          {
            "date": "2025-12-11",
            "count": 1
          },
          {
            "date": "2025-12-12",
            "count": 1
          },
          {
            "date": "2025-12-13",
            "count": 1
          },
          {
            "date": "2025-12-15",
            "count": 1
          },
          {
            "date": "2025-12-20",
            "count": 1
          },
          {
            "date": "2025-12-26",
            "count": 1
          },
          {
            "date": "2025-12-31",
            "count": 1
          },
          {
            "date": "2026-01-02",
            "count": 2
          },
          {
            "date": "2026-01-03",
            "count": 2
          },
          {
            "date": "2026-01-04",
            "count": 1
          },
          {
            "date": "2026-01-05",
            "count": 2
          },
          {
            "date": "2026-01-06",
            "count": 1
          },
          {
            "date": "2026-01-10",
            "count": 1
          },
          {
            "date": "2026-01-12",
            "count": 1
          },
          {
            "date": "2026-01-14",
            "count": 2
          },
          {
            "date": "2026-01-15",
            "count": 1
          },
          {
            "date": "2026-01-24",
            "count": 2
          },
          {
            "date": "2026-01-25",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-01-31",
            "count": 2
          },
          {
            "date": "2026-02-01",
            "count": 2
          },
          {
            "date": "2026-02-02",
            "count": 1
          },
          {
            "date": "2026-02-03",
            "count": 1
          },
          {
            "date": "2026-02-04",
            "count": 1
          },
          {
            "date": "2026-02-05",
            "count": 2
          },
          {
            "date": "2026-02-06",
            "count": 1
          },
          {
            "date": "2026-02-08",
            "count": 5
          },
          {
            "date": "2026-02-09",
            "count": 5
          },
          {
            "date": "2026-02-10",
            "count": 4
          },
          {
            "date": "2026-02-11",
            "count": 1
          },
          {
            "date": "2026-02-12",
            "count": 1
          },
          {
            "date": "2026-02-16",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-02-20",
            "count": 1
          },
          {
            "date": "2026-02-21",
            "count": 1
          },
          {
            "date": "2026-02-23",
            "count": 1
          },
          {
            "date": "2026-03-01",
            "count": 1
          },
          {
            "date": "2026-03-02",
            "count": 1
          },
          {
            "date": "2026-03-05",
            "count": 2
          },
          {
            "date": "2026-03-09",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 2
          },
          {
            "date": "2026-03-14",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 2
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-04-05",
            "count": 1
          },
          {
            "date": "2026-04-11",
            "count": 2
          },
          {
            "date": "2026-04-12",
            "count": 3
          },
          {
            "date": "2026-04-13",
            "count": 2
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-04-24",
            "count": 1
          },
          {
            "date": "2026-04-26",
            "count": 3
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-05-09",
            "count": 1
          },
          {
            "date": "2026-05-10",
            "count": 1
          },
          {
            "date": "2026-05-13",
            "count": 1
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-05-18",
            "count": 1
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-05-26",
            "count": 1
          },
          {
            "date": "2026-05-27",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-02",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-06-09",
            "count": 3
          },
          {
            "date": "2026-06-11",
            "count": 1
          },
          {
            "date": "2026-06-12",
            "count": 2
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-06-23",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 2
          },
          {
            "date": "2026-07-13",
            "count": 1
          },
          {
            "date": "2026-07-14",
            "count": 1
          },
          {
            "date": "2026-07-16",
            "count": 1
          },
          {
            "date": "2026-07-19",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 567,
        "total_stars": 567
      },
      "open_issues_and_prs": 21
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "Cargo.toml",
        "libwebauthn-tests/Cargo.toml",
        "libwebauthn/Cargo.toml"
      ],
      "largest_source_bytes": 102029,
      "source_files_sampled": 142,
      "oversized_source_files": 4,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "libwebauthn-tests/Cargo.toml",
        "libwebauthn/Cargo.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "quinn-proto",
            "direct": false,
            "version": "0.11.14",
            "severity": "high",
            "ecosystem": "crates",
            "cvss_score": 7.5,
            "advisory_ids": [
              "RUSTSEC-2026-0185"
            ],
            "fixed_version": "0.11.15",
            "advisory_count": 1,
            "oldest_advisory_days": 29
          },
          {
            "name": "anyhow",
            "direct": false,
            "version": "1.0.102",
            "severity": "unknown",
            "ecosystem": "crates",
            "cvss_score": null,
            "advisory_ids": [
              "RUSTSEC-2026-0190"
            ],
            "fixed_version": "1.0.103",
            "advisory_count": 1,
            "oldest_advisory_days": 26
          },
          {
            "name": "atomic-polyfill",
            "direct": false,
            "version": "1.0.3",
            "severity": "unknown",
            "ecosystem": "crates",
            "cvss_score": null,
            "advisory_ids": [
              "RUSTSEC-2023-0089"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 1106
          }
        ],
        "collected": true,
        "truncated": false,
        "by_severity": {
          "high": 1,
          "unknown": 2
        },
        "advisory_count": 3,
        "affected_count": 3,
        "assessed_count": 478,
        "assessed_package": null,
        "unassessed_count": 71,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates"
      ],
      "dependencies": [
        {
          "name": "libwebauthn",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "cosey",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.2"
        },
        {
          "name": "ctaphid",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.1"
        },
        {
          "name": "ctaphid-dispatch",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "delog",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "fido-authenticator",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": null
        },
        {
          "name": "interchange",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.0"
        },
        {
          "name": "littlefs2",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.6.0"
        },
        {
          "name": "num_enum",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7.1"
        },
        {
          "name": "rand",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8.5"
        },
        {
          "name": "tracing",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.29"
        },
        {
          "name": "trussed",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "trussed-staging",
          "manifest": "libwebauthn-tests/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.0"
        },
        {
          "name": "base64-url",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3.0.0"
        },
        {
          "name": "dbus",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.9.5"
        },
        {
          "name": "tracing",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.29"
        },
        {
          "name": "idna",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.3"
        },
        {
          "name": "icu_normalizer",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2"
        },
        {
          "name": "publicsuffix",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.3"
        },
        {
          "name": "url",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.5"
        },
        {
          "name": "http",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "maplit",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.2"
        },
        {
          "name": "sha2",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10.2"
        },
        {
          "name": "uuid",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.5.0"
        },
        {
          "name": "async-trait",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.36"
        },
        {
          "name": "futures",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.5"
        },
        {
          "name": "tokio",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.45"
        },
        {
          "name": "serde",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.110"
        },
        {
          "name": "serde_cbor_2",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "serde-indexed",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2.0"
        },
        {
          "name": "serde_derive",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.123"
        },
        {
          "name": "serde_repr",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1.6"
        },
        {
          "name": "serde_bytes",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11.5"
        },
        {
          "name": "num-traits",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.2"
        },
        {
          "name": "num-derive",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.1"
        },
        {
          "name": "byteorder",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.3.4"
        },
        {
          "name": "num_enum",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7.1"
        },
        {
          "name": "x509-parser",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17.0"
        },
        {
          "name": "time",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.35"
        },
        {
          "name": "curve25519-dalek",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4.1.3"
        },
        {
          "name": "hex",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.3"
        },
        {
          "name": "mockall",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13.1"
        },
        {
          "name": "hidapi",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.4.1"
        },
        {
          "name": "bitflags",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.4.1"
        },
        {
          "name": "rand",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8.5"
        },
        {
          "name": "p256",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13.2"
        },
        {
          "name": "heapless",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "cosey",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.2"
        },
        {
          "name": "spki",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "der",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.7"
        },
        {
          "name": "aes",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8.2"
        },
        {
          "name": "aes-gcm",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "flate2",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0"
        },
        {
          "name": "hmac",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12.1"
        },
        {
          "name": "cbc",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "hkdf",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "zeroize",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.8"
        },
        {
          "name": "text_io",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "tungstenite",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26.2"
        },
        {
          "name": "tokio-tungstenite",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26"
        },
        {
          "name": "rustls",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23.27"
        },
        {
          "name": "tokio-stream",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.1"
        },
        {
          "name": "snow",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "ctap-types",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.0"
        },
        {
          "name": "btleplug",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.11.7"
        },
        {
          "name": "bluer",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "thiserror",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.0.12"
        },
        {
          "name": "serde_json",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1.0.141"
        },
        {
          "name": "apdu-core",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.0"
        },
        {
          "name": "apdu",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4.0"
        },
        {
          "name": "pcsc",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "2.9.0"
        },
        {
          "name": "nfc1",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "=0.6.0"
        },
        {
          "name": "nfc1-sys",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3.9"
        },
        {
          "name": "reqwest",
          "manifest": "libwebauthn/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "aes",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "aes",
            "direct": true,
            "version": "0.8.4",
            "ecosystem": "crates"
          },
          {
            "name": "aes-gcm",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "aes-gcm",
            "direct": true,
            "version": "0.10.3",
            "ecosystem": "crates"
          },
          {
            "name": "apdu",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "apdu",
            "direct": true,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "apdu-core",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "apdu-core",
            "direct": true,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "async-trait",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "async-trait",
            "direct": true,
            "version": "0.1.89",
            "ecosystem": "crates"
          },
          {
            "name": "base64-url",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "base64-url",
            "direct": true,
            "version": "3.0.3",
            "ecosystem": "crates"
          },
          {
            "name": "bitflags",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "bitflags",
            "direct": true,
            "version": "1.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "bitflags",
            "direct": true,
            "version": "2.11.1",
            "ecosystem": "crates"
          },
          {
            "name": "bluer",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "bluer",
            "direct": true,
            "version": "0.17.4",
            "ecosystem": "crates"
          },
          {
            "name": "btleplug",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "btleplug",
            "direct": true,
            "version": "0.11.8",
            "ecosystem": "crates"
          },
          {
            "name": "byteorder",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "byteorder",
            "direct": true,
            "version": "1.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "cbc",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "cbc",
            "direct": true,
            "version": "0.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "cosey",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "cosey",
            "direct": true,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "ctap-types",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ctap-types",
            "direct": true,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "ctaphid",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ctaphid",
            "direct": true,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "ctaphid-dispatch",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "ctaphid-dispatch",
            "direct": true,
            "version": "0.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "curve25519-dalek",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "curve25519-dalek",
            "direct": true,
            "version": "4.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "dbus",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "dbus",
            "direct": true,
            "version": "0.9.11",
            "ecosystem": "crates"
          },
          {
            "name": "delog",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "delog",
            "direct": true,
            "version": "0.1.8",
            "ecosystem": "crates"
          },
          {
            "name": "der",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "der",
            "direct": true,
            "version": "0.4.5",
            "ecosystem": "crates"
          },
          {
            "name": "der",
            "direct": true,
            "version": "0.7.10",
            "ecosystem": "crates"
          },
          {
            "name": "fido-authenticator",
            "direct": true,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "flate2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "flate2",
            "direct": true,
            "version": "1.1.9",
            "ecosystem": "crates"
          },
          {
            "name": "futures",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "futures",
            "direct": true,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "heapless",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "heapless",
            "direct": true,
            "version": "0.7.17",
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hex",
            "direct": true,
            "version": "0.4.3",
            "ecosystem": "crates"
          },
          {
            "name": "hidapi",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hidapi",
            "direct": true,
            "version": "2.6.5",
            "ecosystem": "crates"
          },
          {
            "name": "hkdf",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hkdf",
            "direct": true,
            "version": "0.12.4",
            "ecosystem": "crates"
          },
          {
            "name": "hmac",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "hmac",
            "direct": true,
            "version": "0.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "hmac",
            "direct": true,
            "version": "0.12.1",
            "ecosystem": "crates"
          },
          {
            "name": "http",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "http",
            "direct": true,
            "version": "1.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "icu_normalizer",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "icu_normalizer",
            "direct": true,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "idna",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "idna",
            "direct": true,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "interchange",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "interchange",
            "direct": true,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "littlefs2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "littlefs2",
            "direct": true,
            "version": "0.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "maplit",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "maplit",
            "direct": true,
            "version": "1.0.2",
            "ecosystem": "crates"
          },
          {
            "name": "mockall",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "mockall",
            "direct": true,
            "version": "0.13.1",
            "ecosystem": "crates"
          },
          {
            "name": "nfc1",
            "direct": true,
            "version": "0.6.0",
            "ecosystem": "crates"
          },
          {
            "name": "nfc1-sys",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "nfc1-sys",
            "direct": true,
            "version": "0.3.13",
            "ecosystem": "crates"
          },
          {
            "name": "num-derive",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "num-derive",
            "direct": true,
            "version": "0.4.2",
            "ecosystem": "crates"
          },
          {
            "name": "num-traits",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "num-traits",
            "direct": true,
            "version": "0.2.19",
            "ecosystem": "crates"
          },
          {
            "name": "num_enum",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "num_enum",
            "direct": true,
            "version": "0.7.6",
            "ecosystem": "crates"
          },
          {
            "name": "p256",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "p256",
            "direct": true,
            "version": "0.13.2",
            "ecosystem": "crates"
          },
          {
            "name": "p256",
            "direct": true,
            "version": "0.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "pcsc",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "pcsc",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "publicsuffix",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "publicsuffix",
            "direct": true,
            "version": "2.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "rand",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rand",
            "direct": true,
            "version": "0.8.6",
            "ecosystem": "crates"
          },
          {
            "name": "rand",
            "direct": true,
            "version": "0.9.4",
            "ecosystem": "crates"
          },
          {
            "name": "reqwest",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "reqwest",
            "direct": true,
            "version": "0.12.28",
            "ecosystem": "crates"
          },
          {
            "name": "rustls",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "rustls",
            "direct": true,
            "version": "0.23.40",
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde",
            "direct": true,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde-indexed",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde-indexed",
            "direct": true,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "serde-indexed",
            "direct": true,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "serde_bytes",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_bytes",
            "direct": true,
            "version": "0.11.19",
            "ecosystem": "crates"
          },
          {
            "name": "serde_cbor_2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_cbor_2",
            "direct": true,
            "version": "0.13.0",
            "ecosystem": "crates"
          },
          {
            "name": "serde_derive",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_derive",
            "direct": true,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_json",
            "direct": true,
            "version": "1.0.149",
            "ecosystem": "crates"
          },
          {
            "name": "serde_repr",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "serde_repr",
            "direct": true,
            "version": "0.1.20",
            "ecosystem": "crates"
          },
          {
            "name": "sha2",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "sha2",
            "direct": true,
            "version": "0.10.9",
            "ecosystem": "crates"
          },
          {
            "name": "sha2",
            "direct": true,
            "version": "0.9.9",
            "ecosystem": "crates"
          },
          {
            "name": "snow",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "snow",
            "direct": true,
            "version": "0.10.0",
            "ecosystem": "crates"
          },
          {
            "name": "spki",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "spki",
            "direct": true,
            "version": "0.7.3",
            "ecosystem": "crates"
          },
          {
            "name": "text_io",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "text_io",
            "direct": true,
            "version": "0.1.13",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": true,
            "version": "1.0.69",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror",
            "direct": true,
            "version": "2.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "time",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "time",
            "direct": true,
            "version": "0.3.47",
            "ecosystem": "crates"
          },
          {
            "name": "tokio",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio",
            "direct": true,
            "version": "1.52.3",
            "ecosystem": "crates"
          },
          {
            "name": "tokio-stream",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio-stream",
            "direct": true,
            "version": "0.1.18",
            "ecosystem": "crates"
          },
          {
            "name": "tokio-tungstenite",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tokio-tungstenite",
            "direct": true,
            "version": "0.26.2",
            "ecosystem": "crates"
          },
          {
            "name": "tracing",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing",
            "direct": true,
            "version": "0.1.44",
            "ecosystem": "crates"
          },
          {
            "name": "trussed",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "trussed",
            "direct": true,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "trussed-staging",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "trussed-staging",
            "direct": true,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "tungstenite",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tungstenite",
            "direct": true,
            "version": "0.26.2",
            "ecosystem": "crates"
          },
          {
            "name": "url",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "url",
            "direct": true,
            "version": "2.5.8",
            "ecosystem": "crates"
          },
          {
            "name": "uuid",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "uuid",
            "direct": true,
            "version": "1.23.1",
            "ecosystem": "crates"
          },
          {
            "name": "x509-parser",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "x509-parser",
            "direct": true,
            "version": "0.17.0",
            "ecosystem": "crates"
          },
          {
            "name": "zeroize",
            "direct": true,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "zeroize",
            "direct": true,
            "version": "1.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "adler2",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "aead",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "crates"
          },
          {
            "name": "aho-corasick",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "anstream",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle",
            "direct": false,
            "version": "1.0.14",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle-parse",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle-query",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "crates"
          },
          {
            "name": "anstyle-wincon",
            "direct": false,
            "version": "3.0.11",
            "ecosystem": "crates"
          },
          {
            "name": "anyhow",
            "direct": false,
            "version": "1.0.102",
            "ecosystem": "crates"
          },
          {
            "name": "apdu-app",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "apdu-derive",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "asn1-rs",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "crates"
          },
          {
            "name": "asn1-rs-derive",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "crates"
          },
          {
            "name": "asn1-rs-impl",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "atomic-polyfill",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "crates"
          },
          {
            "name": "atomic-waker",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "autocfg",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "base16ct",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "base64",
            "direct": false,
            "version": "0.22.1",
            "ecosystem": "crates"
          },
          {
            "name": "base64ct",
            "direct": false,
            "version": "1.8.3",
            "ecosystem": "crates"
          },
          {
            "name": "bindgen",
            "direct": false,
            "version": "0.70.1",
            "ecosystem": "crates"
          },
          {
            "name": "bindgen",
            "direct": false,
            "version": "0.72.1",
            "ecosystem": "crates"
          },
          {
            "name": "blake2",
            "direct": false,
            "version": "0.10.6",
            "ecosystem": "crates"
          },
          {
            "name": "block-buffer",
            "direct": false,
            "version": "0.10.4",
            "ecosystem": "crates"
          },
          {
            "name": "block-buffer",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "block-padding",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "crates"
          },
          {
            "name": "block2",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "bluez-async",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "bluez-generated",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "bumpalo",
            "direct": false,
            "version": "3.20.2",
            "ecosystem": "crates"
          },
          {
            "name": "bytemuck",
            "direct": false,
            "version": "1.25.0",
            "ecosystem": "crates"
          },
          {
            "name": "byteorder-lite",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "crates"
          },
          {
            "name": "cbor-smol",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "cc",
            "direct": false,
            "version": "1.2.62",
            "ecosystem": "crates"
          },
          {
            "name": "cesu8",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "cexpr",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "crates"
          },
          {
            "name": "cfg-if",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "cfg_aliases",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "chacha20",
            "direct": false,
            "version": "0.9.1",
            "ecosystem": "crates"
          },
          {
            "name": "chacha20poly1305",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "cipher",
            "direct": false,
            "version": "0.4.4",
            "ecosystem": "crates"
          },
          {
            "name": "clang-sys",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "crates"
          },
          {
            "name": "colorchoice",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "crates"
          },
          {
            "name": "combine",
            "direct": false,
            "version": "4.6.7",
            "ecosystem": "crates"
          },
          {
            "name": "const-oid",
            "direct": false,
            "version": "0.9.6",
            "ecosystem": "crates"
          },
          {
            "name": "core-foundation",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "core-foundation-sys",
            "direct": false,
            "version": "0.8.7",
            "ecosystem": "crates"
          },
          {
            "name": "cpufeatures",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "crates"
          },
          {
            "name": "crc32fast",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "critical-section",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "crossbeam-utils",
            "direct": false,
            "version": "0.8.21",
            "ecosystem": "crates"
          },
          {
            "name": "crunchy",
            "direct": false,
            "version": "0.2.4",
            "ecosystem": "crates"
          },
          {
            "name": "crypto-bigint",
            "direct": false,
            "version": "0.2.5",
            "ecosystem": "crates"
          },
          {
            "name": "crypto-bigint",
            "direct": false,
            "version": "0.5.5",
            "ecosystem": "crates"
          },
          {
            "name": "crypto-common",
            "direct": false,
            "version": "0.1.7",
            "ecosystem": "crates"
          },
          {
            "name": "crypto-mac",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "ctaphid-app",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "ctaphid-types",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "ctr",
            "direct": false,
            "version": "0.9.2",
            "ecosystem": "crates"
          },
          {
            "name": "cty",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "curve25519-dalek-derive",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "dashmap",
            "direct": false,
            "version": "5.5.3",
            "ecosystem": "crates"
          },
          {
            "name": "dashmap",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "data-encoding",
            "direct": false,
            "version": "2.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "dbus-tokio",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "crates"
          },
          {
            "name": "der-parser",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "der_derive",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "der_derive",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "crates"
          },
          {
            "name": "deranged",
            "direct": false,
            "version": "0.5.8",
            "ecosystem": "crates"
          },
          {
            "name": "des",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "crates"
          },
          {
            "name": "digest",
            "direct": false,
            "version": "0.10.7",
            "ecosystem": "crates"
          },
          {
            "name": "digest",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "displaydoc",
            "direct": false,
            "version": "0.2.5",
            "ecosystem": "crates"
          },
          {
            "name": "downcast",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "ecdsa",
            "direct": false,
            "version": "0.12.4",
            "ecosystem": "crates"
          },
          {
            "name": "ecdsa",
            "direct": false,
            "version": "0.16.9",
            "ecosystem": "crates"
          },
          {
            "name": "ed25519",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "crates"
          },
          {
            "name": "either",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "crates"
          },
          {
            "name": "elliptic-curve",
            "direct": false,
            "version": "0.10.4",
            "ecosystem": "crates"
          },
          {
            "name": "elliptic-curve",
            "direct": false,
            "version": "0.13.8",
            "ecosystem": "crates"
          },
          {
            "name": "encoding_rs",
            "direct": false,
            "version": "0.8.35",
            "ecosystem": "crates"
          },
          {
            "name": "env_filter",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "env_logger",
            "direct": false,
            "version": "0.11.10",
            "ecosystem": "crates"
          },
          {
            "name": "equivalent",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "crates"
          },
          {
            "name": "errno",
            "direct": false,
            "version": "0.3.14",
            "ecosystem": "crates"
          },
          {
            "name": "fastrand",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "ff",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "ff",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "crates"
          },
          {
            "name": "fiat-crypto",
            "direct": false,
            "version": "0.2.9",
            "ecosystem": "crates"
          },
          {
            "name": "find-msvc-tools",
            "direct": false,
            "version": "0.1.9",
            "ecosystem": "crates"
          },
          {
            "name": "find-winsdk",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "flexiber",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "flexiber_derive",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "fnv",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "crates"
          },
          {
            "name": "foldhash",
            "direct": false,
            "version": "0.1.5",
            "ecosystem": "crates"
          },
          {
            "name": "form_urlencoded",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "fragile",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "futures-channel",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-core",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-executor",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-io",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-macro",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-sink",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-task",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "futures-util",
            "direct": false,
            "version": "0.3.32",
            "ecosystem": "crates"
          },
          {
            "name": "generator",
            "direct": false,
            "version": "0.7.5",
            "ecosystem": "crates"
          },
          {
            "name": "generic-array",
            "direct": false,
            "version": "0.14.7",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": false,
            "version": "0.3.4",
            "ecosystem": "crates"
          },
          {
            "name": "getrandom",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "crates"
          },
          {
            "name": "ghash",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "crates"
          },
          {
            "name": "group",
            "direct": false,
            "version": "0.10.0",
            "ecosystem": "crates"
          },
          {
            "name": "group",
            "direct": false,
            "version": "0.13.0",
            "ecosystem": "crates"
          },
          {
            "name": "h2",
            "direct": false,
            "version": "0.4.14",
            "ecosystem": "crates"
          },
          {
            "name": "half",
            "direct": false,
            "version": "2.7.1",
            "ecosystem": "crates"
          },
          {
            "name": "hash32",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "hashbrown",
            "direct": false,
            "version": "0.14.5",
            "ecosystem": "crates"
          },
          {
            "name": "hashbrown",
            "direct": false,
            "version": "0.15.5",
            "ecosystem": "crates"
          },
          {
            "name": "hashbrown",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "crates"
          },
          {
            "name": "heapless-bytes",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "heck",
            "direct": false,
            "version": "0.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "hex-literal",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "http-body",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "http-body-util",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "httparse",
            "direct": false,
            "version": "1.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "hyper",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "hyper-rustls",
            "direct": false,
            "version": "0.27.9",
            "ecosystem": "crates"
          },
          {
            "name": "hyper-util",
            "direct": false,
            "version": "0.1.20",
            "ecosystem": "crates"
          },
          {
            "name": "icu_collections",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "icu_locale_core",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "icu_normalizer_data",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "icu_properties",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "icu_properties_data",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "icu_provider",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "id-arena",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "idna_adapter",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "image",
            "direct": false,
            "version": "0.25.10",
            "ecosystem": "crates"
          },
          {
            "name": "indexmap",
            "direct": false,
            "version": "2.14.0",
            "ecosystem": "crates"
          },
          {
            "name": "inout",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "ipnet",
            "direct": false,
            "version": "2.12.0",
            "ecosystem": "crates"
          },
          {
            "name": "is_terminal_polyfill",
            "direct": false,
            "version": "1.70.2",
            "ecosystem": "crates"
          },
          {
            "name": "iso7816",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "itertools",
            "direct": false,
            "version": "0.13.0",
            "ecosystem": "crates"
          },
          {
            "name": "itertools",
            "direct": false,
            "version": "0.14.0",
            "ecosystem": "crates"
          },
          {
            "name": "itoa",
            "direct": false,
            "version": "1.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "jni",
            "direct": false,
            "version": "0.19.0",
            "ecosystem": "crates"
          },
          {
            "name": "jni-sys",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "jni-sys",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "jni-sys-macros",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "jni-utils",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "js-sys",
            "direct": false,
            "version": "0.3.98",
            "ecosystem": "crates"
          },
          {
            "name": "lazy_static",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "leb128fmt",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "libc",
            "direct": false,
            "version": "0.2.186",
            "ecosystem": "crates"
          },
          {
            "name": "libdbus-sys",
            "direct": false,
            "version": "0.2.7",
            "ecosystem": "crates"
          },
          {
            "name": "libloading",
            "direct": false,
            "version": "0.8.9",
            "ecosystem": "crates"
          },
          {
            "name": "linux-raw-sys",
            "direct": false,
            "version": "0.12.1",
            "ecosystem": "crates"
          },
          {
            "name": "litemap",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "littlefs2-core",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "littlefs2-sys",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "lock_api",
            "direct": false,
            "version": "0.4.14",
            "ecosystem": "crates"
          },
          {
            "name": "log",
            "direct": false,
            "version": "0.4.29",
            "ecosystem": "crates"
          },
          {
            "name": "loom",
            "direct": false,
            "version": "0.5.6",
            "ecosystem": "crates"
          },
          {
            "name": "lru-slab",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "macaddr",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "matchers",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "memchr",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "crates"
          },
          {
            "name": "mime",
            "direct": false,
            "version": "0.3.17",
            "ecosystem": "crates"
          },
          {
            "name": "minimal-lexical",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "miniz_oxide",
            "direct": false,
            "version": "0.8.9",
            "ecosystem": "crates"
          },
          {
            "name": "mio",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "mockall_derive",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "crates"
          },
          {
            "name": "moxcms",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "crates"
          },
          {
            "name": "nb",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "nix",
            "direct": false,
            "version": "0.29.0",
            "ecosystem": "crates"
          },
          {
            "name": "nom",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "nu-ansi-term",
            "direct": false,
            "version": "0.50.3",
            "ecosystem": "crates"
          },
          {
            "name": "num-bigint",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "crates"
          },
          {
            "name": "num-conv",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "num-integer",
            "direct": false,
            "version": "0.1.46",
            "ecosystem": "crates"
          },
          {
            "name": "num_enum_derive",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "crates"
          },
          {
            "name": "objc-sys",
            "direct": false,
            "version": "0.3.5",
            "ecosystem": "crates"
          },
          {
            "name": "objc2",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-core-bluetooth",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-encode",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "objc2-foundation",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "oid-registry",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "crates"
          },
          {
            "name": "once_cell",
            "direct": false,
            "version": "1.21.4",
            "ecosystem": "crates"
          },
          {
            "name": "once_cell_polyfill",
            "direct": false,
            "version": "1.70.2",
            "ecosystem": "crates"
          },
          {
            "name": "opaque-debug",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "openssl-probe",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "p256-cortex-m4",
            "direct": false,
            "version": "0.1.0-alpha.6",
            "ecosystem": "crates"
          },
          {
            "name": "p256-cortex-m4-sys",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "parking_lot",
            "direct": false,
            "version": "0.12.5",
            "ecosystem": "crates"
          },
          {
            "name": "parking_lot_core",
            "direct": false,
            "version": "0.9.12",
            "ecosystem": "crates"
          },
          {
            "name": "pcsc-sys",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "pem-rfc7468",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "crates"
          },
          {
            "name": "percent-encoding",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "pin-project-lite",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "crates"
          },
          {
            "name": "pkcs8",
            "direct": false,
            "version": "0.10.2",
            "ecosystem": "crates"
          },
          {
            "name": "pkg-config",
            "direct": false,
            "version": "0.3.33",
            "ecosystem": "crates"
          },
          {
            "name": "poly1305",
            "direct": false,
            "version": "0.8.0",
            "ecosystem": "crates"
          },
          {
            "name": "polyval",
            "direct": false,
            "version": "0.6.2",
            "ecosystem": "crates"
          },
          {
            "name": "postcard",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "crates"
          },
          {
            "name": "postcard-cobs",
            "direct": false,
            "version": "0.1.5-pre",
            "ecosystem": "crates"
          },
          {
            "name": "potential_utf",
            "direct": false,
            "version": "0.1.5",
            "ecosystem": "crates"
          },
          {
            "name": "powerfmt",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "ppv-lite86",
            "direct": false,
            "version": "0.2.21",
            "ecosystem": "crates"
          },
          {
            "name": "predicates",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "predicates-core",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "crates"
          },
          {
            "name": "predicates-tree",
            "direct": false,
            "version": "1.0.13",
            "ecosystem": "crates"
          },
          {
            "name": "prettyplease",
            "direct": false,
            "version": "0.2.37",
            "ecosystem": "crates"
          },
          {
            "name": "primeorder",
            "direct": false,
            "version": "0.13.6",
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro-crate",
            "direct": false,
            "version": "3.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "proc-macro2",
            "direct": false,
            "version": "1.0.106",
            "ecosystem": "crates"
          },
          {
            "name": "psl-types",
            "direct": false,
            "version": "2.0.11",
            "ecosystem": "crates"
          },
          {
            "name": "pxfm",
            "direct": false,
            "version": "0.1.29",
            "ecosystem": "crates"
          },
          {
            "name": "qrcode",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "qrcode",
            "direct": false,
            "version": "0.14.1",
            "ecosystem": "crates"
          },
          {
            "name": "quinn",
            "direct": false,
            "version": "0.11.9",
            "ecosystem": "crates"
          },
          {
            "name": "quinn-proto",
            "direct": false,
            "version": "0.11.14",
            "ecosystem": "crates"
          },
          {
            "name": "quinn-udp",
            "direct": false,
            "version": "0.5.14",
            "ecosystem": "crates"
          },
          {
            "name": "quote",
            "direct": false,
            "version": "1.0.45",
            "ecosystem": "crates"
          },
          {
            "name": "r-efi",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "r-efi",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "crates"
          },
          {
            "name": "rand_chacha",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "rand_chacha",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "rand_core",
            "direct": false,
            "version": "0.6.4",
            "ecosystem": "crates"
          },
          {
            "name": "rand_core",
            "direct": false,
            "version": "0.9.5",
            "ecosystem": "crates"
          },
          {
            "name": "redox_syscall",
            "direct": false,
            "version": "0.5.18",
            "ecosystem": "crates"
          },
          {
            "name": "ref-swap",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "regex",
            "direct": false,
            "version": "1.12.3",
            "ecosystem": "crates"
          },
          {
            "name": "regex-automata",
            "direct": false,
            "version": "0.4.14",
            "ecosystem": "crates"
          },
          {
            "name": "regex-syntax",
            "direct": false,
            "version": "0.8.10",
            "ecosystem": "crates"
          },
          {
            "name": "rfc6979",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "ring",
            "direct": false,
            "version": "0.17.14",
            "ecosystem": "crates"
          },
          {
            "name": "rustc-hash",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "rustc-hash",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "rustc_version",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "crates"
          },
          {
            "name": "rusticata-macros",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "rustix",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-native-certs",
            "direct": false,
            "version": "0.8.3",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-pki-types",
            "direct": false,
            "version": "1.14.1",
            "ecosystem": "crates"
          },
          {
            "name": "rustls-webpki",
            "direct": false,
            "version": "0.103.13",
            "ecosystem": "crates"
          },
          {
            "name": "rustversion",
            "direct": false,
            "version": "1.0.22",
            "ecosystem": "crates"
          },
          {
            "name": "ryu",
            "direct": false,
            "version": "1.0.23",
            "ecosystem": "crates"
          },
          {
            "name": "salty",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "same-file",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "crates"
          },
          {
            "name": "schannel",
            "direct": false,
            "version": "0.1.29",
            "ecosystem": "crates"
          },
          {
            "name": "scoped-tls",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "scopeguard",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "sec1",
            "direct": false,
            "version": "0.7.3",
            "ecosystem": "crates"
          },
          {
            "name": "security-framework",
            "direct": false,
            "version": "3.7.0",
            "ecosystem": "crates"
          },
          {
            "name": "security-framework-sys",
            "direct": false,
            "version": "2.17.0",
            "ecosystem": "crates"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "1.0.28",
            "ecosystem": "crates"
          },
          {
            "name": "serde-byte-array",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "crates"
          },
          {
            "name": "serde-xml-rs",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "serde_core",
            "direct": false,
            "version": "1.0.228",
            "ecosystem": "crates"
          },
          {
            "name": "serde_urlencoded",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "crates"
          },
          {
            "name": "serdect",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "sha-1",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "crates"
          },
          {
            "name": "sha1",
            "direct": false,
            "version": "0.10.6",
            "ecosystem": "crates"
          },
          {
            "name": "sharded-slab",
            "direct": false,
            "version": "0.1.7",
            "ecosystem": "crates"
          },
          {
            "name": "shlex",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "signal-hook-registry",
            "direct": false,
            "version": "1.4.8",
            "ecosystem": "crates"
          },
          {
            "name": "signature",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "crates"
          },
          {
            "name": "signature",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "simd-adler32",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "crates"
          },
          {
            "name": "slab",
            "direct": false,
            "version": "0.4.12",
            "ecosystem": "crates"
          },
          {
            "name": "smallvec",
            "direct": false,
            "version": "1.15.1",
            "ecosystem": "crates"
          },
          {
            "name": "socket2",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "crates"
          },
          {
            "name": "spin",
            "direct": false,
            "version": "0.9.8",
            "ecosystem": "crates"
          },
          {
            "name": "stable_deref_trait",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "static_assertions",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "strum",
            "direct": false,
            "version": "0.26.3",
            "ecosystem": "crates"
          },
          {
            "name": "strum_macros",
            "direct": false,
            "version": "0.26.4",
            "ecosystem": "crates"
          },
          {
            "name": "subtle",
            "direct": false,
            "version": "2.6.1",
            "ecosystem": "crates"
          },
          {
            "name": "syn",
            "direct": false,
            "version": "1.0.109",
            "ecosystem": "crates"
          },
          {
            "name": "syn",
            "direct": false,
            "version": "2.0.117",
            "ecosystem": "crates"
          },
          {
            "name": "sync_wrapper",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "crates"
          },
          {
            "name": "synstructure",
            "direct": false,
            "version": "0.12.6",
            "ecosystem": "crates"
          },
          {
            "name": "synstructure",
            "direct": false,
            "version": "0.13.2",
            "ecosystem": "crates"
          },
          {
            "name": "tap",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "crates"
          },
          {
            "name": "tempfile",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tempfile",
            "direct": false,
            "version": "3.27.0",
            "ecosystem": "crates"
          },
          {
            "name": "termtree",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "test-log",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "test-log",
            "direct": false,
            "version": "0.2.20",
            "ecosystem": "crates"
          },
          {
            "name": "test-log-core",
            "direct": false,
            "version": "0.2.20",
            "ecosystem": "crates"
          },
          {
            "name": "test-log-macros",
            "direct": false,
            "version": "0.2.20",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror-impl",
            "direct": false,
            "version": "1.0.69",
            "ecosystem": "crates"
          },
          {
            "name": "thiserror-impl",
            "direct": false,
            "version": "2.0.18",
            "ecosystem": "crates"
          },
          {
            "name": "thread_local",
            "direct": false,
            "version": "1.1.9",
            "ecosystem": "crates"
          },
          {
            "name": "time-core",
            "direct": false,
            "version": "0.1.8",
            "ecosystem": "crates"
          },
          {
            "name": "time-macros",
            "direct": false,
            "version": "0.2.27",
            "ecosystem": "crates"
          },
          {
            "name": "tinystr",
            "direct": false,
            "version": "0.8.3",
            "ecosystem": "crates"
          },
          {
            "name": "tinyvec",
            "direct": false,
            "version": "1.11.0",
            "ecosystem": "crates"
          },
          {
            "name": "tinyvec_macros",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "tokio-macros",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "crates"
          },
          {
            "name": "tokio-rustls",
            "direct": false,
            "version": "0.26.4",
            "ecosystem": "crates"
          },
          {
            "name": "tokio-util",
            "direct": false,
            "version": "0.7.18",
            "ecosystem": "crates"
          },
          {
            "name": "toml_datetime",
            "direct": false,
            "version": "1.1.1+spec-1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "toml_edit",
            "direct": false,
            "version": "0.25.11+spec-1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "toml_parser",
            "direct": false,
            "version": "1.1.2+spec-1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "tower",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "crates"
          },
          {
            "name": "tower-http",
            "direct": false,
            "version": "0.6.10",
            "ecosystem": "crates"
          },
          {
            "name": "tower-layer",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "crates"
          },
          {
            "name": "tower-service",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "crates"
          },
          {
            "name": "tracing-attributes",
            "direct": false,
            "version": "0.1.31",
            "ecosystem": "crates"
          },
          {
            "name": "tracing-core",
            "direct": false,
            "version": "0.1.36",
            "ecosystem": "crates"
          },
          {
            "name": "tracing-log",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "tracing-subscriber",
            "direct": false,
            "version": null,
            "ecosystem": "crates"
          },
          {
            "name": "tracing-subscriber",
            "direct": false,
            "version": "0.3.23",
            "ecosystem": "crates"
          },
          {
            "name": "trussed-chunked",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "trussed-core",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "trussed-fs-info",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "trussed-hkdf",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "try-lock",
            "direct": false,
            "version": "0.2.5",
            "ecosystem": "crates"
          },
          {
            "name": "typenum",
            "direct": false,
            "version": "1.20.0",
            "ecosystem": "crates"
          },
          {
            "name": "unicode-ident",
            "direct": false,
            "version": "1.0.24",
            "ecosystem": "crates"
          },
          {
            "name": "unicode-xid",
            "direct": false,
            "version": "0.2.6",
            "ecosystem": "crates"
          },
          {
            "name": "universal-hash",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "untrusted",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "crates"
          },
          {
            "name": "utf-8",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "crates"
          },
          {
            "name": "utf8_iter",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "crates"
          },
          {
            "name": "utf8parse",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "crates"
          },
          {
            "name": "valuable",
            "direct": false,
            "version": "0.1.1",
            "ecosystem": "crates"
          },
          {
            "name": "vcpkg",
            "direct": false,
            "version": "0.2.15",
            "ecosystem": "crates"
          },
          {
            "name": "version_check",
            "direct": false,
            "version": "0.9.5",
            "ecosystem": "crates"
          },
          {
            "name": "walkdir",
            "direct": false,
            "version": "2.5.0",
            "ecosystem": "crates"
          },
          {
            "name": "want",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "crates"
          },
          {
            "name": "wasi",
            "direct": false,
            "version": "0.11.1+wasi-snapshot-preview1",
            "ecosystem": "crates"
          },
          {
            "name": "wasip2",
            "direct": false,
            "version": "1.0.3+wasi-0.2.9",
            "ecosystem": "crates"
          },
          {
            "name": "wasip3",
            "direct": false,
            "version": "0.4.0+wasi-0.3.0-rc-2026-01-06",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen",
            "direct": false,
            "version": "0.2.121",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen-futures",
            "direct": false,
            "version": "0.4.71",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen-macro",
            "direct": false,
            "version": "0.2.121",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen-macro-support",
            "direct": false,
            "version": "0.2.121",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-bindgen-shared",
            "direct": false,
            "version": "0.2.121",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-encoder",
            "direct": false,
            "version": "0.244.0",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-metadata",
            "direct": false,
            "version": "0.244.0",
            "ecosystem": "crates"
          },
          {
            "name": "wasm-streams",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "crates"
          },
          {
            "name": "wasmparser",
            "direct": false,
            "version": "0.244.0",
            "ecosystem": "crates"
          },
          {
            "name": "web-sys",
            "direct": false,
            "version": "0.3.98",
            "ecosystem": "crates"
          },
          {
            "name": "web-time",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "winapi",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "crates"
          },
          {
            "name": "winapi-i686-pc-windows-gnu",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "winapi-util",
            "direct": false,
            "version": "0.1.11",
            "ecosystem": "crates"
          },
          {
            "name": "winapi-x86_64-pc-windows-gnu",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows",
            "direct": false,
            "version": "0.48.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows",
            "direct": false,
            "version": "0.61.3",
            "ecosystem": "crates"
          },
          {
            "name": "windows-collections",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows-core",
            "direct": false,
            "version": "0.61.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-future",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "windows-implement",
            "direct": false,
            "version": "0.60.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-interface",
            "direct": false,
            "version": "0.59.3",
            "ecosystem": "crates"
          },
          {
            "name": "windows-link",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "crates"
          },
          {
            "name": "windows-link",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "crates"
          },
          {
            "name": "windows-numerics",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows-result",
            "direct": false,
            "version": "0.3.4",
            "ecosystem": "crates"
          },
          {
            "name": "windows-strings",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-sys",
            "direct": false,
            "version": "0.52.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows-sys",
            "direct": false,
            "version": "0.61.2",
            "ecosystem": "crates"
          },
          {
            "name": "windows-targets",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows-targets",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows-threading",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_gnullvm",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_msvc",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_aarch64_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnu",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnu",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_msvc",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_i686_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnu",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnu",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnullvm",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_gnullvm",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_msvc",
            "direct": false,
            "version": "0.48.5",
            "ecosystem": "crates"
          },
          {
            "name": "windows_x86_64_msvc",
            "direct": false,
            "version": "0.52.6",
            "ecosystem": "crates"
          },
          {
            "name": "winnow",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "crates"
          },
          {
            "name": "winreg",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen",
            "direct": false,
            "version": "0.51.0",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen",
            "direct": false,
            "version": "0.57.1",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen-core",
            "direct": false,
            "version": "0.51.0",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen-rust",
            "direct": false,
            "version": "0.51.0",
            "ecosystem": "crates"
          },
          {
            "name": "wit-bindgen-rust-macro",
            "direct": false,
            "version": "0.51.0",
            "ecosystem": "crates"
          },
          {
            "name": "wit-component",
            "direct": false,
            "version": "0.244.0",
            "ecosystem": "crates"
          },
          {
            "name": "wit-parser",
            "direct": false,
            "version": "0.244.0",
            "ecosystem": "crates"
          },
          {
            "name": "writeable",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "crates"
          },
          {
            "name": "xml",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "crates"
          },
          {
            "name": "yoke",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "yoke-derive",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "crates"
          },
          {
            "name": "zerocopy",
            "direct": false,
            "version": "0.8.48",
            "ecosystem": "crates"
          },
          {
            "name": "zerocopy-derive",
            "direct": false,
            "version": "0.8.48",
            "ecosystem": "crates"
          },
          {
            "name": "zerofrom",
            "direct": false,
            "version": "0.1.7",
            "ecosystem": "crates"
          },
          {
            "name": "zerofrom-derive",
            "direct": false,
            "version": "0.1.7",
            "ecosystem": "crates"
          },
          {
            "name": "zeroize_derive",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "crates"
          },
          {
            "name": "zerotrie",
            "direct": false,
            "version": "0.2.4",
            "ecosystem": "crates"
          },
          {
            "name": "zerovec",
            "direct": false,
            "version": "0.11.6",
            "ecosystem": "crates"
          },
          {
            "name": "zerovec-derive",
            "direct": false,
            "version": "0.11.3",
            "ecosystem": "crates"
          },
          {
            "name": "zmij",
            "direct": false,
            "version": "1.0.21",
            "ecosystem": "crates"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 549,
        "direct_count": 144,
        "indirect_count": 405
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 3,
        "merged_prs": 194,
        "open_issues": 18,
        "closed_ratio": 0.812,
        "closed_issues": 78,
        "closed_unmerged_prs": 9
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "AlfioEmanueleFresta",
          "commits": 263,
          "avatar_url": "https://avatars.githubusercontent.com/u/621062?v=4"
        },
        {
          "type": "User",
          "login": "msirringhaus",
          "commits": 41,
          "avatar_url": "https://avatars.githubusercontent.com/u/50315401?v=4"
        },
        {
          "type": "User",
          "login": "iinuwa",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/27717214?v=4"
        },
        {
          "type": "User",
          "login": "jo-bitsch",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/922813?v=4"
        },
        {
          "type": "User",
          "login": "Nisker",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/25254155?v=4"
        },
        {
          "type": "User",
          "login": "jkaiwar",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/31795507?v=4"
        },
        {
          "type": "User",
          "login": "mikma",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/56008?v=4"
        },
        {
          "type": "User",
          "login": "tgagneret-embedded",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/18049285?v=4"
        },
        {
          "type": "User",
          "login": "kalvdans",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1099712?v=4"
        }
      ],
      "contributors_sampled": 9,
      "top_contributor_share": 0.824
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "docs.yml",
        "rust-latest.yml",
        "rust.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 2/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 12 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool is not run on all commits -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 7,
            "reason": "3 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "5bd5f49cbf868b90e99edb5c0471949622992c79",
        "ran_at": "2026-07-21T20:37:34Z",
        "aggregate_score": 6.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/linux-credentials/libwebauthn",
    "host": "github.com",
    "name": "libwebauthn",
    "owner": "linux-credentials"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 69,
      "inputs": {
        "security": 73,
        "vitality": 87,
        "community": 57,
        "governance": 63,
        "engineering": 65
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 87,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "commits_last_year": 142,
              "human_commit_share": 1,
              "days_since_last_push": 7,
              "active_weeks_last_year": 22
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 7 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "22/52 weeks with commits",
                "points": 15.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "142 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 142
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 10,
              "latest_release_tag": "libwebauthn-v0.10.0",
              "releases_from_tags": false,
              "days_since_latest_release": 7,
              "mean_days_between_releases": 39.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "10 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 7 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~39.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 39.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 7,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 7 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 57,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "forks": 25,
              "stars": 567,
              "watchers": 23,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "567 stars",
                "points": 44.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 567
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "25 forks",
                "points": 11.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "23 watchers",
                "points": 7.5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (LGPL-2.1)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "LGPL-2.1"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "libwebauthn"
              ],
              "dependents": null,
              "ecosystems": "crates",
              "total_downloads": 8290,
              "monthly_downloads": 2324
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,324 downloads/month across crates",
                "points": 44.9,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2324,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 63,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 9,
              "top_contributor_share": 0.824
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 82% of commits",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 82
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "9 contributors",
                "points": 12.2,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 12 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "merged_prs": 194,
              "open_issues": 18,
              "closed_issues": 78,
              "issue_closed_ratio": 0.812,
              "closed_unmerged_prs": 9
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "81% of issues closed",
                "points": 38,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 81
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "194/203 decided PRs merged",
                "points": 36.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 194,
                      "decided": 203
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "followers": 226,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "linux-credentials",
              "public_repos": 5,
              "account_age_days": 527
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "226 followers of linux-credentials",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 226,
                      "login": "linux-credentials"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "5 public repos, account ~1 yr old",
                "points": 8.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 5
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "libwebauthn"
              ],
              "ecosystems": "crates",
              "any_deprecated": false,
              "min_days_since_publish": 7
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on crates",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "crates"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 7 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 7
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "11 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 65,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "topics": [
                "fido2",
                "webauthn",
                "xdg-portal",
                "linux",
                "u2f"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "5 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 73,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 12 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "3 existing vulnerabilities detected",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 478 resolved dependencies against OSV; 71 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 478
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 71
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 3,
              "affected_packages": 3,
              "assessed_packages": 478,
              "unassessed_packages": 71,
              "affected_by_severity": "high 1, unknown 2",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 478,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 55,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml",
                "libwebauthn-tests/Cargo.toml",
                "libwebauthn/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Cargo.toml, libwebauthn-tests/Cargo.toml, libwebauthn/Cargo.toml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "Cargo.toml, libwebauthn-tests/Cargo.toml, libwebauthn/Cargo.toml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Rust (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 102029,
              "source_files_sampled": 142,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/142 source files over 60KB",
                "points": 53.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 142,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch crates package 'libwebauthn-tests' from its registry",
    "deps.dev does not index crates:libwebauthn@0.10.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T20:37:56.282071Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/linux-credentials/libwebauthn.svg",
  "full_name": "linux-credentials/libwebauthn",
  "license_state": "standard",
  "license_spdx": "LGPL-2.1"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.23.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticscrates.io.