Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 15:33 UTC

mvnpm / mvnpm

Use npm like any other Maven/Gradle dependency...

Java · TypeScriptApache-2.0★ 59 stars⑂ 9 forkssince Oct 2022View on GitHub ↗

mvnpm/mvnpm holds a health index of 62 out of 100, placing it in the Moderate band. It scores highest on AI Readiness (84/100) and lowest on Community & Adoption (50/100). It was last updated 53 days ago. A single contributor accounts for most of its recent work.

62
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

62
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

mvnpmOrganization
6 followers13 public repossince Oct 2022

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

72Good · 22% of overall
How it's scored
18/36Push recency — last push 53 days ago
6.9/36Commit cadence — 10/52 weeks with commits
18/18Commit volume — 115 commits in the last year
10/10OpenSSF Scorecard: Maintained — 16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year115
human_commit_share1
days_since_last_push53
active_weeks_last_year10

Release discipline

100Excellent
How it's scored
27/27Ships releases — 76 releases published
36/36Release recency — latest release 53 days ago
27/27Release cadence — a release every ~4.4 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count76
latest_release_tag5.1.17
releases_from_tagsno
days_since_latest_release53
mean_days_between_releases4.4
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

50Moderate · 18% of overall
How it's scored
28.6/60Stars — 59 stars
7.5/25Forks — 9 forks
0/15Watchers — 1 watchers
Inputs used
forks9
stars59
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

55Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
9.1/22.5Commit distribution — top contributor authored 60% of commits
9.5/13.5Contributor breadth — 7 contributors
10/10OpenSSF Scorecard: Contributors — project has 7 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled7
top_contributor_share0.595
How it's scored
42.4/46.8Issue resolution — 91% of issues closed
37.8/38.3PR acceptance — 187/189 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 1/17 approved changesets -- score normalized to 0
Inputs used
merged_prs187
open_issues5
closed_issues49
issue_closed_ratio0.907
closed_unmerged_prs2
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
6.1/25Owner reach — 6 followers of mvnpm
15.9/25Track record — 13 public repos, account ~3 yr old
Inputs used
followers6
owner_typeOrganization
is_verified
owner_loginmvnpm
public_repos13
account_age_days1,383

Engineering Quality

Are baseline engineering and documentation practices in place?

71Good · 20% of overall
How it's scored
24/24CI workflows — 2 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno
How it's scored
30/30README
0/25Documentation directory
15/15Documentation / homepage site — https://mvnpm.org/
10/10Repository description
10/10Topics — 4 topics
10/10Wiki
Inputs used
topicsgradle, java, maven, npm
has_wikiyes
homepagehttps://mvnpm.org/
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

60Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 1/17 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 7 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5
Excluded from scoring (no data or not applicable): branch_protection, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages89
unassessed_packages28
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 89 resolved dependencies against OSV. 28 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

84Good · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
15/15Machine-readable docs (llms.txt) — llms.txt present
40/40Legible commit history — 79 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtyes
legible_history_share0.79
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes3,922
How it's scored
12.6/18One-command bootstrap — locker/pom.xml, pom.xml (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — src/main/resources/web/tsconfig.json
10/10Reproducible environment — Dockerfile
10/10Demonstrated agent practice — 57 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configssrc/main/resources/web/tsconfig.json
agent_commit_share0.57
toolchain_manifestslocker/pom.xml, pom.xml
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Java (statically typed)
55/55Manageable file sizes — 0/137 source files over 60KB
Inputs used
primary_languageJava
largest_source_bytes48,297
source_files_sampled137
oversized_source_files0

Key facts

59GitHub stars
7contributors
115commits, last 12 months
53days since last push
76releases
1bus factor
5open issues
Mavenpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch maven package 'io.mvnpm:mvnpm' from its registry

More detail

Star and fork history 0 ★ / 9 ⇿
0Stars
9Forks
76Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

035810922023-082025-012026-07
Major 2Minor 4Patch 67

Each point covers 3 days.

OpenSSF Scorecard 5.0 / 10
5.0aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 15:32 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 1/17 approved changesets -- score normalized to 0
10Contributorsproject has 7 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 106
RegistryPackageVersion constraintManifest
Mavenorg.mvnpm.at.codemirror:autocomplete6.18.7locker/pom.xml
Mavenorg.mvnpm.at.codemirror:commands6.8.1locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-cpp6.0.3locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-css6.3.1locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-go6.0.1locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-html6.4.11locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-java6.0.2locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-javascript6.2.5locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-json6.0.2locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-less6.0.2locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-markdown6.3.4locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-php6.0.2locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-python6.1.7locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-rust6.0.2locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-sass6.0.2locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-sql6.8.0locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-xml6.1.0locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lang-yaml6.1.3locker/pom.xml
Mavenorg.mvnpm.at.codemirror:language6.11.3locker/pom.xml
Mavenorg.mvnpm.at.codemirror:lint6.9.6locker/pom.xml
Mavenorg.mvnpm.at.codemirror:state6.6.0locker/pom.xml
Mavenorg.mvnpm.at.codemirror:view6.43.0locker/pom.xml
Mavenorg.mvnpm.at.deno:darwin-arm642.5.4locker/pom.xml
Mavenorg.mvnpm.at.esbuild:darwin-arm640.25.10locker/pom.xml
Mavenorg.mvnpm.at.fortawesome:fontawesome-common-types6.5.2locker/pom.xml
Mavenorg.mvnpm.at.fortawesome:fontawesome-svg-core6.5.2locker/pom.xml
Mavenorg.mvnpm.at.fortawesome:free-brands-svg-icons6.5.2locker/pom.xml
Mavenorg.mvnpm.at.fortawesome:free-regular-svg-icons6.5.2locker/pom.xml
Mavenorg.mvnpm.at.fortawesome:free-solid-svg-icons6.5.2locker/pom.xml
Mavenorg.mvnpm.at.lezer:common1.5.2locker/pom.xml
Mavenorg.mvnpm.at.lezer:cpp1.1.5locker/pom.xml
Mavenorg.mvnpm.at.lezer:css1.3.3locker/pom.xml
Mavenorg.mvnpm.at.lezer:go1.0.1locker/pom.xml
Mavenorg.mvnpm.at.lezer:highlight1.2.3locker/pom.xml
Mavenorg.mvnpm.at.lezer:html1.3.13locker/pom.xml
Mavenorg.mvnpm.at.lezer:java1.1.3locker/pom.xml
Mavenorg.mvnpm.at.lezer:javascript1.5.4locker/pom.xml
Mavenorg.mvnpm.at.lezer:json1.0.3locker/pom.xml
Mavenorg.mvnpm.at.lezer:lr1.4.10locker/pom.xml
Mavenorg.mvnpm.at.lezer:markdown1.6.3locker/pom.xml
Mavenorg.mvnpm.at.lezer:php1.0.5locker/pom.xml
Mavenorg.mvnpm.at.lezer:python1.1.18locker/pom.xml
Mavenorg.mvnpm.at.lezer:rust1.0.2locker/pom.xml
Mavenorg.mvnpm.at.lezer:sass1.1.0locker/pom.xml
Mavenorg.mvnpm.at.lezer:xml1.0.6locker/pom.xml
Mavenorg.mvnpm.at.lezer:yaml1.0.4locker/pom.xml
Mavenorg.mvnpm.at.lit-labs:ssr-dom-shim1.5.1locker/pom.xml
Mavenorg.mvnpm.at.lit:reactive-element2.1.2locker/pom.xml
Mavenorg.mvnpm.at.marijn:find-cluster-break1.0.2locker/pom.xml
Mavenorg.mvnpm.at.mvnpm:vaadin-webcomponents25.1.0locker/pom.xml
Mavenorg.mvnpm.at.open-wc:dedupe-mixin1.4.0locker/pom.xml
Mavenorg.mvnpm.at.qomponent:qui-badge1.0.4locker/pom.xml
Mavenorg.mvnpm.at.qomponent:qui-card1.0.2locker/pom.xml
Mavenorg.mvnpm.at.qomponent:qui-code-block1.1.1locker/pom.xml
Mavenorg.mvnpm.at.qomponent:qui-icons1.0.2locker/pom.xml
Mavenorg.mvnpm.at.types:trusted-types2.0.7locker/pom.xml
Mavenorg.mvnpm.at.vaadin:router2.0.1locker/pom.xml
Mavenorg.mvnpm.at.vaadin:vaadin-development-mode-detector2.0.7locker/pom.xml
Mavenorg.mvnpm.at.vaadin:vaadin-usage-statistics2.1.3locker/pom.xml
Mavenorg.mvnpm:codemirror-asciidoc2.0.1locker/pom.xml
Mavenorg.mvnpm:compare-versions6.1.1locker/pom.xml
Mavenorg.mvnpm:crelt1.0.6locker/pom.xml
Mavenorg.mvnpm:dompurify3.2.7locker/pom.xml
Mavenorg.mvnpm:esbuild0.25.10locker/pom.xml
Mavenorg.mvnpm:highlight.js11.11.1locker/pom.xml
Mavenorg.mvnpm:ldrs1.1.7locker/pom.xml
Mavenorg.mvnpm:lit-element4.2.2locker/pom.xml
Mavenorg.mvnpm:lit-html3.3.2locker/pom.xml
Mavenorg.mvnpm:lit3.3.2locker/pom.xml
Mavenorg.mvnpm:marked17.0.5locker/pom.xml
Mavenorg.mvnpm:path-to-regexp6.3.0locker/pom.xml
Mavenorg.mvnpm:style-mod4.1.3locker/pom.xml
Mavenorg.mvnpm:tagged-tag1.0.0locker/pom.xml
Mavenorg.mvnpm:type-fest5.4.4locker/pom.xml
Mavenorg.mvnpm:w3c-keyname2.2.8locker/pom.xml
Maven${quarkus.platform.group-id}:${quarkus.platform.artifact-id}${quarkus.platform.version}pom.xml
Mavenorg.mvnpm.at.codemirror:view6.43.0pom.xml
Mavenorg.mvnpm.at.codemirror:state6.6.0pom.xml
Mavenio.smallrye.reactive:smallrye-mutiny-vertx-web-clientpom.xml
Mavenio.quarkus:quarkus-smallrye-healthpom.xml
Mavenio.quarkus:quarkus-restpom.xml
Mavenio.quarkus:quarkus-rest-jacksonpom.xml
Mavenorg.apache.maven:maven-modelpom.xml
Mavenorg.apache.maven:maven-artifactpom.xml
Mavenorg.apache.maven:maven-repository-metadatapom.xml
Mavenio.quarkus:quarkus-cachepom.xml
Mavenorg.apache.commons:commons-compresspom.xml
Mavencommons-codec:commons-codecpom.xml
Mavenio.quarkus:quarkus-rest-client-jacksonpom.xml
Mavenio.quarkus:quarkus-schedulerpom.xml
Mavenio.quarkus:quarkus-websocketspom.xml
Mavenio.quarkus:quarkus-mailerpom.xml
Mavenio.quarkus:quarkus-smallrye-fault-tolerancepom.xml
Mavenio.quarkus:quarkus-hibernate-orm-panachepom.xml
Mavenio.quarkus:quarkus-jdbc-postgresqlpom.xml
Mavenorg.pgpainless:pgpainless-core${pgpainless.version}pom.xml
Mavenorg.pgpainless:pgpainless-sop${pgpainless.version}pom.xml
Mavenio.mvnpm:importmappom.xml
Mavenio.quarkus:quarkus-arcpom.xml
Mavenio.quarkiverse.mcp:quarkus-mcp-server-http1.11.0pom.xml
Mavenio.quarkiverse.web-bundler:quarkus-web-bundler${quarkus-web-bundler.version}pom.xml
Mavenio.quarkiverse.roq:quarkus-roq-frontmatter${quarkus-roq-frontmatter.version}pom.xml
Mavenio.quarkiverse.roq:quarkus-roq-plugin-markdown${quarkus-roq-frontmatter.version}pom.xml
Mavenio.quarkiverse.roq:quarkus-roq-plugin-sitemap2.1.0pom.xml
Mavenio.quarkus:quarkus-ide-config${quarkus.ide-config.version}pom.xml
Mavenio.mvnpm:mvnpm-locker${project.version}pom.xml
All dependencies 117

Full resolved dependency set from the GitHub dependency graph: 108 direct and 9 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Mavencommons-codec:commons-codecdirect
Mavenio.mvnpm:importmapdirect
Mavenio.mvnpm:mvnpm-locker999-SNAPSHOTdirect
Mavenio.quarkiverse.mcp:quarkus-mcp-server-http1.11.0direct
Mavenio.quarkiverse.roq:quarkus-roq-frontmatter2.1.1direct
Mavenio.quarkiverse.roq:quarkus-roq-plugin-markdown2.1.1direct
Mavenio.quarkiverse.roq:quarkus-roq-plugin-sitemap2.1.0direct
Mavenio.quarkiverse.web-bundler:quarkus-web-bundler2.3.1direct
Mavenio.quarkus:quarkus-arcdirect
Mavenio.quarkus:quarkus-cachedirect
Mavenio.quarkus:quarkus-hibernate-orm-panachedirect
Mavenio.quarkus:quarkus-ide-configdirect
Mavenio.quarkus:quarkus-jdbc-postgresqldirect
Mavenio.quarkus:quarkus-mailerdirect
Mavenio.quarkus:quarkus-restdirect
Mavenio.quarkus:quarkus-rest-client-jacksondirect
Mavenio.quarkus:quarkus-rest-jacksondirect
Mavenio.quarkus:quarkus-schedulerdirect
Mavenio.quarkus:quarkus-smallrye-fault-tolerancedirect
Mavenio.quarkus:quarkus-smallrye-healthdirect
Mavenio.quarkus:quarkus-websocketsdirect
Mavenio.smallrye.reactive:smallrye-mutiny-vertx-web-clientdirect
Mavenorg.apache.commons:commons-compressdirect
Mavenorg.apache.maven:maven-artifactdirect
Mavenorg.apache.maven:maven-modeldirect
Mavenorg.apache.maven:maven-repository-metadatadirect
Mavenorg.mvnpm.at.codemirror:autocomplete6.18.7direct
Mavenorg.mvnpm.at.codemirror:commands6.8.1direct
Mavenorg.mvnpm.at.codemirror:lang-cpp6.0.3direct
Mavenorg.mvnpm.at.codemirror:lang-css6.3.1direct
Mavenorg.mvnpm.at.codemirror:lang-go6.0.1direct
Mavenorg.mvnpm.at.codemirror:lang-html6.4.11direct
Mavenorg.mvnpm.at.codemirror:lang-java6.0.2direct
Mavenorg.mvnpm.at.codemirror:lang-javascript6.2.5direct
Mavenorg.mvnpm.at.codemirror:lang-json6.0.2direct
Mavenorg.mvnpm.at.codemirror:lang-less6.0.2direct
Mavenorg.mvnpm.at.codemirror:lang-markdown6.3.4direct
Mavenorg.mvnpm.at.codemirror:lang-php6.0.2direct
Mavenorg.mvnpm.at.codemirror:lang-python6.1.7direct
Mavenorg.mvnpm.at.codemirror:lang-rust6.0.2direct
Mavenorg.mvnpm.at.codemirror:lang-sass6.0.2direct
Mavenorg.mvnpm.at.codemirror:lang-sql6.8.0direct
Mavenorg.mvnpm.at.codemirror:lang-xml6.1.0direct
Mavenorg.mvnpm.at.codemirror:lang-yaml6.1.3direct
Mavenorg.mvnpm.at.codemirror:language6.11.3direct
Mavenorg.mvnpm.at.codemirror:lint6.9.6direct
Mavenorg.mvnpm.at.codemirror:state6.6.0direct
Mavenorg.mvnpm.at.codemirror:view6.43.0direct
Mavenorg.mvnpm.at.deno:darwin-arm642.5.4direct
Mavenorg.mvnpm.at.esbuild:darwin-arm640.25.10direct
Mavenorg.mvnpm.at.fortawesome:fontawesome-common-types6.5.2direct
Mavenorg.mvnpm.at.fortawesome:fontawesome-svg-core6.5.2direct
Mavenorg.mvnpm.at.fortawesome:free-brands-svg-icons6.5.2direct
Mavenorg.mvnpm.at.fortawesome:free-regular-svg-icons6.5.2direct
Mavenorg.mvnpm.at.fortawesome:free-solid-svg-icons6.5.2direct
Mavenorg.mvnpm.at.lezer:common1.5.2direct
Mavenorg.mvnpm.at.lezer:cpp1.1.5direct
Mavenorg.mvnpm.at.lezer:css1.3.3direct
Mavenorg.mvnpm.at.lezer:go1.0.1direct
Mavenorg.mvnpm.at.lezer:highlight1.2.3direct
Mavenorg.mvnpm.at.lezer:html1.3.13direct
Mavenorg.mvnpm.at.lezer:java1.1.3direct
Mavenorg.mvnpm.at.lezer:javascript1.5.4direct
Mavenorg.mvnpm.at.lezer:json1.0.3direct
Mavenorg.mvnpm.at.lezer:lr1.4.10direct
Mavenorg.mvnpm.at.lezer:markdown1.6.3direct
Mavenorg.mvnpm.at.lezer:php1.0.5direct
Mavenorg.mvnpm.at.lezer:python1.1.18direct
Mavenorg.mvnpm.at.lezer:rust1.0.2direct
Mavenorg.mvnpm.at.lezer:sass1.1.0direct
Mavenorg.mvnpm.at.lezer:xml1.0.6direct
Mavenorg.mvnpm.at.lezer:yaml1.0.4direct
Mavenorg.mvnpm.at.lit-labs:ssr-dom-shim1.5.1direct
Mavenorg.mvnpm.at.lit:reactive-element2.1.2direct
Mavenorg.mvnpm.at.marijn:find-cluster-break1.0.2direct
Mavenorg.mvnpm.at.mvnpm:vaadin-webcomponentsdirect
Mavenorg.mvnpm.at.mvnpm:vaadin-webcomponents25.1.0direct
Mavenorg.mvnpm.at.open-wc:dedupe-mixin1.4.0direct
Mavenorg.mvnpm.at.qomponent:qui-badge1.0.4direct
Mavenorg.mvnpm.at.qomponent:qui-card1.0.2direct
Mavenorg.mvnpm.at.qomponent:qui-code-block1.1.1direct
Mavenorg.mvnpm.at.qomponent:qui-icons1.0.2direct
Mavenorg.mvnpm.at.types:trusted-types2.0.7direct
Mavenorg.mvnpm.at.vaadin:routerdirect
Mavenorg.mvnpm.at.vaadin:router2.0.1direct
Mavenorg.mvnpm.at.vaadin:vaadin-development-mode-detector2.0.7direct
Mavenorg.mvnpm.at.vaadin:vaadin-usage-statistics2.1.3direct
Mavenorg.mvnpm:codemirror-asciidoc2.0.1direct
Mavenorg.mvnpm:compare-versions6.1.1direct
Mavenorg.mvnpm:crelt1.0.6direct
Mavenorg.mvnpm:dompurify3.2.7direct
Mavenorg.mvnpm:esbuild0.25.10direct
Mavenorg.mvnpm:highlight.js11.11.1direct
Mavenorg.mvnpm:ldrsdirect
Mavenorg.mvnpm:ldrs1.1.7direct
Mavenorg.mvnpm:litdirect
Mavenorg.mvnpm:lit3.3.2direct
Mavenorg.mvnpm:lit-element4.2.2direct
Mavenorg.mvnpm:lit-html3.3.2direct
Mavenorg.mvnpm:markeddirect
Mavenorg.mvnpm:marked17.0.5direct
Mavenorg.mvnpm:path-to-regexp6.3.0direct
Mavenorg.mvnpm:style-mod4.1.3direct
Mavenorg.mvnpm:tagged-tag1.0.0direct
Mavenorg.mvnpm:type-fest5.4.4direct
Mavenorg.mvnpm:w3c-keyname2.2.8direct
Mavenorg.pgpainless:pgpainless-core1.5.5direct
Mavenorg.pgpainless:pgpainless-sop1.5.5direct
Mavenio.mvnpm:esbuild-java2.1.2indirect
Mavenio.quarkiverse.playwright:quarkus-playwright0.0.1indirect
Mavenio.quarkus.platform:quarkus-bom3.35.3indirect
Mavenio.quarkus.platform:quarkus-maven-plugin3.35.3indirect
Mavenio.quarkus:quarkus-junitindirect
Mavenio.quarkus:quarkus-junit-mockitoindirect
Mavenio.rest-assured:rest-assuredindirect
Mavennet.revelc.code.formatter:formatter-maven-plugin2.23.0indirect
Mavennet.revelc.code:impsort-maven-plugin1.13.0indirect
Dependency advisories 0

This repository publishes no package the index resolves, so its own dependency graph was assessed — 89 packages, which also include development and test pins that never ship: 0 carry known advisories, of which 0 are direct. 28 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "gradle",
        "java",
        "maven",
        "npm"
      ],
      "is_fork": false,
      "size_kb": 2559,
      "has_wiki": true,
      "homepage": "https://mvnpm.org/",
      "languages": {
        "CSS": 20784,
        "HTML": 9418,
        "Java": 412526,
        "Shell": 2179,
        "JavaScript": 278,
        "TypeScript": 80821
      },
      "pushed_at": "2026-06-02T01:07:27Z",
      "created_at": "2022-10-11T05:44:31Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-25T11:28:23Z",
      "description": "Use npm like any other Maven/Gradle dependency...",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Java",
      "significant_languages": [
        "Java",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "http://mvnpm.org",
      "name": "mvnpm",
      "type": "Organization",
      "login": "mvnpm",
      "company": null,
      "location": null,
      "followers": 6,
      "avatar_url": "https://avatars.githubusercontent.com/u/115525273?v=4",
      "created_at": "2022-10-11T05:36:09Z",
      "is_verified": null,
      "public_repos": 13,
      "account_age_days": 1383
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "5.1.17",
          "kind": "patch",
          "published_at": "2026-06-02T01:07:27Z"
        },
        {
          "tag": "5.1.16",
          "kind": "patch",
          "published_at": "2026-05-18T10:31:48Z"
        },
        {
          "tag": "5.1.15",
          "kind": "patch",
          "published_at": "2026-05-18T10:02:57Z"
        },
        {
          "tag": "5.1.14",
          "kind": "patch",
          "published_at": "2026-05-15T09:00:22Z"
        },
        {
          "tag": "5.1.13",
          "kind": "patch",
          "published_at": "2026-05-15T08:47:54Z"
        },
        {
          "tag": "5.1.12-5",
          "kind": "prerelease",
          "published_at": "2026-05-15T08:40:25Z"
        },
        {
          "tag": "5.1.12-4",
          "kind": "prerelease",
          "published_at": "2026-05-15T08:27:44Z"
        },
        {
          "tag": "5.1.12-3",
          "kind": "prerelease",
          "published_at": "2026-05-15T08:10:59Z"
        },
        {
          "tag": "5.1.11",
          "kind": "patch",
          "published_at": "2026-05-07T07:31:06Z"
        },
        {
          "tag": "5.1.10",
          "kind": "patch",
          "published_at": "2026-04-23T03:32:20Z"
        },
        {
          "tag": "5.1.9",
          "kind": "patch",
          "published_at": "2026-04-23T03:12:29Z"
        },
        {
          "tag": "5.1.8",
          "kind": "patch",
          "published_at": "2026-04-08T12:21:00Z"
        },
        {
          "tag": "5.1.7",
          "kind": "patch",
          "published_at": "2026-03-27T12:49:06Z"
        },
        {
          "tag": "5.1.6",
          "kind": "patch",
          "published_at": "2026-03-27T12:06:42Z"
        },
        {
          "tag": "5.1.5",
          "kind": "patch",
          "published_at": "2026-03-27T10:41:09Z"
        },
        {
          "tag": "5.1.4",
          "kind": "patch",
          "published_at": "2026-03-27T09:04:54Z"
        },
        {
          "tag": "5.1.3",
          "kind": "patch",
          "published_at": "2026-03-26T21:19:48Z"
        },
        {
          "tag": "5.1.2",
          "kind": "patch",
          "published_at": "2026-03-26T16:50:02Z"
        },
        {
          "tag": "5.1.1",
          "kind": "patch",
          "published_at": "2026-03-26T15:42:44Z"
        },
        {
          "tag": "5.1.0",
          "kind": "minor",
          "published_at": "2026-03-26T15:17:42Z"
        },
        {
          "tag": "5.0.8",
          "kind": "patch",
          "published_at": "2026-03-26T03:37:15Z"
        },
        {
          "tag": "5.0.7",
          "kind": "patch",
          "published_at": "2026-03-25T22:09:01Z"
        },
        {
          "tag": "5.0.6",
          "kind": "patch",
          "published_at": "2026-03-25T21:19:45Z"
        },
        {
          "tag": "5.0.5",
          "kind": "patch",
          "published_at": "2026-03-25T13:39:08Z"
        },
        {
          "tag": "5.0.4",
          "kind": "patch",
          "published_at": "2026-03-25T13:14:21Z"
        },
        {
          "tag": "5.0.3",
          "kind": "patch",
          "published_at": "2026-03-24T22:11:12Z"
        },
        {
          "tag": "5.0.2",
          "kind": "patch",
          "published_at": "2026-03-24T21:07:20Z"
        },
        {
          "tag": "5.0.1",
          "kind": "patch",
          "published_at": "2026-03-24T13:19:38Z"
        },
        {
          "tag": "5.0.0",
          "kind": "major",
          "published_at": "2026-03-24T07:07:02Z"
        },
        {
          "tag": "4.0.9",
          "kind": "patch",
          "published_at": "2026-03-23T14:11:29Z"
        },
        {
          "tag": "4.0.8",
          "kind": "patch",
          "published_at": "2026-03-17T13:35:09Z"
        },
        {
          "tag": "4.0.7",
          "kind": "patch",
          "published_at": "2026-03-17T12:36:32Z"
        },
        {
          "tag": "4.0.6",
          "kind": "patch",
          "published_at": "2026-03-17T02:29:43Z"
        },
        {
          "tag": "4.0.5",
          "kind": "patch",
          "published_at": "2026-01-12T18:23:32Z"
        },
        {
          "tag": "4.0.4",
          "kind": "patch",
          "published_at": "2025-07-17T05:40:57Z"
        },
        {
          "tag": "4.0.3",
          "kind": "patch",
          "published_at": "2025-07-17T05:22:20Z"
        },
        {
          "tag": "4.0.2",
          "kind": "patch",
          "published_at": "2025-05-13T03:46:53Z"
        },
        {
          "tag": "4.0.1",
          "kind": "patch",
          "published_at": "2025-04-13T04:47:34Z"
        },
        {
          "tag": "4.0.0",
          "kind": "major",
          "published_at": "2025-04-12T06:40:45Z"
        },
        {
          "tag": "3.3.17",
          "kind": "patch",
          "published_at": "2025-04-07T08:58:15Z"
        },
        {
          "tag": "3.3.16",
          "kind": "patch",
          "published_at": "2025-03-31T09:34:12Z"
        },
        {
          "tag": "3.3.15",
          "kind": "patch",
          "published_at": "2025-03-27T14:51:31Z"
        },
        {
          "tag": "3.3.14",
          "kind": "patch",
          "published_at": "2025-03-26T17:42:16Z"
        },
        {
          "tag": "3.3.13",
          "kind": "patch",
          "published_at": "2025-03-26T08:54:20Z"
        },
        {
          "tag": "3.3.12",
          "kind": "patch",
          "published_at": "2025-03-24T13:30:53Z"
        },
        {
          "tag": "3.3.11",
          "kind": "patch",
          "published_at": "2025-03-21T10:38:13Z"
        },
        {
          "tag": "3.3.10",
          "kind": "patch",
          "published_at": "2025-03-21T04:06:15Z"
        },
        {
          "tag": "3.3.9",
          "kind": "patch",
          "published_at": "2025-03-18T17:37:01Z"
        },
        {
          "tag": "3.3.8",
          "kind": "patch",
          "published_at": "2025-03-18T17:07:09Z"
        },
        {
          "tag": "3.3.7",
          "kind": "patch",
          "published_at": "2025-03-18T16:11:35Z"
        },
        {
          "tag": "3.3.6",
          "kind": "patch",
          "published_at": "2025-03-18T10:17:13Z"
        },
        {
          "tag": "3.3.5",
          "kind": "patch",
          "published_at": "2025-03-18T10:00:32Z"
        },
        {
          "tag": "3.3.4",
          "kind": "patch",
          "published_at": "2025-03-17T10:35:36Z"
        },
        {
          "tag": "3.3.3",
          "kind": "patch",
          "published_at": "2025-03-14T17:58:37Z"
        },
        {
          "tag": "3.3.2",
          "kind": "patch",
          "published_at": "2025-03-14T16:52:24Z"
        },
        {
          "tag": "3.3.1",
          "kind": "patch",
          "published_at": "2025-03-13T15:36:01Z"
        },
        {
          "tag": "3.3.0",
          "kind": "minor",
          "published_at": "2025-03-13T15:04:09Z"
        },
        {
          "tag": "3.2.4",
          "kind": "patch",
          "published_at": "2025-03-11T15:40:12Z"
        },
        {
          "tag": "3.2.3",
          "kind": "patch",
          "published_at": "2025-03-11T15:10:26Z"
        },
        {
          "tag": "3.2.2",
          "kind": "patch",
          "published_at": "2025-03-11T14:51:44Z"
        },
        {
          "tag": "3.2.1",
          "kind": "patch",
          "published_at": "2025-03-11T10:04:11Z"
        },
        {
          "tag": "3.2.0",
          "kind": "minor",
          "published_at": "2025-03-11T09:52:45Z"
        },
        {
          "tag": "3.1.12",
          "kind": "patch",
          "published_at": "2025-03-05T13:33:43Z"
        },
        {
          "tag": "3.1.11",
          "kind": "patch",
          "published_at": "2025-03-05T12:55:59Z"
        },
        {
          "tag": "3.1.10",
          "kind": "patch",
          "published_at": "2025-03-05T11:11:26Z"
        },
        {
          "tag": "3.1.9",
          "kind": "patch",
          "published_at": "2025-03-05T10:19:14Z"
        },
        {
          "tag": "3.1.8",
          "kind": "patch",
          "published_at": "2024-11-13T00:19:00Z"
        },
        {
          "tag": "3.1.7",
          "kind": "patch",
          "published_at": "2024-11-12T02:53:24Z"
        },
        {
          "tag": "3.1.6",
          "kind": "patch",
          "published_at": "2024-10-02T06:31:31Z"
        },
        {
          "tag": "3.1.5",
          "kind": "patch",
          "published_at": "2024-10-01T23:22:58Z"
        },
        {
          "tag": "3.1.4",
          "kind": "patch",
          "published_at": "2024-09-10T12:44:07Z"
        },
        {
          "tag": "3.1.3",
          "kind": "patch",
          "published_at": "2024-09-10T12:30:23Z"
        },
        {
          "tag": "3.1.2",
          "kind": "patch",
          "published_at": "2024-09-10T09:12:24Z"
        },
        {
          "tag": "3.1.1",
          "kind": "patch",
          "published_at": "2024-09-10T07:59:46Z"
        },
        {
          "tag": "3.1.0",
          "kind": "minor",
          "published_at": "2024-08-30T12:14:56Z"
        },
        {
          "tag": "3.0.42",
          "kind": "patch",
          "published_at": "2024-08-22T04:13:36Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "75a8168c03d0a0885c7f39e61bff2a4df3207f9e",
          "body": "Handle npm optional peer dependencies in generated POMs",
          "is_bot": false,
          "headline": "Merge pull request #41653 from phillip-kruger/fix-optional-peer-deps",
          "author_name": "Phillip Krüger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-06-02T01:03:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fedb5f9e0993e778f6792d275300c1a19c608450",
          "body": null,
          "is_bot": false,
          "headline": "Remove unused scope/optional params from populateFromMap",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-06-02T00:39:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c41eab9fac4caae651cf9f34702ddc88b36f6eb",
          "body": "Closes #41652",
          "is_bot": false,
          "headline": "Handle npm optional peer dependencies in generated POMs",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-06-02T00:36:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52bdbedcdc5dffa39b32f0aa4aae30be675d62e1",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Invalidate CDN JS bundle cache",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-18T10:00:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8fdd97d540872dd8696a6c171389390976656222",
          "body": "Strip Cache-Control on non-200 responses",
          "is_bot": false,
          "headline": "Merge pull request #41651 from ia3andy/strip-cache-on-error",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-18T09:01:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f430ea79840c706f2f71acd65c31c1a8891094f",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strip Cache-Control on non-200 responses to prevent CDN caching errors",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-18T08:50:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3ab45c91d91bcd83f35228ef355aa5cb6391a5cd",
          "body": "CORS was enabled without allowed origins, causing Quarkus to reject\nrequests with an Origin header (sent by browsers for script fetches).\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix CORS rejecting same-origin JS bundle requests with 403",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T09:00:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bddc4e28db7193a84ffb59e4425c4fe6c852ffc8",
          "body": "CORS was enabled without allowed origins, causing Quarkus to reject\nrequests with an Origin header (sent by browsers for script fetches).\nThis was the root cause of the 403 on static JS bundles.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix CORS rejecting same-origin JS bundle requests with 403",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T08:58:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fac67cfe5d17ebf595b9e6d950db15860271f816",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update locker BOM version in release workflow",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T08:47:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3269732e5a449b5fbea550a4ae247c52244dcf1b",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Upgrade locker-maven-plugin to 1.0.1 and migrate .locker to locker",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T08:39:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a64c05f9b1b6a3ab7ad6accfe001bbf9524c3d9a",
          "body": "Override @codemirror/view (6.43.0) and @codemirror/state (6.6.0) to\nresolve transitive version conflicts from qui-code-block. Remove the\nlocker step from the release workflow since the lock file should be\ncommitted at dev time.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix codemirror version conflicts and remove locker from release workflow",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T08:27:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f611531f5ca53d54a034800edcfe6232e5ae99ee",
          "body": null,
          "is_bot": false,
          "headline": "Change CORS property to enabled in application.properties",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T08:09:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39b4713fd94775972779d352eaea75f11c2ded57",
          "body": null,
          "is_bot": false,
          "headline": "Update Quarkus but revert cors settings",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T07:44:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cacf1f072302629368644b68aa5c840c27f1a4b",
          "body": null,
          "is_bot": false,
          "headline": "Downgrade Quarkus platform version to 3.32.4",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-15T07:30:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de8ed68610b481b7f29bbeaee9125e3d3e48d5d9",
          "body": "Update Quarkus and related dependencies versions",
          "is_bot": false,
          "headline": "Merge pull request #41650 from mvnpm/ia3andy-patch-2",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-07T07:30:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f89a83a43527dfb1fee501d1a5f13f802dff547",
          "body": null,
          "is_bot": false,
          "headline": "Update Quarkus and related dependencies versions",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-05-07T05:53:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c9075b059f1440fe4378eb4d2904d5309a696b9",
          "body": "…p-versions\n\nRestore explicit versions on frontend dependencies",
          "is_bot": false,
          "headline": "Merge pull request #41649 from phillip-kruger/fix/restore-frontend-de…",
          "author_name": "Phillip Krüger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T03:30:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7152d1d0bf60e8937b4f532f2863017bb6873235",
          "body": "The locker-maven-plugin:lock step in the release workflow resolves the POM\nbefore the locker BOM is installed, so these dependencies need explicit\nversions to avoid build failures.",
          "is_bot": false,
          "headline": "Restore explicit versions on frontend dependencies for release workflow",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T03:22:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bcfa6b942d79b4e7503c2db194779473c1e55952",
          "body": "Update Quarkus to 3.34.6 and bump Quarkiverse extensions",
          "is_bot": false,
          "headline": "Merge pull request #41648 from phillip-kruger/update/quarkus-3.34.6",
          "author_name": "Phillip Krüger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T03:10:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "962d0d0d82f5b1ccca876a7796028a439249b0c3",
          "body": "- Quarkus platform 3.32.4 → 3.34.6\n- quarkus-web-bundler 2.2.1 → 2.3.1\n- quarkus-roq-frontmatter 2.0.5 → 2.1.0\n- quarkus-roq-plugin-sitemap 2.0.5 → 2.1.0\n- Rename quarkus-junit5-mockito → quarkus-junit-mockito (relocated)\n- Fix deprecated quarkus.http.cors → quarkus.http.cors.enabled\n- Let mvnpm-locker BOM manage frontend dependency versions",
          "is_bot": false,
          "headline": "Update Quarkus to 3.34.6 and bump Quarkiverse extensions",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T02:57:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce7f1722ad17e1bb8d132fceec779099ca427f0e",
          "body": "…flow\n\nFix desktop scroll on home page",
          "is_bot": false,
          "headline": "Merge pull request #41647 from phillip-kruger/fix/desktop-scroll-over…",
          "author_name": "Phillip Krüger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T01:29:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0663756c8b8f8543ff12ca2f9b9cb6fe60cefd5d",
          "body": "Handle workspace: protocol versions in VersionConverter",
          "is_bot": false,
          "headline": "Merge pull request #41645 from ia3andy/fix-workspace-version",
          "author_name": "Phillip Krüger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T01:18:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b8fdd4978968cff1550f4cf9842f336bb9962eb",
          "body": "The app layout sets overflow:hidden on main at desktop width,\nexpecting each web component to manage its own scrolling. But\nmvnpm-home also had overflow:hidden on :host, so neither layer\nallowed scrolling — content below the fold (like Recently Synced)\nwas unreachable. Change :host to overflow-y:auto so the component\nscrolls internally.\n\nFixes #41646",
          "is_bot": false,
          "headline": "Fix desktop scroll on home page",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-04-23T01:15:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0d49d5ca1894baff31aaea5c3f8309868cca6f6",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Handle workspace: protocol versions in VersionConverter",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T16:53:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b1c13944fa7dafe9f512648528b1f9ffc98619c2",
          "body": "Fix sync stability and reduce memory footprint",
          "is_bot": false,
          "headline": "Merge pull request #41644 from ia3andy/memory-and-stability-fixes",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T11:47:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1fd7e07e67d1009f533023667f4a6c0001028f2",
          "body": "- Stream VersionDeserializer: use skipChildren() instead of deserializing\n  full package manifests just to extract version keys. Eliminates large\n  transient heap spikes on cache miss.\n\n- Cache lightweight ProjectInfo instead of full Project: only retains\n  distTags, version strings, and lastModifie\n[…]\nfactory method from Project.\n\n- Migrate all callers to getProjectInfo() (cached) or getProject()\n  (uncached, for REST API serialization only).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reduce NPM project cache memory footprint",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T11:33:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c8624718a1b7b905ae504a3e81ddbae08186aa5",
          "body": "Use InputStream/OutputStream instead of Files.readAllBytes() for PGP\ndetached signing. Avoids loading entire files into heap, cutting peak\nmemory per signing operation roughly in half. Also uses atomic write\npattern consistent with the rest of FileUtil.\n\nAdd FileUtilAscTest with signature verification tests.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Stream PGP signing to reduce memory pressure",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T10:54:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2213007ad17f4f5156b3da765a9578d48b8a7fa4",
          "body": "- MCP server 1.10.3 → 1.11.0\n- Add streamable auto-init to avoid clients needing to create sessions\n- Bump postgres memory limit from 150Mi to 512Mi (was OOMKilled)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Upgrade MCP server to 1.11.0, enable auto-init, bump postgres memory",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T10:54:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8f070f73f84e0d77f7b3b728dd4e4c0ea527a5a0",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update OpenShift deployment config",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T08:59:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "045142c8d29b9824ef0610ed224e814733686555",
          "body": "Composites (internal packages like @mvnpm/tiptap) don't have a tgz\nfile, but ensureFilesExist passed a non-existent tgz path to\ncreateBundleFiles, causing an UncheckedIOException on the Vert.x event\nloop that escaped the upload try/catch. This left items permanently\nstuck at UPLOADING stage. Regress\n[…]\n.\n\nAlso adds an attempt cap to resetUpload so items that repeatedly hang\nat UPLOADING (10+ attempts) move to ERROR instead of retrying forever.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix composite uploads stuck forever and cap stale upload retries",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-04-08T08:58:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d44bf1762ff2438fcda4f0464ed698b17e96a6eb",
          "body": "Set native image heap limit to match pod memory",
          "is_bot": false,
          "headline": "Merge pull request #41643 from mvnpm/fix-native-heap-limit",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T12:42:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08d3bdac8c89df18951b621698ae7a2f4ce60657",
          "body": "Was hardcoded to -Xmx8g but pod limit is 4Gi, causing OOM kills.\nNow configurable via JAVA_MAX_HEAP env var, defaults to 3g.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Set native image heap limit to match pod memory (3g default)",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T12:40:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4618d2befa2975c46c5a3179321aa6cad1dce368",
          "body": "Defer file creation to upload time",
          "is_bot": false,
          "headline": "Merge pull request #41642 from mvnpm/defer-file-creation",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T12:05:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8639f69fba52100ddc5281655d3fd72a0e3d5e9d",
          "body": "- checkAll/update: only create DB entry at INIT stage, no file creation\n- checkDependencies: same — queue deps for sync without creating files\n- Files are created by ensureFilesExist() on the pod that uploads\n- Avoids duplicate file creation across pods (emptyDir is per-pod)\n- Reduces checkDeps delay from 3s to 1s (no longer creating files)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Defer file creation to upload time to reduce memory pressure",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T12:04:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3c381ccffde5f6032f37ef8d813cadb0f97b3dfb",
          "body": "Throttle background sync to prevent OOM",
          "is_bot": false,
          "headline": "Merge pull request #41641 from mvnpm/throttle-background-sync",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T10:39:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57be54b38669ca49c307d1dde9505729212dd3c0",
          "body": "- Reduce checkAll batch size from 50 to 10 packages\n- Increase checkAll interval from 5m to 10m\n- Add 10s delay between packages to let bundle creation complete\n- Reduce checkError batch size from 50 to 10\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Throttle background sync to prevent OOM during packaging bursts",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T10:36:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ee1d805c68df0266415b1aec48ab3b22baec2176",
          "body": "Reduce NPM cache max size to prevent OOM evictions",
          "is_bot": false,
          "headline": "Merge pull request #41640 from mvnpm/fix-cache-memory-leak",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T09:01:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "248522a717ee74177e3dcd72e8905d999f5df409",
          "body": "Handle unpublished object in NPM time map deserialization",
          "is_bot": false,
          "headline": "Merge pull request #41639 from mvnpm/fix-time-map-deserialization",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T09:00:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33176c854dfb9a368758bf5398b04b4e8790a727",
          "body": "npm-project-cache and npm-package-cache were set to 100K entries each.\nWith Project/Package objects being several KB each, this allowed caches\nto grow to multiple GB, causing node-level OOM evictions.\n\nReduce to 1K (project) and 500 (package) entries — sufficient for\nshort-term deduplication while keeping memory bounded.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reduce NPM cache max size to prevent OOM evictions",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-27T08:46:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "77a555bb353cae5394d7a2250f5900fd316c749b",
          "body": "NPM adds an \"unpublished\" key with an object value to the \"time\" map\nwhen a package is unpublished. This caused a MismatchedInputException\nsince the map was typed as Map<String, String>.\n\nAdd TimeMapDeserializer that skips non-string entries, keeping only\nthe timestamp values we actually use (created, modified, version dates).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Handle unpublished object in NPM time map deserialization",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T21:26:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dd683f1dff7f542f9b5ab4b2baca2a6a28bb12a2",
          "body": "Fix NPM model URL deserialization crash and cleanup orphan sync items",
          "is_bot": false,
          "headline": "Merge pull request #41638 from mvnpm/fix-url-deserialization",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T21:18:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d9b1b2329d0532ab4465056143b8a0fddd5345a",
          "body": "…invalid version\n\nWhen a Maven artifact request creates a CentralSyncItem but the NPM package\ndoesn't exist (404) or has an invalid version, the sync item was left orphaned\nin PACKAGING state until the periodic checkPackaging scheduler cleaned it up.\n\nNow the resolveAndStream wrapper catches these errors and deletes the sync item\nimmediately. Also consolidates 4 duplicate private methods into one using a\nPathResolver functional interface.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refactor MavenRepositoryApi: cleanup orphan sync items on NPM 404 or …",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T19:02:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dbb031c5f535870a32b3f1541069d9f8cae67f54",
          "body": "…protocol crash\n\nPackages like @tanem/react-nprogress use github: shorthand URLs in\nhomepage and bugs fields. On GraalVM native image, java.net.URL rejects\nthe github: protocol, causing MalformedURLException that crashes\ndeserialization and blocks dependency checks indefinitely.\n\nSwitching to String avoids the issue entirely. Maven Central only\nrequires URL fields to be present, not valid HTTP URLs.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Replace java.net.URL with String in NPM model to fix GraalVM github: …",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T18:37:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4b67a58f608b10faf35d08c6431b2953807db00c",
          "body": "Fix stuck PACKAGING items with isPermanentlyUnavailable",
          "is_bot": false,
          "headline": "Merge pull request #41637 from mvnpm/fix-unrecoverable-packaging",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T16:46:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09f9768c344240c86e19809316adb8d3a3f63840",
          "body": "When multiple pods run with separate storage, the pod performing the\nupload may not have the package files created by another pod. This adds\nensureFilesExist() which recreates jar/pom/tgz and all bundle files\n(source, javadoc, signatures, hashes) synchronously before attempting\nthe upload. All creation services are idempotent.\n\nExtracts createBundleFiles() from PackageListener for reuse.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Ensure bundle files exist locally before upload (multi-pod fix)",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T16:38:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "05c09f53430a2e8a3898d5805db93d14795492bf",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Enable CORS for MCP server cross-origin requests",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T16:14:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4d84a684d33d50f3180b61622dafa03098a4b1c1",
          "body": "…cleanup\n\nBroadens the NPM error check to catch all permanently unrecoverable errors\n(400, 404, 405, 410) instead of only 404. This fixes stuck PACKAGING items\nlike @esbuild/linux-x64 (405 MethodNotAllowed) that were never cleaned up.\n\nAlso adds InvalidVersionException handling in checkPackaging and\ncheckDependencies to prevent items with unparsable versions from getting\nstuck indefinitely.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Replace isNotFound with isPermanentlyUnavailable for stuck packaging …",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T16:13:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "37ca0cd5577c56d37c6d48026758a00861e42a50",
          "body": "Fix event loop blocking in checkDependencies and cleanup",
          "is_bot": false,
          "headline": "Merge pull request #41636 from mvnpm/remove-dead-findDistinctGA",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed3c33ff589185fe936118f818ff9ee772a50979",
          "body": "- Add runSubscriptionOn to inner Uni in checkDependencies reactive pipeline\n  to prevent blocking the Vert.x event loop after delayIt() timer fires\n- Add toString() to Gav so [MULTI-POD] logs show actual GAV strings\n- Remove dead findDistinctGA() (replaced by SyncedPackage table)\n- Add test verifying checkDependencies works from a virtual thread\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix event loop blocking in checkDependencies and cleanup",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:36:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b41db83e067e2eda4925d314c9cc95b75a056700",
          "body": "Add index on SyncedPackage.nextCheck for batch claim queries",
          "is_bot": false,
          "headline": "Merge pull request #41635 from mvnpm/add-syncedpackage-nextcheck-index",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:15:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f0a1cdf5e731ffda3a2ae0004ee5bf470501af4",
          "body": "claimBatch() filters and sorts by nextCheck every 5 minutes.\nWithout an index, this does a full table scan on ~9000 rows.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add index on SyncedPackage.nextCheck for batch claim queries",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:15:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "22718bb8544fbffa89bf2e08729ecfcde8d6112a",
          "body": "Fix NPM registry stability and add multi-pod safety",
          "is_bot": false,
          "headline": "Merge pull request #41634 from mvnpm/fix-npm-registry-stability",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:11:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be9345c0c6304c7d41c2c099d4d6295670903409",
          "body": "…IMISTIC_WRITE\n\nExtract shared error retry logic into applyErrorRetry(), used by both\nclaimNextForErrorRetry (queue-based, FOR UPDATE SKIP LOCKED) and\nclaimForErrorRetry (specific GAV, PESSIMISTIC_WRITE). This ensures the\nmanual retry API endpoint is multi-pod safe.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Replace tryErroredItemAgain with atomic claimForErrorRetry using PESS…",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:10:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "851e0b680f7c40f65a5e65a9ac57719d6f68189a",
          "body": "checkCentralStatusAndUpdateStageIfNeeded() already calls changeStage()\nwith PESSIMISTIC_WRITE lock internally. The direct assignment + merge\nwas bypassing the lock and was a dead write.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove redundant direct stage assignment in checkReleaseInDbAndCentral",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:06:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2873aa182648b57ac929375b24c5d535a297f96e",
          "body": "…FLICT\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix insertIfNotPresent to use createNativeQuery for PostgreSQL ON CON…",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:01:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "299015283bd4305b6a3847f09385456236b0862f",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix createIfAbsent to use createNativeQuery for PostgreSQL ON CONFLICT",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T15:00:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0ebb6744d50650cf31650d7730c603a4f581ea9e",
          "body": "…c reset\n\n- changeStage() now uses PESSIMISTIC_WRITE lock to prevent duplicate event\n  publishing when two pods process the same item simultaneously\n- Add claimNextForErrorRetry() with SELECT FOR UPDATE SKIP LOCKED\n- Add claimNextForPackagingCheck() with SELECT FOR UPDATE SKIP LOCKED\n- Add periodicR\n[…]\n claim patterns and changeStage idempotency\n- Fix CheckPackagingTest cleanup ordering (BeforeEach + AfterEach)\n- Increase PostgreSQL PVC to 2Gi\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add multi-pod safety: atomic changeStage, claim patterns, and periodi…",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T14:26:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1254a5813774e4f7736dacc06498fa589318948e",
          "body": "Replace plain SELECT + changeStage pattern in nextToUploadStatusChange\nwith SELECT FOR UPDATE SKIP LOCKED in claimNextForUpload(). This ensures\nonly one pod can claim an INIT item for upload to Maven Central.\n\nKey changes:\n- Add CentralSyncItemService.claimNextForUpload() with atomic row lock\n- Use \n[…]\ndlock)\n- Add 30-minute time guard to resetUpload() for rolling deploy safety\n- Include upload attempt increment in the atomic claim transaction\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix multi-pod duplicate upload with atomic claim",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T11:07:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "363a4bee97fee20f4ea9c4c5f9c7f2efcb1379e2",
          "body": "- CheckPackagingTest: verifies NPM 404 deletes the PACKAGING item,\n  while NPM 429 (rate limit) keeps it for retry\n- SyncedPackageClaimTest: verifies createIfAbsent creates new entries\n  and does not overwrite existing nextCheck values\n- ContinuousSyncServiceTest: verifies changeStage to RELEASED\n  auto-creates a SyncedPackage entry\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add tests for checkPackaging cleanup and SyncedPackage lifecycle",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T11:02:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "89995fcb1c3d9c2a9cedb5555a7361d21d91a2fc",
          "body": "Replace plain SELECT with atomic UPDATE-based claim in SyncedPackage:\n- claimBatch atomically sets nextCheck=now+1h for due items\n- PostgreSQL row-level locking during UPDATE prevents double-claiming\n  across pods without explicit FOR UPDATE SKIP LOCKED\n- If pod crashes, items become eligible again \n[…]\nnextCheckInterval boundaries, full\n  checkAll flow with mocked NPM\n- GetPackageExceptionTest: isNotFound for 404/429/500, status\n  preservation\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make SyncedPackage batch claim atomic and add tests",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T11:02:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fb0064fa9edb5ca4f434df34d232b715181cefde",
          "body": "…years\n\nPackages published within the last 5 years are checked every 3 days.\nOnly truly abandoned packages (> 5 years since last publish) drop to\nthe 30-day interval.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Adjust nextCheck: only use 30-day interval for packages older than 5 …",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T11:02:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5fd001a7e77c06c8639d6b33bab3129d2d2d9b69",
          "body": "All @Blocking work (scheduled tasks, REST endpoints) now runs on\nvirtual threads instead of the platform thread pool. Blocked threads\nwaiting on NPM timeouts no longer consume OS threads, preventing the\nunbounded growth observed in production (thread-1 to thread-454).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Enable virtual threads to prevent thread pool exhaustion",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T11:02:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2083fcfc21a8d1c2fbe41627d113290cff052703",
          "body": "The old checkAll loaded ALL CentralSyncItem rows into memory every 4h\nto find distinct GAs (~9000 rows). Replace with:\n\n- New SyncedPackage entity (GA-level, composite key) with nextCheck field\n- Auto-created when any CentralSyncItem reaches RELEASED stage\n- Scheduler picks batches of 100 where next\n[…]\nncedpackage (groupId, artifactId)\n  SELECT DISTINCT groupId, artifactId FROM centralsyncitem\n  WHERE stage = 'RELEASED' ON CONFLICT DO NOTHING;\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Replace checkAll memory bomb with batch scheduling via SyncedPackage",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T09:42:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "764de64478848a4fe81e6e765a04bac79b43b6a5",
          "body": "GetPackageException now preserves the actual HTTP status from NPM\ninstead of hardcoding 404. Added isNotFound() to distinguish real\n404s from other errors (rate limiting, server errors).\n\ncheckPackaging now cleans up permanently broken items:\n- NPM 404 (package doesn't exist): delete from DB + disk \n[…]\ncy check (fix 4) to use isNotFound() so only\nreal 404s are treated as non-errors, while rate limits and server\nerrors still set the error flag.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix stuck PACKAGING items and preserve real NPM status codes",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T09:38:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "aaef2bd2062728267895e51c4d156af231a8e11f",
          "body": "Catch GetPackageException (NPM 404) separately from real errors in\ncheckDependencies. Packages that don't exist on NPM (e.g. private\nscoped packages like @blue/blue-base) are logged as info and skipped,\nnot treated as errors. This allows dependenciesChecked to be marked\nwhen all failures are just unavailable packages, stopping the infinite\nretry loop (e.g. i18next checked every 5min indefinitely).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix dependency check infinite loop for unavailable NPM packages",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T09:33:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7e69acbea5e3591d3bd99e4153ab124984d69e76",
          "body": "- getPackage: timeout 2min → 30s, retries 2 → 1\n- search: timeout 2min → 30s\n- Frees worker threads 4x faster when NPM is unresponsive\n- Reduces NPM call multiplication when rate-limited\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reduce NPM registry timeouts and retries",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T09:33:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a66c5c79344c4d7f9ed96c77d3158cc80ecf0081",
          "body": "- Add @CacheResult(\"npm-project-cache\") on getProject — uses existing\n  cache config (100k max, 1h TTL). Eliminates redundant NPM calls for\n  the same project metadata.\n- Reduce getProject retries from 3 to 1 — retries against a rate-limited\n  endpoint multiply the problem.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cache getProject and reduce retries to avoid NPM rate limiting",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-26T09:32:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a820f207b1896d2340d8909e535fb99f32035c91",
          "body": "Add MCP server name and description",
          "is_bot": false,
          "headline": "Merge pull request #41633 from phillip-kruger/mcp-desc",
          "author_name": "Phillip Krüger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-03-26T03:36:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "864c06fe25e7cd61574337cbc5807a751a4d15ff",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add MCP server name and description",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-03-26T03:04:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7439b5d92b16fa321ca8fba9d0d956f931efb43e",
          "body": "Fix event loop blocking and switch MCP to Streamable HTTP",
          "is_bot": false,
          "headline": "Merge pull request #41632 from ia3andy/fix-emiton-worker-pool",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T22:02:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "559984f5d4cfdcd3e256ba9e612723385188e0d2",
          "body": "SSE transport fails behind Cloudflare due to connection buffering/timeouts.\nStreamable HTTP uses regular request/response cycles which work reliably\nthrough CDN proxies. Updated docs with new endpoint and setup instructions.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Switch MCP transport from SSE to Streamable HTTP",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T21:53:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f0caf9540c72d780e282dedb9b5d3c692203c38b",
          "body": "The invoke/subscribe block after the reactive delay runs blocking\noperations (package creation). Using emitOn ensures these run on\nthe default worker pool instead of the event loop thread.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Move dependency resolution downstream processing to worker pool",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T21:42:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "68d4dbb5d092356837256729f2ca9d09c5befb2a",
          "body": "Fix NPM registry connection pool exhaustion",
          "is_bot": false,
          "headline": "Merge pull request #41631 from ia3andy/fix-npm-registry-timeouts",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T21:19:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d67d5e2955d4f655ddf43fb58c696d20de9dd87",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove unused Transactional import",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T21:19:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7388df56790321e74c146df26a66b540a7fda499",
          "body": "When the NPM registry becomes slow/unresponsive, getPackage() and search()\nwould block indefinitely (no @Timeout), leaking worker threads and HTTP\nconnections every 60s via checkPackaging(). After hours, the connection pool\nis exhausted and all user-facing requests fail.\n\n- Add @Timeout(2min) on Npm\n[…]\naper cascade)\n- Add connect-timeout(5s) and read-timeout(2min) for npm-registry REST client\n- Increase checkPackaging interval to 10min in prod\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix NPM registry connection pool exhaustion causing server timeouts",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T21:16:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4fe3a39b4c742cfe699bc9c898177c975009141",
          "body": "Add cache-busting UUID to static assets",
          "is_bot": false,
          "headline": "Merge pull request #41630 from ia3andy/fix-asset-caching",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T13:38:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c86037c55bcb180eb52af980106948153420a0f2",
          "body": "Use quarkus.uuid to generate a unique build ID per startup and append\nit as a query parameter to favicons and logo SVGs, ensuring browsers\nfetch fresh assets after each deployment.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add cache-busting UUID to static assets",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T13:35:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7583370640c465d8fc9b955a3044b8dbaf12de8c",
          "body": "Fix mobile padding and frontmatter-driven nav visibility",
          "is_bot": false,
          "headline": "Merge pull request #41629 from ia3andy/fix-mobile-padding",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T12:57:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6d62bd3a9f6bb7603fd7424f4149d29a9c68b21",
          "body": "- Add padding to MCP card on mobile so it doesn't touch screen edges\n- Move MCP nav to 3rd position (after Browse, Getting Started)\n- Replace hardcoded CSS nav hiding with frontmatter `mobile: true/false`\n  flag and `nav-desktop-only` class\n- Hide MCP, Releases, Live, Composites on mobile nav\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix mobile padding and make nav visibility frontmatter-driven",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T12:41:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "21f71567b641b4a2300ca4a5c12913abdb98f5c1",
          "body": "Move sitemap.xml to static public file",
          "is_bot": false,
          "headline": "Merge pull request #41628 from ia3andy/fix-vaadin25-theming",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T12:08:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8885767b693d2e33b61d5f5404600b20167bf2e2",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add /ai/ page to sitemap",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T12:08:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0ae662b5e164d2dd9e38133c508216ab94eb4f25",
          "body": "Replace the dynamic Qute template include in content/sitemap.xml with\na pre-rendered static sitemap.xml in public/, including all current\nsite pages with proper schema location attributes.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Move sitemap.xml from Qute template to static public file",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T12:07:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1a32bcf59bda953a6c450179d5a78f9e9a9bb719",
          "body": "Add MCP Server for AI Agent Integration",
          "is_bot": false,
          "headline": "Merge pull request #41627 from phillip-kruger/mcp",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-25T12:01:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43fcaf5b842e3bfcec785c528457725b2b42436b",
          "body": "- Add /ai-agent doc page with setup guides for Claude Code, Cursor,\n  VS Code, Windsurf, and generic MCP clients\n- Add AI Agent Integration card to home page hero section\n- List all 11 MCP tools with descriptions and endpoint details\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add MCP documentation page and home page teaser card",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-03-25T11:44:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6257af6beda0709f7fd58ccb9a62cf1ed5fa7891",
          "body": "Signed-off-by: Phillip Kruger <phillip.kruger@gmail.com>",
          "is_bot": false,
          "headline": "Added MCP Endpoint",
          "author_name": "Phillip Kruger",
          "author_login": "phillip-kruger",
          "committed_at": "2026-03-25T10:43:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f721809b4938a7e8b29872899124e25c1a27f99b",
          "body": "Fix Vaadin 25 theming and restore missing dep versions",
          "is_bot": false,
          "headline": "Merge pull request #41625 from ia3andy/fix-vaadin25-theming",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T22:10:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b624415c3f5b66fa378641b90e4720ee793ffc75",
          "body": "- Import @vaadin/vaadin-lumo-styles/lumo.css to enable Lumo theme\n  auto-injection into Vaadin component shadow DOMs\n- Add complete --lumo-contrast-* scale (5-90pct) so all Lumo internals\n  resolve to our design system colors instead of default blueish grays\n- Add --lumo-*-text-color overrides (body\n[…]\n(Lumo handles these now)\n- Remove manual radio/checkbox sizing overrides (Lumo sets proper sizes)\n- Add autocomplete=\"off\" to search text field\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Import Vaadin Lumo CSS and fix theming issues",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T22:09:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "82b29e711cb0c1ff12785b58fcb87074e91ae258",
          "body": "Vaadin 25 changed CSS variable system from --lumo-* to --vaadin-* and\nLumo injection into shadow DOM no longer works. This adds comprehensive\n--vaadin-* overrides (selection, buttons, grid, overlay, tabs) in both\ndark/light themes, and per-component overrides for radio buttons,\ncheckboxes, and tabs \n[…]\nns\nfor 4 dependencies not managed by any BOM, centers the scope radio group,\nadds clipboard copy notification, and updates locked dependencies.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix Vaadin 25 theming and restore missing dependency versions",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T21:40:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65626154ae17f1a3187d516c1cea1aece01f7183",
          "body": null,
          "is_bot": false,
          "headline": "Fix layouts css issues",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T21:36:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4e47af3a2244966b3acd22d0f36fddf432b2c17",
          "body": null,
          "is_bot": false,
          "headline": "Merge pull request #41624 from mvnpm/fix-layout",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T19:34:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "107a6236345bf466429a1b731bb3be0019a02588",
          "body": "- Upgrade Quarkus platform from 3.27.1 to 3.32.4 (Vaadin 24 → 25)\n- Migrate CSS from --lumo-* to --vaadin-* variables for Vaadin 25 compatibility\n- Keep --lumo-* overrides for qui-card/qui-badge which still use Lumo\n- Fix search result click requiring two clicks (focusout race condition)\n- Add brows\n[…]\no screen edge\n- Fix mobile search padding-top\n- Restore progress bar sizing lost in Vaadin 25\n- Fix selected tab color in shadow DOM components\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Upgrade Quarkus to 3.32.4 and fix Vaadin 25 theming + search UX",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T17:15:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a10c1a758d3cca6d8bea085187dd9da97dcad509",
          "body": null,
          "is_bot": false,
          "headline": "Fix layouts css issues (#41623)",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T13:00:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce5de1c3e70033ba101828a523c682df02c3d755",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update README with doc/about page content and dark/light logo",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T08:00:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fc579d3bce621c4c36d3c39b66fc1ea72a4e9584",
          "body": null,
          "is_bot": false,
          "headline": "Update image path for mvnpm repository schema (#41622)",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T07:06:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30c3e287d18663285d559fb09082232d5938059c",
          "body": "* feat: add quarkus-roq-frontmatter dependency\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* chore: move static assets to Roq public directory\n\n* feat: add Roq layout template and nav styles\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* feat: add Roq frontmatter content p\n[…]\n\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* Add about page\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Migrate frontend to Roq frontmatter (#41621)",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-24T07:05:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4e8c3328b54466b206bdb4d63f9e031fc74d5644",
          "body": "UI and logo fixes, cleaning and mobile support",
          "is_bot": false,
          "headline": "Merge pull request #41620 from mvnpm/ui-brand-refresh",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-23T14:10:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6575d69d39a5275db75c7b2bb80dcf9bfde41fc1",
          "body": "… assets\n\n- Update {/> logo across all brand assets and favicons\n- Add light/dark theme support with theme-mixin\n- Add how-does-mvnpm-work SVG diagram and generated PNG\n- Add og-image and favicon.ico\n- Remove legacy brand assets (fulllogo, grayscale, icononly, print, textonly)\n- Update .gitignore for Claude Code and Playwright MCP\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "UI brand refresh: update logo, light mode support, and cleanup legacy…",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-23T14:02:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d489758c37604625b20e3f2c45cf226d9e571d72",
          "body": "Fix cleanup to only delete RELEASED items and add GAV logging",
          "is_bot": false,
          "headline": "Merge pull request #41619 from ia3andy/ui-light-mode-and-logo-update",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-17T13:34:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c799ebdfc5d8be9789a3470dfcd3e95404fde6a4",
          "body": "- Only delete version directories for items confirmed RELEASED in DB\n- Log warning for items not found in DB instead of deleting\n- Log GAV for each deleted directory for traceability\n- Fix deprecated config keys (hibernate-orm, mailer)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix cleanup to only delete RELEASED items and add GAV logging",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-17T13:15:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a52a113dec271215c03c6bbf3ff09c65b964601e",
          "body": "Fixes and Improvements",
          "is_bot": false,
          "headline": "Merge pull request #41618 from ia3andy/ui-light-mode-and-logo-update",
          "author_name": "Andy Damevin",
          "author_login": "ia3andy",
          "committed_at": "2026-03-17T12:35:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 76,
      "commits_last_year": 115,
      "latest_release_at": "2026-06-02T01:07:27Z",
      "latest_release_tag": "5.1.17",
      "releases_from_tags": false,
      "days_since_last_push": 53,
      "active_weeks_last_year": 10,
      "days_since_latest_release": 53,
      "mean_days_between_releases": 4.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 9,
      "stars": 59,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2023-08-17",
            "count": 2
          },
          {
            "date": "2023-08-24",
            "count": 1
          },
          {
            "date": "2024-01-16",
            "count": 1
          },
          {
            "date": "2024-09-07",
            "count": 1
          },
          {
            "date": "2024-11-13",
            "count": 1
          },
          {
            "date": "2025-12-04",
            "count": 1
          },
          {
            "date": "2026-04-25",
            "count": 1
          },
          {
            "date": "2026-07-14",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 9,
        "total_forks": 9
      },
      "star_history": null,
      "open_issues_and_prs": 6
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "src/main/resources/web/tsconfig.json"
      ],
      "toolchain_manifests": [
        "locker/pom.xml",
        "pom.xml"
      ],
      "largest_source_bytes": 48297,
      "source_files_sampled": 137,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 3922
    },
    "dependencies": {
      "manifests": [
        "locker/pom.xml",
        "pom.xml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 89,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 28,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "maven"
      ],
      "dependencies": [
        {
          "name": "org.mvnpm.at.codemirror:autocomplete",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.18.7"
        },
        {
          "name": "org.mvnpm.at.codemirror:commands",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.8.1"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-cpp",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.3"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-css",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.3.1"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-go",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.1"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-html",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.4.11"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-java",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.2"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-javascript",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.2.5"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-json",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.2"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-less",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.2"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-markdown",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.3.4"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-php",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.2"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-python",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.1.7"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-rust",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.2"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-sass",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.0.2"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-sql",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.8.0"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-xml",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.1.0"
        },
        {
          "name": "org.mvnpm.at.codemirror:lang-yaml",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.1.3"
        },
        {
          "name": "org.mvnpm.at.codemirror:language",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.11.3"
        },
        {
          "name": "org.mvnpm.at.codemirror:lint",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.9.6"
        },
        {
          "name": "org.mvnpm.at.codemirror:state",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.6.0"
        },
        {
          "name": "org.mvnpm.at.codemirror:view",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.43.0"
        },
        {
          "name": "org.mvnpm.at.deno:darwin-arm64",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.5.4"
        },
        {
          "name": "org.mvnpm.at.esbuild:darwin-arm64",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.25.10"
        },
        {
          "name": "org.mvnpm.at.fortawesome:fontawesome-common-types",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.5.2"
        },
        {
          "name": "org.mvnpm.at.fortawesome:fontawesome-svg-core",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.5.2"
        },
        {
          "name": "org.mvnpm.at.fortawesome:free-brands-svg-icons",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.5.2"
        },
        {
          "name": "org.mvnpm.at.fortawesome:free-regular-svg-icons",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.5.2"
        },
        {
          "name": "org.mvnpm.at.fortawesome:free-solid-svg-icons",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.5.2"
        },
        {
          "name": "org.mvnpm.at.lezer:common",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.5.2"
        },
        {
          "name": "org.mvnpm.at.lezer:cpp",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.5"
        },
        {
          "name": "org.mvnpm.at.lezer:css",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.3.3"
        },
        {
          "name": "org.mvnpm.at.lezer:go",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.1"
        },
        {
          "name": "org.mvnpm.at.lezer:highlight",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.2.3"
        },
        {
          "name": "org.mvnpm.at.lezer:html",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.3.13"
        },
        {
          "name": "org.mvnpm.at.lezer:java",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.3"
        },
        {
          "name": "org.mvnpm.at.lezer:javascript",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.5.4"
        },
        {
          "name": "org.mvnpm.at.lezer:json",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.3"
        },
        {
          "name": "org.mvnpm.at.lezer:lr",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.4.10"
        },
        {
          "name": "org.mvnpm.at.lezer:markdown",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.6.3"
        },
        {
          "name": "org.mvnpm.at.lezer:php",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.5"
        },
        {
          "name": "org.mvnpm.at.lezer:python",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.18"
        },
        {
          "name": "org.mvnpm.at.lezer:rust",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.2"
        },
        {
          "name": "org.mvnpm.at.lezer:sass",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.0"
        },
        {
          "name": "org.mvnpm.at.lezer:xml",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.6"
        },
        {
          "name": "org.mvnpm.at.lezer:yaml",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.4"
        },
        {
          "name": "org.mvnpm.at.lit-labs:ssr-dom-shim",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.5.1"
        },
        {
          "name": "org.mvnpm.at.lit:reactive-element",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.1.2"
        },
        {
          "name": "org.mvnpm.at.marijn:find-cluster-break",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.2"
        },
        {
          "name": "org.mvnpm.at.mvnpm:vaadin-webcomponents",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "25.1.0"
        },
        {
          "name": "org.mvnpm.at.open-wc:dedupe-mixin",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.4.0"
        },
        {
          "name": "org.mvnpm.at.qomponent:qui-badge",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.4"
        },
        {
          "name": "org.mvnpm.at.qomponent:qui-card",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.2"
        },
        {
          "name": "org.mvnpm.at.qomponent:qui-code-block",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.1"
        },
        {
          "name": "org.mvnpm.at.qomponent:qui-icons",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.2"
        },
        {
          "name": "org.mvnpm.at.types:trusted-types",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.7"
        },
        {
          "name": "org.mvnpm.at.vaadin:router",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.1"
        },
        {
          "name": "org.mvnpm.at.vaadin:vaadin-development-mode-detector",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.7"
        },
        {
          "name": "org.mvnpm.at.vaadin:vaadin-usage-statistics",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.1.3"
        },
        {
          "name": "org.mvnpm:codemirror-asciidoc",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.1"
        },
        {
          "name": "org.mvnpm:compare-versions",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.1.1"
        },
        {
          "name": "org.mvnpm:crelt",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.6"
        },
        {
          "name": "org.mvnpm:dompurify",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.2.7"
        },
        {
          "name": "org.mvnpm:esbuild",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.25.10"
        },
        {
          "name": "org.mvnpm:highlight.js",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "11.11.1"
        },
        {
          "name": "org.mvnpm:ldrs",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.7"
        },
        {
          "name": "org.mvnpm:lit-element",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.2.2"
        },
        {
          "name": "org.mvnpm:lit-html",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.3.2"
        },
        {
          "name": "org.mvnpm:lit",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.3.2"
        },
        {
          "name": "org.mvnpm:marked",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "17.0.5"
        },
        {
          "name": "org.mvnpm:path-to-regexp",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.3.0"
        },
        {
          "name": "org.mvnpm:style-mod",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.1.3"
        },
        {
          "name": "org.mvnpm:tagged-tag",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.0"
        },
        {
          "name": "org.mvnpm:type-fest",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "5.4.4"
        },
        {
          "name": "org.mvnpm:w3c-keyname",
          "manifest": "locker/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.2.8"
        },
        {
          "name": "${quarkus.platform.group-id}:${quarkus.platform.artifact-id}",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${quarkus.platform.version}"
        },
        {
          "name": "org.mvnpm.at.codemirror:view",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.43.0"
        },
        {
          "name": "org.mvnpm.at.codemirror:state",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "6.6.0"
        },
        {
          "name": "io.smallrye.reactive:smallrye-mutiny-vertx-web-client",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-smallrye-health",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-rest",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-rest-jackson",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.maven:maven-model",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.maven:maven-artifact",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.maven:maven-repository-metadata",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-cache",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.commons:commons-compress",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "commons-codec:commons-codec",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-rest-client-jackson",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-scheduler",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-websockets",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-mailer",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-smallrye-fault-tolerance",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-hibernate-orm-panache",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-jdbc-postgresql",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.pgpainless:pgpainless-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${pgpainless.version}"
        },
        {
          "name": "org.pgpainless:pgpainless-sop",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${pgpainless.version}"
        },
        {
          "name": "io.mvnpm:importmap",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkus:quarkus-arc",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "io.quarkiverse.mcp:quarkus-mcp-server-http",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.11.0"
        },
        {
          "name": "io.quarkiverse.web-bundler:quarkus-web-bundler",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${quarkus-web-bundler.version}"
        },
        {
          "name": "io.quarkiverse.roq:quarkus-roq-frontmatter",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${quarkus-roq-frontmatter.version}"
        },
        {
          "name": "io.quarkiverse.roq:quarkus-roq-plugin-markdown",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${quarkus-roq-frontmatter.version}"
        },
        {
          "name": "io.quarkiverse.roq:quarkus-roq-plugin-sitemap",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.1.0"
        },
        {
          "name": "io.quarkus:quarkus-ide-config",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${quarkus.ide-config.version}"
        },
        {
          "name": "io.mvnpm:mvnpm-locker",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "commons-codec:commons-codec",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.mvnpm:importmap",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.mvnpm:mvnpm-locker",
            "direct": true,
            "version": "999-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkiverse.mcp:quarkus-mcp-server-http",
            "direct": true,
            "version": "1.11.0",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkiverse.roq:quarkus-roq-frontmatter",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkiverse.roq:quarkus-roq-plugin-markdown",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkiverse.roq:quarkus-roq-plugin-sitemap",
            "direct": true,
            "version": "2.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkiverse.web-bundler:quarkus-web-bundler",
            "direct": true,
            "version": "2.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-arc",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-cache",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-hibernate-orm-panache",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-ide-config",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-jdbc-postgresql",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-mailer",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-rest",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-rest-client-jackson",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-rest-jackson",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-scheduler",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-smallrye-fault-tolerance",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-smallrye-health",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-websockets",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.smallrye.reactive:smallrye-mutiny-vertx-web-client",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-compress",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-artifact",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-model",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-repository-metadata",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:autocomplete",
            "direct": true,
            "version": "6.18.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:commands",
            "direct": true,
            "version": "6.8.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-cpp",
            "direct": true,
            "version": "6.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-css",
            "direct": true,
            "version": "6.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-go",
            "direct": true,
            "version": "6.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-html",
            "direct": true,
            "version": "6.4.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-java",
            "direct": true,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-javascript",
            "direct": true,
            "version": "6.2.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-json",
            "direct": true,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-less",
            "direct": true,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-markdown",
            "direct": true,
            "version": "6.3.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-php",
            "direct": true,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-python",
            "direct": true,
            "version": "6.1.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-rust",
            "direct": true,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-sass",
            "direct": true,
            "version": "6.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-sql",
            "direct": true,
            "version": "6.8.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-xml",
            "direct": true,
            "version": "6.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lang-yaml",
            "direct": true,
            "version": "6.1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:language",
            "direct": true,
            "version": "6.11.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:lint",
            "direct": true,
            "version": "6.9.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:state",
            "direct": true,
            "version": "6.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.codemirror:view",
            "direct": true,
            "version": "6.43.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.deno:darwin-arm64",
            "direct": true,
            "version": "2.5.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.esbuild:darwin-arm64",
            "direct": true,
            "version": "0.25.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.fortawesome:fontawesome-common-types",
            "direct": true,
            "version": "6.5.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.fortawesome:fontawesome-svg-core",
            "direct": true,
            "version": "6.5.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.fortawesome:free-brands-svg-icons",
            "direct": true,
            "version": "6.5.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.fortawesome:free-regular-svg-icons",
            "direct": true,
            "version": "6.5.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.fortawesome:free-solid-svg-icons",
            "direct": true,
            "version": "6.5.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:common",
            "direct": true,
            "version": "1.5.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:cpp",
            "direct": true,
            "version": "1.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:css",
            "direct": true,
            "version": "1.3.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:go",
            "direct": true,
            "version": "1.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:highlight",
            "direct": true,
            "version": "1.2.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:html",
            "direct": true,
            "version": "1.3.13",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:java",
            "direct": true,
            "version": "1.1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:javascript",
            "direct": true,
            "version": "1.5.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:json",
            "direct": true,
            "version": "1.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:lr",
            "direct": true,
            "version": "1.4.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:markdown",
            "direct": true,
            "version": "1.6.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:php",
            "direct": true,
            "version": "1.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:python",
            "direct": true,
            "version": "1.1.18",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:rust",
            "direct": true,
            "version": "1.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:sass",
            "direct": true,
            "version": "1.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:xml",
            "direct": true,
            "version": "1.0.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lezer:yaml",
            "direct": true,
            "version": "1.0.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lit-labs:ssr-dom-shim",
            "direct": true,
            "version": "1.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.lit:reactive-element",
            "direct": true,
            "version": "2.1.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.marijn:find-cluster-break",
            "direct": true,
            "version": "1.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.mvnpm:vaadin-webcomponents",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.mvnpm:vaadin-webcomponents",
            "direct": true,
            "version": "25.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.open-wc:dedupe-mixin",
            "direct": true,
            "version": "1.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.qomponent:qui-badge",
            "direct": true,
            "version": "1.0.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.qomponent:qui-card",
            "direct": true,
            "version": "1.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.qomponent:qui-code-block",
            "direct": true,
            "version": "1.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.qomponent:qui-icons",
            "direct": true,
            "version": "1.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.types:trusted-types",
            "direct": true,
            "version": "2.0.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.vaadin:router",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.vaadin:router",
            "direct": true,
            "version": "2.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.vaadin:vaadin-development-mode-detector",
            "direct": true,
            "version": "2.0.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm.at.vaadin:vaadin-usage-statistics",
            "direct": true,
            "version": "2.1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:codemirror-asciidoc",
            "direct": true,
            "version": "2.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:compare-versions",
            "direct": true,
            "version": "6.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:crelt",
            "direct": true,
            "version": "1.0.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:dompurify",
            "direct": true,
            "version": "3.2.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:esbuild",
            "direct": true,
            "version": "0.25.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:highlight.js",
            "direct": true,
            "version": "11.11.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:ldrs",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:ldrs",
            "direct": true,
            "version": "1.1.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:lit",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:lit",
            "direct": true,
            "version": "3.3.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:lit-element",
            "direct": true,
            "version": "4.2.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:lit-html",
            "direct": true,
            "version": "3.3.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:marked",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:marked",
            "direct": true,
            "version": "17.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:path-to-regexp",
            "direct": true,
            "version": "6.3.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:style-mod",
            "direct": true,
            "version": "4.1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:tagged-tag",
            "direct": true,
            "version": "1.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:type-fest",
            "direct": true,
            "version": "5.4.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.mvnpm:w3c-keyname",
            "direct": true,
            "version": "2.2.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.pgpainless:pgpainless-core",
            "direct": true,
            "version": "1.5.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.pgpainless:pgpainless-sop",
            "direct": true,
            "version": "1.5.5",
            "ecosystem": "maven"
          },
          {
            "name": "io.mvnpm:esbuild-java",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkiverse.playwright:quarkus-playwright",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus.platform:quarkus-bom",
            "direct": false,
            "version": "3.35.3",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus.platform:quarkus-maven-plugin",
            "direct": false,
            "version": "3.35.3",
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-junit",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.quarkus:quarkus-junit-mockito",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.rest-assured:rest-assured",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "net.revelc.code.formatter:formatter-maven-plugin",
            "direct": false,
            "version": "2.23.0",
            "ecosystem": "maven"
          },
          {
            "name": "net.revelc.code:impsort-maven-plugin",
            "direct": false,
            "version": "1.13.0",
            "ecosystem": "maven"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 117,
        "direct_count": 108,
        "indirect_count": 9
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 187,
        "open_issues": 5,
        "closed_ratio": 0.907,
        "closed_issues": 49,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "phillip-kruger",
          "commits": 315,
          "avatar_url": "https://avatars.githubusercontent.com/u/6836179?v=4"
        },
        {
          "type": "User",
          "login": "ia3andy",
          "commits": 209,
          "avatar_url": "https://avatars.githubusercontent.com/u/2223984?v=4"
        },
        {
          "type": "User",
          "login": "chrisruffalo",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/2073493?v=4"
        },
        {
          "type": "User",
          "login": "edewit",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/51133?v=4"
        },
        {
          "type": "User",
          "login": "jponge",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/25961?v=4"
        },
        {
          "type": "User",
          "login": "jmini",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1222165?v=4"
        },
        {
          "type": "User",
          "login": "MikeEdgar",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/20868526?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.595
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "build.yml",
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 1/17 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 7 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "75a8168c03d0a0885c7f39e61bff2a4df3207f9e",
        "ran_at": "2026-07-25T15:32:56Z",
        "aggregate_score": 5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-06-02T01:13:07Z",
      "oldest_open_prs": [
        {
          "number": 41656,
          "created_at": "2026-07-17T10:04:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-06-02T01:03:35Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 73,
          "created_at": "2023-09-07T06:46:22Z",
          "last_comment_at": "2023-09-07T06:58:42Z",
          "last_comment_author": "ia3andy"
        },
        {
          "number": 3505,
          "created_at": "2024-01-17T17:00:39Z",
          "last_comment_at": "2024-02-05T06:45:08Z",
          "last_comment_author": "phillip-kruger"
        },
        {
          "number": 4642,
          "created_at": "2024-02-16T08:02:14Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 39704,
          "created_at": "2026-02-02T03:03:37Z",
          "last_comment_at": "2026-02-02T04:10:12Z",
          "last_comment_author": "phillip-kruger"
        },
        {
          "number": 41655,
          "created_at": "2026-07-17T09:56:12Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/mvnpm/mvnpm",
    "host": "github.com",
    "name": "mvnpm",
    "owner": "mvnpm"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 62,
      "inputs": {
        "security": 60,
        "vitality": 72,
        "community": 50,
        "governance": 55,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 72,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "commits_last_year": 115,
              "human_commit_share": 1,
              "days_since_last_push": 53,
              "active_weeks_last_year": 10
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 53 days ago",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 53
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "10/52 weeks with commits",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "115 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 115
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 76,
              "latest_release_tag": "5.1.17",
              "releases_from_tags": false,
              "days_since_latest_release": 53,
              "mean_days_between_releases": 4.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "76 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 76
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 53 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 53
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 53,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 53 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 53
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 50,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "forks": 9,
              "stars": 59,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "59 stars",
                "points": 28.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 59
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "9 forks",
                "points": 7.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 7,
              "top_contributor_share": 0.595
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 60% of commits",
                "points": 9.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 60
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 7 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "merged_prs": 187,
              "open_issues": 5,
              "closed_issues": 49,
              "issue_closed_ratio": 0.907,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "91% of issues closed",
                "points": 42.4,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 91
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "187/189 decided PRs merged",
                "points": 37.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 187,
                      "decided": 189
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 1/17 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "followers": 6,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "mvnpm",
              "public_repos": 13,
              "account_age_days": 1383
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "6 followers of mvnpm",
                "points": 6.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 6,
                      "login": "mvnpm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "13 public repos, account ~3 yr old",
                "points": 15.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 13
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "gradle",
                "java",
                "maven",
                "npm"
              ],
              "has_wiki": true,
              "homepage": "https://mvnpm.org/",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://mvnpm.org/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 60,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 1/17 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 7 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "16 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 89 resolved dependencies against OSV; 28 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 89
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 28
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 89,
              "unassessed_packages": 28,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 89,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 17
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 84,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 0.79,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 3922
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "79 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 79,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "src/main/resources/web/tsconfig.json"
              ],
              "agent_commit_share": 0.57,
              "toolchain_manifests": [
                "locker/pom.xml",
                "pom.xml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "locker/pom.xml, pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "locker/pom.xml, pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "src/main/resources/web/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "src/main/resources/web/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "57 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 57,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Java",
              "largest_source_bytes": 48297,
              "source_files_sampled": 137,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Java (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/137 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 137,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch maven package 'io.mvnpm:mvnpm' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T15:33:13.201236Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/mvnpm/mvnpm.svg",
  "full_name": "mvnpm/mvnpm",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statistics.