Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [
"interpreter",
"opa",
"rego",
"rust",
"confidential-computing",
"policy-as-code",
"c",
"cpp",
"csharp",
"golang",
"javascript",
"python",
"wasm",
"java",
"no-std"
],
"is_fork": false,
"size_kb": 6535,
"has_wiki": true,
"homepage": null,
"languages": {
"C": 680623,
"C#": 289183,
"Go": 23389,
"C++": 133949,
"Java": 27183,
"Roff": 3926,
"Ruby": 9606,
"Rust": 3513901,
"CMake": 5312,
"Shell": 252,
"Python": 17854,
"JavaScript": 3235,
"Open Policy Agent": 756897
},
"pushed_at": "2026-07-21T22:08:33Z",
"created_at": "2023-02-09T18:46:41Z",
"owner_type": "Organization",
"updated_at": "2026-07-22T15:18:00Z",
"description": "Regorus - A fast, lightweight Rego (OPA policy language) interpreter written in Rust.",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "main",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Rust",
"significant_languages": [
"Rust",
"Open Policy Agent",
"C"
]
},
"owner": {
"blog": "https://opensource.microsoft.com",
"name": "Microsoft",
"type": "Organization",
"login": "microsoft",
"company": null,
"location": "Redmond, WA",
"followers": 125639,
"avatar_url": "https://avatars.githubusercontent.com/u/6154722?v=4",
"created_at": "2013-12-10T19:06:48Z",
"is_verified": null,
"public_repos": 8217,
"account_age_days": 4606
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "regorus-v0.11.0",
"kind": "other",
"published_at": "2026-07-21T22:08:39Z"
},
{
"tag": "regorus-v0.10.1",
"kind": "other",
"published_at": "2026-05-22T20:57:34Z"
},
{
"tag": "regorus-v0.10.0",
"kind": "other",
"published_at": "2026-05-06T16:13:31Z"
},
{
"tag": "regorus-v0.9.1",
"kind": "other",
"published_at": "2026-02-09T18:25:12Z"
},
{
"tag": "regorus-v0.9.0",
"kind": "other",
"published_at": "2026-01-31T00:55:21Z"
},
{
"tag": "regorus-v0.5.0",
"kind": "other",
"published_at": "2025-08-22T17:15:15Z"
},
{
"tag": "regorus-v0.4.0",
"kind": "other",
"published_at": "2025-03-14T22:00:51Z"
},
{
"tag": "regorus-v0.3.0",
"kind": "other",
"published_at": "2025-03-10T19:44:03Z"
},
{
"tag": "regorus-v0.2.8",
"kind": "other",
"published_at": "2024-11-06T21:30:20Z"
},
{
"tag": "regorus-v0.2.7",
"kind": "other",
"published_at": "2024-10-22T21:07:03Z"
},
{
"tag": "regorus-v0.2.6",
"kind": "other",
"published_at": "2024-10-09T19:54:29Z"
},
{
"tag": "regorus-v0.2.5",
"kind": "other",
"published_at": "2024-09-18T21:18:47Z"
},
{
"tag": "regorus-v0.2.4",
"kind": "other",
"published_at": "2024-09-04T17:25:51Z"
},
{
"tag": "regorus-v0.2.3",
"kind": "other",
"published_at": "2024-08-16T15:47:35Z"
},
{
"tag": "regorus-v0.2.2",
"kind": "other",
"published_at": "2024-07-28T07:51:04Z"
},
{
"tag": "regorus-v0.2.1",
"kind": "other",
"published_at": "2024-06-19T23:10:37Z"
},
{
"tag": "regorus-v0.2.0",
"kind": "other",
"published_at": "2024-05-30T13:50:29Z"
},
{
"tag": "regorus-v0.1.5",
"kind": "other",
"published_at": "2024-05-08T01:28:57Z"
},
{
"tag": "regorus-v0.1.4",
"kind": "other",
"published_at": "2024-04-22T22:10:30Z"
},
{
"tag": "regorus-v0.1.3",
"kind": "other",
"published_at": "2024-04-11T14:06:03Z"
},
{
"tag": "regorus-v0.1.2",
"kind": "other",
"published_at": "2024-03-22T17:40:31Z"
},
{
"tag": "regorus-v0.1.1",
"kind": "other",
"published_at": "2024-02-23T05:31:48Z"
},
{
"tag": "regorus-v0.1.0",
"kind": "other",
"published_at": "2024-02-08T15:11:15Z"
},
{
"tag": "regorus-v0.1.0-alpha.3",
"kind": "other",
"published_at": "2024-02-02T00:42:26Z"
},
{
"tag": "v0.1.0-alpha.2",
"kind": "prerelease",
"published_at": "2024-01-19T23:09:44Z"
},
{
"tag": "v0.1.0-alpha.1",
"kind": "prerelease",
"published_at": "2024-01-15T19:48:31Z"
}
],
"recent_commits": [
{
"oid": "f98865fc980b9919d201e20969d9b28685ee72bc",
"body": "Release the core `regorus` crate as v0.11.0 (up from v0.10.1) and align\nevery language binding to the same version.\n\nThis release carries an API-breaking change (flagged by\ncargo-semver-checks), so it takes a minor bump under the 0.x SemVer\nconvention.\n\nHighlights since v0.10.1:\n\n- fix(rvm): assert \n[…]\ndings aligned via `cargo xtask bindings`: ffi, java, python, wasm,\n ruby, csharp (manifests, lockfiles, pom.xml, Directory.Packages.props,\n version.rb)\n- CHANGELOG.md updated with the 0.11.0 section",
"is_bot": false,
"headline": "chore(release): release regorus v0.11.0 (#766)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-07-21T22:06:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6ef5e74eb20a33447f1b308f1c3ac5de7a76e101",
"body": "… (#765)\n\nThe RVM was silently succeeding on `every` quantifiers (and loops nested\ninside an `every` body) that should have failed. In each case the loop\ncomputed a pass/fail into a register that the surrounding query then\nignored, so the RVM disagreed with the interpreter.\n\nFour related fixes:\n\n- c\n[…]\n_TODO_FOLDERS so the interpreter-vs-RVM\ndifferential suite covers it, add an OPA_UNSKIP_FOLDERS env override for\nauditing other still-skipped folders, and add regression cases for every\nvariant above.",
"is_bot": false,
"headline": "fix(rvm): assert every-quantifier results so failing cases don't pass…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-07-21T20:43:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a486c79bfebe47a26e50dc4f303b13cbd94f943",
"body": "* Deep-merge nested data documents in Engine::add_data\n\nadd_data previously performed a shallow merge: adding a nested object under a key that already existed either replaced the whole subtree or errored on a spurious conflict, instead of merging the trees. This makes Engine::add_data (and the share\n[…]\nby: Copilot App <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Mark Birger <markbirger@microsoft.com>\nCo-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: Deep-merge nested data documents in Engine::add_data (#760)",
"author_name": "Mark Birger",
"author_login": "kusha",
"committed_at": "2026-07-21T20:18:00Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9838b25fb750248524789706a29f666627a4430d",
"body": "…th 11 updates (#764)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 11 updates\n\nBumps the rust-dependencies group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [anyhow](https://github.com/dtolnay/anyhow) | `1.0.102` | `1.0.103` |\n| [n\n[…]\ndency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: rust-dependencies\n- dependency-name: spin\n dependency-version: 0.12.2\n dependency-type: direct:productio…",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-21T17:39:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f0acc64195ac3cc92f33c1dd107380400c3d2a8c",
"body": "…nction call syntax (#667)\n\n* feat(compiler): support registered host-await builtins\n\nAllow hosts to register function names at compile time so that calls to\nthose names emit HostAwait instructions directly, enabling natural syntax\nlike fetch(x) instead of __builtin_host_await(x, \"fetch\").\n\n- Add ho\n[…]\ndex.ru>\nCo-authored-by: Mark Birger <markbirger@microsoft.com>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(compiler): support registered host-await builtins for natural fu…",
"author_name": "Mark Birger",
"author_login": "kusha",
"committed_at": "2026-06-29T16:17:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "166ea727b8ce1c166360dba8a8ec047447bb709a",
"body": "…updates (#728)\n\nBumps the per-dependency group with 3 updates in the /bindings/ruby directory: [minitest](https://github.com/minitest/minitest), [rubocop](https://github.com/rubocop/rubocop) and [rb_sys](https://github.com/oxidize-rb/rb-sys).\n\n\nUpdates `minitest` from 6.0.5 to 6.0.6\n- [Changelog](h\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group across 1 directory with 3 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-26T20:40:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c45ebfb6171d2fe585d434e9923910686fd03c7",
"body": "Updates the requirements on [maturin](https://github.com/pyo3/maturin) to permit the latest version.\n\nUpdates `maturin` to 1.14.1\n- [Release notes](https://github.com/pyo3/maturin/releases)\n- [Changelog](https://github.com/PyO3/maturin/blob/main/Changelog.md)\n- [Commits](https://github.com/pyo3/matu\n[…]\ntype: direct:development\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): update maturin requirement (#683)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-26T18:57:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41e130321328adcca56262153921f5b2ac72d941",
"body": "Add an opaque `Set` newtype paralleling `Object`, living under\n`src/value/set/` with the same module structure (`mod.rs` /\n`iter.rs` / `serde.rs`). `Set` wraps `BTreeSet<Value>` today but\nexposes only a curated surface: `contains`, `insert`, `remove`,\n`iter`, `iter_sorted`, `cursor` (resumable), `is\n[…]\net` is unchanged in this commit (still wraps\n`Rc<BTreeSet<Value>>`); the payload swap and call-site migration\nship in the next PR.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(value): introduce Set storage abstraction (#740)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-06-26T18:56:15Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "9b42239327a92420245b224124350c5bd75c1273",
"body": "…eter + RVM) (#744)\n\n* Initial plan\n\n* Add keywords_in_refs: allow reserved keywords as dot-notation field names\n\n* Address review feedback: improve parse_ref_field doc comment and clean up test comment\n\n* Add complex keyword-in-ref test cases\n\n* Polish keyword-ref test expectations and validate coverage\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Expand keyword-in-ref coverage for complex parser edge cases (interpr…",
"author_name": "Copilot",
"author_login": "Copilot",
"committed_at": "2026-06-26T18:55:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "9b6ad0bdac8ee8359073675a1e03441b17d9adb4",
"body": "Bumps the per-dependency group with 1 update in the /bindings/java directory: [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire).\n\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.5 to 3.5.6\n- [Release notes](https://github.com/apache/maven-s\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump org.apache.maven.plugins:maven-surefire-plugin (#732)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-26T15:40:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c394725e41a2190034c2303d209f1f450e0b8bc9",
"body": "…th 4 updates (#754)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 4 updates\n\nBumps the rust-dependencies group with 3 updates in the / directory: spin, [uuid](https://github.com/uuid-rs/uuid) and [jsonschema](https://github.com/Stranger6667/jsonschema).\nBumps the rust-d\n[…]\not] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-26T15:34:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4b8874be9cb376daacedcc3d08d9c624a6db64a9",
"body": "… (#752)\n\n* Initial plan\n\n* Bump pyo3 to 0.29.0 in python binding\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "bindings/python: bump PyO3 to 0.29.0 to remediate GHSA-36hh-v3qg-5jq4…",
"author_name": "Copilot",
"author_login": "Copilot",
"committed_at": "2026-06-24T17:32:03Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "096c69315593f5ac2e533879378a8fd3a27a0bb0",
"body": "…th 6 updates (#750)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 6 updates\n\nBumps the rust-dependencies group with 3 updates in the / directory: [regex](https://github.com/rust-lang/regex), [uuid](https://github.com/uuid-rs/uuid) and [chrono](https://github.com/chronot\n[…]\not] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-23T16:11:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed6ae465b0668b9602d2589875d29a65e55bf4de",
"body": "…(#736)\n\nBuilds on #57. Swap Value::Object's payload from Rc<BTreeMap<Value, Value>>\nto Rc<Object> and migrate all call sites to the Object API.\n\nas_object / as_object_mut keep their names but return &Object / &mut Object.\nThe mutable accessor handles Rc::make_mut internally, so callers no longer\ndo\n[…]\nnst a mutated alias.\n\nValue::Set still wraps Rc<BTreeSet<Value>>; the matching Set abstraction\nand its swap ship in follow-up PRs.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "refactor(value): migrate Value::Object to Object storage abstraction …",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-06-05T23:04:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd90453dd38b9b2d5afd81b052b2e50deb1d4076",
"body": "`run_opa_tests` builds `path_dir_str` from `path.strip_prefix(...).to_string_lossy()`,\nwhich on Windows yields strings with backslash separators (e.g.\n`v0\\aggregates`). The folder filter then does an exact-string\ncomparison against the CLI arguments:\n\n let run_test = folders.is_empty()\n ||\n[…]\nhe change minimal — the backslash branch\nbecomes redundant but is harmless.\n\nCo-authored-by: Mark Birger <markbirger@microsoft.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "tests/opa: normalize path separators in folder filter on Windows (#742)",
"author_name": "Mark Birger",
"author_login": "kusha",
"committed_at": "2026-06-05T21:00:24Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "11940ddb0431c516c9ea054e7c3ba621bd7f76ff",
"body": "Add an opaque Object type for the key→value storage backing\nValue::Object. It exposes a small set of methods (get, insert, remove,\niter, iter_sorted, cursor, serde) and keeps the backing store private,\nso future representations -- inline small-map, hash-backed, lazy,\narena, FFI-callback -- can plug \n[…]\nimdjson DOM), and the\nconcrete workloads the abstraction is meant to unlock.\n\nA matching Set abstraction follows in a separate PR.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Introduce Object storage abstraction (#735)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-06-04T17:31:15Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5b7010ba16fd6e7443ec82b71bdc6adab65b2cd0",
"body": "Encode VM stack/context/register lifecycle invariants as\ndebug_assert!s. Zero cost in release; surfaces violations during\ndebug-mode tests and CI.\n\nInvariants covered:\n- reset_execution_state postcondition: all stacks empty, registers\n resized to base and Undefined, rule_cache reset, pc/executed\n \n[…]\nating_add.\n\nAll assertions are gated by #[cfg(debug_assertions)] (directly or via\ndebug_assert!) so release builds are unaffected.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(rvm): add debug-mode invariant assertions (#737)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-06-04T17:28:47Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ba7d29b134d75d3d1ac82c1831ed0927cda67e2d",
"body": "…th 5 updates (#734)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 5 updates\n\nBumps the rust-dependencies group with 4 updates in the / directory: [serde_json](https://github.com/serde-rs/json), spin, [dashmap](https://github.com/xacrimon/dashmap) and [toml_edit](https:/\n[…]\not] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-28T19:58:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "acf7f7a25ec718be7c0d58eb2bd8dd1e6c0163df",
"body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: release (#731)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-22T20:50:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "86b4a279fa8ed620979c86b9dd180dc768be480f",
"body": "…FI (#727)\n\n* fix(ffi): eliminate aliasing UB via to_shared_ref migration\n\nAdd to_shared_ref() helper that creates &T (shared reference) from raw\npointers instead of &mut T. This eliminates undefined behavior caused by\nviolating Rust's aliasing invariant when C# SafeHandle permits concurrent\nFFI cal\n[…]\ne-existing clippy warnings across multiple crates\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(ffi): eliminate aliasing UB + add Azure Policy JSON compilation F…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-22T17:50:16Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5467cd9e69edf8dcc26bcf39d45d2425a3728739",
"body": "…ng (#725)\n\nReplace the compiler's two cloned BTreeMap fields (alias_map and\nalias_modifiable) with a single Option<Rc<AliasRegistry>>. This\neliminates cloning two 73K-entry maps on every compilation by sharing\nthe registry through a reference-counted pointer.\n\nAdditional improvements:\n- alias_map()\n[…]\n AliasEntry.paths (~97% of real\n Azure catalog entries emit \"paths\": null)\n\nAll changes are within the azure_policy feature gate.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "refactor(azure_policy): reduce AliasRegistry allocations via Rc shari…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-18T22:55:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "dae305278136b9481bb6743b62de3300e12abb10",
"body": "…ification (#718)\n\nPartial object rules with dynamic keys (e.g. `violations[k] if { ... }`)\nonly produced a single entry instead of collecting all bindings. Two\nindependent bugs caused this:\n\n1. Interpreter: the early-return optimization in eval_output_expr_in_loop\n checked whether the rule_ref wa\n[…]\nre raised, rather than blanket-skipping entire\nfolders. This preserves RVM coverage for unrelated tests in the same\nfolders.\n\nCloses #712\n\nCo-authored-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "fix(interpreter,rvm): correct partial object rule iteration and class…",
"author_name": "Copilot",
"author_login": "Copilot",
"committed_at": "2026-05-18T20:14:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3111bf58f270b8005db45cb5e38ba302ffd3868d",
"body": "…locations (#726)\n\nReplace per-alias heap allocations with reference-counted string interning\nthroughout the normalizer's alias resolution pipeline:\n\n- Store alias ARM path segments as Vec<Rc<str>> instead of Vec<String>,\n enabling zero-alloc BTreeMap lookups via Rc::clone (refcount bump)\n rather \n[…]\nn\n\nMeasured 27-49% improvement in normalization time across a range of\nAzure Policy alias-heavy resource types (293-608 aliases per type).\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "perf(normalizer): use Rc<str> interning to reduce alias resolution al…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-18T20:13:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "be3fde7706dd60331ec1024d4088b1a90e8520ba",
"body": "…709)\n\nThe cloud agent checks out a branch like copilot/review-pr-NNN which\nmay not have upstream/main or origin/main refs available for merge-base.\n\nChanges:\n- Use gh pr diff as primary method (always works in PR context)\n- Fall back to git merge-base for local non-PR usage\n- Remove path filters (*\n[…]\niff\n- Remove head -2000 truncation — let agents see everything\n- Explicitly fetch origin/main in copilot-setup-steps.yml as backup\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(copilot): robust diff computation for cloud agent environments (#…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-18T20:12:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d2c483e93e54a8414869086e235f5486c7c6c296",
"body": "…th 2 updates (#724)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 2 updates\n\nBumps the rust-dependencies group with 2 updates in the / directory: [hashbrown](https://github.com/rust-lang/hashbrown) and [jsonschema](https://github.com/Stranger6667/jsonschema).\nBumps the \n[…]\not] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-14T15:37:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "093e50f0a11e25bed52e8e6d05e6f7b938acf5f0",
"body": "…th 4 updates (#717)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 4 updates\n\nBumps the rust-dependencies group with 3 updates in the / directory: [hashbrown](https://github.com/rust-lang/hashbrown), [jsonschema](https://github.com/Stranger6667/jsonschema) and [lru](http\n[…]\not] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-07T11:42:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47124623abafc4d59417482dd2c078537804a423",
"body": "Update regorus core crate and all language bindings (ffi, java, python,\nwasm, ruby, csharp) to version 0.10.0.\n\n- Centralize C# package version via Directory.Packages.props\n- Remove redundant C# version suffix properties from project files\n- Regenerate all binding Cargo.lock files including Ruby\n- F\n[…]\nrom Directory.Packages.props\n instead of parsing VersionPrefix from the csproj (which now uses an MSBuild\n property indirection)\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "chore: bump version to 0.10.0 across all bindings (#710)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-06T15:58:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "88c7ef822838736fb16db626c11154acf79679e3",
"body": "Add Copilot review skills, project instructions, and coding agent setup\nfor automated code review on regorus PRs.\n\nFiles added:\n- .github/copilot-instructions.md — project context (no_std, 9 bindings,\n dual execution paths, deny lints, security-critical evaluation)\n- .github/skills/code-review/SKIL\n[…]\n zero false positives\n and produces verified findings with confidence levels, test gap analysis,\n and agent performance metrics.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(copilot): add multi-agent code review skills (#707)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-04T20:20:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "87f22a79ca399fe602176f9aea44028be0323dd9",
"body": "Add a 100KB cap on compiled regex NFA size via RegexBuilder::size_limit()\nto block patterns that blow up in memory or CPU. Regex compilation now\ngoes through a single helper (compile_regex_for_builtin) so the limit\nis enforced consistently across all regex builtins.\n\nWhile doing this, found and fixe\n[…]\nuiltin\ncall, RVM builtin dispatch, and RVM rule-execution loop) to recognize\nLimitError and let it propagate instead of eating it.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: harden regex builtins with compiled-size limit (#705)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-04T20:20:29Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c312e3037230e7192e49222b9d8e86f65a0ece58",
"body": "…rkflow (#704)\n\n* build(deps): update all Rust dependencies to latest versions\n\nBulk-update all Cargo.lock files across the workspace and bindings\nto their latest compatible versions. This supersedes the individual\nper-directory dependabot PRs (#678-#682) that fail CI due to version\nskew when only o\n[…]\ngithub.com/dependabot/dependabot-core/issues/7547\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "build(deps): update all Rust dependencies and fix lockfile refresh wo…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-05-04T20:20:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bbf7ad785429f10243c0665ff5b3db4ce75af3e8",
"body": "Bumps the per-dependency group in /bindings/java with 1 update: [com.google.code.gson:gson](https://github.com/google/gson).\n\n\nUpdates `com.google.code.gson:gson` from 2.13.2 to 2.14.0\n- [Release notes](https://github.com/google/gson/releases)\n- [Changelog](https://github.com/google/gson/blob/main/C\n[…]\nsion-update:semver-minor\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump com.google.code.gson:gson (#702)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T20:46:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c3cafcb907f40531a77577e36b5d35cba66878e",
"body": "…ates (#690)\n\nBumps the github-actions group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.35.1` | `4.35.2` |\n|\n[…]\nsion-update:semver-minor\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci(deps): bump the github-actions group across 1 directory with 5 upd…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T20:45:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b734e47c1c00d2b13d321c241fd66bd249850786",
"body": "…updates (#703)\n\nBumps the per-dependency group with 4 updates in the /bindings/ruby directory: [minitest](https://github.com/minitest/minitest), [rake](https://github.com/ruby/rake), [rake-compiler-dock](https://github.com/rake-compiler/rake-compiler-dock) and [rubocop](https://github.com/rubocop/r\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group across 1 directory with 5 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T20:44:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b148d64b2b3de909a2577cecab1e654430b622ff",
"body": "…701)\n\n* Initial plan\n\n* Make git rev-parse optional in build.rs, fall back to empty string\n\nAgent-Logs-Url: https://github.com/microsoft/regorus/sessions/070084fe-288a-4029-b4a0-006ff18f8c94\n\nCo-authored-by: anakrish <35780660+anakrish@users.noreply.github.com>\n\n* Use \\\"unknown\\\" as fallback for GI\n[…]\nanakrish@users.noreply.github.com>\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: anakrish <35780660+anakrish@users.noreply.github.com>",
"is_bot": false,
"headline": "Make `git rev-parse` in `build.rs` optional with graceful fallback (#…",
"author_name": "Copilot",
"author_login": "Copilot",
"committed_at": "2026-04-30T20:43:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4c92fb4d9243f0a3bd99bc110a2ffb1121eaadec",
"body": "…(#700)\n\nAdds the YAML test runner that exercises the companion test data PRs, plus\nseveral compiler fixes surfaced during testing:\n\n- Removed parameter register caching that produced wrong results inside\n short-circuiting allOf/anyOf blocks; added literal-index caching for\n parameter defaults to \n[…]\normalization tests, and documents Azure Policy support in the README.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(azure_policy): test runner, compiler fixes, and example program …",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-30T18:02:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7f42115b6338999efd13916e89b81ac278bc6273",
"body": "YAML-driven test cases for the core Azure Policy compiler. These cover\nalias resolution, field conditions, logical operators, type coercion,\ncount expressions, template functions, effect compilation, and policy\ndefinition parsing. 24 files, each a self-contained scenario exercised\nby the test runner in the companion code PR.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "test(azure_policy): add foundation test cases (#698)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-28T16:03:39Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "afdb894d8508009375c481737bdb3bffc5013195",
"body": "50 end-to-end test cases derived from real Azure built-in policies. Each\nfile contains a complete policy definition, sample resources, and expected\nevaluation results. Coverage spans storage, networking, compute, security,\nmonitoring, database, identity, governance, and update management scenarios.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "test(azure_policy): add end-to-end policy test cases (#699)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-27T23:04:50Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "b989888dab8f61c2e95d94201483cc8b967d4b7d",
"body": "…ion (#691)\n\nReplace the stub implementations in effects.rs, effects_modify_append.rs,\nand metadata.rs with full working code.\n\nEffect compilation dispatches all effect kinds (Deny, Audit, Modify, Append,\nAuditIfNotExists, DeployIfNotExists, etc.) including parameterized effects\nthat resolve at runt\n[…]\nre compiled\nas expressions rather than frozen as literals, so template expressions like\n[field('name')] are properly evaluated at runtime.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "feat(azure-policy): implement effect compilation and metadata populat…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-27T16:31:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad82227ddb440d38f10b429cefb6bf0f1e5fc3a9",
"body": "Implement the full count loop compiler, replacing the stubs in count.rs,\ncount_any.rs, and count_bindings.rs with a single consolidated module.\n\nHandles both field-based and value-based count nodes. Field counts walk\nthe resource via resolve_alias_path then iterate the wildcard array;\nvalue counts o\n[…]\n\n\nAlso fixes the bound_len arithmetic in conditions_wildcard.rs with a\ncleaner strip_prefix call, and removes the nested-wildcard bail in\nsplit_count_wildcard_path since the compiler now handles them.",
"is_bot": false,
"headline": "feat(azure-policy): implement count/count.where compilation (#688)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-23T16:53:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f50a9744ff2a6c530836db1af9041ca5eac4edf9",
"body": "…ate dispatch compilation (#686)\n\nFill in the compiler stubs for the evaluation layer.\n\nCondition and wildcard compilation:\n- Compile allOf/anyOf/not constraints, operator conditions with\n value-condition guards, and implicit allOf for unbound [*] fields\n via recursive Every loops.\n- Defensively l\n[…]\n- Add span context to bail errors in stubs so diagnostics carry\n source locations.\n- Take CountBinding by reference in compile_from_binding.\n- Suppress clippy warnings on the no-op memory_check stub.",
"is_bot": false,
"headline": "feat(azure-policy): implement condition, expression, field, and templ…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-21T21:51:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f727096a1d6bb7327bb17216dcb48c24a7415fe0",
"body": "…#674)\n\nAdd the compiler module structure with:\n- core.rs: Compiler struct, CountBinding, new(), compile() pipeline,\n register allocation, span/emit helpers\n- mod.rs: module declarations, public entry points\n (compile_policy_rule, compile_policy_definition, etc.)\n- utils.rs: pure helper functions (path splitting, JSON conversion)\n- Stub files for conditions, expressions, fields, template dispatch,\n count, effects, and metadata — real implementations follow in\n subsequent commits.",
"is_bot": false,
"headline": "feat(azure-policy): add compiler skeleton with core types and stubs (…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-20T20:29:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce235356bc3c794fc58ab1d401b2e8e853a1d20a",
"body": "Update Cargo.lock to move rand to 0.10.1 so cargo-deny stops failing on RUSTSEC-2026-0097.\n\nAlso tighten the Python workflow cache boundaries by keying rust-cache to pinned runner images. The workflow now keeps Ubuntu 22.04, Ubuntu 24.04, and Windows 2022 caches separate, which avoids reusing host build artifacts across runner image changes. That is the class of issue behind the intermittent GLIBC mismatch seen in CI.",
"is_bot": false,
"headline": "build: fix rand advisory and harden python CI caching (#675)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-13T22:55:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d34021dea21547abb03b328fbfd77260022b337",
"body": "Some Azure Policy JSON documents contain very long lines — ARM template\nexpressions with deeply nested if()/concat() calls can easily exceed\nthe default 1024-column lexer limit.\n\nAdd Parser::new_with_max_col() and corresponding parse_policy_rule_with_max_col()\n/ parse_policy_definition_with_max_col() entry points so callers can raise\nthe limit when needed. Also bump ExprParser's own default to 65536 since\ntemplate expressions are routinely thousands of characters wide.",
"is_bot": false,
"headline": "azure-policy parser: allow overriding the column-width limit (#673)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-10T23:23:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "35521ce900e2c577c3ce11855da2f1e538cfd1c9",
"body": "…th 6 updates (#671)\n\nBumps the rust-dependencies group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [semver](https://github.com/dtolnay/semver) | `1.0.27` | `1.0.28` |\n| [jsonschema](https://github.com/Stranger6667/jsonschema) | `0.45.0` | `0.45.1` |\n| [indexmap\n[…]\nn-update:semver-patch\n dependency-group: rust-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-09T22:14:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "478a88430ec04b4ab842c5fad2f9202a0e5b896e",
"body": "Bumps the github-actions group with 1 update: [ruby/setup-ruby](https://github.com/ruby/setup-ruby).\n\n\nUpdates `ruby/setup-ruby` from 1.299.0 to 1.300.0\n- [Release notes](https://github.com/ruby/setup-ruby/releases)\n- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)\n- [Commits]\n[…]\nsion-update:semver-minor\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci(deps): bump ruby/setup-ruby in the github-actions group (#670)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-09T21:42:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b9eca934a879bf9cab33370413e97c31613f699e",
"body": "* build(csharp): rename NuGet package to Microsoft.Regorus\n\nAlign the NuGet package identity with the Microsoft.Regorus\nnamespace and the Microsoft.* reserved prefix on nuget.org\nin preparation for publishing the package.\n\n- Add explicit <PackageId>Microsoft.Regorus</PackageId>\n- Update PackageVersi\n[…]\nnupkg into local-packages/ directory\n- Pass /p:UsePackageReference=true from xtask for CI testing\n- Add restore validation step to the xtask test flow\n- Add .gitignore for the local-packages directory",
"is_bot": false,
"headline": "build(csharp): prepare NuGet package for nuget.org publishing (#668)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-09T21:40:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d35744c4f92d68d59b87bed5aa657fc661e0c3c",
"body": "Add VM support for Azure Policy's condition operators and allOf/anyOf\nshort-circuit logic, gated behind cfg(feature = \"azure_policy\").\n\nPolicy conditions (equals, contains, like, match, exists, and their\nnegations — 21 total) are encoded as a single PolicyCondition\ninstruction with a PolicyOp sub-op\n[…]\nd comparison, wildcard/glob matching, and\ntype coercion live in builtins::azure_policy::helpers.\n\nTwo YAML test suites (~2200 lines) exercise the full operator matrix and\nthe allOf/anyOf control flow.",
"is_bot": false,
"headline": "feat(rvm): implement Azure Policy condition evaluation (#661)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-08T00:04:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "83ce8c35800a21a3ad4ab30a0842eacbd36283c8",
"body": "Default-only rules (e.g., `default deny := true` with no conditional body)\nreturned Undefined in the RVM instead of the default value.\n\nCompiler:\n- compute_rule_type: return Complete when rule exists only in default_rules map\n- compile_worklist_rule: emit register slots and data-tree entries for\n d\n[…]\nmpty\n\nTests:\n- 3 new RVM cases (default_rules.yaml): bool, object, entry-point\n- 3 new interpreter cases (default/basic.yaml): matching coverage\n\nCo-authored-by: Mark Birger <markbirger@microsoft.com>",
"is_bot": false,
"headline": "Fix RVM evaluation of default-only rules (#664)",
"author_name": "Mark Birger",
"author_login": "kusha",
"committed_at": "2026-04-07T16:38:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e5ac9a27347a76adaecc958c4f2fe91ed5bf0ecf",
"body": "…rt (#659)\n\nThe Rego VM was designed around Rego's semantics, but Azure Policy needs\na few things Rego doesn't: host-supplied context alongside input/data,\nundefined-to-null coercion for missing fields, skip-undefined collection\nbehavior for wildcard aliases, and non-vacuous iteration over non-array\n[…]\nl site.\n\nFour new YAML test suites (~880 lines) cover the new instructions and\ncontext/metadata loading, along with instruction parser, display, and\nassembly listing support for everything added here.",
"is_bot": false,
"headline": "feat(rvm): new instructions and loop semantics for Azure Policy suppo…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-06T20:40:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f740e2f6f76dcff269909033d4185265e616c07",
"body": "Extend the Azure Policy parser to handle complete policyRule and\npolicyDefinition JSON structures, not just standalone constraints.\n\nPolicy rule parser (policy_rule.rs):\n- Parse top-level { \"if\": ..., \"then\": ... } objects\n- Extract effect kind (deny, audit, append, modify, etc.) into typed AST\n- Pa\n[…]\neCondition, parameterized effects, complex conditions, and\n extra key handling\n- Add policy_definition.yaml with wrapped, unwrapped, parameterized,\n missing-policyRule, and duplicate-key error cases",
"is_bot": false,
"headline": "feat(azure-policy): add policy rule and policy definition parsers (#660)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-06T16:36:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "687be2850b5e1fe20812765c0c2ff175dc50d40d",
"body": "Add constraint.rs module that parses Azure Policy JSON constraints\ninto span-annotated AST nodes:\n\n- Logical combinators: allOf, anyOf, not\n- Leaf conditions: field/value with all 19 operators\n- Count blocks: field-count and value-count with where clauses\n\nPublic API: parse_constraint() parses a standalone constraint from JSON.\n\nIncludes YAML-driven test suite with 6 test files covering operators,\nfields, expressions, logical combinators, count, and parse errors.",
"is_bot": false,
"headline": "feat: add Azure Policy constraint parser (#658)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-04T00:09:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "95bffcb5f903ae00739999207a79a9338b40bec8",
"body": "Add typed metadata support to RVM programs so that language frontends\ncan store language identity and arbitrary annotations alongside the\ncompiled bytecode.\n\nProgram metadata:\n- Add `language` field to identify the source language (e.g. \"rego\",\n \"azure_policy\") so the VM can adjust semantics at run\n[…]\nn from 5 to 6\n- Add JSON serialization for the new metadata fields\n\nAssembly listing:\n- Display language and annotations in the program header\n\nCompiler:\n- Track has_host_await during Rego compilation",
"is_bot": false,
"headline": "feat(rvm): extend program metadata and bump serialization to v6 (#654)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-03T17:53:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "db8a9abf130a01d416dbd0d7d19e37f1a2372588",
"body": "…oup (#656)\n\nBumps the per-dependency group in /bindings/ruby with 1 update: [minitest](https://github.com/minitest/minitest).\n\n\nUpdates `minitest` from 6.0.2 to 6.0.3\n- [Changelog](https://github.com/minitest/minitest/blob/master/History.rdoc)\n- [Commits](https://github.com/minitest/minitest/compar\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump minitest in /bindings/ruby in the per-dependency gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-02T18:08:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "421ee6af9b751a1bbd3e26955d08c92a4ecf6caa",
"body": "…th 3 updates (#657)\n\nBumps the rust-dependencies group with 2 updates in the / directory: [toml_edit](https://github.com/toml-rs/toml) and [zip](https://github.com/zip-rs/zip2).\nBumps the rust-dependencies group with 1 update in the /bindings/wasm directory: [wasm-bindgen-test](https://github.com/w\n[…]\nn-update:semver-patch\n dependency-group: rust-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 2 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-02T18:08:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "64f71dee34bcbafffe528950a445544893e6652c",
"body": "Add the foundational parsing infrastructure for Azure Policy JSON:\n\n- ExprParser: ARM template expression parser for \"[...]\" strings,\n supporting function calls, dot access, index access, and literals\n- Parser (core): recursive-descent JSON tokenizer-to-AST parser that\n reads directly from Lexer t\n[…]\ntion, operator kind parsing, and\n ARM template expression detection\n\nThese components are consumed by the policy-aware parsing modules\n(constraint, policy_rule, policy_definition) in a subsequent PR.",
"is_bot": false,
"headline": "feat: add Azure Policy core JSON parser and expression parser (#655)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-02T16:42:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "648ba40126da84a3ecab7bcf9530ab167890a032",
"body": "Add span-annotated AST types for Azure Policy conditions and rules.\n\n- PolicyDefinition, PolicyRule with if/then/details structure\n- Condition enum: field conditions, value conditions, logical\n combinators (allOf, anyOf, not), and count expressions\n- Operator enums for all 19 Azure Policy constrain\n[…]\nsitively, etc.)\n- Expr enum for field references, literal values (number, string,\n bool), template function calls, and policy function invocations\n- Value types with span tracking for error reporting",
"is_bot": false,
"headline": "feat: add Azure Policy AST types (#653)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-01T16:54:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "126cc12eb5b6f96266ef4e68296773120ca1d406",
"body": "…als (#651)\n\nMerge the three separate Assert* instructions (AssertNot, AssertCondition,\nAssertNotUndefined) into a single `Guard { register, mode }` instruction\nwith a GuardMode enum. This cuts duplicated match arms across display,\nlisting, parser, dispatch, and all compiler emit sites.\n\nDrop the un\n[…]\nelper.\n- Move the memory check into dispatch (runs per instruction) and remove the\n now-dead enforce_memory_check() entry-point calls.\n- Apply map_or_else style throughout listing.rs for consistency.",
"is_bot": false,
"headline": "refactor: consolidate RVM instruction variants and clean up VM intern…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-04-01T10:34:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a8fc08773cada360cf5da006ad5f67de09948f9",
"body": "Bumps the rust-dependencies group with 1 update in the /bindings/wasm directory: [wasm-bindgen-test](https://github.com/wasm-bindgen/wasm-bindgen).\n\n\nUpdates `wasm-bindgen-test` from 0.3.65 to 0.3.66\n- [Release notes](https://github.com/wasm-bindgen/wasm-bindgen/releases)\n- [Changelog](https://githu\n[…]\nn-update:semver-patch\n dependency-group: rust-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump wasm-bindgen-test (#650)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-31T16:56:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c164917d6358d1e29d154936d98f1f1d9823e222",
"body": "…p (#649)\n\nBumps the per-dependency group in /bindings/ruby with 1 update: [rb_sys](https://github.com/oxidize-rb/rb-sys).\n\n\nUpdates `rb_sys` from 0.9.124 to 0.9.125\n- [Release notes](https://github.com/oxidize-rb/rb-sys/releases)\n- [Commits](https://github.com/oxidize-rb/rb-sys/compare/v0.9.124...v\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump rb_sys in /bindings/ruby in the per-dependency grou…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-31T16:55:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a6cc659b7566749c993032a728bbffed8328bdc",
"body": "…th 4 updates (#647)\n\nBumps the rust-dependencies group with 2 updates in the / directory: [toml_edit](https://github.com/toml-rs/toml) and [zip](https://github.com/zip-rs/zip2).\nBumps the rust-dependencies group with 1 update in the /bindings/python directory: [ordered-float](https://github.com/ree\n[…]\nn-update:semver-patch\n dependency-group: rust-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 3 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-31T12:16:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a86cf1119f2bc18215d9a5e244cc33a5cf4822e8",
"body": "…ates (#646)\n\nBumps the github-actions group with 3 updates in the / directory: [actions/setup-go](https://github.com/actions/setup-go), [github/codeql-action](https://github.com/github/codeql-action) and [ruby/setup-ruby](https://github.com/ruby/setup-ruby).\n\n\nUpdates `actions/setup-go` from 6.3.0 \n[…]\nsion-update:semver-minor\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci(deps): bump the github-actions group across 1 directory with 3 upd…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-31T12:15:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "989ca6df2e74b4975a64daa2c16da0171f34a16b",
"body": "Without grouping, dependabot creates a separate PR per directory for the\nsame dependency. Each individual PR fails to build due to version skew\nacross the root workspace and binding crates.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "ci(dependabot): restore cargo dependency grouping (#645)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-30T23:44:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d36f952133380474e5f3ccf60c44eccfac9e5744",
"body": "* feat: add Azure Policy alias normalization/denormalization\n\nAdd normalizer and denormalizer for ARM JSON resources, enabling Azure\nPolicy alias short names to become direct paths into a flat structure.\n\n- Normalizer: flattens properties wrappers, lowercases keys, resolves\n per-alias versioned ARM\n[…]\nng resources, and denormalizing back to ARM JSON\n- C#: AliasRegistry wrapper class with NativeMethods P/Invoke bindings\n and integration tests\n- Updated Cargo.lock files for new serde_json dependency",
"is_bot": false,
"headline": "feat(azure-policy): add alias normalization and denormalization (#635)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-30T23:44:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "35fb5d59536043958de5254cbf224e9824929bef",
"body": "* fix: update bindings and builtins for breaking dependency upgrades\n\n- Update rand 0.10 API: use RngExt trait instead of removed Rng trait\n- Update jsonschema 0.45 API: replace removed BasicOutput/apply with\n iter_errors for schema validation\n- Update jni 0.22 API: migrate from deprecated JNIEnv t\n[…]\nec\n- Use JNI_TRUE/JNI_FALSE for jboolean instead of bool coercion\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\n\n---------\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "Fix build break (#634)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-27T17:34:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "296b34171ae82670c676332a28ff52f0e724d4ce",
"body": "…th 16 updates (#633)\n\n* build(deps): bump the rust-dependencies group across 5 directories with 16 updates\n\nBumps the rust-dependencies group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [anyhow](https://github.com/dtolnay/anyhow) | `1.0.100` | `1.0.102` |\n| [s\n[…]\not] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the rust-dependencies group across 5 directories wi…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-26T17:51:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f9d54cd4360f4789803893065bde2ca685783085",
"body": null,
"is_bot": false,
"headline": "ci(dependabot): fix cargo config quoting (#632)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-26T16:18:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b60daabd90a788aaef592197c83827311d4a601",
"body": "* feat: add Azure Policy builtins with YAML test suite\n\nImplement ARM template functions for Azure Policy evaluation:\n\nBuiltins:\n- String: indexOf, lastIndexOf, trim, format, split, startsWith, endsWith,\n padLeft, concat, replace, toLower, toUpper, substring, guid, uniqueString\n- DateTime: dateTime\n[…]\nant_error test branch (code bails on\n Undefined, not accepts it)\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\n\n---------\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "feat: add Azure Policy builtins with YAML test suite (#630)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-25T22:32:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f69974dc1bdc7a80b40a2be3d844e7b37a3390d4",
"body": "* ci(dependabot): fix cargo workspace updates and refresh lockfiles\n\nRemove nested Cargo workspace members from Dependabot's cargo directories to avoid manifest resolution failures during grouped updates.\n\nAdd a Dependabot-only workflow that refreshes affected Cargo lockfiles, including the no_std t\n[…]\nharden refresh workflow\n\n* ci(dependabot): refine workflow gating and staging\n\n* ci(dependabot): harden workflow git operations\n\n---------\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "ci(dependabot): fix cargo workspace updates and refresh lockfiles (#629)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-25T21:58:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "942dd471637fc331c7b1bfd6a4ed383601b063dd",
"body": "…up (#622)\n\nBumps the per-dependency group in /bindings/ruby with 1 update: [rubocop](https://github.com/rubocop/rubocop).\n\n\nUpdates `rubocop` from 1.85.0 to 1.85.1\n- [Release notes](https://github.com/rubocop/rubocop/releases)\n- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.m\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump rubocop in /bindings/ruby in the per-dependency gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-24T17:37:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ac701b4933896b8f707c0b6fa0b929ff2a57c2f6",
"body": "Bumps the github-actions group with 11 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/checkout](https://github.com/actions/checkout) | `4` | `6` |\n| [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) | `2.8.2` | `2.9.1` |\n| [actions/setup-go](https://github.com/actions/s\n[…]\nsion-update:semver-patch\n dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci(deps): bump the github-actions group with 11 updates (#628)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-24T17:35:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "86088d20495e992e7580405dc0f9aa9f2fa50d53",
"body": "…atrix CI (#627)\n\n* build: consolidate dependabot cargo entries and add commit prefixes\n\nConsolidate all 9 separate cargo ecosystem entries into a single entry\nusing the 'directories' key. This ensures Dependabot creates one PR per\ndependency update across the root workspace and all bindings, preven\n[…]\nguards around the\ncall sites and the MEMORY_LIMIT_BYTES constant.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\n\n---------\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "Consolidate Dependabot, fix #595 (mimalloc + indexmap), add feature-m…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-24T16:54:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "83891d778284a029541833cb5b04c67ca259d0f6",
"body": "…nstant hoisting, and correctness fixes (#626)\n\n* perf!: add LRU caches for compiled regex and glob patterns\n\nAdd bounded LRU caches for compiled regex and glob patterns used by\nRego builtins, avoiding repeated recompilation of the same patterns\nduring policy evaluation.\n\nNew `cache` feature (includ\n[…]\n addition across ffi, java, python,\n and wasm binding lockfiles.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>\n\n---------\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "RVM compiler & runtime optimizations: caching, instruction fusion, co…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-24T02:00:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "898643129e3652efd43e596f978d99f85e770235",
"body": "- Add PolicyLengthConfig struct with max_col, max_file_bytes, and\n max_lines fields, replacing hardcoded constants in the lexer.\n- Add Engine::set_policy_length_config and clear_policy_length_config\n to allow callers to override the default limits.\n- Add Source::from_contents_with_limits and from_\n[…]\n_contents\n and from_file signatures are preserved using defaults.\n- Add tests for default rejection, custom limits, and engine plumbing.\n- Add bindings for C, C++, Python, WASM/JS, Java, Ruby, C#, Go",
"is_bot": false,
"headline": "feat: make policy length limits configurable per engine (#624)",
"author_name": "antmhs",
"author_login": "antmhs",
"committed_at": "2026-03-13T17:19:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "50c0215fdbba332a24fb010e98e535dacdac9294",
"body": "* perf(rvm): fix O(n²) comprehension yield by mutating in-place\n\nInstead of cloning the entire accumulator collection on every yield\niteration, use take_register + Rc::make_mut to get exclusive ownership\nand mutate in-place. This reduces comprehension yield from O(n²) to O(n)\nfor both run-to-complet\n[…]\netion and suspendable)\n- Avoid clone in resume() invalid-state error path by formatting\n debug string before moving state back\n\n---------\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "Rvm optimizations (#620)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-12T02:39:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee3dff9a3dadf10cd82ceea477521d85aa0780a3",
"body": "- Add cfg(not(miri)) guards to mimalloc module, global allocator, and\n allocator-memory-limits code paths so Miri falls back to the default\n system allocator instead of calling unsupported FFI functions.\n- Set MIRIFLAGS=\"-Zmiri-disable-isolation\" in the workflow so tests\n that perform file I/O ca\n[…]\n under Miri.\n- Skip units/parse tests under Miri due to Float-vs-BigInt Number\n representation mismatch with Miri's soft-float emulation.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "fix(ci): skip mimalloc FFI and disable isolation for Miri (#621)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-11T20:13:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b8e15f46f3992522ec133a8bd286885e56dd93ae",
"body": "…up (#618)\n\nBumps the per-dependency group in /bindings/ruby with 1 update: [rubocop](https://github.com/rubocop/rubocop).\n\n\nUpdates `rubocop` from 1.84.2 to 1.85.0\n- [Release notes](https://github.com/rubocop/rubocop/releases)\n- [Changelog](https://github.com/rubocop/rubocop/blob/master/CHANGELOG.m\n[…]\nsion-update:semver-minor\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump rubocop in /bindings/ruby in the per-dependency gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-05T21:10:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "37144968c8b4a60c28e8552584ade4a566b5c645",
"body": "Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "chore(ci): add miri workflow (#581)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-05T19:18:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ee503ccdc2d02c6ff880f863adc82cfe9deeb5f",
"body": "Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "chore(ci): add cargo audit and deny (#580)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-05T19:18:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "006e819d52b37d9546c32ee4730dfaccf45f549b",
"body": "Move RVM binary encoding from bincode to postcard and bump the format version. Update test helpers, docs, changelog, and refresh lockfiles after the swap.\n\nCloses #575\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "rvm: switch binary serialization to postcard (#582)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-03-03T21:09:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b6f11c56028f1e764a4e9d3ad22f4630d547be3f",
"body": "…(#605)\n\nBumps the per-dependency group in /bindings/java with 1 update: [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire).\n\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.4 to 3.5.5\n- [Release notes](https://github.com/apache/maven-surefi\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): bump org.apache.maven.plugins:maven-surefire-plugin …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-27T22:52:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72033e77da8fa53d4b69ab7790d1ce9e3e6315bd",
"body": "Bumps the cargo group with 1 update in the /bindings/java directory: [bytes](https://github.com/tokio-rs/bytes).\n\n\nUpdates `bytes` from 1.11.0 to 1.11.1\n- [Release notes](https://github.com/tokio-rs/bytes/releases)\n- [Changelog](https://github.com/tokio-rs/bytes/blob/master/CHANGELOG.md)\n- [Commits]\n[…]\n.11.1\n dependency-type: indirect\n dependency-group: cargo\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump bytes (#569)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-27T22:52:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "be34063dbaaea6c6841c350bcd6787fdd3ea25fb",
"body": "Bumps the per-dependency group with 2 updates: [github/codeql-action](https://github.com/github/codeql-action) and [MarcoIeni/release-plz-action](https://github.com/marcoieni/release-plz-action).\n\n\nUpdates `github/codeql-action` from 4.32.2 to 4.32.3\n- [Release notes](https://github.com/github/codeq\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group with 2 updates (#603)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-27T22:51:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04bf417c065936a233b19362f9fee3b86df3a3c0",
"body": "…updates (#607)\n\nBumps the per-dependency group with 3 updates in the /bindings/ruby directory: [minitest](https://github.com/minitest/minitest), [rubocop](https://github.com/rubocop/rubocop) and [rubocop-minitest](https://github.com/rubocop/rubocop-minitest).\n\n\nUpdates `minitest` from 6.0.1 to 6.0.\n[…]\nsion-update:semver-minor\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group across 1 directory with 3 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-27T22:50:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bc23cd08acaed0e881eb63db7a1b037d3d6883e7",
"body": "* fix(python): boolean and integer mapping",
"is_bot": false,
"headline": "Python: boolean mapping (#612)",
"author_name": "Paulo Lieuthier",
"author_login": "paulolieuthier",
"committed_at": "2026-02-27T21:55:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1c607dc1d3be247979373d011a2d72f510336874",
"body": "Add support for registering custom Python functions as Rego extensions,\nallowing users to call Python callables directly from Rego policies.\n\nThe implementation:\n- Converts Rego values to Python types on call, and back on return\n- Validates that the extension is callable at registration time\n- Wraps\n[…]\ntype conversions (int, float, bool, None,\nlist, dict, set), zero-arg extensions, wrong arity, exception\npropagation, non-callable rejection, and duplicate registration.\n\nContributed by @paulolieuthier",
"is_bot": false,
"headline": "feat: implement add_extension in Python binding (#596)",
"author_name": "Paulo Lieuthier",
"author_login": "paulolieuthier",
"committed_at": "2026-02-25T21:55:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47cc27ff496c182465a5521bfb60e33da90f63e0",
"body": "… (#577)\n\n- add Azure RBAC condition interpreter and builtin evaluation in core (expressions, parser updates, evaluator, and test harness)\n- introduce comprehensive RBAC YAML test suites and coverage for i\n - action/suboperation\n - strings\n - numbers\n - bools\n - IP\n - GUID\n - dates\n - times\n\n[…]\n tests to execute all RBAC YAML cases with per-case logging\n- wire test assets into C# test output and centralize YAML dependency versions\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "feat(rbac)!: add Azure RBAC engine, FFI API, and cross-language tests…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-02-19T21:30:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8814eda0ae9cccf0b9041cf5ca43cbc1034a51c2",
"body": "Bumps Microsoft.Build.NoTargets from 3.7.56 to 3.7.134\n\n---\nupdated-dependencies:\n- dependency-name: Microsoft.Build.NoTargets\n dependency-version: 3.7.134\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump the per-dependency group with 1 update (#587)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-12T22:47:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4a69a13ba9ff857fc523c43fd19c1e3cfbfae99",
"body": "---\nupdated-dependencies:\n- dependency-name: magnus\n dependency-version: 0.8.2\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: per-dependency\n- dependency-name: regorus\n dependency-version: 0.9.1\n dependency-type: direct:production\n update-type\n[…]\nsion-update:semver-minor\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group (#585)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-12T15:53:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e83a47497a9e31f81e6ac31040455158d942ca66",
"body": "Bumps the per-dependency group in /bindings/ruby with 7 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [minitest](https://github.com/minitest/minitest) | `5.25.4` | `6.0.1` |\n| [rake](https://github.com/ruby/rake) | `13.2.1` | `13.3.1` |\n| [rake-compiler](https://github.com/rake-compiler/ra\n[…]\nsion-update:semver-patch\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group (#586)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-12T15:53:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "241c1d445bb339f97c2c3174cf8f8ccfdc7c9291",
"body": "Bumps the per-dependency group in /bindings/java with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [junit:junit](https://github.com/junit-team/junit4) | `3.8.1` | `4.13.2` |\n| [com.google.code.gson:gson](https://github.com/google/gson) | `2.10.1` | `2.13.2` |\n| [org.codehaus.mojo:exec-m\n[…]\nsion-update:semver-minor\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): bump the per-dependency group (#583)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-12T15:46:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4054d1b6b6116a4625f43ec61efa460a9b1993c8",
"body": "Bumps the per-dependency group with 12 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/checkout](https://github.com/actions/checkout) | `4.3.1` | `6.0.2` |\n| [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `6.2.0` |\n| [actions/setup-java](https://github.c\n[…]\nsion-update:semver-minor\n dependency-group: per-dependency\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump the per-dependency group with 12 updates (#593)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-12T12:30:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f7ca44bdf73eddd07f4a94e6c03a5c11e3e70d3",
"body": "- Expand dependabot coverage across Rust subcrates and other ecosystems.\n\n- Group updates per dependency and ignore vendored mimalloc crates.\n\n- Pin GitHub Actions to exact SHAs in existing workflows.",
"is_bot": false,
"headline": "chore(dependabot): expand coverage and pin workflows (#579)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-02-11T23:43:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "96360fa9d8e54c5890aa6b63274da6a64b7d3b34",
"body": "….1 (#571)\n\n- Introduce SafeHandleWrapper with gating, short drain wait, and deferred release on last in-flight exit.\n- Wire Engine/Program/Rvm/CompiledPolicy to wrapper (centralized handle use, interop helper).\n- Add C# memory growth tests (using/finalizer paths) and extend xtask C# runner options.\n- Add pooled marshalling utilities, ResultHelpers, and API cleanups; update versions/changelog.\n\nFixes #570. Closes #554\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "fix(bindings): add SafeHandleWrapper + memory growth checks; bump 0.9…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-02-09T18:22:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "455d2aa588753c3fbd2378371316949d53a7e726",
"body": "Additionally\n- Include more metadata in nuget package\n- Also generate snupkg for native symbols.\n We intentionally don't add the symbols for native rust shared library\n to the nuget package since that could increase the size of the nuget.\n We will revisit that later.\n- update licenses of all the bindings.\n\ncloses #551\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "chore(nuget): Add support for macosx (#553)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-02-02T18:39:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e5fe9b9acac1c97d28412e78b220c696b3c841b",
"body": null,
"is_bot": false,
"headline": "feat: add tests for number semantics (#555)",
"author_name": "Elijah Koulaxis",
"author_login": "kx0101",
"committed_at": "2026-01-31T01:57:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e9e34a519e9ed181295a1c7f3ead584d62149a6",
"body": "This is needed to publish regorus-mimalloc\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "chore: Gate exports using allocator-limits feature (#564)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-01-30T18:26:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f7a5496dcdddf4ebebb591cf710dd8691a52782",
"body": "…ings (#565)\n\n- FFI: add RVM/Program APIs, execution state accessors, HostAwait handling, and buffer/result helpers in rvm.rs, common.rs, engine.rs.\n- Compiler: emit HostAwait for __builtin_host_await in function_calls.rs.\n- RVM tests: add HostAwait regression cases and extend harness for suspend/re\n[…]\nam/Rvm bindings and examples in lib.rs, test.js.\n- Tooling: wire binding tests in xtask and ignore generated Java artifacts in .gitignore.\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "feat(bindings)!: add RVM/Program support across FFI and language bind…",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-01-30T18:25:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0316ccd90cb5539dc861fb6fc3d376582d4f765f",
"body": "- Prefix regorus- to mimalloc crates and add MIT licenses\n- alias dependencies to avoid code changes\n- add versions and release-plz publish entries\n- update Cargo.lock files for new crate names\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "chore(release): publish vendored mimalloc crates (#563)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-01-30T03:33:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "10eebfe54c18f0e8790454213b34cf647fa39188",
"body": "…flakiness (#558)\n\nHaving a separate integration test allows the execution tests to freely\nchange the global fallback limits without affecting other tests.\n\nalso ask release-plz to ignore xtask package\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "test(rvm): Move vm execution limit tests to a separate test to avoid …",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-01-28T22:45:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e688806ca0c7a63eb221d93969be1742365ad3c8",
"body": "Bump up the versions to 0.9.0 to match the C# binding version.\n\nAlso use central version management for C# projects\n\nAlso fix clippy lint errors\n\nSigned-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>",
"is_bot": false,
"headline": "chore: Keep regorus and binding versions in sync (#552)",
"author_name": "Anand Krishnamoorthi",
"author_login": "anakrish",
"committed_at": "2026-01-28T00:28:34Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 26,
"commits_last_year": 192,
"latest_release_at": "2026-07-21T22:08:39Z",
"latest_release_tag": "regorus-v0.11.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 43,
"days_since_latest_release": 0,
"mean_days_between_releases": 70.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 62,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "regorus",
"exists": true,
"license": "MIT AND Apache-2.0 AND BSD-3-Clause",
"keywords": [
"interpreter",
"no_std",
"opa",
"policy-as-code",
"rego"
],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/regorus",
"is_deprecated": false,
"latest_version": "0.11.0",
"repository_url": "https://github.com/microsoft/regorus",
"versions_count": 26,
"total_downloads": 1494931,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 216794,
"first_published_at": "2024-01-15T19:48:25.938901Z",
"latest_published_at": "2026-07-21T22:08:29.225759Z",
"latest_version_yanked": false,
"days_since_latest_publish": 0
},
{
"name": "xtask",
"exists": true,
"license": "MIT OR Apache-2.0",
"keywords": [
"automation",
"macos",
"release",
"codesign",
"xtask",
"command-line-utilities",
"development-tools::build-utils"
],
"ecosystem": "crates",
"matches_repo": false,
"registry_url": "https://crates.io/crates/xtask",
"is_deprecated": false,
"latest_version": "0.1.4",
"repository_url": "https://github.com/arcboxlabs/xtask",
"versions_count": 5,
"total_downloads": 549,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 183,
"first_published_at": "2026-06-24T11:01:25.012607Z",
"latest_published_at": "2026-06-30T09:55:36.509458Z",
"latest_version_yanked": false,
"days_since_latest_publish": 22
},
{
"name": "regorus-mimalloc",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "crates",
"matches_repo": true,
"registry_url": "https://crates.io/crates/regorus-mimalloc",
"is_deprecated": false,
"latest_version": "2.2.7",
"repository_url": "https://github.com/microsoft/regorus",
"versions_count": 2,
"total_downloads": 80560,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 7917,
"first_published_at": "2026-01-31T00:54:18.982746Z",
"latest_published_at": "2026-05-22T20:56:54.952225Z",
"latest_version_yanked": false,
"days_since_latest_publish": 60
}
]
},
"popularity": {
"forks": 68,
"stars": 330,
"watchers": 6,
"fork_history": {
"days": [
{
"date": "2023-02-28",
"count": 1
},
{
"date": "2023-03-02",
"count": 1
},
{
"date": "2023-05-14",
"count": 1
},
{
"date": "2023-11-15",
"count": 1
},
{
"date": "2023-11-23",
"count": 1
},
{
"date": "2023-12-21",
"count": 1
},
{
"date": "2023-12-23",
"count": 2
},
{
"date": "2024-02-15",
"count": 1
},
{
"date": "2024-02-29",
"count": 1
},
{
"date": "2024-03-06",
"count": 1
},
{
"date": "2024-03-10",
"count": 7
},
{
"date": "2024-03-29",
"count": 2
},
{
"date": "2024-04-05",
"count": 1
},
{
"date": "2024-04-09",
"count": 1
},
{
"date": "2024-04-23",
"count": 1
},
{
"date": "2024-07-15",
"count": 1
},
{
"date": "2024-09-04",
"count": 1
},
{
"date": "2024-09-14",
"count": 1
},
{
"date": "2024-09-28",
"count": 1
},
{
"date": "2024-10-04",
"count": 1
},
{
"date": "2024-11-15",
"count": 1
},
{
"date": "2024-12-21",
"count": 1
},
{
"date": "2025-01-22",
"count": 1
},
{
"date": "2025-02-14",
"count": 1
},
{
"date": "2025-04-09",
"count": 1
},
{
"date": "2025-05-02",
"count": 1
},
{
"date": "2025-05-12",
"count": 1
},
{
"date": "2025-05-15",
"count": 1
},
{
"date": "2025-06-02",
"count": 1
},
{
"date": "2025-06-24",
"count": 1
},
{
"date": "2025-07-06",
"count": 1
},
{
"date": "2025-07-26",
"count": 1
},
{
"date": "2025-08-06",
"count": 1
},
{
"date": "2025-08-13",
"count": 1
},
{
"date": "2025-09-03",
"count": 1
},
{
"date": "2025-10-28",
"count": 1
},
{
"date": "2025-12-08",
"count": 1
},
{
"date": "2025-12-13",
"count": 1
},
{
"date": "2025-12-23",
"count": 1
},
{
"date": "2025-12-30",
"count": 1
},
{
"date": "2026-01-09",
"count": 1
},
{
"date": "2026-01-20",
"count": 1
},
{
"date": "2026-01-28",
"count": 1
},
{
"date": "2026-02-12",
"count": 1
},
{
"date": "2026-02-18",
"count": 1
},
{
"date": "2026-02-25",
"count": 1
},
{
"date": "2026-03-12",
"count": 1
},
{
"date": "2026-03-23",
"count": 1
},
{
"date": "2026-03-25",
"count": 1
},
{
"date": "2026-04-01",
"count": 1
},
{
"date": "2026-04-09",
"count": 1
},
{
"date": "2026-04-15",
"count": 1
},
{
"date": "2026-06-12",
"count": 1
},
{
"date": "2026-06-27",
"count": 1
},
{
"date": "2026-06-30",
"count": 1
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-12",
"count": 1
},
{
"date": "2026-07-19",
"count": 1
},
{
"date": "2026-07-22",
"count": 1
}
],
"complete": true,
"collected": 67,
"total_forks": 68
},
"star_history": null,
"open_issues_and_prs": 58
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": true,
"typecheck_configs": [],
"toolchain_manifests": [
"Cargo.toml",
"bindings/csharp/Benchmarks/Benchmarks.csproj",
"bindings/csharp/Regorus.Tests/Regorus.Tests.csproj",
"bindings/csharp/Regorus/Regorus.csproj",
"bindings/csharp/TargetExampleApp/TargetExampleApp.csproj",
"bindings/csharp/TestApp/TestApp.csproj",
"bindings/ffi/Cargo.toml",
"bindings/go/go.mod",
"bindings/java/Cargo.toml",
"bindings/java/pom.xml",
"bindings/python/Cargo.toml",
"bindings/ruby/Cargo.toml",
"bindings/ruby/ext/regorusrb/Cargo.toml",
"bindings/wasm/Cargo.toml",
"mimalloc/Cargo.toml",
"mimalloc/mimalloc-sys/Cargo.toml",
"tests/ensure_no_std/Cargo.toml",
"xtask/Cargo.toml"
],
"largest_source_bytes": 167598,
"source_files_sampled": 422,
"oversized_source_files": 5,
"agent_instruction_files": [
".github/copilot-instructions.md"
],
"agent_instruction_max_bytes": 6013
},
"dependencies": {
"manifests": [
"Cargo.toml",
"mimalloc/Cargo.toml",
"xtask/Cargo.toml"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 308,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 17,
"direct_affected_count": 0
},
"ecosystems": [
"crates"
],
"dependencies": [
{
"name": "anyhow",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0.102"
},
{
"name": "serde",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0.150"
},
{
"name": "serde_json",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0.150"
},
{
"name": "hashbrown",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.17"
},
{
"name": "lazy_static",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.4.0"
},
{
"name": "thiserror",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.0"
},
{
"name": "data-encoding",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.8.0"
},
{
"name": "num-bigint",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.5"
},
{
"name": "num-traits",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.2"
},
{
"name": "parking_lot",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.12"
},
{
"name": "spin",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.12.0"
},
{
"name": "globset",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4.16"
},
{
"name": "regex",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.12.3"
},
{
"name": "semver",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0.28"
},
{
"name": "url",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.5.4"
},
{
"name": "uuid",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.22.0"
},
{
"name": "jsonschema",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.47.0"
},
{
"name": "chrono",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.4.44"
},
{
"name": "chrono-tz",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.10.1"
},
{
"name": "ipnet",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.12.0"
},
{
"name": "icu_casemap",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.1"
},
{
"name": "serde_yaml",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.9.16"
},
{
"name": "rand",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.10.0"
},
{
"name": "msvc_spectre_libs",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.1"
},
{
"name": "dashmap",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "6.1"
},
{
"name": "lru",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.18"
},
{
"name": "mimalloc",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.2.7"
},
{
"name": "indexmap",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "2.13.1"
},
{
"name": "postcard",
"manifest": "Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.1.3"
},
{
"name": "anyhow",
"manifest": "xtask/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0"
},
{
"name": "clap",
"manifest": "xtask/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "4.5"
},
{
"name": "regex",
"manifest": "xtask/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.12"
},
{
"name": "toml_edit",
"manifest": "xtask/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "0.25"
},
{
"name": "semver",
"manifest": "xtask/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "1.0"
},
{
"name": "zip",
"manifest": "xtask/Cargo.toml",
"ecosystem": "crates",
"version_constraint": "8.5"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "anyhow",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "anyhow",
"direct": true,
"version": "1.0.103",
"ecosystem": "crates"
},
{
"name": "chrono",
"direct": true,
"version": "0.4.45",
"ecosystem": "crates"
},
{
"name": "chrono-tz",
"direct": true,
"version": "0.10.4",
"ecosystem": "crates"
},
{
"name": "clap",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "clap",
"direct": true,
"version": "4.6.2",
"ecosystem": "crates"
},
{
"name": "dashmap",
"direct": true,
"version": "6.2.1",
"ecosystem": "crates"
},
{
"name": "data-encoding",
"direct": true,
"version": "2.11.0",
"ecosystem": "crates"
},
{
"name": "globset",
"direct": true,
"version": "0.4.19",
"ecosystem": "crates"
},
{
"name": "hashbrown",
"direct": true,
"version": "0.14.5",
"ecosystem": "crates"
},
{
"name": "hashbrown",
"direct": true,
"version": "0.17.1",
"ecosystem": "crates"
},
{
"name": "icu_casemap",
"direct": true,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "indexmap",
"direct": true,
"version": "2.14.0",
"ecosystem": "crates"
},
{
"name": "ipnet",
"direct": true,
"version": "2.12.0",
"ecosystem": "crates"
},
{
"name": "jsonschema",
"direct": true,
"version": "0.47.0",
"ecosystem": "crates"
},
{
"name": "lazy_static",
"direct": true,
"version": "1.5.0",
"ecosystem": "crates"
},
{
"name": "lru",
"direct": true,
"version": "0.18.1",
"ecosystem": "crates"
},
{
"name": "msvc_spectre_libs",
"direct": true,
"version": "0.1.3",
"ecosystem": "crates"
},
{
"name": "num-bigint",
"direct": true,
"version": "0.4.8",
"ecosystem": "crates"
},
{
"name": "num-bigint",
"direct": true,
"version": "0.5.1",
"ecosystem": "crates"
},
{
"name": "num-traits",
"direct": true,
"version": "0.2.19",
"ecosystem": "crates"
},
{
"name": "parking_lot",
"direct": true,
"version": "0.12.5",
"ecosystem": "crates"
},
{
"name": "postcard",
"direct": true,
"version": "1.1.3",
"ecosystem": "crates"
},
{
"name": "rand",
"direct": true,
"version": "0.10.2",
"ecosystem": "crates"
},
{
"name": "regex",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "regex",
"direct": true,
"version": "1.13.1",
"ecosystem": "crates"
},
{
"name": "semver",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "semver",
"direct": true,
"version": "1.0.28",
"ecosystem": "crates"
},
{
"name": "serde",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "serde",
"direct": true,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_json",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "serde_json",
"direct": true,
"version": "1.0.150",
"ecosystem": "crates"
},
{
"name": "serde_yaml",
"direct": true,
"version": "0.9.34+deprecated",
"ecosystem": "crates"
},
{
"name": "spin",
"direct": true,
"version": "0.12.2",
"ecosystem": "crates"
},
{
"name": "spin",
"direct": true,
"version": "0.9.9",
"ecosystem": "crates"
},
{
"name": "thiserror",
"direct": true,
"version": "2.0.18",
"ecosystem": "crates"
},
{
"name": "toml_edit",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "toml_edit",
"direct": true,
"version": "0.25.13+spec-1.1.0",
"ecosystem": "crates"
},
{
"name": "url",
"direct": true,
"version": "2.5.8",
"ecosystem": "crates"
},
{
"name": "uuid",
"direct": true,
"version": "1.24.0",
"ecosystem": "crates"
},
{
"name": "zip",
"direct": true,
"version": null,
"ecosystem": "crates"
},
{
"name": "zip",
"direct": true,
"version": "8.6.0",
"ecosystem": "crates"
},
{
"name": "adler2",
"direct": false,
"version": "2.0.1",
"ecosystem": "crates"
},
{
"name": "ahash",
"direct": false,
"version": "0.8.12",
"ecosystem": "crates"
},
{
"name": "aho-corasick",
"direct": false,
"version": "1.1.4",
"ecosystem": "crates"
},
{
"name": "alloca",
"direct": false,
"version": "0.4.0",
"ecosystem": "crates"
},
{
"name": "allocator-api2",
"direct": false,
"version": "0.2.21",
"ecosystem": "crates"
},
{
"name": "android_system_properties",
"direct": false,
"version": "0.1.5",
"ecosystem": "crates"
},
{
"name": "anes",
"direct": false,
"version": "0.1.6",
"ecosystem": "crates"
},
{
"name": "anstream",
"direct": false,
"version": "1.0.0",
"ecosystem": "crates"
},
{
"name": "anstyle",
"direct": false,
"version": "1.0.14",
"ecosystem": "crates"
},
{
"name": "anstyle-parse",
"direct": false,
"version": "1.0.0",
"ecosystem": "crates"
},
{
"name": "anstyle-query",
"direct": false,
"version": "1.1.5",
"ecosystem": "crates"
},
{
"name": "anstyle-wincon",
"direct": false,
"version": "3.0.11",
"ecosystem": "crates"
},
{
"name": "async-trait",
"direct": false,
"version": "0.1.89",
"ecosystem": "crates"
},
{
"name": "autocfg",
"direct": false,
"version": "1.5.1",
"ecosystem": "crates"
},
{
"name": "bindgen",
"direct": false,
"version": "0.72.1",
"ecosystem": "crates"
},
{
"name": "bit-set",
"direct": false,
"version": "0.8.0",
"ecosystem": "crates"
},
{
"name": "bit-vec",
"direct": false,
"version": "0.8.0",
"ecosystem": "crates"
},
{
"name": "bitflags",
"direct": false,
"version": "2.13.1",
"ecosystem": "crates"
},
{
"name": "borrow-or-share",
"direct": false,
"version": "0.2.4",
"ecosystem": "crates"
},
{
"name": "bstr",
"direct": false,
"version": "1.13.0",
"ecosystem": "crates"
},
{
"name": "bumpalo",
"direct": false,
"version": "3.20.3",
"ecosystem": "crates"
},
{
"name": "bytecount",
"direct": false,
"version": "0.6.9",
"ecosystem": "crates"
},
{
"name": "bytes",
"direct": false,
"version": "1.12.1",
"ecosystem": "crates"
},
{
"name": "cast",
"direct": false,
"version": "0.3.0",
"ecosystem": "crates"
},
{
"name": "cbindgen",
"direct": false,
"version": "0.29.4",
"ecosystem": "crates"
},
{
"name": "cc",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "cc",
"direct": false,
"version": "1.2.67",
"ecosystem": "crates"
},
{
"name": "cexpr",
"direct": false,
"version": "0.6.0",
"ecosystem": "crates"
},
{
"name": "cfg-if",
"direct": false,
"version": "1.0.4",
"ecosystem": "crates"
},
{
"name": "chacha20",
"direct": false,
"version": "0.10.1",
"ecosystem": "crates"
},
{
"name": "ciborium",
"direct": false,
"version": "0.2.2",
"ecosystem": "crates"
},
{
"name": "ciborium-io",
"direct": false,
"version": "0.2.2",
"ecosystem": "crates"
},
{
"name": "ciborium-ll",
"direct": false,
"version": "0.2.2",
"ecosystem": "crates"
},
{
"name": "clang-sys",
"direct": false,
"version": "1.8.1",
"ecosystem": "crates"
},
{
"name": "clap_builder",
"direct": false,
"version": "4.6.2",
"ecosystem": "crates"
},
{
"name": "clap_derive",
"direct": false,
"version": "4.6.1",
"ecosystem": "crates"
},
{
"name": "clap_lex",
"direct": false,
"version": "1.1.0",
"ecosystem": "crates"
},
{
"name": "cobs",
"direct": false,
"version": "0.3.0",
"ecosystem": "crates"
},
{
"name": "colorchoice",
"direct": false,
"version": "1.0.5",
"ecosystem": "crates"
},
{
"name": "combine",
"direct": false,
"version": "4.6.7",
"ecosystem": "crates"
},
{
"name": "core-foundation-sys",
"direct": false,
"version": "0.8.7",
"ecosystem": "crates"
},
{
"name": "cpufeatures",
"direct": false,
"version": "0.3.0",
"ecosystem": "crates"
},
{
"name": "crc32fast",
"direct": false,
"version": "1.5.0",
"ecosystem": "crates"
},
{
"name": "criterion",
"direct": false,
"version": "0.8.2",
"ecosystem": "crates"
},
{
"name": "criterion-plot",
"direct": false,
"version": "0.8.2",
"ecosystem": "crates"
},
{
"name": "crossbeam-deque",
"direct": false,
"version": "0.8.7",
"ecosystem": "crates"
},
{
"name": "crossbeam-epoch",
"direct": false,
"version": "0.9.20",
"ecosystem": "crates"
},
{
"name": "crossbeam-utils",
"direct": false,
"version": "0.8.22",
"ecosystem": "crates"
},
{
"name": "crunchy",
"direct": false,
"version": "0.2.4",
"ecosystem": "crates"
},
{
"name": "displaydoc",
"direct": false,
"version": "0.2.6",
"ecosystem": "crates"
},
{
"name": "either",
"direct": false,
"version": "1.16.0",
"ecosystem": "crates"
},
{
"name": "email_address",
"direct": false,
"version": "0.2.9",
"ecosystem": "crates"
},
{
"name": "embedded-io",
"direct": false,
"version": "0.4.0",
"ecosystem": "crates"
},
{
"name": "embedded-io",
"direct": false,
"version": "0.6.1",
"ecosystem": "crates"
},
{
"name": "equivalent",
"direct": false,
"version": "1.0.2",
"ecosystem": "crates"
},
{
"name": "errno",
"direct": false,
"version": "0.3.14",
"ecosystem": "crates"
},
{
"name": "fancy-regex",
"direct": false,
"version": "0.18.0",
"ecosystem": "crates"
},
{
"name": "fastrand",
"direct": false,
"version": "2.4.1",
"ecosystem": "crates"
},
{
"name": "find-msvc-tools",
"direct": false,
"version": "0.1.9",
"ecosystem": "crates"
},
{
"name": "flate2",
"direct": false,
"version": "1.1.9",
"ecosystem": "crates"
},
{
"name": "fluent-uri",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "foldhash",
"direct": false,
"version": "0.2.0",
"ecosystem": "crates"
},
{
"name": "form_urlencoded",
"direct": false,
"version": "1.2.2",
"ecosystem": "crates"
},
{
"name": "fraction",
"direct": false,
"version": "0.15.4",
"ecosystem": "crates"
},
{
"name": "futures-core",
"direct": false,
"version": "0.3.32",
"ecosystem": "crates"
},
{
"name": "futures-task",
"direct": false,
"version": "0.3.32",
"ecosystem": "crates"
},
{
"name": "futures-util",
"direct": false,
"version": "0.3.32",
"ecosystem": "crates"
},
{
"name": "getrandom",
"direct": false,
"version": "0.2.17",
"ecosystem": "crates"
},
{
"name": "getrandom",
"direct": false,
"version": "0.3.4",
"ecosystem": "crates"
},
{
"name": "getrandom",
"direct": false,
"version": "0.4.3",
"ecosystem": "crates"
},
{
"name": "glob",
"direct": false,
"version": "0.3.3",
"ecosystem": "crates"
},
{
"name": "half",
"direct": false,
"version": "2.7.1",
"ecosystem": "crates"
},
{
"name": "heck",
"direct": false,
"version": "0.5.0",
"ecosystem": "crates"
},
{
"name": "hermit-abi",
"direct": false,
"version": "0.5.2",
"ecosystem": "crates"
},
{
"name": "iana-time-zone",
"direct": false,
"version": "0.1.65",
"ecosystem": "crates"
},
{
"name": "iana-time-zone-haiku",
"direct": false,
"version": "0.1.2",
"ecosystem": "crates"
},
{
"name": "icu_casemap_data",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_collections",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_locale_core",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_normalizer",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_normalizer_data",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_properties",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_properties_data",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "icu_provider",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "idna",
"direct": false,
"version": "1.1.0",
"ecosystem": "crates"
},
{
"name": "idna_adapter",
"direct": false,
"version": "1.2.2",
"ecosystem": "crates"
},
{
"name": "is_terminal_polyfill",
"direct": false,
"version": "1.70.2",
"ecosystem": "crates"
},
{
"name": "itertools",
"direct": false,
"version": "0.13.0",
"ecosystem": "crates"
},
{
"name": "itoa",
"direct": false,
"version": "1.0.18",
"ecosystem": "crates"
},
{
"name": "jni",
"direct": false,
"version": "0.22.4",
"ecosystem": "crates"
},
{
"name": "jni-macros",
"direct": false,
"version": "0.22.4",
"ecosystem": "crates"
},
{
"name": "jni-sys",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "jni-sys-macros",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "js-sys",
"direct": false,
"version": "0.3.103",
"ecosystem": "crates"
},
{
"name": "jsonschema-regex",
"direct": false,
"version": "0.47.0",
"ecosystem": "crates"
},
{
"name": "libc",
"direct": false,
"version": "0.2.186",
"ecosystem": "crates"
},
{
"name": "libloading",
"direct": false,
"version": "0.8.9",
"ecosystem": "crates"
},
{
"name": "libm",
"direct": false,
"version": "0.2.16",
"ecosystem": "crates"
},
{
"name": "linux-raw-sys",
"direct": false,
"version": "0.12.1",
"ecosystem": "crates"
},
{
"name": "litemap",
"direct": false,
"version": "0.8.2",
"ecosystem": "crates"
},
{
"name": "lock_api",
"direct": false,
"version": "0.4.14",
"ecosystem": "crates"
},
{
"name": "log",
"direct": false,
"version": "0.4.33",
"ecosystem": "crates"
},
{
"name": "magnus",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "magnus",
"direct": false,
"version": "0.8.2",
"ecosystem": "crates"
},
{
"name": "magnus-macros",
"direct": false,
"version": "0.8.0",
"ecosystem": "crates"
},
{
"name": "memchr",
"direct": false,
"version": "2.8.3",
"ecosystem": "crates"
},
{
"name": "micromap",
"direct": false,
"version": "0.3.0",
"ecosystem": "crates"
},
{
"name": "minicov",
"direct": false,
"version": "0.3.8",
"ecosystem": "crates"
},
{
"name": "minimal-lexical",
"direct": false,
"version": "0.2.1",
"ecosystem": "crates"
},
{
"name": "miniz_oxide",
"direct": false,
"version": "0.8.9",
"ecosystem": "crates"
},
{
"name": "nom",
"direct": false,
"version": "7.1.3",
"ecosystem": "crates"
},
{
"name": "nu-ansi-term",
"direct": false,
"version": "0.50.3",
"ecosystem": "crates"
},
{
"name": "num",
"direct": false,
"version": "0.4.3",
"ecosystem": "crates"
},
{
"name": "num-cmp",
"direct": false,
"version": "0.1.0",
"ecosystem": "crates"
},
{
"name": "num-complex",
"direct": false,
"version": "0.4.6",
"ecosystem": "crates"
},
{
"name": "num-integer",
"direct": false,
"version": "0.1.46",
"ecosystem": "crates"
},
{
"name": "num-iter",
"direct": false,
"version": "0.1.46",
"ecosystem": "crates"
},
{
"name": "num-rational",
"direct": false,
"version": "0.4.2",
"ecosystem": "crates"
},
{
"name": "num_cpus",
"direct": false,
"version": "1.17.0",
"ecosystem": "crates"
},
{
"name": "once_cell",
"direct": false,
"version": "1.21.4",
"ecosystem": "crates"
},
{
"name": "once_cell_polyfill",
"direct": false,
"version": "1.70.2",
"ecosystem": "crates"
},
{
"name": "oorandom",
"direct": false,
"version": "11.1.5",
"ecosystem": "crates"
},
{
"name": "ordered-float",
"direct": false,
"version": "5.3.0",
"ecosystem": "crates"
},
{
"name": "outref",
"direct": false,
"version": "0.5.2",
"ecosystem": "crates"
},
{
"name": "owo-colors",
"direct": false,
"version": "4.3.0",
"ecosystem": "crates"
},
{
"name": "page_size",
"direct": false,
"version": "0.6.0",
"ecosystem": "crates"
},
{
"name": "parking_lot_core",
"direct": false,
"version": "0.9.12",
"ecosystem": "crates"
},
{
"name": "percent-encoding",
"direct": false,
"version": "2.3.2",
"ecosystem": "crates"
},
{
"name": "phf",
"direct": false,
"version": "0.12.1",
"ecosystem": "crates"
},
{
"name": "phf_shared",
"direct": false,
"version": "0.12.1",
"ecosystem": "crates"
},
{
"name": "pin-project-lite",
"direct": false,
"version": "0.2.17",
"ecosystem": "crates"
},
{
"name": "plotters",
"direct": false,
"version": "0.3.7",
"ecosystem": "crates"
},
{
"name": "plotters-backend",
"direct": false,
"version": "0.3.7",
"ecosystem": "crates"
},
{
"name": "plotters-svg",
"direct": false,
"version": "0.3.7",
"ecosystem": "crates"
},
{
"name": "portable-atomic",
"direct": false,
"version": "1.13.1",
"ecosystem": "crates"
},
{
"name": "potential_utf",
"direct": false,
"version": "0.1.5",
"ecosystem": "crates"
},
{
"name": "prettydiff",
"direct": false,
"version": "0.9.0",
"ecosystem": "crates"
},
{
"name": "proc-macro2",
"direct": false,
"version": "0.4.30",
"ecosystem": "crates"
},
{
"name": "proc-macro2",
"direct": false,
"version": "1.0.106",
"ecosystem": "crates"
},
{
"name": "pyo3",
"direct": false,
"version": "0.29.0",
"ecosystem": "crates"
},
{
"name": "pyo3-build-config",
"direct": false,
"version": "0.29.0",
"ecosystem": "crates"
},
{
"name": "pyo3-ffi",
"direct": false,
"version": "0.29.0",
"ecosystem": "crates"
},
{
"name": "pyo3-macros",
"direct": false,
"version": "0.29.0",
"ecosystem": "crates"
},
{
"name": "pyo3-macros-backend",
"direct": false,
"version": "0.29.0",
"ecosystem": "crates"
},
{
"name": "quote",
"direct": false,
"version": "0.6.13",
"ecosystem": "crates"
},
{
"name": "quote",
"direct": false,
"version": "1.0.46",
"ecosystem": "crates"
},
{
"name": "r-efi",
"direct": false,
"version": "5.3.0",
"ecosystem": "crates"
},
{
"name": "r-efi",
"direct": false,
"version": "6.0.0",
"ecosystem": "crates"
},
{
"name": "rand_core",
"direct": false,
"version": "0.10.1",
"ecosystem": "crates"
},
{
"name": "rayon",
"direct": false,
"version": "1.12.0",
"ecosystem": "crates"
},
{
"name": "rayon-core",
"direct": false,
"version": "1.13.0",
"ecosystem": "crates"
},
{
"name": "rb-sys",
"direct": false,
"version": "0.9.128",
"ecosystem": "crates"
},
{
"name": "rb-sys-build",
"direct": false,
"version": "0.9.128",
"ecosystem": "crates"
},
{
"name": "rb-sys-env",
"direct": false,
"version": "0.2.3",
"ecosystem": "crates"
},
{
"name": "redox_syscall",
"direct": false,
"version": "0.5.18",
"ecosystem": "crates"
},
{
"name": "ref-cast",
"direct": false,
"version": "1.0.25",
"ecosystem": "crates"
},
{
"name": "ref-cast-impl",
"direct": false,
"version": "1.0.25",
"ecosystem": "crates"
},
{
"name": "referencing",
"direct": false,
"version": "0.47.0",
"ecosystem": "crates"
},
{
"name": "regex-automata",
"direct": false,
"version": "0.4.16",
"ecosystem": "crates"
},
{
"name": "regex-syntax",
"direct": false,
"version": "0.8.11",
"ecosystem": "crates"
},
{
"name": "regorus-mimalloc-sys",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "rustc-hash",
"direct": false,
"version": "2.1.3",
"ecosystem": "crates"
},
{
"name": "rustc_version",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "rustix",
"direct": false,
"version": "1.1.4",
"ecosystem": "crates"
},
{
"name": "rustversion",
"direct": false,
"version": "1.0.23",
"ecosystem": "crates"
},
{
"name": "ryu",
"direct": false,
"version": "1.0.23",
"ecosystem": "crates"
},
{
"name": "same-file",
"direct": false,
"version": "1.0.6",
"ecosystem": "crates"
},
{
"name": "scopeguard",
"direct": false,
"version": "1.2.0",
"ecosystem": "crates"
},
{
"name": "seq-macro",
"direct": false,
"version": "0.3.6",
"ecosystem": "crates"
},
{
"name": "serde-wasm-bindgen",
"direct": false,
"version": "0.6.5",
"ecosystem": "crates"
},
{
"name": "serde_core",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_derive",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_magnus",
"direct": false,
"version": null,
"ecosystem": "crates"
},
{
"name": "serde_magnus",
"direct": false,
"version": "0.11.0",
"ecosystem": "crates"
},
{
"name": "serde_spanned",
"direct": false,
"version": "1.1.1",
"ecosystem": "crates"
},
{
"name": "shell-words",
"direct": false,
"version": "1.1.1",
"ecosystem": "crates"
},
{
"name": "shlex",
"direct": false,
"version": "1.3.0",
"ecosystem": "crates"
},
{
"name": "shlex",
"direct": false,
"version": "2.0.1",
"ecosystem": "crates"
},
{
"name": "simd-adler32",
"direct": false,
"version": "0.3.10",
"ecosystem": "crates"
},
{
"name": "simd_cesu8",
"direct": false,
"version": "1.2.0",
"ecosystem": "crates"
},
{
"name": "simdutf8",
"direct": false,
"version": "0.1.5",
"ecosystem": "crates"
},
{
"name": "siphasher",
"direct": false,
"version": "1.0.3",
"ecosystem": "crates"
},
{
"name": "slab",
"direct": false,
"version": "0.4.12",
"ecosystem": "crates"
},
{
"name": "smallvec",
"direct": false,
"version": "1.15.2",
"ecosystem": "crates"
},
{
"name": "stable_deref_trait",
"direct": false,
"version": "1.2.1",
"ecosystem": "crates"
},
{
"name": "strsim",
"direct": false,
"version": "0.11.1",
"ecosystem": "crates"
},
{
"name": "syn",
"direct": false,
"version": "0.15.44",
"ecosystem": "crates"
},
{
"name": "syn",
"direct": false,
"version": "2.0.119",
"ecosystem": "crates"
},
{
"name": "synstructure",
"direct": false,
"version": "0.13.2",
"ecosystem": "crates"
},
{
"name": "tap",
"direct": false,
"version": "1.0.1",
"ecosystem": "crates"
},
{
"name": "target-lexicon",
"direct": false,
"version": "0.13.5",
"ecosystem": "crates"
},
{
"name": "tempfile",
"direct": false,
"version": "3.27.0",
"ecosystem": "crates"
},
{
"name": "test-generator",
"direct": false,
"version": "0.3.1",
"ecosystem": "crates"
},
{
"name": "thiserror-impl",
"direct": false,
"version": "2.0.18",
"ecosystem": "crates"
},
{
"name": "tinystr",
"direct": false,
"version": "0.8.3",
"ecosystem": "crates"
},
{
"name": "tinytemplate",
"direct": false,
"version": "1.2.1",
"ecosystem": "crates"
},
{
"name": "toml",
"direct": false,
"version": "0.9.12+spec-1.1.0",
"ecosystem": "crates"
},
{
"name": "toml_datetime",
"direct": false,
"version": "0.7.5+spec-1.1.0",
"ecosystem": "crates"
},
{
"name": "toml_datetime",
"direct": false,
"version": "1.1.1+spec-1.1.0",
"ecosystem": "crates"
},
{
"name": "toml_parser",
"direct": false,
"version": "1.1.2+spec-1.1.0",
"ecosystem": "crates"
},
{
"name": "toml_writer",
"direct": false,
"version": "1.1.2+spec-1.1.0",
"ecosystem": "crates"
},
{
"name": "typed-path",
"direct": false,
"version": "0.12.3",
"ecosystem": "crates"
},
{
"name": "unicode-general-category",
"direct": false,
"version": "1.1.0",
"ecosystem": "crates"
},
{
"name": "unicode-ident",
"direct": false,
"version": "1.0.24",
"ecosystem": "crates"
},
{
"name": "unicode-xid",
"direct": false,
"version": "0.1.0",
"ecosystem": "crates"
},
{
"name": "unsafe-libyaml",
"direct": false,
"version": "0.2.11",
"ecosystem": "crates"
},
{
"name": "utf8_iter",
"direct": false,
"version": "1.0.4",
"ecosystem": "crates"
},
{
"name": "utf8parse",
"direct": false,
"version": "0.2.2",
"ecosystem": "crates"
},
{
"name": "uuid-simd",
"direct": false,
"version": "0.8.0",
"ecosystem": "crates"
},
{
"name": "version_check",
"direct": false,
"version": "0.9.5",
"ecosystem": "crates"
},
{
"name": "vsimd",
"direct": false,
"version": "0.8.0",
"ecosystem": "crates"
},
{
"name": "walkdir",
"direct": false,
"version": "2.5.0",
"ecosystem": "crates"
},
{
"name": "wasi",
"direct": false,
"version": "0.11.1+wasi-snapshot-preview1",
"ecosystem": "crates"
},
{
"name": "wasip2",
"direct": false,
"version": "1.0.4+wasi-0.2.12",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen",
"direct": false,
"version": "0.2.126",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-futures",
"direct": false,
"version": "0.4.76",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-macro",
"direct": false,
"version": "0.2.126",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-macro-support",
"direct": false,
"version": "0.2.126",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-shared",
"direct": false,
"version": "0.2.126",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-test",
"direct": false,
"version": "0.3.76",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-test-macro",
"direct": false,
"version": "0.3.76",
"ecosystem": "crates"
},
{
"name": "wasm-bindgen-test-shared",
"direct": false,
"version": "0.2.126",
"ecosystem": "crates"
},
{
"name": "web-sys",
"direct": false,
"version": "0.3.103",
"ecosystem": "crates"
},
{
"name": "winapi",
"direct": false,
"version": "0.3.9",
"ecosystem": "crates"
},
{
"name": "winapi-i686-pc-windows-gnu",
"direct": false,
"version": "0.4.0",
"ecosystem": "crates"
},
{
"name": "winapi-util",
"direct": false,
"version": "0.1.11",
"ecosystem": "crates"
},
{
"name": "winapi-x86_64-pc-windows-gnu",
"direct": false,
"version": "0.4.0",
"ecosystem": "crates"
},
{
"name": "windows-core",
"direct": false,
"version": "0.62.2",
"ecosystem": "crates"
},
{
"name": "windows-implement",
"direct": false,
"version": "0.60.2",
"ecosystem": "crates"
},
{
"name": "windows-interface",
"direct": false,
"version": "0.59.3",
"ecosystem": "crates"
},
{
"name": "windows-link",
"direct": false,
"version": "0.2.1",
"ecosystem": "crates"
},
{
"name": "windows-result",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "windows-strings",
"direct": false,
"version": "0.5.1",
"ecosystem": "crates"
},
{
"name": "windows-sys",
"direct": false,
"version": "0.61.2",
"ecosystem": "crates"
},
{
"name": "winnow",
"direct": false,
"version": "0.7.15",
"ecosystem": "crates"
},
{
"name": "winnow",
"direct": false,
"version": "1.0.4",
"ecosystem": "crates"
},
{
"name": "wit-bindgen",
"direct": false,
"version": "0.57.1",
"ecosystem": "crates"
},
{
"name": "writeable",
"direct": false,
"version": "0.6.3",
"ecosystem": "crates"
},
{
"name": "yoke",
"direct": false,
"version": "0.8.3",
"ecosystem": "crates"
},
{
"name": "yoke-derive",
"direct": false,
"version": "0.8.2",
"ecosystem": "crates"
},
{
"name": "zerocopy",
"direct": false,
"version": "0.8.54",
"ecosystem": "crates"
},
{
"name": "zerocopy-derive",
"direct": false,
"version": "0.8.54",
"ecosystem": "crates"
},
{
"name": "zerofrom",
"direct": false,
"version": "0.1.8",
"ecosystem": "crates"
},
{
"name": "zerofrom-derive",
"direct": false,
"version": "0.1.7",
"ecosystem": "crates"
},
{
"name": "zerotrie",
"direct": false,
"version": "0.2.4",
"ecosystem": "crates"
},
{
"name": "zerovec",
"direct": false,
"version": "0.11.6",
"ecosystem": "crates"
},
{
"name": "zerovec-derive",
"direct": false,
"version": "0.11.3",
"ecosystem": "crates"
},
{
"name": "zlib-rs",
"direct": false,
"version": "0.6.6",
"ecosystem": "crates"
},
{
"name": "zmij",
"direct": false,
"version": "1.0.23",
"ecosystem": "crates"
},
{
"name": "zopfli",
"direct": false,
"version": "0.8.3",
"ecosystem": "crates"
},
{
"name": "com.google.code.gson:gson",
"direct": false,
"version": "2.14.0",
"ecosystem": "maven"
},
{
"name": "junit:junit",
"direct": false,
"version": "4.13.2",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-javadoc-plugin",
"direct": false,
"version": "3.12.0",
"ecosystem": "maven"
},
{
"name": "org.apache.maven.plugins:maven-source-plugin",
"direct": false,
"version": "3.4.0",
"ecosystem": "maven"
},
{
"name": "org.codehaus.mojo:exec-maven-plugin",
"direct": false,
"version": "3.6.3",
"ecosystem": "maven"
},
{
"name": "Microsoft.Regorus",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "MSTest",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "System.Text.Json",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "YamlDotNet",
"direct": false,
"version": null,
"ecosystem": "nuget"
},
{
"name": "maturin",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "ast",
"direct": false,
"version": "2.4.3",
"ecosystem": "rubygems"
},
{
"name": "drb",
"direct": false,
"version": "2.2.3",
"ecosystem": "rubygems"
},
{
"name": "json",
"direct": false,
"version": "2.20.0",
"ecosystem": "rubygems"
},
{
"name": "language_server-protocol",
"direct": false,
"version": "3.17.0.5",
"ecosystem": "rubygems"
},
{
"name": "lint_roller",
"direct": false,
"version": "1.1.0",
"ecosystem": "rubygems"
},
{
"name": "minitest",
"direct": false,
"version": "6.0.6",
"ecosystem": "rubygems"
},
{
"name": "parallel",
"direct": false,
"version": "2.1.0",
"ecosystem": "rubygems"
},
{
"name": "parser",
"direct": false,
"version": "3.3.11.1",
"ecosystem": "rubygems"
},
{
"name": "prism",
"direct": false,
"version": "1.9.0",
"ecosystem": "rubygems"
},
{
"name": "racc",
"direct": false,
"version": "1.8.1",
"ecosystem": "rubygems"
},
{
"name": "rainbow",
"direct": false,
"version": "3.1.1",
"ecosystem": "rubygems"
},
{
"name": "rake",
"direct": false,
"version": "13.4.2",
"ecosystem": "rubygems"
},
{
"name": "rake-compiler",
"direct": false,
"version": "1.3.1",
"ecosystem": "rubygems"
},
{
"name": "rake-compiler-dock",
"direct": false,
"version": "1.12.0",
"ecosystem": "rubygems"
},
{
"name": "rb_sys",
"direct": false,
"version": "0.9.128",
"ecosystem": "rubygems"
},
{
"name": "regexp_parser",
"direct": false,
"version": "2.12.0",
"ecosystem": "rubygems"
},
{
"name": "rubocop",
"direct": false,
"version": "1.88.0",
"ecosystem": "rubygems"
},
{
"name": "rubocop-ast",
"direct": false,
"version": "1.49.1",
"ecosystem": "rubygems"
},
{
"name": "rubocop-minitest",
"direct": false,
"version": "0.39.1",
"ecosystem": "rubygems"
},
{
"name": "rubocop-rake",
"direct": false,
"version": "0.7.1",
"ecosystem": "rubygems"
},
{
"name": "ruby-progressbar",
"direct": false,
"version": "1.13.0",
"ecosystem": "rubygems"
},
{
"name": "unicode-display_width",
"direct": false,
"version": "3.2.0",
"ecosystem": "rubygems"
},
{
"name": "unicode-emoji",
"direct": false,
"version": "4.2.0",
"ecosystem": "rubygems"
}
],
"collected": true,
"truncated": false,
"total_count": 325,
"direct_count": 42,
"indirect_count": 283
}
},
"maintainership": {
"issues": {
"open_prs": 21,
"merged_prs": 429,
"open_issues": 37,
"closed_ratio": 0.75,
"closed_issues": 111,
"closed_unmerged_prs": 153
},
"bus_factor": 1,
"bot_contributors": 3,
"top_contributors": [
{
"type": "User",
"login": "anakrish",
"commits": 352,
"avatar_url": "https://avatars.githubusercontent.com/u/35780660?v=4"
},
{
"type": "User",
"login": "unexge",
"commits": 16,
"avatar_url": "https://avatars.githubusercontent.com/u/16212576?v=4"
},
{
"type": "User",
"login": "mingweishih",
"commits": 9,
"avatar_url": "https://avatars.githubusercontent.com/u/58993167?v=4"
},
{
"type": "User",
"login": "thedavemarshall",
"commits": 8,
"avatar_url": "https://avatars.githubusercontent.com/u/2751868?v=4"
},
{
"type": "User",
"login": "microsoftopensource",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/22527892?v=4"
},
{
"type": "User",
"login": "eric-therond",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/11455652?v=4"
},
{
"type": "User",
"login": "dekomissMSFT",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/73666576?v=4"
},
{
"type": "User",
"login": "kusha",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/1497090?v=4"
},
{
"type": "User",
"login": "tjons",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/6244502?v=4"
},
{
"type": "User",
"login": "Sumynwa",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/80809794?v=4"
}
],
"contributors_sampled": 22,
"top_contributor_share": 0.832
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"codeql.yml",
"dependabot-refresh-cargo-lockfiles.yml",
"dependency-audit.yml",
"feature-matrix.yml",
"miri.yml",
"pr-extensions.yml",
"pr.yml",
"publish-java.yml",
"publish-python.yml",
"publish-wasm.yml",
"release-plz.yml",
"rust-clippy.yml",
"test-c-cpp.yml",
"test-csharp.yml",
"test-ffi.yml",
"test-go.yml",
"test-java.yml",
"test-musl.yml",
"test-no-std.yml",
"test-python.yml",
"test-ruby.yml",
"test-wasm.yml",
"tests-debug.yml"
],
"has_docs_dir": true,
"linter_configs": [
".rubocop.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Cargo.lock",
"Gemfile.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 9,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 6,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 0,
"reason": "dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 7,
"reason": "dependency not pinned by hash detected -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "f98865fc980b9919d201e20969d9b28685ee72bc",
"ran_at": "2026-07-22T19:05:30Z",
"aggregate_score": 6.5,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-22T09:02:51Z",
"oldest_open_prs": [
{
"number": 212,
"created_at": "2024-04-24T12:33:33Z",
"last_comment_at": "2024-04-27T18:07:09Z",
"last_comment_author": "anakrish"
},
{
"number": 441,
"created_at": "2025-07-26T06:17:05Z",
"last_comment_at": "2025-08-20T11:07:12Z",
"last_comment_author": "anakrish"
},
{
"number": 442,
"created_at": "2025-07-26T07:00:32Z",
"last_comment_at": "2025-08-20T11:06:30Z",
"last_comment_author": "anakrish"
},
{
"number": 490,
"created_at": "2025-10-27T21:09:16Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 492,
"created_at": "2025-10-28T20:32:33Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 497,
"created_at": "2025-11-06T18:37:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 498,
"created_at": "2025-11-07T16:09:26Z",
"last_comment_at": "2026-01-31T14:28:25Z",
"last_comment_author": "wetpeanuts"
},
{
"number": 513,
"created_at": "2025-12-02T01:08:58Z",
"last_comment_at": "2025-12-31T15:14:06Z",
"last_comment_author": "anakrish"
},
{
"number": 648,
"created_at": "2026-03-31T13:17:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 665,
"created_at": "2026-04-07T18:08:47Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 666,
"created_at": "2026-04-07T22:10:48Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 672,
"created_at": "2026-04-09T13:04:15Z",
"last_comment_at": "2026-06-29T17:04:51Z",
"last_comment_author": "anakrish"
},
{
"number": 677,
"created_at": "2026-04-13T22:06:46Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 687,
"created_at": "2026-04-17T00:37:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 708,
"created_at": "2026-05-04T20:38:27Z",
"last_comment_at": "2026-05-04T20:39:33Z",
"last_comment_author": "anakrish"
},
{
"number": 722,
"created_at": "2026-05-13T20:10:10Z",
"last_comment_at": "2026-05-15T12:08:01Z",
"last_comment_author": "copilot-swe-agent"
},
{
"number": 745,
"created_at": "2026-06-09T17:05:22Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 755,
"created_at": "2026-07-02T02:33:16Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 759,
"created_at": "2026-07-02T20:35:18Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 762,
"created_at": "2026-07-13T20:23:52Z",
"last_comment_at": "2026-07-16T13:12:30Z",
"last_comment_author": "anakrish"
}
],
"last_merged_pr_at": "2026-07-21T22:06:45Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 58,
"created_at": "2023-12-06T15:58:37Z",
"last_comment_at": "2023-12-06T16:00:18Z",
"last_comment_author": "anakrish"
},
{
"number": 91,
"created_at": "2024-01-05T19:13:09Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 92,
"created_at": "2024-01-05T19:23:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 93,
"created_at": "2024-01-05T19:28:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 94,
"created_at": "2024-01-05T19:37:30Z",
"last_comment_at": "2025-09-09T19:02:21Z",
"last_comment_author": "anakrish"
},
{
"number": 95,
"created_at": "2024-01-05T19:39:38Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 96,
"created_at": "2024-01-05T19:48:29Z",
"last_comment_at": "2025-08-07T07:43:55Z",
"last_comment_author": "burgerdev"
},
{
"number": 97,
"created_at": "2024-01-05T19:54:24Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 98,
"created_at": "2024-01-05T19:59:06Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 99,
"created_at": "2024-01-05T20:02:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 150,
"created_at": "2024-02-21T14:53:37Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 161,
"created_at": "2024-02-23T21:37:48Z",
"last_comment_at": "2025-01-23T19:14:40Z",
"last_comment_author": "rijenkii"
},
{
"number": 166,
"created_at": "2024-02-29T15:13:51Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 167,
"created_at": "2024-02-29T15:31:27Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 168,
"created_at": "2024-02-29T15:51:48Z",
"last_comment_at": "2026-02-09T17:53:59Z",
"last_comment_author": "lc-spxl"
},
{
"number": 178,
"created_at": "2024-03-11T02:24:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 202,
"created_at": "2024-04-10T13:22:59Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 243,
"created_at": "2024-05-18T15:56:35Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 340,
"created_at": "2024-11-04T16:55:10Z",
"last_comment_at": "2024-11-06T21:22:37Z",
"last_comment_author": "anakrish"
},
{
"number": 440,
"created_at": "2025-07-21T15:00:35Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/microsoft/regorus",
"host": "github.com",
"name": "regorus",
"owner": "microsoft"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"security": 72,
"vitality": 93,
"community": 67,
"governance": 68,
"engineering": 84
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 93,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 94,
"inputs": {
"commits_last_year": 192,
"human_commit_share": 0.67,
"days_since_last_push": 0,
"active_weeks_last_year": 43
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "43/52 weeks with commits",
"points": 29.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 43
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "192 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 192
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 92,
"inputs": {
"releases_count": 26,
"latest_release_tag": "regorus-v0.11.0",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 70.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "26 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 26
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~70.8 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 70.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 67,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"forks": 68,
"stars": 330,
"watchers": 6,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "330 stars",
"points": 40.8,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 330
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "68 forks",
"points": 15.2,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 68
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "6 watchers",
"points": 3.9,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 6
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "excellent",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 89,
"inputs": {
"packages": [
"regorus",
"regorus-mimalloc"
],
"dependents": null,
"ecosystems": "crates",
"total_downloads": 1575491,
"monthly_downloads": 224711
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "224,711 downloads/month across crates",
"points": 71.4,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 224711,
"ecosystems": "crates"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 68,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 29,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 22,
"top_contributor_share": 0.832
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 83% of commits",
"points": 3.8,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 83
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "22 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 22
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"merged_prs": 429,
"open_issues": 37,
"closed_issues": 111,
"issue_closed_ratio": 0.75,
"closed_unmerged_prs": 153
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "75% of issues closed",
"points": 35.1,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 75
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "429/582 decided PRs merged",
"points": 28.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 429,
"decided": 582
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"followers": 125639,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "microsoft",
"public_repos": 8217,
"account_age_days": 4606
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "125,639 followers of microsoft",
"points": 25,
"status": "met",
"details": [
{
"code": "owner_followers",
"params": {
"count": 125639,
"login": "microsoft"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "8217 public repos, account ~12 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 8217
}
},
{
"code": "account_age_years",
"params": {
"years": 12
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"regorus",
"regorus-mimalloc"
],
"ecosystems": "crates",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on crates",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "crates"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "26 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 26
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 84,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "23 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 23
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".rubocop.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".rubocop.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"topics": [
"interpreter",
"opa",
"rego",
"rust",
"confidential-computing",
"policy-as-code",
"c",
"cpp",
"csharp",
"golang",
"javascript",
"python",
"wasm",
"java",
"no-std"
],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "15 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 15
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 72,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 65,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 6.5
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "dangerous workflow patterns detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 12 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 3.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 308 resolved dependencies against OSV; 17 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 308
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 17
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 308,
"unassessed_packages": 17,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 308,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 8
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 83,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
".github/copilot-instructions.md"
],
"agent_instruction_max_bytes": 6013
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": ".github/copilot-instructions.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".github/copilot-instructions.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 67,
"sampled": 67
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Cargo.lock",
"Gemfile.lock"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": true,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.2,
"toolchain_manifests": [
"Cargo.toml",
"bindings/csharp/Benchmarks/Benchmarks.csproj",
"bindings/csharp/Regorus.Tests/Regorus.Tests.csproj",
"bindings/csharp/Regorus/Regorus.csproj",
"bindings/csharp/TargetExampleApp/TargetExampleApp.csproj",
"bindings/csharp/TestApp/TestApp.csproj",
"bindings/ffi/Cargo.toml",
"bindings/go/go.mod",
"bindings/java/Cargo.toml",
"bindings/java/pom.xml",
"bindings/python/Cargo.toml",
"bindings/ruby/Cargo.toml",
"bindings/ruby/ext/regorusrb/Cargo.toml",
"bindings/wasm/Cargo.toml",
"mimalloc/Cargo.toml",
"mimalloc/mimalloc-sys/Cargo.toml",
"tests/ensure_no_std/Cargo.toml",
"xtask/Cargo.toml"
],
"dependency_bot_commit_share": 0.33
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Cargo.toml, bindings/csharp/Benchmarks/Benchmarks.csproj, bindings/csharp/Regorus.Tests/Regorus.Tests.csproj (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "Cargo.toml, bindings/csharp/Benchmarks/Benchmarks.csproj, bindings/csharp/Regorus.Tests/Regorus.Tests.csproj"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".rubocop.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".rubocop.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Rust (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "devcontainer, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "devcontainer, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "20 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 20,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "33 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 33,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 7,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Rust",
"largest_source_bytes": 167598,
"source_files_sampled": 422,
"oversized_source_files": 5
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Rust (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Rust"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "5/422 source files over 60KB",
"points": 54.3,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 422,
"oversized": 5
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"crates package 'xtask' points at a different repository (https://github.com/arcboxlabs/xtask); excluded from ecosystem scoring",
"deps.dev does not index crates:regorus@0.11.0; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-22T19:05:59.544459Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/microsoft/regorus.svg",
"full_name": "microsoft/regorus",
"license_state": "custom",
"license_spdx": null
}