Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 03:13 UTC

nebari-dev / nebari-infrastructure-core

CLI tool for managing Nebari cloud infrastructure using OpenTofu, ArgoCD, and GitOps

GoApache-2.0★ 12 stars⑂ 10 forkssince Oct 2025View on GitHub ↗

nebari-dev/nebari-infrastructure-core holds a health index of 72 out of 100, placing it in the Good band. It scores highest on Vitality (89/100) and lowest on Security (56/100). It was last updated today. 2 contributors account for most of its recent work.

72
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

72
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

nebari-devOrganization
70 followers77 public repossince Jan 2022

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/nebari-dev/nebari-infrastructure-corev0.10.0-114 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

89Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
22.8/36Commit cadence — 33/52 weeks with commits
18/18Commit volume — 252 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year252
human_commit_share1
days_since_last_push0
active_weeks_last_year33
How it's scored
27/27Ships releases — 9 releases published
36/36Release recency — latest release 4 days ago
27/27Release cadence — a release every ~14 days
1/10OpenSSF Scorecard: Signed-Releases — 1 out of the last 5 releases have a total of 1 signed artifacts.
Inputs used
releases_count9
latest_release_tagv0.10.0
releases_from_tagsno
days_since_latest_release4
mean_days_between_releases14

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

56Moderate · 18% of overall
How it's scored
16.9/60Stars — 12 stars
8/25Forks — 10 forks
0/15Watchers — 1 watchers
Inputs used
forks10
stars12
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

70Good · 24% of overall
How it's scored
25.2/54Bus factor — 2 contributor(s) cover half of all commits
11.4/22.5Commit distribution — top contributor authored 49% of commits
13.5/13.5Contributor breadth — 12 contributors
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Inputs used
bus_factor2
contributors_sampled12
top_contributor_share0.492
How it's scored
18/46.8Issue resolution — 38% of issues closed
30.6/38.3PR acceptance — 125/156 decided PRs merged
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs125
open_issues192
closed_issues120
issue_closed_ratio0.385
closed_unmerged_prs31
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
13.3/25Owner reach — 70 followers of nebari-dev
22/25Track record — 77 public repos, account ~4 yr old
Inputs used
followers70
owner_typeOrganization
is_verified
owner_loginnebari-dev
public_repos77
account_age_days1,638
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 4 days ago
20/20Version history — 11 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/nebari-dev/nebari-infrastructure-core
ecosystemsgo
any_deprecatedno
min_days_since_publish4

Engineering Quality

Are baseline engineering and documentation practices in place?

82Good · 20% of overall
How it's scored
24/24CI workflows — 4 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yml
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes

Documentation

65Moderate
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

56Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
6/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0.8/7.5Signed-Releases — 1 out of the last 5 releases have a total of 1 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate5.6

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

81Good · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 99 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.99
agent_instruction_filesAGENTS.md
agent_instruction_max_bytes22,135
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
11/11Lint / format config — .golangci.yml
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
4/10Demonstrated agent practice — 2 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
10/10OpenSSF Scorecard: Pinned-Dependencies — all dependencies are pinned
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageyes
bootstrap_filesMakefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0.02
toolchain_manifestsgo.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
55/55Manageable file sizes — 0/164 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes45,244
source_files_sampled164
oversized_source_files0
How it's scored
0/40API schema (OpenAPI/GraphQL/proto)
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_files

Key facts

12GitHub stars
12contributors
252commits, last 12 months
0days since last push
9releases
2bus factor
192open issues
Gopackage ecosystems

Data collection warnings

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

More detail

Star and fork history 12 ★ / 10 ⇿
12Stars
10Forks
9Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

024681012121022026-022026-042026-07
Major 0Minor 9Patch 0
OpenSSF Scorecard 5.6 / 10
5.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 03:13 UTC

10Binary-Artifactsno binaries found in the repo
8Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
1Signed-Releases1 out of the last 5 releases have a total of 1 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
3Vulnerabilities7 existing vulnerabilities detected
Direct dependencies 37
RegistryPackageVersion constraintManifest
Gogithub.com/Azure/azure-sdk-for-go/sdk/azcorev1.22.0go.mod
Gogithub.com/Azure/azure-sdk-for-go/sdk/azidentityv1.14.0go.mod
Gogithub.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v6v6.6.0go.mod
Gogithub.com/Azure/azure-sdk-for-go/sdk/resourcemanager/resources/armresourcesv1.2.0go.mod
Gogithub.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstoragev1.8.1go.mod
Gogithub.com/aws/aws-sdk-go-v2v1.42.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.25go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/ec2v1.307.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/eksv1.86.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv1.34.6go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2v1.55.4go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/s3v1.104.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.43.3go.mod
Gogithub.com/aws/smithy-gov1.27.2go.mod
Gogithub.com/cloudflare/cloudflare-go/v4v4.6.0go.mod
Gogithub.com/go-git/go-git/v5v5.19.1go.mod
Gogithub.com/goccy/go-yamlv1.19.2go.mod
Gogithub.com/hashicorp/terraform-execv0.25.2go.mod
Gogithub.com/joho/godotenvv1.5.1go.mod
Gogithub.com/opentofu/tofudlv0.0.1go.mod
Gogithub.com/skeema/knownhostsv1.3.2go.mod
Gogithub.com/spf13/aferov1.15.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogolang.org/x/cryptov0.53.0go.mod
Gogolang.org/x/modv0.36.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gohelm.sh/helm/v3v3.21.1go.mod
Gok8s.io/apiv0.36.2go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gok8s.io/client-gov0.36.2go.mod
Gosigs.k8s.io/kindv0.32.0go.mod
Gosigs.k8s.io/yamlv1.6.0go.mod
All dependencies not collected

The resolved dependency set could not be collected for this report: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 3606,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 1139351,
        "HCL": 11301,
        "Shell": 4781,
        "Makefile": 5180
      },
      "pushed_at": "2026-07-21T21:12:32Z",
      "created_at": "2025-10-29T13:30:29Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T14:58:38Z",
      "description": "CLI tool for managing Nebari cloud infrastructure using OpenTofu, ArgoCD, and GitOps",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://www.nebari.dev",
      "name": null,
      "type": "Organization",
      "login": "nebari-dev",
      "company": null,
      "location": null,
      "followers": 70,
      "avatar_url": "https://avatars.githubusercontent.com/u/98419235?v=4",
      "created_at": "2022-01-25T18:08:40Z",
      "is_verified": null,
      "public_repos": 77,
      "account_age_days": 1638
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-17T15:25:17Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-09T15:22:00Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-06-24T14:48:18Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-01T20:37:49Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-28T16:31:40Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-21T13:07:42Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-05-11T12:09:23Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-04-08T08:58:23Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-03-27T16:10:08Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "3c0d20727783239738ede4b7813fa1a1c211fa19",
          "body": "…ew cask (#487)\n\nversion and commit were declared const in cmd/nic/version.go, so the linker's\n-X flags were silently dropped and every build reported \"1.0.0 / dev\"\nregardless of how it was built. Switch them to var and add the date var that\nboth the Makefile and GoReleaser already set. Un-stamped b\n[…]\nTHUB_TOKEN cannot write cross-repo.\n\nMigrate three deprecated GoReleaser keys (archives.formats,\nformat_overrides.formats, snapshot version_template) so a future action bump\nkeeps working.\n\nFixes #451",
          "is_bot": false,
          "headline": "fix(release): stamp version into binary, fix install docs, add Homebr…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-17T14:56:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9547e51b57d374212ead798fd12ef26e6d3a7ad9",
          "body": "…wn default (#458) (#481)\n\n* feat(argocd): derive foundational project scopes from embedded templates\n\n* fix(argocd): robust multi-doc split, surface parse errors, document recognized shapes\n\n* feat(argocd): render foundational, nebari-apps, and locked-down default projects\n\n* fix(argocd): use robus\n[…]\n\n\n* docs(argocd): link #480 issue reference in project-scoping doc\n\nA bare #480 does not render as a link in a committed markdown file;\nmake it an explicit link to the admission-controller work issue.",
          "is_bot": false,
          "headline": "feat(argocd): scope foundational AppProject, add nebari-apps, lock do…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-17T14:55:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "09f215f92aa9a580a225e2f0147659e022af22f9",
          "body": "…ests, containerd bump, Go 1.26 docs (#491)\n\n* chore(deps): bump containerd to v1.7.33 (GO-2026-5758, GO-2026-5475)\n\n* docs: track go.mod Go version (1.26) in README and ARCHITECTURE\n\n* ci(security): add fail-on-fixable-only govulncheck gate (#460)\n\n* test(security): guard helm and go-git dependency floors (#460)\n\n* docs: bump remaining Go version references to 1.26; clarify govulncheck gate label (#459)\n\n* chore(deps): build on Go 1.26.5 to clear reachable stdlib CVEs (#459)",
          "is_bot": false,
          "headline": "security: #459/#460 follow-ups - govulncheck gate, dependency-floor t…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-17T13:20:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "467a8edb64977708f032e92d6b809412f325f2d1",
          "body": "…ix numbering (#483)\n\nRecord the accepted decision behind #154 (design) and #289 (Phase 1a\nimplementation): replace the imperative realm-setup shell script with a\ndeclarative keycloak-config-cli pipeline, with realm input in an in-cluster\nSecret rather than the GitOps repo. Status is Accepted becaus\n[…]\nd by #434 and #479); its code reference in\nopentelemetry-collector.yaml is updated, and the README index is rebuilt to\ninclude the previously-missing ADR-0003 alongside the renumbered and new\nentries.",
          "is_bot": false,
          "headline": "docs(adr): record declarative Keycloak config decision (ADR-0009) + f…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-17T12:32:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e406655545ab2de83a397bddb0fb5765b97cb9ed",
          "body": "GitHub now forces actions/checkout, actions/setup-go, and\ngoreleaser/goreleaser-action off the deprecated Node 20 runtime and will\ndrop Node 20 entirely later. Bump each SHA pin to its Node 24 release and\nupdate the version comments:\n\n- actions/checkout        v4      -> v7.0.0\n- actions/setup-go   \n[…]\n.0.2\n\ngolangci-lint-action, cosign-installer, sbom-action, and\nattest-build-provenance are already on their latest releases. Pins remain\nfull 40-char commit SHAs, so check-action-pins.sh still passes.",
          "is_bot": false,
          "headline": "ci: bump pinned actions onto Node 24 runtimes (#488)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-07-16T18:21:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc43c5de10b6b2f31e797a5ed39b2a7e7c67c0cc",
          "body": "… SHA pins (#461) (#476)\n\n* build(release): sign checksums (cosign keyless) and emit SPDX SBOMs\n\n* build(release): modernize deprecated GoReleaser fields (formats, version_template)\n\n* ci(release): add keyless signing, SBOM, and build-provenance; pin actions and add approval gate\n\n* ci: pin actions \n[…]\nrained PAT with minimal\nscope (org Projects RW; repo Issues/PRs/Metadata read-only), so no\nregeneration is needed. The only token-side hardening here is pinning\nthe reusable workflow that consumes it.",
          "is_bot": false,
          "headline": "ci(release): harden the release pipeline - signing, SBOM, provenance,…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-16T14:26:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "368515eeb109ab0f06cc23f4c6d833e5e52ae190",
          "body": "The golangci-lint pre-commit hook ran `golangci-lint run --fix`. golangci-lint's\nautofix (notably nolintlint) silently rewrites the files being committed: it\ndeletes nolint directives it considers \"unused\", which aborts the commit with\n\"files were modified by this hook\" and can leak unrelated edits \n[…]\n--fix` so the hook is a report-and-block gate matching CI and `make lint`,\nwhich both run `golangci-lint run` without --fix. Run `golangci-lint run --fix`\nby hand when you actually want fixes applied.",
          "is_bot": false,
          "headline": "chore(pre-commit): drop --fix from golangci-lint hook (#485)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-16T14:24:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "48a6979aee9257ff2fc28829fd981d0f5866de9e",
          "body": "* Fix local GitOps repo path and permissions\n\n* use ~/.nic\n\n* fix linter findings\n\n* address review findings\n\n* fix: clarify GitOps repository permissions\n\n* drop init level normalization\n\n* log about leftover gitops dir on destroy\n\n* address review findings\n\n* fix: scope local GitOps permission repair\n\n* test: cover existing local repository permissions\n\n* fix git permission repair review feedback",
          "is_bot": false,
          "headline": "Fix Gitops file permissions and host path (#448)",
          "author_name": "James Olds",
          "author_login": "oldsj",
          "committed_at": "2026-07-16T12:26:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4cdccb29f126bd86f9f71bba8645fede070baaf",
          "body": "…ucture (#455)\n\nEmit apps/cloudnative-pg.yaml unconditionally on every GitOps bootstrap,\nthe same way postgresql.yaml and keycloak.yaml are emitted. Chart\ncloudnative-pg 0.29.0 (operator 1.30.0), namespace cnpg-system,\nsync-wave 3, ServerSideApply=true because the CNPG CRDs overflow the\nclient-side \n[…]\ns the DatabaseConfig type, the\nwriter gating, and the disable-never-deletes machinery from earlier\nrevisions of this branch.\n\nCloses https://github.com/nebari-dev/nebari-infrastructure-core/issues/303",
          "is_bot": false,
          "headline": "feat(argocd): install CloudNativePG operator as foundational infrastr…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-07-16T05:28:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "304c84d52130f33bbba2347b5178c5987ee94b01",
          "body": "* fix(git): verify SSH host keys against known_hosts by default\n\nGit operations over SSH previously used InsecureIgnoreHostKey(),\naccepting any host key and leaving the GitOps repository — the source\nof truth for what ArgoCD deploys — open to man-in-the-middle\nimpersonation during clone and push.\n\nH\n[…]\nsuppressing directives as unused and fails CI. Remove them.\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(git): verify SSH host keys against known_hosts by default (#379)",
          "author_name": "Adam Lewis",
          "author_login": "Adam-D-Lewis",
          "committed_at": "2026-07-15T15:56:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "12b9a23a7bfb6923a889abbbf767fbbc4ee7a5b3",
          "body": "…328)\n\n* docs(longhorn): design spec for Keycloak-gated UI exposure via Envoy Gateway\n\nAdds the design doc for exposing the Longhorn UI at longhorn.<domain>\nthrough the existing nebari-gateway, gated by Keycloak OIDC enforced\nvia an Envoy Gateway SecurityPolicy. Mirrors the existing ArgoCD SSO\ndesig\n[…]\n-claim.md.\n- Annotate the empty-render skip in the generic HTTPRoute listener test.\n- Consolidate duplicate managed-by label constants onto the names main\n  standardized on (done in the merge commit).",
          "is_bot": false,
          "headline": "feat(longhorn): expose UI through Envoy Gateway with Keycloak OIDC (#…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-07-15T14:21:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4f774a1e7a44993e75a96765eab7b00a89b9992",
          "body": "* chore(deps): update Go dependencies\n\n* ci: use Go version from go.mod\n\n* ci(release): derive Go version from go.mod\n\nThe release workflow hardcoded go-version: '1.25.1' while go.mod and CI\nalready moved to Go 1.26.0 via go-version-file, so release binaries would\nstill build on the stale toolchain. Point the release job at\ngo-version-file: go.mod to track the same single source of truth as CI.",
          "is_bot": false,
          "headline": "chore(deps): update Go dependencies (#393)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-15T12:53:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb21d3bbe4428f19246b1d7220fd9f2a81fa14fd",
          "body": "… (#385)\n\nThe data-science-pack rbac-bootstrap job reconciles the Keycloak\ngroup-membership mapper to full.path=true on every sync (JupyterHub\nneeds full group paths for /shared/<group> mounts), which changes the\ntoken groups claim from \"argocd-admins\" to \"/argocd-admins\". With\npolicy.default empty,\n[…]\nall visibility in ArgoCD.\n\nMap both forms for each group so access works regardless of whether\nthe realm-setup job (full.path=false) or the ds-pack bootstrap job\n(full.path=true) ran last.\n\nFixes #384",
          "is_bot": false,
          "headline": "fix(argocd): match both bare and full-path group names in RBAC policy…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-07-14T14:44:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d85e10940ba4990f9eebd202b2d55b1eaaf5fe3",
          "body": "* docs: ADR-0005 CloudNativePG as foundational database infrastructure\n\nProposes adding CloudNativePG (CNPG) as a foundational operator NIC\ndeploys, with a per-pack database-request contract through the\nNebariApp CRD. Status: Proposed.\n\nThe Bitnami situation (catalog moved behind a paywall on 2025-0\n[…]\nce\ncontract that survives the next upstream disruption) and cite the\nconcrete repos in the Bitnami-removal driver.\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "ADR-0005: CloudNativePG as foundational database infrastructure (#314)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-07-14T10:34:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2f0377b6c92bf9e238b8a97d371a4e8518ee426",
          "body": "Installs the NVIDIA GPU Operator on AWS clusters that declare GPU node groups\n(gpu: true), so nvidia.com/gpu is advertised without each software pack\nshipping its own operator app. Follows the cluster-autoscaler / LBC\nimperative-Helm-in-Deploy pattern, gated on the config flag rather than a\nGitOps A\n[…]\nts it v-prefixed). No IAM\n  needed; the operator only touches in-cluster resources.\n\nDeploy installs when hasGPUNodeGroups() is true; Destroy uninstalls before\ntofu destroy, best-effort like Longhorn.",
          "is_bot": false,
          "headline": "feat(gpu): install NVIDIA GPU Operator on AWS via Helm (#348)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-07-09T13:44:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3792caea9c36f61a3ba451497a3cb436284acba5",
          "body": "* feat(argocd): trust org CA bundle in the repo-server\n\nWhen a top-level trust_bundle is configured, create an install-time\nargocd-org-ca ConfigMap and wire the repo-server to trust it: an init\ncontainer concatenates the image's system CA bundle with the org CA into a\nshared emptyDir, and the repo-s\n[…]\ng each string to 4 package-wide occurrences and tripping goconst\n(min-occurrences 4). Extract PartOfLabel and keyType/keyMountPath\nconstants and reuse the existing ManagedByLabel/NebariManagedByValue.",
          "is_bot": false,
          "headline": "feat(argocd): trust org CA bundle in the repo-server (#353)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-07-08T20:47:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "96316570128d6f7c4debdd3cd94201b3f3bcb000",
          "body": "…#346)\n\n* feat(aws): plumb trust_bundle config into terraform-aws-eks-cluster\n\nAdds an optional cluster.aws.trust_bundle config block (path | inline PEM)\nthat resolves to a base64-encoded PEM string and is forwarded to the EKS\ncluster module as extra_ca_bundle. The module then installs the bundle\nin\n[…]\n true\nto the Bundle sources and pin defaultPackage.enabled in the chart values\nsince the Bundle now depends on it.\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(argocd): deploy trust-manager and project org CA bundle in-pod (…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-07-08T18:16:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d4aec98cc83255926f6a5028d6360e76714fe20",
          "body": "* Have the local provider deploy a kind cluster\n\n* Update config for local example\n\n* Update README.md and ARCHITECTURE.md with changes to the local provider\n\n* Remove obsolete makefile targets\n\n* Add comment clarifying dependency on order of operations when populating\np.metalLBPool\n\n* Fix typo\n\n* Capitalize new sentence in comment\n\n* Instrument kind provider\n\n* Improve wording when cluster already exists\n\n* Add comment clarifying why having kindReadyTimeout instead of uing\nDeployOptions.Timeout",
          "is_bot": false,
          "headline": "Update local provider to deploy a kind cluster (#400)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-29T09:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c3ca4dc64e97237a8eb8f448923974373c64700",
          "body": null,
          "is_bot": false,
          "headline": "Fix bad import after providers refactor (#408)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-22T17:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09e026c663d698de3b1e9ad0a921f9362a755aa4",
          "body": "* feat(certificate): support user-supplied TLS cert for the gateway\n\nAdd `certificate.type: existing` so operators can supply their own TLS\ncertificate for the Nebari gateway instead of having cert-manager mint one.\nThree mutually-exclusive sources are supported:\n\n- `existing_secret` — reference a k\n[…]\nrom\nConfigureGatewayTLS, so it keeps its non-fatal behavior without the call\nsite needing to branch on the source.\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(certificate): support user-supplied TLS cert for the gateway (#404)",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-06-22T14:37:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c8cc246ad6b7112c51e5520b0f602c7eb244950",
          "body": "* Move pkg/provider and pkg/dnsprovider into umbrella pkg/providers folder\n\n* Rename prov to clusterProvider for clarity and consistency\n\n* Update tofu lockfiles\n\n* Update stale design docs",
          "is_bot": false,
          "headline": "Move provider and dnsprovider into pkg/providers (#405)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-22T12:24:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96c32f4cc04ee80250cddc9075d6ea5a71aac51e",
          "body": "…(#370)\n\nAWS node groups with `gpu: true` now receive the taint\nnvidia.com/gpu=true:NO_SCHEDULE automatically, so ordinary pods stay off\nGPU nodes without hand-written taint config. The NVIDIA GPU Operator\ndoes not taint nodes itself; it only tolerates this taint on its own\noperands, so applying it \n[…]\nPU pools, so adding the same\non GCP would double-taint, and Azure is out of scope here.\n\nRenames resolveNodeGroupAMIs to resolveNodeGroupDefaults since it now\nresolves both the AMI type and the taint.",
          "is_bot": false,
          "headline": "feat(aws): auto-apply nvidia.com/gpu taint to GPU node groups (#368) …",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-06-19T09:09:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67d5f230f09612ca82be6efee06caa13b0c94a9e",
          "body": "…es-pods relabel (#397)\n\n* otel: escape kubernetes-pods relabel replacement ($$1:$$2)\n\nNormalize the kubernetes-pods scrape job's address relabel from the bare\n$1:$2 backreference to the escaped $$1:$$2 form. The OTel collector's\nconfmap resolver expands ${...}, so a bare $1 is treated as env-style\n\n[…]\nri-operator instead of rejected with\nNamespaceNotOptedIn. A pack cannot set this label itself: managedNamespaceMetadata\nonly applies to a namespace the app creates, and the collector creates it first.",
          "is_bot": false,
          "headline": "fix(otel): opt monitoring ns into Nebari management + escape kubernet…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-06-17T19:20:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e820f21d4bf0e2837f7aff0a55832f39aa507735",
          "body": "…ter RBAC (#331)\n\n* docs: spec for OTel collector ConfigMap handoff to LGTM pack\n\nDesign for nebari-dev/nebari-lgtm-pack#8: NIC adds ignoreDifferences +\nRespectIgnoreDifferences=true on the OTel collector ConfigMap data.relay\nfield; LGTM pack ships a Helm post-install hook Job that merges its\nexport\n[…]\nte extraEnvs K8S_NODE_NAME; the kubernetesAttributes preset\n  injects it via fieldRef in daemonset mode. Document the dependency.\n- ADR-0005: fix 'unusual' -> 'common' in the single-backend rationale.",
          "is_bot": false,
          "headline": "feat(otel): software-pack extension point for collector config + clus…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-06-17T18:52:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a25e806432e72b1c05b88c9e57192a2bd6dc4a7",
          "body": null,
          "is_bot": false,
          "headline": "enable service for OTEL collector (#392)",
          "author_name": "Philip Meier",
          "author_login": "pmeier",
          "committed_at": "2026-06-17T17:57:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc1d54e60be00219eae48f7098a64bee9004129f",
          "body": "* Set SilenceErrors and SilenceUsage to true\n\n* Remove redundant slog.Error calls that will be logged in main already\n\n* Set SilenceErrors and SilenceUsage to true inside PersistentPreRun\n\n* Add note about not logging errors inside RunE\n\n* Set flag inside PersistentPreRun to accurately distinguish between\nruntime and usage errors",
          "is_bot": false,
          "headline": "Remove duplicate CLI error logging and usage output on failures (#376)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-17T14:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "870311caf664e3b7effd409a9d5a266d1aef761d",
          "body": null,
          "is_bot": false,
          "headline": "add k8s preset to otel collector (#387)",
          "author_name": "Philip Meier",
          "author_login": "pmeier",
          "committed_at": "2026-06-12T22:37:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a9bd1ccb38a01f6c2ffc7d70ad6ff984c615885",
          "body": "…#361)\n\nDocuments that provider/cluster-conditional foundational software installs\nimperatively via provider-driven Helm rather than as ArgoCD apps, while\nunconditional software stays in GitOps. Refines the blanket \"GitOps for\nsoftware\" rule in ADR-0001 / AGENTS.md for this case, which is what makes\n[…]\nation lands in #349, with #348 (GPU operator) and #352\n(autoscaler) as the first instances and MetalLB flagged for migration.\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(adr): record conditional-software-via-Helm decision (ADR-0006) (…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-06-09T12:48:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c75331be5f929051d23103e652f78bc23e61b66c",
          "body": "Captures the design discussion for a future `nic config init` /\n`nic config schema` user-facing CLI surface, including reflection-driven\nflag generation and four options for examples/ regeneration. Status is\nProposed pending team review; no user-facing change introduced.\n\nAlso adds the ADR-0005 row to docs/adr/README.md.",
          "is_bot": false,
          "headline": "docs(adr): add ADR-0005 nic config CLI surface (Proposed) (#360)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-06-09T12:30:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f221a5edbea521336e6d56c82439e16328b4102e",
          "body": "* docs: add AGENTS.md and fix stale OpenTofu doc on Provider interface\n\nAdds AGENTS.md at the repo root as the canonical, committed guide for\nhuman contributors and any AI coding agent (Claude Code, Codex, Cursor,\nAider, etc.). Content audited against actual code: cluster + DNS\nprovider categories, \n[…]\nd as\nif the interface mandates Tofu, which it does not.\n\nCloses #296\n\n* Apply suggestion from @viniciusdc\n\n---------\n\nCo-authored-by: Vinicius D. Cerutti <51954708+viniciusdc@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: add AGENTS.md as canonical contributor + agent guide (#297)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-06-09T12:17:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "10bcb6f92436917c21e609fd1a26544369145d35",
          "body": "…#344)",
          "is_bot": false,
          "headline": "Add additional information about local testing with volume mounting (…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-06-09T08:03:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "089677f41d6ac9fc8900a9fdb5eebd05e869d232",
          "body": "…#359)\n\nPRs opened from forks run the add-to-project workflow under the\npull_request event, which withholds secrets from cross-repo PRs. The\nADD_TO_PROJECT_PAT secret resolves to empty, GH_TOKEN is blank, and the\nreusable sync-project-priority workflow fails on its first gh api call\n(exit 4).\n\nSwitc\n[…]\nhis is safe because the reusable workflow never\nchecks out PR head code — it only reads trusted event metadata\n(node_id, labels) and calls the GitHub API. Issue and same-repo PR\nbehavior is unchanged.",
          "is_bot": false,
          "headline": "fix(ci): trigger add-to-project on pull_request_target for fork PRs (…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-06-09T08:01:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "afe714a95ef30f31bc39c84294eb83671983e21e",
          "body": "… #369) (#367)\n\n* fix(longhorn): pass nodeSelector as map[string]any so Helm coalesces it\n\nWith dedicated_nodes: true, longhornManager/longhornDriver received their\nnodeSelector as a map[string]string. Helm's value coalescing only treats\nmap[string]any as a table (chartutil.istable), so a map[string\n[…]\nd unschedulable; with\n\":\" the csi-plugin and instance-manager run there and mounts succeed.\n\nRefs #366, #363, #368\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(longhorn): make dedicated_nodes serve volumes cluster-wide (#366,…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-06-08T16:02:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6d4ae978261b7ed9d1ea9735d2f3b3c1cb0c3b3",
          "body": "Exposes a new `cluster.aws.enable_irsa` YAML knob (pointer/optional) that\nis plumbed through to the upstream `nebari-dev/eks-cluster/aws` module's\n`enable_irsa` variable. When unset, the upstream default (`true`) applies\nand existing deployments are unaffected.\n\nSet `enable_irsa: false` when the clu\n[…]\nte thumbprint as part of provider creation.\n\nBumps the module pin to 0.5.0 to pick up the new variable.\n\nDepends on terraform-aws-eks-cluster v0.5.0 (carrying nebari-dev/terraform-aws-eks-cluster#31).",
          "is_bot": false,
          "headline": "feat(aws): add enable_irsa config field to skip EKS OIDC provider (#335)",
          "author_name": "Oren Fromberg",
          "author_login": "oren-openteams",
          "committed_at": "2026-06-05T14:08:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89b63124cb432631d28af8a102aa75db9c6df31b",
          "body": "…ents (#356)\n\n* fix(longhorn): tolerate storage-node taints for system-managed components\n\nWhen dedicated_nodes is true, NIC added a nodeSelector and a toleration\nfor the storage-node taint only to the user-deployed longhornManager and\nlonghornDriver. Longhorn's system-managed components (instance-m\n[…]\nand\nlets the valid cases assert a nil error instead of only checking the\nerror text.\n\nAlso reference the taint-parameterization tracking issue (#363) from the\nlonghorn.Config.NodeSelector doc comment.",
          "is_bot": false,
          "headline": "fix(longhorn): tolerate storage-node taints for system-managed compon…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-06-05T12:36:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f32f9a8b1d1ba7502dc5b105047732678d149c4",
          "body": "* Install cluster autoscaler helm chart by default on AWS provider\n\n* Wire cluster autoscaler installation to tofu module variables\n\n* Pass `kubernetesClusterAutoscalerEnabled` to the longhorn helm chart to\nallow nodes to scale down when autoscaling is enabled\n\n* Use ProviderName instead of hardcodi\n[…]\nutation and nil-receiver\npaths.\n\n---------\n\nCo-authored-by: Vinicius D. Cerutti <51954708+viniciusdc@users.noreply.github.com>\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Support autoscaling in AWS provider (#352)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-05T10:57:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68a2d0060a582a7b8d9ff991e4a92aa4fbf1188d",
          "body": null,
          "is_bot": false,
          "headline": "remove planning files (#358)",
          "author_name": "Andrew Fulton",
          "author_login": "andrewfulton9",
          "committed_at": "2026-06-05T09:30:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7729f10b1d4e030c65421bfae0509ee3517229ee",
          "body": "…#336)\n\n* feat(aws): plumb trust_bundle config into terraform-aws-eks-cluster\n\nAdds an optional cluster.aws.trust_bundle config block (path | inline PEM)\nthat resolves to a base64-encoded PEM string and is forwarded to the EKS\ncluster module as extra_ca_bundle. The module then installs the bundle\nin\n[…]\nw resolves azurerm to 4.75.0. Regenerate the\ncommitted lock across all five CI platforms so the drift job passes.\n\n---------\n\nCo-authored-by: Tyler Potts <49161327+tylerpotts@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(aws): plumb trust_bundle config into terraform-aws-eks-cluster (…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-06-02T23:37:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91b4272dfec799e644207e009ed381fdac6e11dc",
          "body": null,
          "is_bot": false,
          "headline": "Propagate context to child calls in AWS provider (#341)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-01T20:48:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1840e018af0e2279bd50e40f6ee6c63f5a4c1372",
          "body": "… (#324)\n\n* docs: add design spec for Azure AKS Terraform module + NIC provider\n\nTwo coupled deliverables, MVP scope:\n- New module repo terraform-azurerm-aks-cluster (Registry:\n  nebari-dev/aks-cluster/azurerm), mirroring terraform-aws-eks-cluster.\n- Flesh out pkg/provider/azure/ to consume it via a\n[…]\n- Rename cleanupOrphans -> reportOrphans to match its report-only behavior\n- Extract hardcoded \"nic\" managed-by value into a constant\n\n* fix(aws): refresh .terraform.lock.hcl for hashicorp/aws v6.47.0",
          "is_bot": false,
          "headline": "implement Azure provider end-to-end via terraform-azurerm-aks-cluster…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-06-01T15:36:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53db11486c27aea340b5dd5c2d5fafb832bfea3c",
          "body": "* Remove irrelevant docker-compose file and integration tests guide for\nAWS\n\n* Remove localstack makefile targets\n\n* Remove outdated comment regarding localstack",
          "is_bot": false,
          "headline": "Remove LocalStack references (#342)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-06-01T15:34:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "508eff57f009863942b7b50d4c0a8a36438ea259",
          "body": "* Extract orchestration into pkg/action\n\n* Rename pkg/action to pkg/nic and integrate with latests changes in main\n\n* Replace hardcoded \"main\" in favor of git.DefaultBranch\n\n* Create default registry inside the client instead of every function\n\n* Add explicit gitConfig argument to argocd functions t\n[…]\nstent warning when the installation of foundational\nservices fails\n\n* Use cmd.Context() in runVersion for symmetry with other commands\n\n* Wrap errors instead of directly returning them for consistency",
          "is_bot": false,
          "headline": "Extract CLI orchestration into its own package (#266)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-05-28T16:30:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e1f0ac00b9fd0020528575c1ad95e6e61684dcc",
          "body": "* Add aws-sdk-go-v2/service/eks as a dependency\n\n* Add function to get the kubeconfig for a cluster using the EKS client\n\n* Use EKS over tofu to get kubeconfig and cache it for subsequent runs\n\n* Run go fmt\n\n* Alias aws-sdk-go-v2/config to awsconfig\n\n* Instrument func newEKSClient\n\n* Instrument func\n[…]\nnd read cache entries in the tests\n\n* Run go fmt\n\n* Keep ctx when starting a span in GetKubeconfig function\n\n* Add small comment documenting decision of not using singleflight to\navoid duplicate calls",
          "is_bot": false,
          "headline": "Use EKS client to get kubeconfig and cache it (#315)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-05-28T15:31:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "974603522448f851e0ce361e8d1b39dcc226de0a",
          "body": "* feat(aws): make load balancer scheme configurable\n\nAdd cluster.aws.load_balancer_scheme to override the hardcoded\n\"internet-facing\" aws-load-balancer-scheme annotation. Defaults preserve\nexisting behavior. Operators with private-only VPCs (no public subnets)\ncan now set \"internal\" so the AWS Load \n[…]\n- Add TestValidate_LoadBalancerScheme covering rejection paths (typo,\n  arbitrary string, mixed case); the default and valid-value paths are\n  already exercised by TestInfraSettings_LoadBalancerScheme",
          "is_bot": false,
          "headline": "feat(aws): make load balancer scheme configurable (#330)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-05-27T20:22:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "60e71ae2a694e40efe55d88439fc7001e4796bce",
          "body": "…v0.1.0-alpha.5 (#320)\n\n- nebari-operator: v0.1.0-alpha.19 -> v0.1.0-alpha.20 (released 2026-05-20)\n- nebari-landing: v0.1.0-alpha.4 -> v0.1.0-alpha.5 (released 2026-05-12)",
          "is_bot": false,
          "headline": "chore: bump nebari-operator to v0.1.0-alpha.20 and nebari-landing to …",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-05-21T12:13:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39cf1df44a190606771f609adae4e681ced90187",
          "body": "* feat(longhorn): generalize install for non-AWS providers\n\nLift the Longhorn install logic out of the AWS provider into a shared\npackage so the existing-cluster and hetzner providers can opt in. On\nclusters without managed RWX (Hetzner hcloud-volumes is RWO-only,\non-prem k3s, kind/k3d), charts that\n[…]\norn_test.go (goconst). Lift to a package-level\nconst.\n\n---------\n\nCo-authored-by: Amit Kumar <aktech@users.noreply.github.com>\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(longhorn): generalize install for non-AWS providers (#270)",
          "author_name": "Amit Kumar",
          "author_login": "aktech",
          "committed_at": "2026-05-21T11:38:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0de398ba690b51f175b4b2026194d7cbc71d86fa",
          "body": "* feat(aws): install AWS Load Balancer Controller after tf.Apply\n\nInstalls the aws-load-balancer-controller Helm chart (v3.2.1) post-apply\nso Service type=LoadBalancer no longer relies on the deprecated in-tree\nAWS cloud-provider controller. Auth is via EKS Pod Identity; the service\naccount is creat\n[…]\ng up hashicorp/aws 6.43.0.\n\n* chore(aws): use OpenTofu registry source for eks-cluster v0.4.0\n\nSwitch from git+ref source to the OpenTofu registry source+version\nformat per review feedback on PR #259.",
          "is_bot": false,
          "headline": "feat(aws): install AWS Load Balancer Controller after tf.Apply (#259)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-05-12T07:39:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d951c1b6fd7af8a2ef4bd4ee1b9d4c0d82c0dc98",
          "body": "* Stream OpenTofu output through slog\n\n* Drop .Terraform selector as it is already embedded in the type\n\n* Refactor implementation to use io.Writer and send tofu output through\nstatus\n\n* Remove source metadata key in favor of having a standard way of adding\nsource via status in the near future\n\n* Remove pkg/action/deploy_test.go as it belongs to another branch\n\n* Rename payload to detail",
          "is_bot": false,
          "headline": "Stream OpenTofu output through the status channel (#281)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-05-12T07:33:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05203fd1a4a2e906b57dbe459c2ae4744703e8a1",
          "body": "* Add design spec for ArgoCD Keycloak SSO integration (#227)\n\n* Add implementation plan for ArgoCD Keycloak SSO (#227)\n\n* feat: add ConfigWithOIDC for ArgoCD Keycloak OIDC SSO (#227)\n\n* feat: add ArgoCDSSOConfig and OIDC client secret creation (#227)\n\n* refactor: accept Config parameter in argocd.In\n[…]\nh SSO info (#227)\n\n* fix: resolve lint issues in argocd package\n\n- Extract \"nebari-foundational\" string into NebariFoundationalPartOf constant (goconst)\n- Remove extra blank line in install.go (gofmt)",
          "is_bot": false,
          "headline": "ArgoCD SSO via Keycloak OIDC (#234)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-05-11T17:46:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11ffad72210bf774f5ed65316114f5826285abef",
          "body": null,
          "is_bot": false,
          "headline": "Update nebari-landing chart to v0.1.0-alpha.4 (#279)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-05-06T10:36:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4481d70460c03467a4ad0566c42c38996c0c33be",
          "body": "* fix(lint): resolve goconst violations across packages\n\nTune goconst to skip generic noise strings (true/false/Config/name) and\nbump min-occurrences to 4 so only repeats that clearly warrant a constant\nget flagged. Extract named constants for the meaningful repeats: Argo CD\nchart version and namesp\n[…]\nnt; add a parallel local.ProviderName.\n\n* fix(lint): use array form for goconst ignore-string-values\n\nCI's config verify rejects the regex string form; the schema requires an\narray of literal strings.",
          "is_bot": false,
          "headline": "fix(lint): resolve goconst violations across packages (#280)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-05-06T10:11:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "36fea3219a532c96f78bdf8aacb3ef2c27b5df8a",
          "body": "…#201)\n\n* feat(local): add StorageClass, HTTPSPort, MetalLB config fields\n\n* test(local): add table-driven tests for configurable InfraSettings\n\n* feat(local): read InfraSettings from config with defaults\n\n* docs: add configurable InfraSettings examples to local-config.yaml\n\n* test(local): assert Lo\n[…]\n the existing zero-value field checks.\n\n---------\n\nCo-authored-by: Vinicius D. Cerutti <51954708+viniciusdc@users.noreply.github.com>\nCo-authored-by: vinicius douglas cerutti <vinivdc2009@hotmail.com>",
          "is_bot": false,
          "headline": "feat(local): make StorageClass, MetalLB, and HTTPSPort configurable (…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-05-01T15:32:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff50d1690e928aeb49e6bfcd5ecea62c88e05a0e",
          "body": "* working with specified git repo\n\n* Switch sync wave of envoy and cert-manager so cert-manager can find the proper CRD\n\n* Auto-generated tmp directory filepath\n\n* add documentation for local kind development\n\n* Add config file to output folder, add tests\n\n* golangci-ling fixes\n\n* Fix broken tests\n\n\n[…]\nRefactor stageAndCommit to create own span from ctx instead of accepting span param\n- Add RedactedCopy method to git.Config\n- Update tests for new YAML output format and SupportsLocalGitOps capability",
          "is_bot": false,
          "headline": "Add local filesystem GitOps support for Kind development (#136)",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-04-29T16:58:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b9ab65b2ff3e3185ab92caf8134120e1f56833a6",
          "body": null,
          "is_bot": false,
          "headline": "Bump Nebari Operator version to v0.1.0-alpha.19 (#272)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-04-29T10:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2c4a2f365217ee78ffaf67f7b0538c0b2f2401b",
          "body": null,
          "is_bot": false,
          "headline": "docs: add ADR-0004 for out-of-tree provider plugin architecture (#256)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-27T14:40:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "487912cd28b7e757814417335ca300fdb1eb34da",
          "body": "…PI (#206)\n\n* fix: Resolve k3s versions from hetzner-k3s binary instead of GitHub API\n\nThe GitHub k3s releases API can return versions newer than what\nhetzner-k3s supports, causing deploy failures. Use `hetzner-k3s releases`\nas the authoritative source of supported versions.\n\nFixes #205\n\n* fix: addr\n[…]\n- Replace loose strings.Contains with strict prereleasePattern regex\n- Update test fixtures to oldest-first order matching real binary output\n- Add TestK3sVersionPattern and TestExtractAvailableMinors",
          "is_bot": false,
          "headline": "fix: Resolve k3s versions from hetzner-k3s binary instead of GitHub A…",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-04-27T12:04:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3e8e71812f0cb1bd3ddcdd6edfd43f95c35bbd5",
          "body": "* Introduce nested cluster provider configuration in NebariConfig\n\n* Update provider references to use Cluster.ProviderName() and Cluster.ProviderConfig()\n\n* Remove unused Provider reference\n\n* Update tests to use nested cluster config\n\n* Remove unnecessary reference to Provider\n\n* Update architectu\n[…]\nProvider\"] instead of result[\"Mode\"] to be consistent with\nthe Hetzner implementation\n\n* Pass context and instrument `loadAndValidateContext` function\n\n* Update test to mirror change in summary method",
          "is_bot": false,
          "headline": "Add Existing Cluster Provider (#233)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-04-23T12:37:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d6a6af4f50ffe2f966f20b65275cc90d3e952a1a",
          "body": "* chore: sync priority labels to project Priority field\n\n* refactor: use reusable workflow from nebari-dev/.github\n\n* refactor: use reusable workflow from nebari-dev/.github",
          "is_bot": false,
          "headline": "chore: sync priority labels to project Priority field (#255)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-17T11:35:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "839645f034e4d91c9ae198f760c7b87e8e086763",
          "body": "* feat: create EFS StorageClass when EFS is enabled (#235)\n\nAfter tf.Apply completes and EFS is provisioned, create a Kubernetes\nStorageClass backed by the EFS CSI driver so workloads can dynamically\nprovision ReadWriteMany PVCs. The StorageClass name defaults to \"efs-sc\"\nand is configurable via sto\n[…]\nr aws provider 6.40.0\n\n`tofu init -upgrade` (triggered by the eks-cluster module bump to v0.2.0)\nalso pulled in hashicorp/aws 6.40.0. Regenerated the multi-platform\nlockfile to match what CI produces.",
          "is_bot": false,
          "headline": "feat: create EFS StorageClass when EFS is enabled (#236)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-15T10:57:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "145cb05599feceeacadc1ca2ebfc448372c9266c",
          "body": "Bumps the operator image and kustomize ref to pick up recent fixes\nincluding OIDC issuer URL provisioning for NebariApp resources.",
          "is_bot": false,
          "headline": "chore(operator): upgrade nebari-operator to v0.1.0-alpha.17 (#242)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-04-10T12:34:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f80a421391834ba948df01fdb0e6a6e0ef60bb8a",
          "body": "* Introduce nested cluster provider configuration in NebariConfig\n\n* Update provider references to use Cluster.ProviderName() and Cluster.ProviderConfig()\n\n* Remove unused Provider reference\n\n* Update tests to use nested cluster config\n\n* Remove unnecessary reference to Provider\n\n* Update architectu\n[…]\ns ClusterConfig instead of NebariConfig in provider interface and\nimplementations\n\n* Update example given that kubecontext is now read only from the provider\nconfig and not the top level nebari config",
          "is_bot": false,
          "headline": "Narrow Provider interface to accept only cluster-scoped config (#211)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-04-10T09:01:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fa6ae4063221532b4a615cf406194e474f786c8",
          "body": null,
          "is_bot": false,
          "headline": "Fix typo in roadmap link (#239)",
          "author_name": "Pierre-Olivier Simonard",
          "author_login": "pierrotsmnrd",
          "committed_at": "2026-04-10T07:37:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f910de8c4ba99a52e9e44f67d614d948eb225e5f",
          "body": "* docs: fix AWS EKS endpoint field names in config reference\n\nReplace non-existent  (string enum) and\n (list) fields with the actual boolean\nfields  and  that\nexist in the Config struct (pkg/provider/aws/config.go).\n\nThe old field names were silently ignored by the YAML parser, causing\nconfusing Ter\n[…]\nusers following the documentation.\n\nCloses #93\nRelated: #82, #83\n\n* docs: address PR feedback on EKS endpoint docs\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: fix AWS EKS endpoint field names in configuration reference (#183)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-04-09T09:33:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bac9693d0fd17bb468fcf723dbda73592dbe4f8b",
          "body": "The LandingPage config was never populated in the FoundationalConfig\nstruct, so RedisPassword defaulted to empty string. This caused Redis\nto start with no authentication and enable protected mode, rejecting\nall non-loopback connections from the webapi pod.\n\nCloses #224",
          "is_bot": false,
          "headline": "fix: generate Redis password for landing page secret (#225)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-09T09:33:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a2c4487e885624da308101124e9076b8f604edf",
          "body": null,
          "is_bot": false,
          "headline": "Update nebari-operator version to v0.1.0-alpha.16 (#223)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-09T09:33:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f01e24f38d596b2fea5875c73fdbb8a5b1df4ed3",
          "body": "Required for the nebari-operator to configure OAuth 2.0 Token Exchange\n(RFC 8693) per-client permissions. The token-exchange feature enables\nthe grant type, and admin-fine-grained-authz:v1 enables the management\npermissions API used by the operator to set up token exchange policies.",
          "is_bot": false,
          "headline": "Enable token-exchange and admin-fine-grained-authz in Keycloak (#212)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-08T09:25:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecb57d1aa3611edc96dafb8f184446b40fd0ec38",
          "body": "* Introduce nested cluster provider configuration in NebariConfig\n\n* Update provider references to use Cluster.ProviderName() and Cluster.ProviderConfig()\n\n* Remove unused Provider reference\n\n* Update tests to use nested cluster config\n\n* Remove unnecessary reference to Provider\n\n* Update architectu\n[…]\nRemove Provider field from TemplateData in gateway and health probe tests\n\n* Remove ConfigKey from the provider interface as it is no longer needed\n\n* Decouple deploy/destroy options from NebariConfig",
          "is_bot": false,
          "headline": "Decouple deploy/destroy options from NebariConfig (#208)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-04-06T13:06:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be9cd4773957f43f903329113a06ee2a714b4f72",
          "body": "…(#222)\n\n* refactor: unify provider registries into single pkg/registry package\n\nConsolidate separate provider.Registry and dnsprovider.Registry into a\nsingle registry.Registry struct. CLI commands now use one registry\ninstance with typed methods (RegisterClusterProvider, RegisterDNSProvider,\netc.) \n[…]\n- Standardize span names to registry.{name}.{method} convention\n- Move validation assembly to getValidNames helper in cmd/nic\n- Replace type-specific tests with generic ProviderList table-driven tests",
          "is_bot": false,
          "headline": "refactor: unify provider registries into single pkg/registry package …",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-06T12:44:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f392a8094d3b2e6af205199fc37642759b536495",
          "body": "* Add group-membership mapper to groups client scope in realm setup\n\nThe groups client scope had no protocol mapper, so tokens never\ncontained group claims. This prevented the landing page webapi from\nmatching users against requiredGroups for service visibility filtering.\n\nCloses #215\n\n* Replace python3 with grep/sed for JSON parsing and add realm default scope\n\n---------\n\nCo-authored-by: Vinicius D. Cerutti <51954708+viniciusdc@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add group-membership mapper to groups client scope in realm setup (#218)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-04-01T16:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b313fd3910fa40f4daf0718a35cdb4c595fe333",
          "body": "* Introduce nested cluster provider configuration in NebariConfig\n\n* Update provider references to use Cluster.ProviderName() and Cluster.ProviderConfig()\n\n* Remove unused Provider reference\n\n* Update tests to use nested cluster config\n\n* Remove unnecessary reference to Provider\n\n* Update architectu\n[…]\ns no longer needed\n\n* Decouple config parsin from validation and pass registry lists to ensure\nproviders are valid\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Introduce nested cluster provider configuration in NebariConfig (#190)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-04-01T13:55:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e81f539f7fb3cfb0a56a079b61368e9895b3defa",
          "body": "…alpha.15 (#214)\n\n* chore: update nebari-landing to v0.2.0 and nebari-operator to v0.1.0-alpha.15\n\n- Update nebari-landing from v0.1.0-alpha.2 to v0.2.0\n- Update nebari-operator from v0.1.0-alpha.14 to v0.1.0-alpha.15\n- Update nebari-operator image tag from 0.1.0-alpha.13 to 0.1.0-alpha.15\n- Add Redis secret management for nebari-landing to prevent password rotation on ArgoCD sync\n\n* chore: update nebari-landing to v0.1.0-alpha.3\n\n- Update nebari-landing from v0.2.0 to v0.1.0-alpha.3",
          "is_bot": false,
          "headline": "chore: update nebari-landing to v0.2.0 and nebari-operator to v0.1.0-…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-04-01T13:13:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5a1bd88fb5863e61aff051038b2ff3aae8bebac",
          "body": "…lpha.2 (#202)\n\n* fix: bootstrap nebari-system namespace with nebari.dev/managed=true label\n\nCloses #197\n\n- Add NebariSystemNamespace constant (\"nebari-system\")\n- Add createNamespaceWithLabels() helper; createNamespace() delegates to it\n- Always create nebari-system with nebari.dev/managed=true befo\n[…]\ng and webapi stuck in Init:0/1.\n\nv0.1.0-alpha.2 includes:\n- redis secret init hook (BeforeHookCreation + PreSync ArgoCD hook)\n- UI branding/customization support\n- All other fixes merged since alpha.1",
          "is_bot": false,
          "headline": "fix: label nebari-system namespace and bump landing chart to v0.1.0-a…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-03-31T15:44:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90793ead6e029ea99ccf4b5b5a7e4d5e7a95089d",
          "body": "* Update EKS cluster module source and version\n\n* Remove -upgrade flag from tofu init\n\n* Revert change to drift detection workflow\n\n* Update lockfile",
          "is_bot": false,
          "headline": "Update EKS cluster module source and version (#203)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-03-30T18:09:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7e3cc4f96b9d05df75e905f1fe0d79bb4261d77",
          "body": "…lows\n\nsetup-go@v5 has built-in caching enabled by default. The explicit\nactions/cache steps conflict with it, causing \"Cannot open: File exists\"\nerrors during cache restore.",
          "is_bot": false,
          "headline": "fix: remove redundant Go module cache steps from CI and release workf…",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-27T15:53:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96bd5cfb37f795ccae0ee9b640c7965f2c327359",
          "body": "GoReleaser requires GITHUB_TOKEN to create releases and upload\nartifacts. The env block was missing from the workflow step.",
          "is_bot": false,
          "headline": "fix: add GITHUB_TOKEN to GoReleaser step in release workflow",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-27T14:22:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80f8c6dac5196c10b116047516396c500679cade",
          "body": "…#181)\n\n* feat: make --file/-f flag optional with smart config auto-discovery\n\nCloses #50\n\n- Add resolveConfigFile() helper that checks in priority order:\n  1. Explicit --file/-f flag\n  2. NIC_CONFIG_PATH environment variable\n  3. ./config.yaml auto-discovery in the current working directory\n- Add c\n[…]\nd explicit invocations\n- Document NIC_CONFIG_PATH in the CLI reference env vars table and\n  in the deploy command description in README\n- Update OTel examples to use the no-arg form for auto-discovery",
          "is_bot": false,
          "headline": "feat: make --file/-f flag optional with smart config auto-discovery (…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-03-26T18:06:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e742cd87d2936c64e1e988aac4fe22b8e01aa632",
          "body": "Proposes a design for auto-generating ArgoCD Application manifests\nfrom a software_packs config key, using a layered approach of\nconventions, optional pack metadata, and user overrides.\n\nRelates to #152",
          "is_bot": false,
          "headline": "Add ADR-0003: Software pack codegen via ArgoCD app generation (#153)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-26T17:54:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "048da1361fa029f7baa7e0327abd7ed5d716fa3a",
          "body": "Updated logo display in README to support light and dark themes.\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Enhance logo display with responsive images (#185)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-03-25T16:21:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2961d808907bc30674bec8258acb82273cffeba3",
          "body": null,
          "is_bot": false,
          "headline": "bump nebari-operator to v0.1.0-alpha.14 (#199)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-25T15:57:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66f0e14557dbd1bc2b44c7567be967374c84b771",
          "body": null,
          "is_bot": false,
          "headline": "feat: pass KEYCLOAK_EXTERNAL_URL to nebari-operator deployment (#196)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-25T14:29:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5e49c7df144d8145b897897f05b968301d46d12",
          "body": "* Add HTTP-to-HTTPS redirect for nebari-gateway\n\nServices were accessible over plain HTTP because HTTPRoutes attached to\nboth gateway listeners without specifying a sectionName. Add a catch-all\nredirect route on the http listener (port 80) that returns 301 to HTTPS,\nand pin service routes (argocd, k\n[…]\nrify\nthat NewTemplateData normalizes HTTPSPort 0 to 443. Document that all\nNebari services must be served over HTTPS (catch-all invariant).\n\nSee #171 for the cert-manager solver sectionName follow-up.",
          "is_bot": false,
          "headline": "Add HTTP-to-HTTPS redirect for nebari-gateway (#158)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-24T15:16:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8d10135528260c92ed7c85c6482bcfdf40c7a71",
          "body": "…tion (#155)\n\n* feat: add nebari-landingpage ArgoCD application with Keycloak integration\n\n- Add nebari-landingpage.yaml template with Keycloak OIDC configuration\n- Add KeycloakIssuerURL and KeycloakAdminSecretNamespace to TemplateData\n- Configure landing page to use NebariApp CR with wave 6 orderin\n[…]\ns/nebari\", which oauth2-proxy would reject.\nIn practice this path is not hit because Domain defaults to \"nebari.local\",\nbut the note is left for awareness if bare-LB-IP deployments are ever\nsupported.",
          "is_bot": false,
          "headline": "feat: Add nebari-landingpage ArgoCD application with Keycloak integra…",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-03-20T16:04:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d33ed2e3df6d4144f49f26ef1a7c819ce6b7000a",
          "body": "* feat: add InfraSettings to Provider interface\n\nAdds InfraSettings struct and method to the Provider interface.\nProviders return storage class, MetalLB needs, LB annotations,\nand Keycloak base path instead of the ArgoCD writer switching\non provider name strings.\n\n* feat: implement InfraSettings for\n[…]\nthem.\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: Nick Byrne <byrnen8@tcd.ie>\nCo-authored-by: Vinicius D. Cerutti <51954708+viniciusdc@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: Add Hetzner Cloud provider with hetzner-k3s integration (#130)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-13T19:57:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e6dbb76c7274eaabcce27754a55c6db933a6eb4",
          "body": "* upgrade argocd, don't run helm upgrade if cluster version matches what's in defaultconfig\n\n* add check for case with zero releases\n\n* Address PR review\n\n* fix golangci-lint issues\n\n* fix: add nil guards for helm chart metadata version\n\n- Prevent potential nil pointer dereference when current.Chart\n[…]\ntautological)\n- Add test cases for failed and pending-upgrade status scenarios\n- Use table-driven tests throughout\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "upgrade argocd, streamline deploy logic (#85)",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-03-09T11:06:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91c2e04f58442817afe91c2f0f1ca59f1de66426",
          "body": "* Add StorageClass() to Provider interface\n\nEach provider returns its default Kubernetes StorageClass name:\n- AWS: \"longhorn\" (default) or \"gp2\" when Longhorn is disabled\n- GCP: \"standard-rwo\"\n- Azure: \"managed-csi\"\n- Local: \"standard\"\n\nIncludes a stub LonghornEnabled() on AWS Config that always ret\n[…]\n G118 lint error and lockfile drift\n\nAdd defer cancel() to satisfy gosec G118 in cleanup_test.go context\ncancellation test. Regenerate .terraform.lock.hcl for AWS provider\n6.35.1 across all platforms.",
          "is_bot": false,
          "headline": "Implement Longhorn distributed block storage for AWS (#107)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-03-09T10:32:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3465c61b7c1e9ec0ed203e75df442669ef92a8b4",
          "body": null,
          "is_bot": false,
          "headline": "Update nebari-operator to version 0.1.0-alpha.5 (#140)",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-03-05T21:24:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f381a72dacb6828c5a5ec09f6a0df223e78bc47",
          "body": "* Refactor DNS configuration to accept a key and provider config instead of having two separate keys for them\n\n* Refactor tests\n\n* Replace typed DNSConfig with inline map pattern\n\nRemove cloudflare import from pkg/config to fix abstraction violation.\nDNSConfig now uses yaml:\",inline\" map (same patte\n[…]\nderConfig() now safely handle nil receivers\nand document the single-entry map precondition enforced by Validate().\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Refactor DNS config to typed nested format (#129)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-03-05T08:27:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebb4104bc698d989f60c1dcfa577e33115aeb2d5",
          "body": "…s (#121)\n\n* test: add unit tests for GetKubeconfig (fixes #9)\n\n* test(aws): add table-driven tests for buildKubeconfig and remove provider test seams\n\n* test(aws): validate exec.APIVersion and remove unnecessary tt capture\n\n* ci: auto-generate OpenTofu provider lockfiles for template changes (fixes\n[…]\n (split PR/push, concurrency, cleanup)\n\n* ci: finalize workflow hardening (pin setup-opentofu, concurrency, cleanup)\n\n* ci: remove auto-commit workflow; add local lockfile regeneration helper and docs",
          "is_bot": false,
          "headline": "CI: Automatically regenerate OpenTofu lockfiles for provider template…",
          "author_name": "0rlych1kk4",
          "author_login": "0rlych1kk4",
          "committed_at": "2026-03-04T12:29:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4ec20166e3c5bbdf6f9db3b312ce4c789a74493",
          "body": null,
          "is_bot": false,
          "headline": "update the operator version (#133)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-02-27T16:22:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a8fd013b177287d33213fc0d0d0bc0dee1efa2d",
          "body": "* Update eks_cluster module source and version\n\n* Avoid serializing the gpu field in node groups to json as the TF module does not take it anymore\n\n* Add node group ami_type when converting to tfvars JSON if none was specified\n\n* Replace if-else with switch statement as per the linter complaints\n\n* Replace if-else with switch statement for AMIType validation in tests",
          "is_bot": false,
          "headline": "Update terraform-aws-eks-cluster module (#128)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-02-27T15:47:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19b17a488adeaf61b194b99a26926f0937324ce6",
          "body": "* docs: update DNS provider architecture to match implementation\n\nUpdate 09-dns-provider-architecture.md to reflect the actual\nCloudflare DNS provider implementation:\n\n- Replace old verbose interface (GetRecord, AddRecord, etc.) with\n  the simplified stateless ProvisionRecords/DestroyRecords interfa\n[…]\nCLOUDFLARE_EMAIL alternatives\n- Remove stale GetCertManagerConfig() reference\n- Update Cloudflare provider status from \"Stub\" to \"Implemented\"\n- Add complete file table for cloudflare provider package",
          "is_bot": false,
          "headline": "docs: update DNS provider architecture to match implementation (#113)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-02-25T12:38:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "753dda83cee8da2c04a838d65c497dfd40a2c0fc",
          "body": "* Write cached tofu binary to temporary working directory to avoid conflicts when running multiple deployments concurrently\n\n* Run go fmt\n\n* Update constant name to match changes in main",
          "is_bot": false,
          "headline": "Write tofu binary to working directory instead of shared cache (#104)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-02-23T14:26:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c81d473fd36732e7f0b86586c98687b8f3f53a4f",
          "body": null,
          "is_bot": false,
          "headline": "Fix double SIGINT on Ctrl+C by wrapping tofu context per platform (#122)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-02-20T16:37:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34b42fb1c07e07052deb40b32b64761b31e107a8",
          "body": "Unblock destruction by pre-destroying security group, load balancer, and references to security group",
          "is_bot": false,
          "headline": "Enable Successful Destroy (#91)",
          "author_name": "Tyler",
          "author_login": "tylerpotts",
          "committed_at": "2026-02-20T15:18:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ef37cc8955abf22a324850005ffe3dfe46bdca3",
          "body": "* refactor: rename DefaultVersion to TofuVersion for clarity\n\n* Rename TofuVersion to Version",
          "is_bot": false,
          "headline": "Rename DefaultVersion to TofuVersion for clarity (#120)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-02-20T14:28:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "668f1ab9ef2f487899a63eef09a9167134f8df2b",
          "body": null,
          "is_bot": false,
          "headline": "Update default OpenTofu version to 1.11.3 (#119)",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-02-20T12:01:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf3b3522e42fea7258ef37c28b45379e83df59d8",
          "body": "…time (#103)\n\n* Add function to override remote backend config with local one\n\n* Implement state bucket existence checks and modify dry-run behavior in Deploy and Destroy functions\n\n* Move backend configuration to a separate file for better organization\n\n---------\n\nCo-authored-by: Tyler <49161327+tylerpotts@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Avoid creating state bucket when deploying with dry run on the first …",
          "author_name": "Marcelo Villa",
          "author_login": "marcelovilla",
          "committed_at": "2026-02-18T17:07:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f90a7e4b30107ab0a398c9fd195c20307dc1df69",
          "body": "* refactor: simplify DNSProvider interface to ProvisionRecords/DestroyRecords\n\n* feat: define CloudflareClient interface and DNSRecordResult type\n\n* test: add ProvisionRecords tests with mock CloudflareClient\n\n* feat: implement ProvisionRecords with ensure-record logic\n\n* test: add DestroyRecords te\n[…]\n\n\nExtract inline DNS cleanup logic in destroy command into a dedicated\ndestroyDNS function for readability. Remove the unused email field\nfrom the DNS example config to match the Config struct change.",
          "is_bot": false,
          "headline": "feat: implement Cloudflare DNS provider (#87)",
          "author_name": "Chuck McAndrew",
          "author_login": "dcmcand",
          "committed_at": "2026-02-18T16:30:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8cc6a2691d818a319b9ed54e5d0ffab1f5e12d4f",
          "body": "Keycloak 26 replaced hostname v1 with v2. KC_HOSTNAME now accepts a\nfull URL, and KC_HOSTNAME_STRICT is a deprecated v1 option that is\nsilently ignored. Pass the full URL with scheme and context path so\nOIDC discovery returns correct https URLs.\n\nCloses #108\n\nCo-authored-by: Amit Kumar <aktech@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Fix KC_HOSTNAME for Keycloak 26 hostname v2 (#109)",
          "author_name": "Amit Kumar",
          "author_login": "aktech",
          "committed_at": "2026-02-18T15:06:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5525f3924b69c181af7e86aa0c51514e1d463e70",
          "body": "…(#55)\n\n* Add argo app for nebari-operator chart install\n\n* Apply suggestion from @viniciusdc\n\n* add extra settings for operator\n\n* Update resource URL to specific release version\n\n* fix version of operatora\n\n* address chuck's comments\n\n- use kuistomize native git-based resource loading\n- centralize\n[…]\nbari-operator to version v0.1.0-alpha.2\n\n---------\n\nCo-authored-by: Chuck McAndrew <6248903+dcmcand@users.noreply.github.com>\nCo-authored-by: Tyler Potts <49161327+tylerpotts@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: Add ArgoCD Application manifest for nebari-operator deployment …",
          "author_name": "Vinicius D. Cerutti",
          "author_login": "viniciusdc",
          "committed_at": "2026-02-17T16:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 9,
      "commits_last_year": 252,
      "latest_release_at": "2026-07-17T15:25:17Z",
      "latest_release_tag": "v0.10.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 33,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 14
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/nebari-dev/nebari-infrastructure-core",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/nebari-dev/nebari-infrastructure-core",
          "is_deprecated": false,
          "latest_version": "v0.10.0",
          "repository_url": "https://github.com/nebari-dev/nebari-infrastructure-core",
          "versions_count": 11,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-17T14:56:46Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 10,
      "stars": 12,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-11",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-04-23",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-25",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 10,
        "total_forks": 10
      },
      "star_history": {
        "days": [
          {
            "date": "2026-02-09",
            "count": 1
          },
          {
            "date": "2026-02-25",
            "count": 1
          },
          {
            "date": "2026-03-11",
            "count": 2
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-16",
            "count": 2
          },
          {
            "date": "2026-04-29",
            "count": 1
          },
          {
            "date": "2026-05-14",
            "count": 1
          },
          {
            "date": "2026-05-17",
            "count": 1
          },
          {
            "date": "2026-06-10",
            "count": 1
          },
          {
            "date": "2026-07-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 12,
        "total_stars": 12
      },
      "open_issues_and_prs": 214
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 45244,
      "source_files_sampled": 164,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md"
      ],
      "agent_instruction_max_bytes": 22135
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/Azure/azure-sdk-for-go/sdk/azcore",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.22.0"
        },
        {
          "name": "github.com/Azure/azure-sdk-for-go/sdk/azidentity",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.0"
        },
        {
          "name": "github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v6",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v6.6.0"
        },
        {
          "name": "github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/resources/armresources",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/Azure/azure-sdk-for-go/sdk/resourcemanager/storage/armstorage",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.1"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.25"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/ec2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.307.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/eks",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.86.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.34.6"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.55.4"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/s3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.104.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.3"
        },
        {
          "name": "github.com/aws/smithy-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.2"
        },
        {
          "name": "github.com/cloudflare/cloudflare-go/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.6.0"
        },
        {
          "name": "github.com/go-git/go-git/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.19.1"
        },
        {
          "name": "github.com/goccy/go-yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.2"
        },
        {
          "name": "github.com/hashicorp/terraform-exec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.25.2"
        },
        {
          "name": "github.com/joho/godotenv",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.1"
        },
        {
          "name": "github.com/opentofu/tofudl",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.1"
        },
        {
          "name": "github.com/skeema/knownhosts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.2"
        },
        {
          "name": "github.com/spf13/afero",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.15.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.53.0"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "helm.sh/helm/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.21.1"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "sigs.k8s.io/kind",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.32.0"
        },
        {
          "name": "sigs.k8s.io/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 22,
        "merged_prs": 125,
        "open_issues": 192,
        "closed_ratio": 0.385,
        "closed_issues": 120,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 2,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "dcmcand",
          "commits": 124,
          "avatar_url": "https://avatars.githubusercontent.com/u/6248903?v=4"
        },
        {
          "type": "User",
          "login": "marcelovilla",
          "commits": 84,
          "avatar_url": "https://avatars.githubusercontent.com/u/36754005?v=4"
        },
        {
          "type": "User",
          "login": "viniciusdc",
          "commits": 18,
          "avatar_url": "https://avatars.githubusercontent.com/u/51954708?v=4"
        },
        {
          "type": "User",
          "login": "tylerpotts",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/49161327?v=4"
        },
        {
          "type": "User",
          "login": "0rlych1kk4",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/108985066?v=4"
        },
        {
          "type": "User",
          "login": "aktech",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/5647941?v=4"
        },
        {
          "type": "User",
          "login": "pmeier",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/6849766?v=4"
        },
        {
          "type": "User",
          "login": "Adam-D-Lewis",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/23342526?v=4"
        },
        {
          "type": "User",
          "login": "andrewfulton9",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/13774419?v=4"
        },
        {
          "type": "User",
          "login": "oldsj",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/12104969?v=4"
        }
      ],
      "contributors_sampled": 12,
      "top_contributor_share": 0.492
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "add-to-project.yaml",
        "ci.yml",
        "opentofu-lockfile-pr.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 8,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 1,
            "reason": "1 out of the last 5 releases have a total of 1 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "3c0d20727783239738ede4b7813fa1a1c211fa19",
        "ran_at": "2026-07-22T03:13:27Z",
        "aggregate_score": 5.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-17T15:25:45Z",
      "oldest_open_prs": [
        {
          "number": 182,
          "created_at": "2026-03-20T20:48:45Z",
          "last_comment_at": "2026-03-23T15:45:07Z",
          "last_comment_author": "viniciusdc"
        },
        {
          "number": 245,
          "created_at": "2026-04-11T19:36:53Z",
          "last_comment_at": "2026-04-17T12:58:16Z",
          "last_comment_author": "dcmcand"
        },
        {
          "number": 289,
          "created_at": "2026-05-12T02:31:42Z",
          "last_comment_at": "2026-07-17T16:53:57Z",
          "last_comment_author": "viniciusdc"
        },
        {
          "number": 301,
          "created_at": "2026-05-12T18:02:50Z",
          "last_comment_at": "2026-05-13T10:59:38Z",
          "last_comment_author": "dcmcand"
        },
        {
          "number": 362,
          "created_at": "2026-06-05T01:41:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 416,
          "created_at": "2026-06-25T09:11:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 433,
          "created_at": "2026-06-26T20:43:48Z",
          "last_comment_at": "2026-06-30T18:30:38Z",
          "last_comment_author": "brandonrc"
        },
        {
          "number": 434,
          "created_at": "2026-06-26T23:01:32Z",
          "last_comment_at": "2026-07-10T22:57:11Z",
          "last_comment_author": "andrewfulton9"
        },
        {
          "number": 439,
          "created_at": "2026-06-29T14:01:37Z",
          "last_comment_at": "2026-07-17T13:00:30Z",
          "last_comment_author": "dcmcand"
        },
        {
          "number": 443,
          "created_at": "2026-07-06T14:30:17Z",
          "last_comment_at": "2026-07-21T19:03:39Z",
          "last_comment_author": "tylerpotts"
        },
        {
          "number": 444,
          "created_at": "2026-07-06T16:00:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 446,
          "created_at": "2026-07-07T16:23:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 449,
          "created_at": "2026-07-08T15:50:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 473,
          "created_at": "2026-07-13T22:36:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 479,
          "created_at": "2026-07-15T08:04:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 482,
          "created_at": "2026-07-15T14:13:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 489,
          "created_at": "2026-07-16T19:16:31Z",
          "last_comment_at": "2026-07-17T19:19:48Z",
          "last_comment_author": "viniciusdc"
        },
        {
          "number": 493,
          "created_at": "2026-07-17T14:55:56Z",
          "last_comment_at": "2026-07-20T17:00:24Z",
          "last_comment_author": "oldsj"
        },
        {
          "number": 494,
          "created_at": "2026-07-17T15:03:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 495,
          "created_at": "2026-07-17T16:35:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-17T14:56:47Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 6,
          "created_at": "2025-11-25T17:39:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 31,
          "created_at": "2026-01-08T15:31:54Z",
          "last_comment_at": "2026-02-11T09:16:23Z",
          "last_comment_author": "0rlych1kk4"
        },
        {
          "number": 54,
          "created_at": "2026-02-05T10:08:21Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 60,
          "created_at": "2026-02-05T15:45:48Z",
          "last_comment_at": "2026-02-11T09:20:38Z",
          "last_comment_author": "0rlych1kk4"
        },
        {
          "number": 64,
          "created_at": "2026-02-06T08:33:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 66,
          "created_at": "2026-02-06T10:12:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 71,
          "created_at": "2026-02-09T11:42:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 72,
          "created_at": "2026-02-09T12:04:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 74,
          "created_at": "2026-02-09T12:23:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 94,
          "created_at": "2026-02-13T11:46:42Z",
          "last_comment_at": "2026-02-16T13:51:55Z",
          "last_comment_author": "marcelovilla"
        },
        {
          "number": 98,
          "created_at": "2026-02-13T16:59:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 99,
          "created_at": "2026-02-13T19:48:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 100,
          "created_at": "2026-02-13T21:16:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 102,
          "created_at": "2026-02-13T23:00:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 106,
          "created_at": "2026-02-17T16:09:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 110,
          "created_at": "2026-02-18T14:11:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 111,
          "created_at": "2026-02-18T15:41:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 116,
          "created_at": "2026-02-19T10:07:47Z",
          "last_comment_at": "2026-03-23T17:59:17Z",
          "last_comment_author": "marcelovilla"
        },
        {
          "number": 117,
          "created_at": "2026-02-19T11:39:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 125,
          "created_at": "2026-02-26T15:34:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/nebari-dev/nebari-infrastructure-core",
    "host": "github.com",
    "name": "nebari-infrastructure-core",
    "owner": "nebari-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 72,
      "inputs": {
        "security": 56,
        "vitality": 89,
        "community": 56,
        "governance": 70,
        "engineering": 82
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 89,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "commits_last_year": 252,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 33
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "33/52 weeks with commits",
                "points": 22.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 33
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "252 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 252
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 91,
            "inputs": {
              "releases_count": 9,
              "latest_release_tag": "v0.10.0",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 14
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "9 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~14 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 14
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 4,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 4 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 56,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "forks": 10,
              "stars": 12,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "12 stars",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "10 forks",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 70,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 12,
              "top_contributor_share": 0.492
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 49% of commits",
                "points": 11.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 49
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "12 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 125,
              "open_issues": 192,
              "closed_issues": 120,
              "issue_closed_ratio": 0.385,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "38% of issues closed",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 38
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "125/156 decided PRs merged",
                "points": 30.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 125,
                      "decided": 156
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "followers": 70,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "nebari-dev",
              "public_repos": 77,
              "account_age_days": 1638
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "70 followers of nebari-dev",
                "points": 13.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 70,
                      "login": "nebari-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "77 public repos, account ~4 yr old",
                "points": 22,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 77
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/nebari-dev/nebari-infrastructure-core"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "11 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 82,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 5.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "1 out of the last 5 releases have a total of 1 signed artifacts.",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 12
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 81,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "AGENTS.md"
              ],
              "agent_instruction_max_bytes": 22135
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 45244,
              "source_files_sampled": 164,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/164 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 164,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T03:13:50.777373Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/nebari-dev/nebari-infrastructure-core.svg",
  "full_name": "nebari-dev/nebari-infrastructure-core",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.