Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 14:21 UTC

nginx / nginx-gateway-fabric

NGINX Gateway Fabric provides an implementation for the Gateway API using NGINX as the data plane.

GoApache-2.0★ 1,128 stars⑂ 203 forkssince Oct 2021View on GitHub ↗

nginx/nginx-gateway-fabric holds a health index of 89 out of 100, placing it in the Excellent band. It scores highest on Vitality (96/100) and lowest on AI Readiness (74/100). It was last updated today. 3 contributors account for most of its recent work.

89
overall / 100
Excellent

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

89
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

nginxOrganization
2,106 followers61 public repossince Feb 2012

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/nginx/nginx-gateway-fabric/v2v2.6.7-256 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

96Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
36/36Commit cadence — 52/52 weeks with commits
18/18Commit volume — 1,028 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year1,028
human_commit_share0.44
days_since_last_push0
active_weeks_last_year52
How it's scored
27/27Ships releases — 41 releases published
36/36Release recency — latest release 6 days ago
27/27Release cadence — a release every ~11.9 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count41
latest_release_tagv2.6.7
releases_from_tagsno
days_since_latest_release6
mean_days_between_releases11.9

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

84Good · 18% of overall
How it's scored
49.5/60Stars — 1,128 stars
19.2/25Forks — 203 forks
8.1/15Watchers — 30 watchers
Inputs used
forks203
stars1,128
watchers30
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

85Excellent · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
17/22.5Commit distribution — top contributor authored 24% of commits
13.5/13.5Contributor breadth — 72 contributors
10/10OpenSSF Scorecard: Contributors — project has 9 contributing companies or organizations
Inputs used
bus_factor3
contributors_sampled72
top_contributor_share0.243
How it's scored
42.8/46.8Issue resolution — 92% of issues closed
32.7/38.3PR acceptance — 3,493/4,084 decided PRs merged
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs3,493
open_issues114
closed_issues1,222
issue_closed_ratio0.915
closed_unmerged_prs591
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
23.9/25Owner reach — 2,106 followers of nginx
25/25Track record — 61 public repos, account ~14 yr old
Inputs used
followers2,106
owner_typeOrganization
is_verified
owner_loginnginx
public_repos61
account_age_days5,280
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 6 days ago
20/20Version history — 25 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/nginx/nginx-gateway-fabric/v2
ecosystemsgo
any_deprecatedno
min_days_since_publish6

Engineering Quality

Are baseline engineering and documentation practices in place?

94Excellent · 20% of overall
How it's scored
24/24CI workflows — 22 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yml
9.6/9.6Pre-commit hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configyes
has_precommit_configyes

Documentation

85Excellent
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 4 topics
10/10Wiki
Inputs used
topicskubernetes, gateway-api, k8s, nginx
has_wikiyes
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

85Excellent · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 9 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate8.1
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories0
affected_packages0
assessed_packages237
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 237 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

74Good · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 43 of 44 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.977
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — Makefile, dev/nginx/Makefile, operators/Makefile, tests/Makefile
22/22Automated tests
11/11Lint / format config — .golangci.yml
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 55 of the last 100 commits are automated dependency updates
8/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum, package-lock.json
has_dockerfileyes
typed_languageyes
bootstrap_filesMakefile, dev/nginx/Makefile, operators/Makefile, tests/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod, tests/framework/crossplane/go.mod, tests/go.mod
dependency_bot_commit_share0.55
How it's scored
45/45Type-checkable code — Go (statically typed)
52.2/55Manageable file sizes — 24/467 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes344,726
source_files_sampled467
oversized_source_files24
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — examples/grpc-routing/grpc.proto
0/20MCP server
40/40Runnable examples — examples, samples
Inputs used
example_dirsexamples, samples
has_mcp_signalno
api_schema_filesexamples/grpc-routing/grpc.proto

Key facts

1,128GitHub stars
72contributors
1,028commits, last 12 months
0days since last push
41releases
3bus factor
114open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 203 ⇿
0Stars
203Forks
41Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0408012016020024020142022-042024-052026-07
Major 2Minor 18Patch 21

Each point covers 4 days.

OpenSSF Scorecard 8.1 / 10
8.1aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 14:20 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 9 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
Direct dependencies 32
RegistryPackageVersion constraintManifest
Gogithub.com/aws/aws-sdk-go-v2v1.42.1go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.30go.mod
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.29go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/s3v1.105.2go.mod
Gogithub.com/dlclark/regexp2/v2v2.5.1go.mod
Gogithub.com/envoyproxy/go-control-plane/envoyv1.37.0go.mod
Gogithub.com/fsnotify/fsnotifyv1.10.1go.mod
Gogithub.com/go-logr/logrv1.4.3go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/nginx/agent/v3v3.11.2go.mod
Gogithub.com/nginx/telemetry-exporterv0.1.5go.mod
Gogithub.com/onsi/ginkgo/v2v2.32.0go.mod
Gogithub.com/onsi/gomegav1.42.1go.mod
Gogithub.com/prometheus/client_golangv1.23.2go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/pflagv1.0.10go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0go.mod
Gogo.uber.org/zapv1.28.0go.mod
Gogolang.org/x/textv0.40.0go.mod
Gogoogle.golang.org/grpcv1.82.1go.mod
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afgo.mod
Gogopkg.in/evanphx/json-patch.v4v4.13.0go.mod
Gok8s.io/apiv0.36.2go.mod
Gok8s.io/apiextensions-apiserverv0.36.2go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gok8s.io/client-gov0.36.2go.mod
Gok8s.io/klog/v2v2.140.0go.mod
Gosigs.k8s.io/controller-runtimev0.24.1go.mod
Gosigs.k8s.io/gateway-apiv1.6.1go.mod
Gosigs.k8s.io/gateway-api-inference-extensionv1.5.0go.mod
All dependencies 237

Full resolved dependency set from the GitHub dependency graph: 32 direct and 205 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/aws/aws-sdk-go-v2v1.42.1direct
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.30direct
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.29direct
Gogithub.com/aws/aws-sdk-go-v2/service/s3v1.105.2direct
Gogithub.com/dlclark/regexp2/v2v2.5.1direct
Gogithub.com/envoyproxy/go-control-plane/envoyv1.37.0direct
Gogithub.com/fsnotify/fsnotifyv1.10.1direct
Gogithub.com/go-logr/logrv1.4.3direct
Gogithub.com/google/go-cmpv0.7.0direct
Gogithub.com/google/uuidv1.6.0direct
Gogithub.com/nginx/agent/v3v3.11.2direct
Gogithub.com/nginx/telemetry-exporterv0.1.5direct
Gogithub.com/onsi/ginkgo/v2v2.32.0direct
Gogithub.com/onsi/gomegav1.42.1direct
Gogithub.com/prometheus/client_golangv1.23.2direct
Gogithub.com/spf13/cobrav1.10.2direct
Gogithub.com/spf13/pflagv1.0.10direct
Gogo.opentelemetry.io/otelv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0direct
Gogo.uber.org/zapv1.28.0direct
Gogolang.org/x/textv0.40.0direct
Gogoogle.golang.org/grpcv1.82.1direct
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afdirect
Gogopkg.in/evanphx/json-patch.v4v4.13.0direct
Gok8s.io/apiv0.36.2direct
Gok8s.io/apiextensions-apiserverv0.36.2direct
Gok8s.io/apimachineryv0.36.2direct
Gok8s.io/client-gov0.36.2direct
Gok8s.io/klog/v2v2.140.0direct
Gosigs.k8s.io/controller-runtimev0.24.1direct
Gosigs.k8s.io/gateway-apiv1.6.1direct
Gosigs.k8s.io/gateway-api-inference-extensionv1.5.0direct
Gobuf.build/gen/go/bufbuild/protovalidate/protocolbuffers/gov1.36.11-20260415201107-50325440f8f2.1indirect
Gogithub.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamv1.7.14indirect
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.30indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.30indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.30indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.31indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.13indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/checksumv1.9.23indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.30indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/s3sharedv1.19.31indirect
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.4.1indirect
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.32.1indirect
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.37.1indirect
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.44.1indirect
Gogithub.com/aws/smithy-gov1.27.3indirect
Gogithub.com/beorn7/perksv1.0.1indirect
Gogithub.com/cenkalti/backoff/v5v5.0.3indirect
Gogithub.com/cespare/xxhash/v2v2.3.0indirect
Gogithub.com/cncf/xds/gov0.0.0-20260202195803-dba9d589def2indirect
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirect
Gogithub.com/emicklei/go-restful/v3v3.13.0indirect
Gogithub.com/envoyproxy/protoc-gen-validatev1.3.3indirect
Gogithub.com/evanphx/json-patch/v5v5.9.11indirect
Gogithub.com/fxamacker/cbor/v2v2.9.2indirect
Gogithub.com/go-logr/stdrv1.2.2indirect
Gogithub.com/go-logr/zaprv1.3.0indirect
Gogithub.com/go-openapi/jsonpointerv0.23.1indirect
Gogithub.com/go-openapi/jsonreferencev0.21.5indirect
Gogithub.com/go-openapi/swagv0.26.0indirect
Gogithub.com/go-openapi/swag/cmdutilsv0.26.0indirect
Gogithub.com/go-openapi/swag/convv0.26.0indirect
Gogithub.com/go-openapi/swag/fileutilsv0.26.0indirect
Gogithub.com/go-openapi/swag/jsonnamev0.26.0indirect
Gogithub.com/go-openapi/swag/jsonutilsv0.26.0indirect
Gogithub.com/go-openapi/swag/loadingv0.26.0indirect
Gogithub.com/go-openapi/swag/manglingv0.26.0indirect
Gogithub.com/go-openapi/swag/netutilsv0.26.0indirect
Gogithub.com/go-openapi/swag/stringutilsv0.26.0indirect
Gogithub.com/go-openapi/swag/typeutilsv0.26.0indirect
Gogithub.com/go-openapi/swag/yamlutilsv0.26.0indirect
Gogithub.com/go-task/slim-sprig/v3v3.0.0indirect
Gogithub.com/golang-jwt/jwt/v5v5.3.1indirect
Gogithub.com/google/gnostic-modelsv0.7.1indirect
Gogithub.com/google/pprofv0.0.0-20260507013755-92041b743c96indirect
Gogithub.com/gorilla/websocketv1.5.4-0.20250319132907-e064f32e3674indirect
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0indirect
Gogithub.com/inconshreveable/mousetrapv1.1.0indirect
Gogithub.com/influxdata/tdigestv0.0.1indirect
Gogithub.com/josharian/internv1.0.0indirect
Gogithub.com/json-iterator/gov1.1.12indirect
Gogithub.com/jstemmer/go-junit-reportv1.0.0indirect
Gogithub.com/mailru/easyjsonv0.9.2indirect
Gogithub.com/masterminds/semver/v3v3.5.0indirect
Gogithub.com/maxbrunsfeld/counterfeiter/v6v6.12.2indirect
Gogithub.com/miekg/dnsv1.1.72indirect
Gogithub.com/moby/spdystreamv0.5.1indirect
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirect
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31eeindirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/nginxinc/nginx-go-crossplanev0.4.89indirect
Gogithub.com/planetscale/vtprotobufv0.6.1-0.20240319094008-0393e58bdf10indirect
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirect
Gogithub.com/prometheus/client_modelv0.6.2indirect
Gogithub.com/prometheus/commonv0.69.0indirect
Gogithub.com/prometheus/commonv0.70.0indirect
Gogithub.com/prometheus/procfsv0.20.1indirect
Gogithub.com/prometheus/procfsv0.21.0indirect
Gogithub.com/rs/dnscachev0.0.0-20230804202142-fc85eb664529indirect
Gogithub.com/stretchr/testifyv1.11.1indirect
Gogithub.com/tsenart/vegeta/v12v12.13.0indirect
Gogithub.com/x448/float16v0.8.4indirect
Gogo.opentelemetry.io/auto/sdkv1.2.1indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0indirect
Gogo.opentelemetry.io/otel/metricv1.44.0indirect
Gogo.opentelemetry.io/otel/sdkv1.44.0indirect
Gogo.opentelemetry.io/otel/tracev1.44.0indirect
Gogo.opentelemetry.io/proto/otlpv1.10.0indirect
Gogo.uber.org/multierrv1.11.0indirect
Gogo.yaml.in/yaml/v2v2.4.4indirect
Gogo.yaml.in/yaml/v3v3.0.4indirect
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90indirect
Gogolang.org/x/modv0.24.0indirect
Gogolang.org/x/modv0.37.0indirect
Gogolang.org/x/netv0.56.0indirect
Gogolang.org/x/netv0.57.0indirect
Gogolang.org/x/oauth2v0.36.0indirect
Gogolang.org/x/syncv0.13.0indirect
Gogolang.org/x/syncv0.22.0indirect
Gogolang.org/x/sysv0.46.0indirect
Gogolang.org/x/sysv0.47.0indirect
Gogolang.org/x/termv0.44.0indirect
Gogolang.org/x/termv0.45.0indirect
Gogolang.org/x/timev0.15.0indirect
Gogolang.org/x/toolsv0.32.0indirect
Gogolang.org/x/toolsv0.47.0indirect
Gogomodules.xyz/jsonpatch/v2v2.5.0indirect
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaaindirect
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260526163538-3dc84a4a5aaaindirect
Gogopkg.in/inf.v0v0.9.1indirect
Gogopkg.in/yaml.v3v3.0.1indirect
Gok8s.io/kube-openapiv0.0.0-20260520065146-aa012df4f4afindirect
Gok8s.io/streamingv0.36.2indirect
Gok8s.io/utilsv0.0.0-20260507154919-ff6756f316d2indirect
Gosigs.k8s.io/gateway-api/conformancev1.6.1indirect
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730indirect
Gosigs.k8s.io/randfillv1.0.0indirect
Gosigs.k8s.io/structured-merge-diff/v6v6.4.0indirect
Gosigs.k8s.io/structured-merge-diff/v6v6.4.2indirect
Gosigs.k8s.io/yamlv1.6.0indirect
npm@babel/helper-string-parser7.29.7indirect
npm@babel/helper-validator-identifier7.29.7indirect
npm@babel/parser7.29.7indirect
npm@babel/types7.29.7indirect
npm@bcoe/v8-coverage1.0.2indirect
npm@emnapi/core1.11.1indirect
npm@emnapi/runtime1.11.1indirect
npm@emnapi/wasi-threads1.2.2indirect
npm@jridgewell/resolve-uri3.1.2indirect
npm@jridgewell/sourcemap-codec1.5.5indirect
npm@jridgewell/trace-mapping0.3.31indirect
npm@napi-rs/wasm-runtime1.1.6indirect
npm@oxc-project/types0.139.0indirect
npm@rolldown/binding-android-arm641.1.5indirect
npm@rolldown/binding-darwin-arm641.1.5indirect
npm@rolldown/binding-darwin-x641.1.5indirect
npm@rolldown/binding-freebsd-x641.1.5indirect
npm@rolldown/binding-linux-arm-gnueabihf1.1.5indirect
npm@rolldown/binding-linux-arm64-gnu1.1.5indirect
npm@rolldown/binding-linux-arm64-musl1.1.5indirect
npm@rolldown/binding-linux-ppc64-gnu1.1.5indirect
npm@rolldown/binding-linux-s390x-gnu1.1.5indirect
npm@rolldown/binding-linux-x64-gnu1.1.5indirect
npm@rolldown/binding-linux-x64-musl1.1.5indirect
npm@rolldown/binding-openharmony-arm641.1.5indirect
npm@rolldown/binding-wasm32-wasi1.1.5indirect
npm@rolldown/binding-win32-arm64-msvc1.1.5indirect
npm@rolldown/binding-win32-x64-msvc1.1.5indirect
npm@rolldown/pluginutils1.0.1indirect
npm@standard-schema/spec1.1.0indirect
npm@tybys/wasm-util0.10.3indirect
npm@types/chai5.2.3indirect
npm@types/deep-eql4.0.2indirect
npm@types/estree1.0.9indirect
npm@vitest/coverage-v84.1.10indirect
npm@vitest/expect4.1.10indirect
npm@vitest/mocker4.1.10indirect
npm@vitest/pretty-format4.1.10indirect
npm@vitest/runner4.1.10indirect
npm@vitest/snapshot4.1.10indirect
npm@vitest/spy4.1.10indirect
npm@vitest/utils4.1.10indirect
npmassertion-error2.0.1indirect
npmast-v8-to-istanbul1.0.5indirect
npmchai6.2.2indirect
npmconvert-source-map2.0.0indirect
npmdetect-libc2.1.2indirect
npmes-module-lexer2.3.1indirect
npmesm3.2.25indirect
npmestree-walker3.0.3indirect
npmexpect-type1.4.0indirect
npmfdir6.5.0indirect
npmfsevents2.3.3indirect
npmhas-flag4.0.0indirect
npmhtml-escaper2.0.2indirect
npmistanbul-lib-coverage3.2.2indirect
npmistanbul-lib-report3.0.1indirect
npmistanbul-reports3.2.0indirect
npmjs-tokens10.0.0indirect
npmlightningcss1.33.0indirect
npmlightningcss-android-arm641.33.0indirect
npmlightningcss-darwin-arm641.33.0indirect
npmlightningcss-darwin-x641.33.0indirect
npmlightningcss-freebsd-x641.33.0indirect
npmlightningcss-linux-arm-gnueabihf1.33.0indirect
npmlightningcss-linux-arm64-gnu1.33.0indirect
npmlightningcss-linux-arm64-musl1.33.0indirect
npmlightningcss-linux-x64-gnu1.33.0indirect
npmlightningcss-linux-x64-musl1.33.0indirect
npmlightningcss-win32-arm64-msvc1.33.0indirect
npmlightningcss-win32-x64-msvc1.33.0indirect
npmmagic-string0.30.21indirect
npmmagicast0.5.3indirect
npmmake-dir4.0.0indirect
npmnanoid3.3.16indirect
npmobug2.1.4indirect
npmpathe2.0.3indirect
npmpicocolors1.1.1indirect
npmpicomatch4.0.5indirect
npmpostcss8.5.20indirect
npmprettier3.9.5indirect
npmrolldown1.1.5indirect
npmsemver7.8.5indirect
npmsiginfo2.0.0indirect
npmsource-map-js1.2.1indirect
npmstackback0.0.2indirect
npmstd-env4.2.0indirect
npmsupports-color7.2.0indirect
npmtinybench2.9.0indirect
npmtinyexec1.2.4indirect
npmtinyglobby0.2.17indirect
npmtinyrainbow3.1.0indirect
npmtslib2.8.1indirect
npmvite8.1.5indirect
npmvitest4.1.10indirect
npmwhy-is-node-running2.3.0indirect
Dependency advisories 0

This repository publishes no package the index resolves, so its own dependency graph was assessed — 237 packages, which also include development and test pins that never ship: 0 carry known advisories, of which 0 are direct.

No known advisories affect the assessed dependencies.

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "kubernetes",
        "gateway-api",
        "k8s",
        "nginx"
      ],
      "is_fork": false,
      "size_kb": 66010,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 6130266,
        "Shell": 48272,
        "Gnuplot": 1790,
        "Makefile": 47336,
        "Dockerfile": 5954,
        "JavaScript": 29268,
        "TypeScript": 161,
        "Go Template": 9238
      },
      "pushed_at": "2026-07-22T14:12:44Z",
      "created_at": "2021-10-22T17:59:15Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T13:15:06Z",
      "description": "NGINX Gateway Fabric provides an implementation for the Gateway API using NGINX as the data plane.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://nginx.org/",
      "name": "nginx",
      "type": "Organization",
      "login": "nginx",
      "company": null,
      "location": null,
      "followers": 2106,
      "avatar_url": "https://avatars.githubusercontent.com/u/1412239?v=4",
      "created_at": "2012-02-06T10:50:45Z",
      "is_verified": null,
      "public_repos": 61,
      "account_age_days": 5280
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.6.7",
          "kind": "patch",
          "published_at": "2026-07-15T21:27:36Z"
        },
        {
          "tag": "v2.6.6",
          "kind": "patch",
          "published_at": "2026-06-26T20:49:14Z"
        },
        {
          "tag": "v2.6.5",
          "kind": "patch",
          "published_at": "2026-06-17T23:20:54Z"
        },
        {
          "tag": "v2.6.4",
          "kind": "patch",
          "published_at": "2026-06-17T14:04:00Z"
        },
        {
          "tag": "v2.6.3",
          "kind": "patch",
          "published_at": "2026-05-29T16:16:17Z"
        },
        {
          "tag": "v2.6.2",
          "kind": "patch",
          "published_at": "2026-05-22T20:05:59Z"
        },
        {
          "tag": "v2.6.1",
          "kind": "patch",
          "published_at": "2026-05-20T19:19:16Z"
        },
        {
          "tag": "v2.6.0",
          "kind": "minor",
          "published_at": "2026-05-07T12:46:33Z"
        },
        {
          "tag": "v2.5.1",
          "kind": "patch",
          "published_at": "2026-04-08T15:35:24Z"
        },
        {
          "tag": "v2.5.0",
          "kind": "minor",
          "published_at": "2026-03-30T17:08:25Z"
        },
        {
          "tag": "v2.4.2",
          "kind": "patch",
          "published_at": "2026-02-18T20:21:39Z"
        },
        {
          "tag": "v2.4.1",
          "kind": "patch",
          "published_at": "2026-02-06T18:03:14Z"
        },
        {
          "tag": "v2.4.0",
          "kind": "minor",
          "published_at": "2026-01-29T17:39:05Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2025-12-18T15:02:42Z"
        },
        {
          "tag": "v2.2.2",
          "kind": "patch",
          "published_at": "2025-12-10T19:55:21Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2025-11-13T17:45:40Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2025-10-22T19:16:43Z"
        },
        {
          "tag": "v2.1.4",
          "kind": "patch",
          "published_at": "2025-10-01T22:32:23Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2025-10-01T18:47:42Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2025-09-25T19:39:41Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2025-09-03T16:46:34Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2025-08-14T19:47:35Z"
        },
        {
          "tag": "v2.0.2",
          "kind": "patch",
          "published_at": "2025-07-08T17:06:27Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2025-06-12T00:40:27Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2025-06-05T16:20:25Z"
        },
        {
          "tag": "v1.6.2",
          "kind": "patch",
          "published_at": "2025-03-11T17:45:00Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2025-02-07T00:08:10Z"
        },
        {
          "tag": "v1.6.0",
          "kind": "minor",
          "published_at": "2025-01-15T19:46:25Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2024-12-16T20:59:38Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2024-11-20T20:53:23Z"
        },
        {
          "tag": "v1.4.0",
          "kind": "minor",
          "published_at": "2024-08-20T18:31:49Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2024-06-11T16:53:23Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2024-03-21T15:46:46Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2023-12-14T20:01:21Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2023-10-24T18:38:58Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2023-08-31T16:32:31Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2023-07-17T17:43:58Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2023-07-06T18:48:12Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2023-04-24T19:00:21Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2022-10-25T16:38:58Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2022-08-22T20:25:09Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "8e8b1c61661e68423c37d18f8986543cc1dd6b61",
          "body": "…1.19.2 (#5618)\n\n| datasource  | package                                        | from   | to     |\n| ----------- | ---------------------------------------------- | ------ | ------ |\n| github-tags | redhat-openshift-ecosystem/openshift-preflight | 1.19.1 | 1.19.2 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency redhat-openshift-ecosystem/openshift-preflight to v…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-21T22:17:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a58ceed9297ebfe387effcf4c3efbd359d72bf2c",
          "body": "| datasource  | package                  | from   | to     |\n| ----------- | ------------------------ | ------ | ------ |\n| github-tags | rbubley/mirrors-prettier | v3.9.5 | v3.9.6 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pre-commit hook rbubley/mirrors-prettier to v3.9.6 (#5622)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-21T20:06:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d0a59efc7cfd96e5fce3f17fb803a510e119e44",
          "body": "| datasource  | package          | from   | to     |\n| ----------- | ---------------- | ------ | ------ |\n| github-tags | actions/checkout | v7.0.0 | v7.0.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/checkout action to v7.0.1 (#5617)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-21T18:18:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fc2e01d0815105fd09bfebaecb6e4754795e329",
          "body": "| datasource  | package         | from   | to     |\n| ----------- | --------------- | ------ | ------ |\n| github-tags | actions/labeler | v6.2.0 | v7.0.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/labeler action to v7 (#5621)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-21T16:08:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46e65354002872c217dd6d2caa2a572c2e115416",
          "body": "Problem: We currently do not inherit the default KeepAlive setting from NGINX.\n\nSolution: Remove static KeepAlive setting of 16 and inherit the default of 32. Also ensure a connection value of 0 disables the KeepAlive",
          "is_bot": false,
          "headline": "Update default upstream keepalive value to NGINX default (#5592)",
          "author_name": "Morgan-P-04",
          "author_login": "Morgan-P-04",
          "committed_at": "2026-07-21T09:11:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30363b80adaee93ee71c275c21d4e37ba9c0507e",
          "body": "Problem: Several edge cases in the route and policy graph could cause\npanics, silent misconfigurations, or overly broad invalidation of\nroutes:\n- NGF could panic when generating NGINX resource names for gateways or\n  listeners with very long names.\n- NGF could panic when processing routes if their t\n[…]\n input validation and boundary checks across route\nattachment, gRPC match conversion, BackendTLSPolicy resolution, OIDC\nfilter validation, and NGINX resource name generation.\nunit tests for each case.",
          "is_bot": false,
          "headline": "Fix route and policy attachment edge cases (#5599)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-20T23:09:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67ebefafdd05d7abdd6151d2fc4b9ef795ccc285",
          "body": "Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#5615)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T22:00:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1829f1d8ff9c3a06657d18a13c5147715041d8cf",
          "body": "| datasource | package                 | from    | to      |\n| ---------- | ----------------------- | ------- | ------- |\n| helm       | opentelemetry-collector | 0.164.1 | 0.165.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update Helm release opentelemetry-collector to v0.165.0 (#5613)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T21:16:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "202afcbf44f9ab9fd62a47ab8ad3ca2d56a7b80a",
          "body": "| datasource | package  | from  | to    |\n| ---------- | -------- | ----- | ----- |\n| npm        | prettier | 3.9.4 | 3.9.5 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency prettier to v3.9.5 (#5610)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T20:13:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40248b51ece4bc6d88185af5c31546d4cc324dde",
          "body": "| datasource  | package              | from   | to     |\n| ----------- | -------------------- | ------ | ------ |\n| github-tags | actions/setup-python | v6.3.0 | v7.0.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/setup-python action to v7 (#5614)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T17:27:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9faa15ee37c3cbea801a16bc9849b374637acdc5",
          "body": "With the release of Gateway API 1.6, we can update our support for TCPRoute and UDPRoute from v1alpha2 to v1.",
          "is_bot": false,
          "headline": "Support v1 TCPRoute and UDPRoute (#5604)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-20T16:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0d7b64290cb0d9a088d11eb34a1141dcbc73c71",
          "body": "| datasource  | package              | from    | to      |\n| ----------- | -------------------- | ------- | ------- |\n| github-tags | github/codeql-action | v4.36.3 | v4.37.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update github/codeql-action action to v4.37.1 (#5612)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T16:26:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83af17830a15e9df2f408270b0ee58e627b38c0a",
          "body": "…b9dd8 (#5606)\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update ghcr.io/nginx/dependencies/nginx-ubi:ubi10 Docker digest to 81…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-20T15:44:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddc84efe2288b9c086a519dc86a6341718a593c6",
          "body": null,
          "is_bot": false,
          "headline": "feat: add useClusterIP to NginxProxy (#5557)",
          "author_name": "Sidharath Bansal",
          "author_login": "SidharathBansal",
          "committed_at": "2026-07-20T14:55:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7cb2ab6625ff63ec0233e9de8fe54802f6d7fc8",
          "body": "| datasource  | package                             | from    | to      |\n| ----------- | ----------------------------------- | ------- | ------- |\n| github-tags | DavidAnson/markdownlint-cli2-action | v24.0.0 | v24.1.0 |\n| github-tags | reviewdog/action-yamllint           | v1.22.0 | v1.23.0 |\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update GitHub Actions (#5572)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-19T14:55:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1ea5cb4ea903080ed28867c176b3d3be6df3a26",
          "body": "| datasource | package                       | from   | to     |\n| ---------- | ----------------------------- | ------ | ------ |\n| go         | github.com/dlclark/regexp2/v2 | v2.5.0 | v2.5.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/dlclark/regexp2/v2 to v2.5.1 (#5594)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-17T19:22:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40bf49e8bd1a7a3c5b47ceec743d6fb23bc0292c",
          "body": "With the recent Gateway API release, some CRD changes require k8s v1.32 or higher. Bumping our supported minimum from 1.31 to 1.32.",
          "is_bot": false,
          "headline": "Update min k8s version to 1.32 (#5602)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-17T18:43:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8835b86c8b618d0dc35c62a885d1eaf3e84ce226",
          "body": "| datasource  | package                      | from    | to      |\n| ----------- | ---------------------------- | ------- | ------- |\n| github-tags | DavidAnson/markdownlint-cli2 | v0.23.0 | v0.23.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pre-commit hook DavidAnson/markdownlint-cli2 to v0.23.1 (#5595)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-17T18:04:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4cf01becab8808fa8d9857fcb0d596efc152c4c0",
          "body": "Problem: Gateway with invalid parametersRef reports Accepted=True, failing the GatewayInvalidParametersRef conformance test. The Gateway API spec requires Accepted=False with reason InvalidParameters when the parametersRef refers to an unsupported kind or non-existent resource.\n\nAdditionally, if a U\n[…]\n spec. The Gateway remains Valid in the graph so the data plane config is not torn down, but the status now correctly reports the Gateway as not accepted.\n\nOmit 0.00 weights from stream split_clients.",
          "is_bot": false,
          "headline": "Update GatewayInvalidParametersRef condition; fix UDP weighting (#5601)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-17T17:28:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e0736f7c9d77a2b9a5b3e33cb6305c86cd5eb8e",
          "body": "…593)\n\n| datasource | package                                 | from     | to       |\n| ---------- | --------------------------------------- | -------- | -------- |\n| go         | github.com/aws/aws-sdk-go-v2/service/s3 | v1.105.1 | v1.105.2 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/s3 to v1.105.2 (#5…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-17T16:28:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b98d518fb6940ea76d33cc478988a4dd4c4d093",
          "body": null,
          "is_bot": false,
          "headline": "Update Gateway API dependencies for 1.6.1",
          "author_name": "Shaun",
          "author_login": "shaun-nx",
          "committed_at": "2026-07-17T15:37:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b5056a494f1d0df2e5486ec4034b9cd36ccc448",
          "body": "| datasource | package                                  | from   | to     |\n| ---------- | ---------------------------------------- | ------ | ------ |\n| go         | github.com/nginx/nginx-gateway-fabric/v2 | v2.6.6 | v2.6.7 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/nginx/nginx-gateway-fabric/v2 to v2.6.7 (#5588)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-16T19:36:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf0d513d89ee390e105770d62f317162035b659e",
          "body": "| datasource  | package          | from   | to     |\n| ----------- | ---------------- | ------ | ------ |\n| github-tags | actions/setup-go | v6.5.0 | v7.0.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/setup-go action to v7 (#5590)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-16T18:23:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c028b055b84a1816669b8e73b0c6aebf8c947eb0",
          "body": "Problem: The GatewayStaticAddress conformance test intermittently fails due to two issues:\n\n    When a Gateway gains IP addresses, the provisioner sets spec.loadBalancerClass on the Service. Kubernetes marks this field as immutable, so the subsequent CreateOrUpdate fails with an Invalid error that r\n[…]\nsts and clean it up in cleanup-conformance-tests, removing a manual step from the conformance test workflow. Removed a skip from a graceful recovery test for NGINX Plus that appears to be passing now.",
          "is_bot": false,
          "headline": "Fix GatewayStaticAddress test failure and provisioning bug (#5576)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-16T17:55:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7c60743eaf8eccb49f2be3a2c7fc23c5f754cfc",
          "body": "| datasource | package                | from    | to      |\n| ---------- | ---------------------- | ------- | ------- |\n| go         | google.golang.org/grpc | v1.82.0 | v1.82.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module google.golang.org/grpc to v1.82.1 (#5589)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-16T16:07:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "efb993c29e45d5445f9447250ae1c59f9ba7baf5",
          "body": null,
          "is_bot": false,
          "headline": "Fix indentation in YAML files causing pipeline errors (#5578)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-16T14:11:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf2a485452b3a921e53134ad0403b72567636d5c",
          "body": null,
          "is_bot": false,
          "headline": "Update docs for release 2.6.7 (#5584)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-15T23:43:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c889ea5199ab4d8e8891ff70509b770b76cc1b2",
          "body": null,
          "is_bot": false,
          "headline": "Generate operator bundle for v1.4.7 (#5585)",
          "author_name": "nginx-bot",
          "author_login": "nginx-bot",
          "committed_at": "2026-07-15T22:38:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "417879c38683a158ee1b1f45cc852eb56e0a00ca",
          "body": "Add operator version to manual steps in release process.",
          "is_bot": false,
          "headline": "Add operator version to manual steps in release process (#5527)",
          "author_name": "bjee19",
          "author_login": "bjee19",
          "committed_at": "2026-07-15T21:36:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f937033796ef7c51c301901c4eea1fcd0fc52207",
          "body": "| datasource | package                                  | from     | to       |\n| ---------- | ---------------------------------------- | -------- | -------- |\n| go         | github.com/aws/aws-sdk-go-v2/config      | v1.32.29 | v1.32.30 |\n| go         | github.com/aws/aws-sdk-go-v2/credentials | v1\n[…]\no-v2/service/s3  | v1.105.0 | v1.105.1 |\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update aws-sdk-go-v2 monorepo (#5571)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-15T20:44:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b12a93ee87d509eea0ecd371103c2a4da6c6576",
          "body": null,
          "is_bot": false,
          "headline": "Update NGINX OSS to 1.31.3 (#5580)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-15T20:13:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e427fbbc1ef29e77816cc4e8b2683ebf3e9942ac",
          "body": "| datasource  | package            | from   | to     |\n| ----------- | ------------------ | ------ | ------ |\n| github-tags | actions/setup-node | v6.4.0 | v7.0.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/setup-node action to v7 (#5573)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-15T19:27:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ba79b0b496eb7b37c0a8bcc6e6f3a3a22177145",
          "body": "Problem: The test UseClusterIP is enabled for an UpstreamSettingsPolicy fails when running with NGINX Plus.\n\nSolution: Check for Cluster IP value and server directive in the NGINX Plus state file.",
          "is_bot": false,
          "headline": "Fix failing test for `UseClusterIP` (#5579)",
          "author_name": "Shaun",
          "author_login": "shaun-nx",
          "committed_at": "2026-07-15T18:59:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f79877f3b0abebd33ccda280a3a8a906fae5359",
          "body": "Problem:\nThe _helpers.tpl file references .Values.nameOverride and .Values.fullnameOverride in the nginx-gateway.name and nginx-gateway.fullname helper templates, but these values are not defined in values.yaml or values.schema.json. This makes them undiscoverable for users who want to customize release naming.\n\nSolution:\nAdded nameOverride and fullnameOverride entries to both values.yaml and values.schema.json.",
          "is_bot": false,
          "headline": "helm: add missing nameOverride/fullnameOverride (#5383)",
          "author_name": "Aldi Jayadi",
          "author_login": "Alja9",
          "committed_at": "2026-07-15T15:34:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b12fef6b5529463efcf3e1656ef5ff31eeb0151b",
          "body": "Problem: The Helm chart's gateways[] values did not expose the Gateway API\nallowedListeners field, so users could not restrict which namespaces are\nallowed to attach Listeners to a Gateway created via the chart.\n\nSolution: Render spec.allowedListeners in the Gateway template using the\nexisting with + toYaml | nindent pattern (identical to how\ninfrastructure, addresses, and tls are already handled), and document the\nfield in the commented Gateway example in values.yaml.",
          "is_bot": false,
          "headline": "Support allowedListeners field in Gateway Helm values (#5553)",
          "author_name": "sgavrylenko",
          "author_login": "sgavrylenko",
          "committed_at": "2026-07-14T20:34:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bad059edec7ce23a4754669a8993d79b8b86329",
          "body": "Problem: NGINX Gateway Fabric routes traffic directly to Pod IPs via EndpointSlice resolution. This bypasses the Service ClusterIP, which breaks service mesh features (Linkerd, Istio mTLS/traffic policies) and F5 BIG-IP/CIS integration patterns that require traffic to flow through the Service VIP.\n\n\n[…]\n: Added a useClusterIP field to UpstreamSettingsPolicy. When set to true, NGINX uses a single upstream server at <Service.ClusterIP>:<port> instead of resolving individual Pod IPs from EndpointSlices.",
          "is_bot": false,
          "headline": "feat: add UseClusterIP to UpstreamSettingsPolicy (#5280)",
          "author_name": "Michael",
          "author_login": "oyiz-michael",
          "committed_at": "2026-07-13T21:09:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e2fb648f863b412a0a7a0ceda1efe927d0c34a36",
          "body": null,
          "is_bot": false,
          "headline": "Update operator commit for CVE fixes (#5567)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-13T17:49:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf09b0629ff6371f4460de6199f81c816449363",
          "body": "Once again attempting to fix drafts not being published when releasing, now that the import hopefully has the proper fix.",
          "is_bot": false,
          "headline": "Add draft release context (again) (#5568)",
          "author_name": "Saylor Berman",
          "author_login": "sjberman",
          "committed_at": "2026-07-13T17:22:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddccbc62d27f3d21ff44cfb007b101a4ab3ec615",
          "body": "| datasource | package                       | from   | to     |\n| ---------- | ----------------------------- | ------ | ------ |\n| go         | github.com/dlclark/regexp2/v2 | v2.2.2 | v2.3.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/dlclark/regexp2/v2 to v2.3.0 (#5566)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-13T16:51:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6f44f5f2e08012b6d45fabdb032cc99293cafcf",
          "body": "…557f5 (#5565)\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update ghcr.io/nginx/dependencies/nginx-ubi:ubi10 Docker digest to 0d…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-13T16:14:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05d0a5215ec0b3f97965f7704afe85667c3e823c",
          "body": "| datasource | package                      | from    | to      |\n| ---------- | ---------------------------- | ------- | ------- |\n| go         | github.com/prometheus/common | v0.69.0 | v0.70.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/prometheus/common to v0.70.0 (#5564)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-13T15:13:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee8f2fd8047cc9cb6ec40e18711fc2a5b2c2f0d3",
          "body": "| datasource  | package                  | from   | to     |\n| ----------- | ------------------------ | ------ | ------ |\n| github-tags | rbubley/mirrors-prettier | v3.9.4 | v3.9.5 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pre-commit hook rbubley/mirrors-prettier to v3.9.5 (#5563)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-13T14:42:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccac63bf6dacc521ebd39bd89c02689177181d67",
          "body": "| datasource | package           | from    | to      |\n| ---------- | ----------------- | ------- | ------- |\n| go         | golang.org/x/text | v0.38.0 | v0.39.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module golang.org/x/text to v0.39.0 (#5552)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-10T20:58:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f3f04fb8644fa1c9b561845cd054f813a6657b1",
          "body": "| datasource  | package         | from   | to     |\n| ----------- | --------------- | ------ | ------ |\n| github-tags | actions/labeler | v6.1.0 | v6.2.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/labeler action to v6.2.0 (#5559)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-10T03:25:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6713a7f372d3ca859e3c201267d57fe13b857d73",
          "body": "| datasource | package                 | from    | to      |\n| ---------- | ----------------------- | ------- | ------- |\n| helm       | opentelemetry-collector | 0.153.0 | 0.162.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update Helm release opentelemetry-collector to v0.162.0 (#5547)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T23:04:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bed78c2fc1147472cb8f64b9cdbb6bbdf2449b17",
          "body": "…1.6 (#5556)\n\nProblem: The idleTimeout field is removed from the sessionPersistence spec on the HTTPRoute in Gateway API version v1.6.0. This is causing some conformance tests to fail.\n\nSolution: Remove idleTimeout field from sessionPersistence spec on HTTPRoutes.",
          "is_bot": false,
          "headline": "Remove idle timeout to ensure seamless integration with Gateway API v…",
          "author_name": "Saloni Choudhary",
          "author_login": "salonichf5",
          "committed_at": "2026-07-09T22:35:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83463874974dca8076b615f26ac2f905955f7622",
          "body": "| datasource | package                                  | from     | to       |\n| ---------- | ---------------------------------------- | -------- | -------- |\n| go         | github.com/aws/aws-sdk-go-v2/config      | v1.32.28 | v1.32.29 |\n| go         | github.com/aws/aws-sdk-go-v2/credentials | v1.19.27 | v1.19.28 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update aws-sdk-go-v2 monorepo (#5558)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T19:09:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcf30b2857e38fc1637de08210bb1616a3c6eb6f",
          "body": "| datasource | package                   | from | to   |\n| ---------- | ------------------------- | ---- | ---- |\n| docker     | quay.io/keycloak/keycloak | 26.6 | 26.7 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update quay.io/keycloak/keycloak Docker tag to v26.7 (#5560)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T18:41:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdae5685a569456e8fdeeac528463801a3ec9a51",
          "body": "Introduces the design document for GatewayLink feature.",
          "is_bot": false,
          "headline": "Design document for GatewayLink (#5497)",
          "author_name": "Saloni Choudhary",
          "author_login": "salonichf5",
          "committed_at": "2026-07-09T18:13:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eea34d4374321ca23ed147a11b73d19662c3dd67",
          "body": "…1948b (#5535)\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update ghcr.io/nginx/dependencies/nginx-ubi:ubi10 Docker digest to a2…",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T12:38:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c77dd06cb6e46719c2ca81016066099b7e8eca59",
          "body": "| datasource  | package                      | from    | to      |\n| ----------- | ---------------------------- | ------- | ------- |\n| github-tags | DavidAnson/markdownlint-cli2 | v0.22.1 | v0.23.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pre-commit hook DavidAnson/markdownlint-cli2 to v0.23.0 (#5542)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-09T12:05:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4836865f89555ac817e74798a21f5989e5e08eba",
          "body": "| datasource  | package                             | from    | to      |\n| ----------- | ----------------------------------- | ------- | ------- |\n| github-tags | DavidAnson/markdownlint-cli2-action | v23.2.0 | v24.0.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update DavidAnson/markdownlint-cli2-action action to v24 (#5543)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T19:15:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "986790547344ea0993c8cf4284215e2a5689de8a",
          "body": "| datasource | package                                  | from     | to       |\n| ---------- | ---------------------------------------- | -------- | -------- |\n| go         | github.com/aws/aws-sdk-go-v2             | v1.42.0  | v1.42.1  |\n| go         | github.com/aws/aws-sdk-go-v2/config      | v1\n[…]\n-v2/credentials | v1.19.24 | v1.19.26 |\n| go         | github.com/aws/aws-sdk-go-v2/service/s3  | v1.104.0 | v1.104.2 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update aws-sdk-go-v2 monorepo (#5536)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T18:45:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "959ee5a835e70fa8d943b619423e8942db3e627c",
          "body": "…ingsPolicy, ObservabilityPolicy, ProxySettingsPolicy, RateLimitPolicy, and SnippetsPolicy (#5392)\n\nProblem: The NGF custom policies do not report a GEP-713 Programmed status condition, so a user cannot tell from a policy's status whether its settings have actually been programmed into the NGINX dat\n[…]\non to ClientSettingsPolicy, UpstreamSettingsPolicy, ObservabilityPolicy, ProxySettingsPolicy, RateLimitPolicy, and SnippetsPolicy in PrepareNGFPolicyRequests, mirroring the existing WAFPolicy handling",
          "is_bot": false,
          "headline": "Add Programmed status condition to ClientSettingsPolicy, UpstreamSett…",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-07-08T13:52:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "38fbd6a2501e2c7948a2ac346e8bb59fdd7d2f9a",
          "body": "| datasource  | package               | from    | to      |\n| ----------- | --------------------- | ------- | ------- |\n| github-tags | goreleaser/goreleaser | v2.16.0 | v2.17.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency goreleaser/goreleaser to v2.17.0 (#5544)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T13:04:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad942a7531a62da14674649a12b9d2668d8496b7",
          "body": "| datasource  | package                    | from   | to     |\n| ----------- | -------------------------- | ------ | ------ |\n| github-tags | docker/build-push-action   | v7.2.0 | v7.3.0 |\n| github-tags | docker/login-action        | v4.2.0 | v4.3.0 |\n| github-tags | docker/metadata-action     | v6.\n[…]\nub-tags | docker/setup-qemu-action   | v4.1.0 | v4.2.0 |\n| github-tags | dorny/paths-filter         | v4.0.1 | v4.0.2 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update GitHub Actions (#5538)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T10:12:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a0fcb8872a13db62d964010435261a815931668",
          "body": "| datasource | package             | from  | to     |\n| ---------- | ------------------- | ----- | ------ |\n| npm        | @vitest/coverage-v8 | 4.1.9 | 4.1.10 |\n| npm        | prettier            | 3.9.3 | 3.9.4  |\n| npm        | vitest              | 4.1.9 | 4.1.10 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update npm dependencies (#5545)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T05:38:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5811b6c721b37fa2ca2e3f12317ba6518fb11c07",
          "body": "| datasource  | package              | from    | to      |\n| ----------- | -------------------- | ------- | ------- |\n| github-tags | github/codeql-action | v4.35.2 | v4.36.3 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update github/codeql-action action to v4.36.3 (#5546)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T03:00:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a2bd538fd1c506409587447f520a7cdb90395f6",
          "body": "Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Lock file maintenance (#5548)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-08T02:32:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3039337fdcc117f1e0993f6a273f8cb0c62d5a57",
          "body": "Problem: When an NginxProxy dnsResolver entry has type: Hostname, the\ncontroller silently drops the value because buildDNSResolver filters\nthrough net.ParseIP. The generated nginx config contains an empty\n`resolver ;` directive, which nginx rejects with \"invalid number of\narguments in \\\"resolver\\\" d\n[…]\nfrom GH-5410 (a cluster-local\nKubernetes service hostname). Verified the new cases fail before the\nfix and pass after.\n\nCloses #5410\n\nCo-authored-by: bjee19 <139261241+bjee19@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Support hostname addresses in NginxProxy dnsResolver (#5531)",
          "author_name": "MaayanZ",
          "author_login": "mzimry",
          "committed_at": "2026-07-06T18:23:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81fd82d121fb285c43e59fe8878b4821c4839811",
          "body": "| datasource | package                | from    | to      |\n| ---------- | ---------------------- | ------- | ------- |\n| go         | google.golang.org/grpc | v1.81.1 | v1.82.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module google.golang.org/grpc to v1.82.0 (#5539)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-06T16:54:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bdaf688ee043c8190afc66b2ae80620d30879130",
          "body": "| datasource  | package                             | from    | to      |\n| ----------- | ----------------------------------- | ------- | ------- |\n| github-tags | kubernetes-sigs/cloud-provider-kind | v0.11.0 | v0.11.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency kubernetes-sigs/cloud-provider-kind to v0.11.1 (#5504)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-02T20:53:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d35f6fa7f5779ea6d952a01a163b23a4e8ee790e",
          "body": "Co-authored-by: nginx-bot <integrations@nginx.com>",
          "is_bot": true,
          "headline": "NFR Test Results for NGF version edge (#5533)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-02T18:07:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e8137c67451b6f013d8236e7eb96d1d010aabbc",
          "body": "Problem: InferencePool failclose method wasn't being honored as our nginx map logic was skipping the failure-mode-aware routing and defaulting to backend.UpstreamName.\n\nSolution: Adjust the nginx map logic so if there is no response (or empty) from the EPP, the value is the defaultResult which has t\n[…]\nuests with an empty body to be forwarded to the EPP as the conformance test uses GET requests with empty bodies when sending traffic.\n\nTesting: Updated unit tests and verified the nginx conf manually.",
          "is_bot": false,
          "headline": "Add fix for inference pool failclose (#5494)",
          "author_name": "bjee19",
          "author_login": "bjee19",
          "committed_at": "2026-07-01T22:39:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7fd2c2965f5dba0a97bb69e37fd70d0920e23383",
          "body": "| datasource  | package                              | from   | to     |\n| ----------- | ------------------------------------ | ------ | ------ |\n| github-tags | stefanzweifel/git-auto-commit-action | v7.1.0 | v7.2.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update stefanzweifel/git-auto-commit-action action to v7.2.0 (#5522)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-07-01T19:17:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d4abb0dfd9452d1799ec220a6b759bae66610ee",
          "body": "Problem: Current package dependency update via RUN microdnf update -y && microdnf clean all is erroring because of an image version skew in packages.\n\nSolution: Adding the --refresh and --nobest flags fix this issue. --refresh refreshes the repository metadata to help with resolving packages and --nobest ensures the update doesn't fail if the newest package can't be installed/resolved.\n\nTesting: Pipeline passes.",
          "is_bot": false,
          "headline": "Adjust Operator dockerfile package update command (#5526)",
          "author_name": "bjee19",
          "author_login": "bjee19",
          "committed_at": "2026-07-01T18:49:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "903211b7f256263c546d17dbbc037f7756f492e1",
          "body": "Problem: NGF hardcodes worker_processes auto;, which starts one NGINX worker per\nnode CPU core regardless of the container's CPU limit. On large nodes with small CPU\nlimits this spawns far more workers than intended, driving up per-pod memory and\ncontributing to OOMKills (see #1617). There was no native way to control the worker count.\n\nSolution: Add a workerProcesses field to the NginxProxy API, following the existing\nWorkerConnections precedent.",
          "is_bot": false,
          "headline": "Add configurable workerProcesses to NginxProxy API (#5519)",
          "author_name": "Sidharath Bansal",
          "author_login": "SidharathBansal",
          "committed_at": "2026-06-30T17:57:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e801214dfd83eb6ba3514861ba74cb879ee9417b",
          "body": "Updates main docs for release 2.6.6",
          "is_bot": false,
          "headline": "Update main docs for 2.6.6 (#5518)",
          "author_name": "Saloni Choudhary",
          "author_login": "salonichf5",
          "committed_at": "2026-06-30T16:32:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4290cccf6b8caa99d71c2e027809b7839d06b852",
          "body": "| datasource  | package                  | from   | to     |\n| ----------- | ------------------------ | ------ | ------ |\n| github-tags | rbubley/mirrors-prettier | v3.8.4 | v3.8.5 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update pre-commit hook rbubley/mirrors-prettier to v3.8.5 (#5520)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-30T12:25:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7eb686b8f8d16552fddcd47ec06689a75b4faeae",
          "body": "| datasource | package             | from  | to    |\n| ---------- | ------------------- | ----- | ----- |\n| npm        | @vitest/coverage-v8 | 4.1.5 | 4.1.9 |\n| npm        | prettier            | 3.8.3 | 3.9.1 |\n| npm        | vitest              | 4.1.5 | 4.1.9 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update npm dependencies (#5523)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-29T18:37:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10e3f5d6629e8039ac2f153b1201ad34cda1640c",
          "body": "| datasource | package                                  | from   | to     |\n| ---------- | ---------------------------------------- | ------ | ------ |\n| go         | github.com/nginx/nginx-gateway-fabric/v2 | v2.6.5 | v2.6.6 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/nginx/nginx-gateway-fabric/v2 to v2.6.6 (#5521)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-29T18:07:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5504d0d7de1706d1bda281281fbb0753a7b32806",
          "body": "This automated PR generates the operator bundle for v1.4.6.",
          "is_bot": false,
          "headline": "Generate operator bundle for v1.4.6 (#5515)",
          "author_name": "nginx-bot",
          "author_login": "nginx-bot",
          "committed_at": "2026-06-26T21:58:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "362039eab57bc8627edefda34dce37dcbb2a63ff",
          "body": "When NGF starts the NGINX data-plane Pod, the in-Pod NGINX agent dials the NGF control plane's gRPC server as soon as it can. NGF's connection validator authenticates the bearer token via a TokenReview and then lists Pods for the agent's ServiceAccount, requiring at least one in PodRunning phase. On\n[…]\nnning pods found for service account waf-policy/gateway-nginx-1\"). That terminated the gRPC stream, blocked NGINX config delivery, kept the Pod from becoming Ready, and failed the WAFPolicy BeforeAll.",
          "is_bot": false,
          "headline": "Fix agent startup race condition when waf is enabled (#5512)",
          "author_name": "Ciara Stacke",
          "author_login": "ciarams87",
          "committed_at": "2026-06-26T19:15:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d40397f9d5ea8ed4b4e4653460a078c4835b8e3",
          "body": "* Update NGINX Agent to v3.11.2\n\n| datasource  | package                   | from    | to      |\n| ----------- | ------------------------- | ------- | ------- |\n| go          | github.com/nginx/agent/v3 | v3.11.1 | v3.11.2 |\n| github-tags | nginx/agent               | v3.11.1 | v3.11.2 |\n\n\nSigned-of\n[…]\nned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\nCo-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>\nCo-authored-by: shaun-nx <s.odonovan@f5.com>",
          "is_bot": true,
          "headline": "Update NGINX Agent to v3.11.2 (#5501)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-26T16:47:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "37d436fc7b48ff5e936f0614b1160312da33c415",
          "body": null,
          "is_bot": false,
          "headline": "Bump WAF version to 5.13.2 (#5503)",
          "author_name": "Shaun",
          "author_login": "shaun-nx",
          "committed_at": "2026-06-26T10:32:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ae52680ef920ad09f38c7b14c747ebca3b4a6d1",
          "body": "| datasource | package                       | from   | to     |\n| ---------- | ----------------------------- | ------ | ------ |\n| go         | github.com/dlclark/regexp2/v2 | v2.2.1 | v2.2.2 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update module github.com/dlclark/regexp2/v2 to v2.2.2 (#5457)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-26T09:58:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbb22678b3b87fcba9888e3b33e4b3faa12e5488",
          "body": "…ployment not found errors (#5444)\n\nCo-authored-by: Saloni Choudhary <146118978+salonichf5@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Change gRPC error code from NotFound to Internal for connection or de…",
          "author_name": "Donal Hurley",
          "author_login": "dhurley",
          "committed_at": "2026-06-26T09:30:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0d91f1b003cd75a97a80505a5798ca022da1da7",
          "body": null,
          "is_bot": false,
          "headline": "Add claim validation to OIDC Auth (#5484)",
          "author_name": "Shaun",
          "author_login": "shaun-nx",
          "committed_at": "2026-06-26T08:32:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7648bd569fcc4552ff37c40a08eecd20b4ffc852",
          "body": "| datasource | package         | from   | to     |\n| ---------- | --------------- | ------ | ------ |\n| docker     | curlimages/curl | 8.20.0 | 8.21.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update curlimages/curl Docker tag to v8.21.0 (#5498)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-25T21:22:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af0f08e1ea9fca1882dac87487577819e05d1d2e",
          "body": "| datasource  | package                             | from    | to      |\n| ----------- | ----------------------------------- | ------- | ------- |\n| github-tags | kubernetes-sigs/cloud-provider-kind | v0.10.0 | v0.11.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update dependency kubernetes-sigs/cloud-provider-kind to v0.11.0 (#5499)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-25T18:46:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf4a3477b19a95fd18e8e3f6e9fd953a297150f1",
          "body": "Problem: Parts of the NGINX configuration are generated by ranging over Go maps without sorting, so the output order can change between reconciles even when nothing has changed.\n\nSolution: Emit map-derived configuration in a stable, sorted order, consistent with the existing HTTP upstream builder",
          "is_bot": false,
          "headline": "Sort map-derived NGINX config for deterministic output (#5486)",
          "author_name": "Vignesh Murugan",
          "author_login": "ItsVigneshMurugan",
          "committed_at": "2026-06-25T18:17:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "952913184581450b977285ebd23b5d03095f6a60",
          "body": "… complexity (#5491)\n\nProblem: registerSecretInGatewayConfig carried a //nolint:gocyclo because it duplicated the same five-case named-secret switch across the new-entry and existing-entry branches.\n\nSolution: extract the duplicated named-secret switch into a small assignNamedSecret helper (shared b\n[…]\ninal asymmetry exactly (the new-entry path overwrites the map entry on first match with break; the existing-entry path appends). This is a behavior-preserving refactor that drops the //nolint:gocyclo.",
          "is_bot": false,
          "headline": "refactor: simplify registerSecretInGatewayConfig to reduce cyclomatic…",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-25T17:39:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c592045e645429e8ea82dcbd60f15c2d4cf7489c",
          "body": "| datasource | package                                 | from     | to       |\n| ---------- | --------------------------------------- | -------- | -------- |\n| go         | github.com/aws/aws-sdk-go-v2/service/s3 | v1.103.3 | v1.104.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update aws-sdk-go-v2 monorepo (#5458)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-25T15:42:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b418f1fffb20134fb7967d5e755c31a3026ad29f",
          "body": "Lays out the goals and non goals for Gateway Link feature",
          "is_bot": false,
          "headline": "Provisional design for Gateway Link (#5489)",
          "author_name": "Saloni Choudhary",
          "author_login": "salonichf5",
          "committed_at": "2026-06-25T01:40:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d48ca367cc03958eb378abe1b57a238883e69188",
          "body": "Problem: We want to collect the number of different WAFPolicy types watched by NGF.\n\nSolution: Collect the count of different WAFPolicy types.\n\nTesting: Unit tests and manually verified collection via debug logs.",
          "is_bot": false,
          "headline": "Add telemetry collection of WAF Policy type (#5473)",
          "author_name": "bjee19",
          "author_login": "bjee19",
          "committed_at": "2026-06-25T00:41:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f171979b79114561c87b8608bb42f4c4990ed1e",
          "body": "| datasource | package                        | from    | to      |\n| ---------- | ------------------------------ | ------- | ------- |\n| go         | k8s.io/api                     | v0.36.1 | v0.36.2 |\n| go         | k8s.io/apiextensions-apiserver | v0.36.1 | v0.36.2 |\n| go         | k8s.io/apimachinery            | v0.36.1 | v0.36.2 |\n| go         | k8s.io/client-go               | v0.36.1 | v0.36.2 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update kubernetes monorepo to v0.36.2 (#5447)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-25T00:10:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dace4c52d42427ca3783fc8ff7c744effdd064b2",
          "body": "…5452)\n\nProblem: provisionNginx carries a //nolint:gocyclo directive (#5253).\n\nSolution: decompose it into focused helpers (createOrUpdateNginxResource, nginxProvisionState.track, patchLoadBalancerServiceStatus, restartNginxAfterConfigUpdate). Behavior-preserving — no functional change.",
          "is_bot": false,
          "headline": "refactor: decompose provisionNginx to reduce cyclomatic complexity (#…",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T23:41:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "303d7a79a3ec40365dc7e621bd10703aa0c26fd0",
          "body": "| datasource | package                   | from    | to      |\n| ---------- | ------------------------- | ------- | ------- |\n| go         | github.com/onsi/ginkgo/v2 | v2.30.0 | v2.31.0 |\n| go         | github.com/onsi/gomega    | v1.41.0 | v1.42.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update Testing dependencies (#5460)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T21:42:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f7713a1e612d56e202dc1b77074e4da28380569",
          "body": "…461)\n\nProblem: gatewayExistsForResource carried a //nolint:gocyclo // will refactor at some point marker; its per-resource-type switch pushed cyclomatic complexity over the project's gocyclo threshold of 15.\n\nSolution: Extract the type dispatch into a new (*NginxResources).matchesObject method and \n[…]\n.) { return ... } arm into a direct return resourceMatches(...). As a result gatewayExistsForResource drops to cyclomatic complexity 3 and matchesObject sits at 12, so the //nolint:gocyclo is removed.",
          "is_bot": false,
          "headline": "Refactor gatewayExistsForResource to reduce cyclomatic complexity (#5…",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T21:14:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5459fdc9846e57e36c602ca714fa4674a90a4b61",
          "body": "| datasource | package           | from | to   |\n| ---------- | ----------------- | ---- | ---- |\n| docker     | docker/dockerfile | 1.24 | 1.25 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update docker/dockerfile Docker tag to v1.25 (#5482)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T20:44:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be7039c4988b1ff2960b5d0770641c72f78796f7",
          "body": "Problem: createHTTPFilters (internal/controller/state/dataplane/configuration.go) carries a //nolint:gocyclo. Its single for/switch over filter types pushed cyclomatic complexity to ~24, well past the project min-complexity: 15 gate.\n\nSolution: decompose per-filter-type handling into 8 *HTTPFilters methods (addRequestRedirect / addURLRewrite / addRequestMirror / addRequestHeaderModifier / addResponseHeaderModifier / addExtensionRef / addCORS / addExternalAuth).",
          "is_bot": false,
          "headline": "Refactor createHTTPFilters to remove gocyclo nolint #5480",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T20:15:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c58523c044ee4b046b12cb685202d9e8eb3103fe",
          "body": "| datasource  | package                   | from    | to      |\n| ----------- | ------------------------- | ------- | ------- |\n| github-tags | reviewdog/action-yamllint | v1.21.0 | v1.22.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update GitHub Actions to v1.22.0 (#5487)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T19:47:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28f6b1ab40b36bc0bf4ca9566f9e189b3a876151",
          "body": "| datasource | package      | from    | to      |\n| ---------- | ------------ | ------- | ------- |\n| docker     | kindest/node | v1.35.1 | v1.36.1 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update kindest/node Docker tag to v1.36.1 (#5386)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T19:18:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2f243e6d0fe210682051b065784c7fd0973575a",
          "body": "Problem: bindL7RouteToListeners carries a //nolint:gocyclo directive.\n\nSolution: extract the inline switch ref.Kind parent-ref resolution (which computes the target ListenerSet and skips refs that target a different Gateway or a ListenerSet not owned by this Gateway) into a new resolveAttachmentListenerSet helper.",
          "is_bot": false,
          "headline": "Refactor bindL7RouteToListeners to remove nolint:gocyclo #5455",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T18:49:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d35ed38eddfaade1d9774e4ef3c172ac903df39",
          "body": "| datasource  | package          | from   | to     |\n| ----------- | ---------------- | ------ | ------ |\n| github-tags | actions/checkout | v6.0.3 | v7.0.0 |\n\n\nSigned-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update actions/checkout action to v7 (#5483)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T18:10:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a86fb8031079c4f957f88fc5ced5ea4b0035352",
          "body": "Problem: getResourceVersionForObject carries a //nolint:gocyclo directive (#5253).\n\nSolution: extract a resourceVersionIfNameMatches helper and collapse the eight repetitive ObjectMeta switch cases (Deployment, HPA, PDB, DaemonSet, Service, ServiceAccount, Role, RoleBinding) into single returns.",
          "is_bot": false,
          "headline": "Refactor getResourceVersionForObject to remove nolint:gocyclo #5454",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T17:42:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "387ca850545570df9cd6618b20974b00525e34bf",
          "body": "Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Update Docker digests (#5495)",
          "author_name": "renovate[bot]",
          "author_login": "renovate[bot]",
          "committed_at": "2026-06-24T16:49:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93526a17f8fd4055af7cd4dd79068386e136ace9",
          "body": "Problem: registerResourceInGatewayConfig carries a //nolint:gocyclo directive (#5253).\n\nSolution: extract a getOrCreateNginxResources helper and collapse the eight repetitive ObjectMeta switch cases (Deployment, HPA, PDB, DaemonSet, Service, ServiceAccount, Role, RoleBinding) into single assignments.",
          "is_bot": false,
          "headline": "Refactor registerResourceInGatewayConfig to remove nolint:gocyclo #5453",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T16:17:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c95b367f81e2d625eb31bf8b955be09180e9079",
          "body": "Problem: addBackendRefsToRules carries a //nolint:gocyclo. Its cyclomatic complexity comes from inline backendRef-path selection and a nested InferencePool-resolution block.\n\nSolution: extract backendRefPath (mirror / external-auth path selection) and resolveInferencePoolRef (InferencePool port / EndpointPicker enrichment + invalid-pool skip) as behavior-preserving helpers, and drop the nolint. gocyclo now falls below the min-complexity: 15 gate.",
          "is_bot": false,
          "headline": "Refactor addBackendRefsToRules to remove gocyclo nolint (#5441)",
          "author_name": "somaz",
          "author_login": "somaz94",
          "committed_at": "2026-06-24T15:51:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34f736ec3ad3fc04f65ed7804ed59c1dbfb8e59d",
          "body": "Update the tests go.mod NGF version to 2.6.5.",
          "is_bot": false,
          "headline": "Update ngf test version to 2.6.5 (#5490)",
          "author_name": "bjee19",
          "author_login": "bjee19",
          "committed_at": "2026-06-23T06:44:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 41,
      "commits_last_year": 1028,
      "latest_release_at": "2026-07-15T21:27:36Z",
      "latest_release_tag": "v2.6.7",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 52,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 11.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/nginx/nginx-gateway-fabric/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/nginx/nginx-gateway-fabric/v2",
          "is_deprecated": false,
          "latest_version": "v2.6.7",
          "repository_url": "https://github.com/nginx/nginx-gateway-fabric",
          "versions_count": 25,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-15T21:17:14Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 203,
      "stars": 1128,
      "watchers": 30,
      "fork_history": {
        "days": [
          {
            "date": "2022-04-04",
            "count": 3
          },
          {
            "date": "2022-05-05",
            "count": 1
          },
          {
            "date": "2022-05-20",
            "count": 1
          },
          {
            "date": "2022-07-04",
            "count": 1
          },
          {
            "date": "2022-08-23",
            "count": 2
          },
          {
            "date": "2022-08-26",
            "count": 2
          },
          {
            "date": "2022-08-31",
            "count": 1
          },
          {
            "date": "2022-09-21",
            "count": 1
          },
          {
            "date": "2022-09-22",
            "count": 1
          },
          {
            "date": "2022-10-14",
            "count": 2
          },
          {
            "date": "2022-10-29",
            "count": 2
          },
          {
            "date": "2022-11-13",
            "count": 1
          },
          {
            "date": "2022-11-21",
            "count": 1
          },
          {
            "date": "2023-01-02",
            "count": 2
          },
          {
            "date": "2023-01-20",
            "count": 1
          },
          {
            "date": "2023-03-09",
            "count": 1
          },
          {
            "date": "2023-03-24",
            "count": 1
          },
          {
            "date": "2023-04-05",
            "count": 1
          },
          {
            "date": "2023-04-11",
            "count": 1
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-05-23",
            "count": 1
          },
          {
            "date": "2023-06-05",
            "count": 1
          },
          {
            "date": "2023-06-06",
            "count": 1
          },
          {
            "date": "2023-07-11",
            "count": 1
          },
          {
            "date": "2023-08-02",
            "count": 1
          },
          {
            "date": "2023-08-05",
            "count": 1
          },
          {
            "date": "2023-09-17",
            "count": 1
          },
          {
            "date": "2023-10-09",
            "count": 1
          },
          {
            "date": "2023-10-13",
            "count": 2
          },
          {
            "date": "2023-10-17",
            "count": 1
          },
          {
            "date": "2023-10-25",
            "count": 1
          },
          {
            "date": "2023-11-08",
            "count": 1
          },
          {
            "date": "2023-11-22",
            "count": 1
          },
          {
            "date": "2023-11-26",
            "count": 1
          },
          {
            "date": "2023-11-30",
            "count": 1
          },
          {
            "date": "2023-12-02",
            "count": 2
          },
          {
            "date": "2023-12-13",
            "count": 1
          },
          {
            "date": "2023-12-24",
            "count": 1
          },
          {
            "date": "2023-12-25",
            "count": 1
          },
          {
            "date": "2023-12-27",
            "count": 1
          },
          {
            "date": "2024-02-01",
            "count": 1
          },
          {
            "date": "2024-02-05",
            "count": 1
          },
          {
            "date": "2024-02-09",
            "count": 1
          },
          {
            "date": "2024-02-16",
            "count": 1
          },
          {
            "date": "2024-02-24",
            "count": 1
          },
          {
            "date": "2024-03-04",
            "count": 1
          },
          {
            "date": "2024-03-14",
            "count": 3
          },
          {
            "date": "2024-03-15",
            "count": 1
          },
          {
            "date": "2024-03-17",
            "count": 1
          },
          {
            "date": "2024-03-20",
            "count": 1
          },
          {
            "date": "2024-04-23",
            "count": 1
          },
          {
            "date": "2024-04-29",
            "count": 1
          },
          {
            "date": "2024-05-02",
            "count": 1
          },
          {
            "date": "2024-05-20",
            "count": 1
          },
          {
            "date": "2024-05-23",
            "count": 1
          },
          {
            "date": "2024-06-18",
            "count": 1
          },
          {
            "date": "2024-07-03",
            "count": 1
          },
          {
            "date": "2024-07-04",
            "count": 1
          },
          {
            "date": "2024-07-08",
            "count": 1
          },
          {
            "date": "2024-07-10",
            "count": 2
          },
          {
            "date": "2024-07-11",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-07-19",
            "count": 1
          },
          {
            "date": "2024-07-23",
            "count": 1
          },
          {
            "date": "2024-09-06",
            "count": 1
          },
          {
            "date": "2024-09-17",
            "count": 1
          },
          {
            "date": "2024-09-18",
            "count": 1
          },
          {
            "date": "2024-09-20",
            "count": 1
          },
          {
            "date": "2024-09-21",
            "count": 1
          },
          {
            "date": "2024-10-07",
            "count": 1
          },
          {
            "date": "2024-10-25",
            "count": 1
          },
          {
            "date": "2024-10-28",
            "count": 1
          },
          {
            "date": "2024-11-04",
            "count": 1
          },
          {
            "date": "2024-11-15",
            "count": 1
          },
          {
            "date": "2024-12-16",
            "count": 2
          },
          {
            "date": "2025-01-06",
            "count": 1
          },
          {
            "date": "2025-01-09",
            "count": 1
          },
          {
            "date": "2025-01-23",
            "count": 1
          },
          {
            "date": "2025-01-24",
            "count": 1
          },
          {
            "date": "2025-01-29",
            "count": 1
          },
          {
            "date": "2025-02-11",
            "count": 1
          },
          {
            "date": "2025-02-18",
            "count": 1
          },
          {
            "date": "2025-02-21",
            "count": 1
          },
          {
            "date": "2025-02-27",
            "count": 1
          },
          {
            "date": "2025-02-28",
            "count": 1
          },
          {
            "date": "2025-03-01",
            "count": 1
          },
          {
            "date": "2025-03-13",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-04-06",
            "count": 1
          },
          {
            "date": "2025-04-09",
            "count": 1
          },
          {
            "date": "2025-04-16",
            "count": 1
          },
          {
            "date": "2025-04-24",
            "count": 1
          },
          {
            "date": "2025-05-05",
            "count": 1
          },
          {
            "date": "2025-05-09",
            "count": 1
          },
          {
            "date": "2025-05-21",
            "count": 1
          },
          {
            "date": "2025-05-24",
            "count": 1
          },
          {
            "date": "2025-06-11",
            "count": 3
          },
          {
            "date": "2025-06-13",
            "count": 1
          },
          {
            "date": "2025-06-18",
            "count": 2
          },
          {
            "date": "2025-06-25",
            "count": 1
          },
          {
            "date": "2025-07-03",
            "count": 2
          },
          {
            "date": "2025-07-13",
            "count": 1
          },
          {
            "date": "2025-07-29",
            "count": 1
          },
          {
            "date": "2025-08-05",
            "count": 1
          },
          {
            "date": "2025-08-06",
            "count": 1
          },
          {
            "date": "2025-08-18",
            "count": 1
          },
          {
            "date": "2025-08-19",
            "count": 1
          },
          {
            "date": "2025-08-20",
            "count": 2
          },
          {
            "date": "2025-08-27",
            "count": 1
          },
          {
            "date": "2025-09-06",
            "count": 1
          },
          {
            "date": "2025-10-05",
            "count": 1
          },
          {
            "date": "2025-10-19",
            "count": 1
          },
          {
            "date": "2025-10-21",
            "count": 1
          },
          {
            "date": "2025-10-24",
            "count": 1
          },
          {
            "date": "2025-10-25",
            "count": 1
          },
          {
            "date": "2025-11-06",
            "count": 1
          },
          {
            "date": "2025-11-14",
            "count": 1
          },
          {
            "date": "2025-11-17",
            "count": 1
          },
          {
            "date": "2025-11-24",
            "count": 1
          },
          {
            "date": "2025-11-28",
            "count": 2
          },
          {
            "date": "2025-11-29",
            "count": 2
          },
          {
            "date": "2025-12-04",
            "count": 1
          },
          {
            "date": "2025-12-10",
            "count": 1
          },
          {
            "date": "2025-12-11",
            "count": 1
          },
          {
            "date": "2025-12-16",
            "count": 1
          },
          {
            "date": "2025-12-22",
            "count": 1
          },
          {
            "date": "2025-12-23",
            "count": 1
          },
          {
            "date": "2025-12-27",
            "count": 1
          },
          {
            "date": "2026-01-01",
            "count": 1
          },
          {
            "date": "2026-01-02",
            "count": 1
          },
          {
            "date": "2026-01-04",
            "count": 2
          },
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-01-09",
            "count": 1
          },
          {
            "date": "2026-01-14",
            "count": 1
          },
          {
            "date": "2026-01-21",
            "count": 1
          },
          {
            "date": "2026-01-27",
            "count": 1
          },
          {
            "date": "2026-01-29",
            "count": 1
          },
          {
            "date": "2026-02-02",
            "count": 1
          },
          {
            "date": "2026-02-06",
            "count": 1
          },
          {
            "date": "2026-02-10",
            "count": 1
          },
          {
            "date": "2026-02-12",
            "count": 1
          },
          {
            "date": "2026-02-22",
            "count": 1
          },
          {
            "date": "2026-03-04",
            "count": 1
          },
          {
            "date": "2026-03-08",
            "count": 2
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-04-02",
            "count": 1
          },
          {
            "date": "2026-04-07",
            "count": 1
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-16",
            "count": 1
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          },
          {
            "date": "2026-04-29",
            "count": 1
          },
          {
            "date": "2026-05-04",
            "count": 1
          },
          {
            "date": "2026-05-17",
            "count": 1
          },
          {
            "date": "2026-05-20",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-05-25",
            "count": 1
          },
          {
            "date": "2026-05-26",
            "count": 1
          },
          {
            "date": "2026-06-02",
            "count": 1
          },
          {
            "date": "2026-06-14",
            "count": 2
          },
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 2
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-06-24",
            "count": 2
          },
          {
            "date": "2026-06-25",
            "count": 1
          },
          {
            "date": "2026-06-26",
            "count": 1
          },
          {
            "date": "2026-06-27",
            "count": 1
          },
          {
            "date": "2026-06-29",
            "count": 1
          },
          {
            "date": "2026-07-01",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 2
          }
        ],
        "complete": true,
        "collected": 201,
        "total_forks": 203
      },
      "star_history": null,
      "open_issues_and_prs": 127
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "dev/nginx/Makefile",
        "operators/Makefile",
        "tests/Makefile"
      ],
      "api_schema_files": [
        "examples/grpc-routing/grpc.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "tests/framework/crossplane/go.mod",
        "tests/go.mod"
      ],
      "largest_source_bytes": 344726,
      "source_files_sampled": 467,
      "oversized_source_files": 24,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "tests/go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 237,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.1"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.30"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/credentials",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.29"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/s3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.105.2"
        },
        {
          "name": "github.com/dlclark/regexp2/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.5.1"
        },
        {
          "name": "github.com/envoyproxy/go-control-plane/envoy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.37.0"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.1"
        },
        {
          "name": "github.com/go-logr/logr",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.3"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/nginx/agent/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.11.2"
        },
        {
          "name": "github.com/nginx/telemetry-exporter",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.5"
        },
        {
          "name": "github.com/onsi/ginkgo/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.32.0"
        },
        {
          "name": "github.com/onsi/gomega",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.1"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.23.2"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/pflag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.10"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.28.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.82.1"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.12-0.20260120151049-f2248ac996af"
        },
        {
          "name": "gopkg.in/evanphx/json-patch.v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.13.0"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/apiextensions-apiserver",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/klog/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.140.0"
        },
        {
          "name": "sigs.k8s.io/controller-runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.24.1"
        },
        {
          "name": "sigs.k8s.io/gateway-api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.1"
        },
        {
          "name": "sigs.k8s.io/gateway-api-inference-extension",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": true,
            "version": "v1.42.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": true,
            "version": "v1.32.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": true,
            "version": "v1.19.29",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/s3",
            "direct": true,
            "version": "v1.105.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dlclark/regexp2/v2",
            "direct": true,
            "version": "v2.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/envoyproxy/go-control-plane/envoy",
            "direct": true,
            "version": "v1.37.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": true,
            "version": "v1.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": true,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nginx/agent/v3",
            "direct": true,
            "version": "v3.11.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nginx/telemetry-exporter",
            "direct": true,
            "version": "v0.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/onsi/ginkgo/v2",
            "direct": true,
            "version": "v2.32.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/onsi/gomega",
            "direct": true,
            "version": "v1.42.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": true,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": true,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": true,
            "version": "v1.28.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.82.1",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.12-0.20260120151049-f2248ac996af",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": true,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": true,
            "version": "v2.140.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/controller-runtime",
            "direct": true,
            "version": "v0.24.1",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/gateway-api",
            "direct": true,
            "version": "v1.6.1",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/gateway-api-inference-extension",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
            "direct": false,
            "version": "v1.36.11-20260415201107-50325440f8f2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream",
            "direct": false,
            "version": "v1.7.14",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/checksum",
            "direct": false,
            "version": "v1.9.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/s3shared",
            "direct": false,
            "version": "v1.19.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.32.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.37.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": false,
            "version": "v1.44.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": false,
            "version": "v1.27.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cncf/xds/go",
            "direct": false,
            "version": "v0.0.0-20260202195803-dba9d589def2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/envoyproxy/protoc-gen-validate",
            "direct": false,
            "version": "v1.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/evanphx/json-patch/v5",
            "direct": false,
            "version": "v5.9.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/zapr",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.23.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.21.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/cmdutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/conv",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/fileutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonname",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/loading",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/mangling",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/netutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/stringutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/typeutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/yamlutils",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-task/slim-sprig/v3",
            "direct": false,
            "version": "v3.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": false,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/pprof",
            "direct": false,
            "version": "v0.0.0-20260507013755-92041b743c96",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/websocket",
            "direct": false,
            "version": "v1.5.4-0.20250319132907-e064f32e3674",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/influxdata/tdigest",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jstemmer/go-junit-report",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.9.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masterminds/semver/v3",
            "direct": false,
            "version": "v3.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/maxbrunsfeld/counterfeiter/v6",
            "direct": false,
            "version": "v6.12.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/miekg/dns",
            "direct": false,
            "version": "v1.1.72",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/spdystream",
            "direct": false,
            "version": "v0.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nginxinc/nginx-go-crossplane",
            "direct": false,
            "version": "v0.4.89",
            "ecosystem": "go"
          },
          {
            "name": "github.com/planetscale/vtprotobuf",
            "direct": false,
            "version": "v0.6.1-0.20240319094008-0393e58bdf10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.70.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rs/dnscache",
            "direct": false,
            "version": "v0.0.0-20230804202142-fc85eb664529",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": false,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsenart/vegeta/v12",
            "direct": false,
            "version": "v12.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.4",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260312153236-7ab1446f8b90",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.57.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.13.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.32.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "gomodules.xyz/jsonpatch/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20260520065146-aa012df4f4af",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/streaming",
            "direct": false,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": false,
            "version": "v0.0.0-20260507154919-ff6756f316d2",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/gateway-api/conformance",
            "direct": false,
            "version": "v1.6.1",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.4.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.4.2",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/core",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/wasi-threads",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/wasm-runtime",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@oxc-project/types",
            "direct": false,
            "version": "0.139.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-android-arm64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-arm64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-x64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-freebsd-x64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-musl",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-gnu",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-musl",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-openharmony-arm64",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-wasm32-wasi",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-x64-msvc",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/pluginutils",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@standard-schema/spec",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tybys/wasm-util",
            "direct": false,
            "version": "0.10.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "esm",
            "direct": false,
            "version": "3.2.25",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-android-arm64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-arm64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-x64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-freebsd-x64",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-gnu",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-musl",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-gnu",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-musl",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-arm64-msvc",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-x64-msvc",
            "direct": false,
            "version": "1.33.0",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.16",
            "ecosystem": "npm"
          },
          {
            "name": "obug",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.20",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.9.5",
            "ecosystem": "npm"
          },
          {
            "name": "rolldown",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "8.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "4.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 237,
        "direct_count": 32,
        "indirect_count": 205
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 13,
        "merged_prs": 3493,
        "open_issues": 114,
        "closed_ratio": 0.915,
        "closed_issues": 1222,
        "closed_unmerged_prs": 591
      },
      "bus_factor": 3,
      "bot_contributors": 4,
      "top_contributors": [
        {
          "type": "User",
          "login": "sjberman",
          "commits": 312,
          "avatar_url": "https://avatars.githubusercontent.com/u/8921145?v=4"
        },
        {
          "type": "User",
          "login": "lucacome",
          "commits": 190,
          "avatar_url": "https://avatars.githubusercontent.com/u/603885?v=4"
        },
        {
          "type": "User",
          "login": "ciarams87",
          "commits": 161,
          "avatar_url": "https://avatars.githubusercontent.com/u/18287516?v=4"
        },
        {
          "type": "User",
          "login": "kate-osborn",
          "commits": 116,
          "avatar_url": "https://avatars.githubusercontent.com/u/50597707?v=4"
        },
        {
          "type": "User",
          "login": "bjee19",
          "commits": 115,
          "avatar_url": "https://avatars.githubusercontent.com/u/139261241?v=4"
        },
        {
          "type": "User",
          "login": "pleshakov",
          "commits": 92,
          "avatar_url": "https://avatars.githubusercontent.com/u/2199726?v=4"
        },
        {
          "type": "User",
          "login": "salonichf5",
          "commits": 86,
          "avatar_url": "https://avatars.githubusercontent.com/u/146118978?v=4"
        },
        {
          "type": "User",
          "login": "shaun-nx",
          "commits": 34,
          "avatar_url": "https://avatars.githubusercontent.com/u/100570330?v=4"
        },
        {
          "type": "User",
          "login": "nginx-bot",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/68849795?v=4"
        },
        {
          "type": "User",
          "login": "dhurley",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/3164544?v=4"
        }
      ],
      "contributors_sampled": 72,
      "top_contributor_share": 0.243
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "build.yml",
        "cherry-pick.yml",
        "ci.yml",
        "codeql-analysis.yml",
        "conformance.yml",
        "dependency-review.yml",
        "f5-cla.yml",
        "functional.yml",
        "helm.yml",
        "labeler.yml",
        "lint.yml",
        "longevity-start.yml",
        "longevity-stop.yml",
        "mend.yml",
        "nfr.yml",
        "operator-bundle-pr.yml",
        "redhat-certification.yml",
        "release-pr.yml",
        "renovate-build.yml",
        "scorecards.yml",
        "stale.yml",
        "update-docker-images.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 9 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "8e8b1c61661e68423c37d18f8986543cc1dd6b61",
        "ran_at": "2026-07-22T14:20:49Z",
        "aggregate_score": 8.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T14:05:15Z",
      "oldest_open_prs": [
        {
          "number": 5164,
          "created_at": "2026-04-21T19:11:45Z",
          "last_comment_at": "2026-06-28T03:47:51Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 5466,
          "created_at": "2026-06-17T13:01:23Z",
          "last_comment_at": "2026-07-21T13:51:42Z",
          "last_comment_author": "shaun-nx"
        },
        {
          "number": 5496,
          "created_at": "2026-06-24T14:52:19Z",
          "last_comment_at": "2026-07-22T09:41:28Z",
          "last_comment_author": "shaun-nx"
        },
        {
          "number": 5530,
          "created_at": "2026-07-01T04:16:21Z",
          "last_comment_at": "2026-07-18T14:22:33Z",
          "last_comment_author": "tanayarun"
        },
        {
          "number": 5534,
          "created_at": "2026-07-03T05:34:42Z",
          "last_comment_at": "2026-07-22T09:23:45Z",
          "last_comment_author": "shaun-nx"
        },
        {
          "number": 5581,
          "created_at": "2026-07-15T18:51:21Z",
          "last_comment_at": "2026-07-15T20:00:59Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 5587,
          "created_at": "2026-07-16T01:18:18Z",
          "last_comment_at": "2026-07-20T20:24:41Z",
          "last_comment_author": "salonichf5"
        },
        {
          "number": 5605,
          "created_at": "2026-07-18T08:40:26Z",
          "last_comment_at": "2026-07-18T08:40:36Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 5611,
          "created_at": "2026-07-20T09:10:55Z",
          "last_comment_at": "2026-07-20T09:15:15Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 5619,
          "created_at": "2026-07-21T08:35:02Z",
          "last_comment_at": "2026-07-22T12:31:19Z",
          "last_comment_author": "renovate"
        },
        {
          "number": 5623,
          "created_at": "2026-07-21T15:24:06Z",
          "last_comment_at": "2026-07-21T15:28:25Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 5625,
          "created_at": "2026-07-21T20:29:45Z",
          "last_comment_at": "2026-07-21T21:00:24Z",
          "last_comment_author": "theoilie"
        },
        {
          "number": 5626,
          "created_at": "2026-07-22T14:12:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-21T22:17:26Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 460,
          "created_at": "2023-03-09T21:20:24Z",
          "last_comment_at": "2024-03-14T17:40:33Z",
          "last_comment_author": "bjee19"
        },
        {
          "number": 525,
          "created_at": "2023-04-04T21:54:45Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 564,
          "created_at": "2023-04-05T23:19:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 617,
          "created_at": "2023-05-03T19:40:40Z",
          "last_comment_at": "2024-05-11T02:35:05Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 662,
          "created_at": "2023-05-23T14:36:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 831,
          "created_at": "2023-07-07T19:41:07Z",
          "last_comment_at": "2023-10-16T02:34:55Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 912,
          "created_at": "2023-07-27T14:34:07Z",
          "last_comment_at": "2023-08-03T16:30:06Z",
          "last_comment_author": "mpstefan"
        },
        {
          "number": 917,
          "created_at": "2023-08-02T15:28:41Z",
          "last_comment_at": "2025-02-16T10:37:00Z",
          "last_comment_author": "miledxz"
        },
        {
          "number": 918,
          "created_at": "2023-08-02T15:30:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 920,
          "created_at": "2023-08-02T15:34:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 922,
          "created_at": "2023-08-02T15:36:01Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 923,
          "created_at": "2023-08-02T15:36:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 924,
          "created_at": "2023-08-02T15:37:23Z",
          "last_comment_at": "2026-07-21T16:59:11Z",
          "last_comment_author": "SidharathBansal"
        },
        {
          "number": 925,
          "created_at": "2023-08-02T15:38:11Z",
          "last_comment_at": "2023-11-01T02:35:54Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 926,
          "created_at": "2023-08-02T15:39:00Z",
          "last_comment_at": "2023-11-01T02:35:52Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 935,
          "created_at": "2023-08-04T21:14:13Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1011,
          "created_at": "2023-08-30T08:44:51Z",
          "last_comment_at": "2023-11-29T02:37:11Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 1014,
          "created_at": "2023-08-30T17:28:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1015,
          "created_at": "2023-08-30T17:33:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1142,
          "created_at": "2023-10-16T16:19:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/nginx/nginx-gateway-fabric",
    "host": "github.com",
    "name": "nginx-gateway-fabric",
    "owner": "nginx"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "excellent",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 89,
      "inputs": {
        "security": 85,
        "vitality": 96,
        "community": 84,
        "governance": 85,
        "engineering": 94
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 96,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "commits_last_year": 1028,
              "human_commit_share": 0.44,
              "days_since_last_push": 0,
              "active_weeks_last_year": 52
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "52/52 weeks with commits",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 52
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1028 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1028
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 41,
              "latest_release_tag": "v2.6.7",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 11.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "41 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 41
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~11.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 11.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 84,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "good",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "forks": 203,
              "stars": 1128,
              "watchers": 30,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,128 stars",
                "points": 49.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1128
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "203 forks",
                "points": 19.2,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 203
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "30 watchers",
                "points": 8.1,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "excellent",
        "name": "Sustainability & Governance",
        "value": 85,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 72,
              "top_contributor_share": 0.243
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 24% of commits",
                "points": 17,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 24
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "72 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 72
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "merged_prs": 3493,
              "open_issues": 114,
              "closed_issues": 1222,
              "issue_closed_ratio": 0.915,
              "closed_unmerged_prs": 591
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "92% of issues closed",
                "points": 42.8,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 92
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "3493/4084 decided PRs merged",
                "points": 32.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 3493,
                      "decided": 4084
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "followers": 2106,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "nginx",
              "public_repos": 61,
              "account_age_days": 5280
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2,106 followers of nginx",
                "points": 23.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2106,
                      "login": "nginx"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "61 public repos, account ~14 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 61
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/nginx/nginx-gateway-fabric/v2"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "25 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 94,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "22 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 22
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "kubernetes",
                "gateway-api",
                "k8s",
                "nginx"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "excellent",
        "name": "Security",
        "value": 85,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 8.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 237 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 237
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 237,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 237,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 74,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.977,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "43 of 44 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 43,
                      "sampled": 44
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "dev/nginx/Makefile",
                "operators/Makefile",
                "tests/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod",
                "tests/framework/crossplane/go.mod",
                "tests/go.mod"
              ],
              "dependency_bot_commit_share": 0.55
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, dev/nginx/Makefile, operators/Makefile, tests/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, dev/nginx/Makefile, operators/Makefile, tests/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "55 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 55,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 344726,
              "source_files_sampled": 467,
              "oversized_source_files": 24
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "24/467 source files over 60KB",
                "points": 52.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 467,
                      "oversized": 24
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples",
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "examples/grpc-routing/grpc.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "examples/grpc-routing/grpc.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/grpc-routing/grpc.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T14:21:26.869693Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/nginx/nginx-gateway-fabric.svg",
  "full_name": "nginx/nginx-gateway-fabric",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.