Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 21:04 UTC

nodejs / node-core-utils

CLI tools for Node.js Core collaborators

JavaScriptMIT★ 313 stars⑂ 131 forkssince Oct 2017View on GitHub ↗

nodejs/node-core-utils holds a health index of 82 out of 100, placing it in the Good band. It scores highest on Vitality (92/100) and lowest on AI Readiness (43/100). It was last updated 1 day ago. 3 contributors account for most of its recent work.

82
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

82
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Node.jsOrganization
16,225 followers231 public repossince Nov 2014

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
npm@node-core/utils6.4.03,3334573 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

92Excellent · 22% of overall
How it's scored
36/36Push recency — last push 1 days ago
22.8/36Commit cadence — 33/52 weeks with commits
18/18Commit volume — 147 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year147
human_commit_share0.73
days_since_last_push1
active_weeks_last_year33

Release discipline

100Excellent
How it's scored
27/27Ships releases — 92 releases published
36/36Release recency — latest release 73 days ago
27/27Release cadence — a release every ~15.9 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count92
latest_release_tagv6.4.0
releases_from_tagsno
days_since_latest_release73
mean_days_between_releases15.9
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

70Good · 18% of overall
How it's scored
40.5/60Stars — 313 stars
17.6/25Forks — 131 forks
6.7/15Watchers — 17 watchers
Inputs used
forks131
stars313
watchers17
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

85Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (MIT)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateno
How it's scored
47/80Monthly downloads — 3,333 downloads/month across npm
0/20Registry dependents — not reported by this ecosystem
Inputs used
packages@node-core/utils
dependents
ecosystemsnpm
total_downloads
monthly_downloads3,333
Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

84Good · 24% of overall
How it's scored
36/54Bus factor — 3 contributor(s) cover half of all commits
16.6/22.5Commit distribution — top contributor authored 26% of commits
13.5/13.5Contributor breadth — 67 contributors
10/10OpenSSF Scorecard: Contributors — project has 73 contributing companies or organizations
Inputs used
bus_factor3
contributors_sampled67
top_contributor_share0.262
How it's scored
35.6/46.8Issue resolution — 76% of issues closed
35.2/38.3PR acceptance — 772/838 decided PRs merged
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs772
open_issues63
closed_issues201
issue_closed_ratio0.761
closed_unmerged_prs66
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
25/25Owner reach — 16,225 followers of nodejs
25/25Track record — 231 public repos, account ~11 yr old
Inputs used
followers16,225
owner_typeOrganization
is_verified
owner_loginnodejs
public_repos231
account_age_days4,260
How it's scored
25/25Published & resolvable — 1 package(s) on npm
35/35Publish recency — latest publish 73 days ago
20/20Version history — 45 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packages@node-core/utils
ecosystemsnpm
any_deprecatedno
min_days_since_publish73

Engineering Quality

Are baseline engineering and documentation practices in place?

90Excellent · 20% of overall
How it's scored
24/24CI workflows — 3 workflow(s)
24/24Tests present
16/16Linter config — eslint.config.js
0/9.6Pre-commit hooks
6.4/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configyes
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://nodejs.github.io/node-core-utils/
10/10Repository description
10/10Topics — 2 topics
0/10Wiki
Inputs used
topicsnodejs, node
has_wikino
homepagehttps://nodejs.github.io/node-core-utils/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

67Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
3.8/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 73 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 21 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6.3
Excluded from scoring (no data or not applicable): signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
14.4/25Indirect dependencies free of known advisories — 1 affected: yargs-parser 2.4.1 (moderate 5.3)
35.3/40No advisories left outstanding — 1 advisory-carrying package(s) unaddressed past 90 days; oldest published 2,150 days ago
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages425
unassessed_packages0
affected_by_severitymoderate 1
direct_affected_packages0
Matched the npm:@node-core/utils@6.4.0 runtime dependency closure — what installing the published package pulls in — 425 packages. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

43At risk · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 73 of 73 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
0/18One-command bootstrap
22/22Automated tests
11/11Lint / format config — eslint.config.js
0/11Static type checking
0/10Reproducible environment
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 27 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfiles
has_dockerfileno
typed_languageno
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.27
How it's scored
0/45Type-checkable code — JavaScript without a type-check config
54.6/55Manageable file sizes — 1/128 source files over 60KB
Inputs used
primary_languageJavaScript
largest_source_bytes80,496
source_files_sampled128
oversized_source_files1

Key facts

313GitHub stars
67contributors
147commits, last 12 months
1days since last push
92releases
3bus factor
63open issues
npmpackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 131 ⇿
0Stars
131Forks
92Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

025507510012515012752017-102022-022026-06
Major 5Minor 48Patch 39

Each point covers 8 days.

OpenSSF Scorecard 6.3 / 10
6.3aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 21:04 UTC

10Binary-Artifactsno binaries found in the repo
5Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 73 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities21 existing vulnerabilities detected
Direct dependencies 24
RegistryPackageVersion constraintManifest
npm@inquirer/prompts^7.4.1package.json
npm@listr2/prompt-adapter-enquirer^2.0.12package.json
npm@node-core/caritat^1.6.0package.json
npm@pkgjs/nv^0.3.0package.json
npmbranch-diff^3.1.1package.json
npmchalk^5.4.1package.json
npmchangelog-maker^4.4.1package.json
npmcheerio^1.0.0package.json
npmclipboardy^5.0.2package.json
npmcore-validate-commit^6.0.0package.json
npmfigures^6.1.0package.json
npmghauth^7.0.1package.json
npmgit-secure-tag^2.3.1package.json
npmjs-yaml^5.2.1package.json
npmlistr2^9.0.5package.json
npmlodash^4.17.21package.json
npmlog-symbols^7.0.0package.json
npmora^9.0.0package.json
npmreplace-in-file^8.3.0package.json
npmsemver^7.7.1package.json
npmsmol-toml^1.7.0package.json
npmundici^8.3.0package.json
npmwhich^7.0.0package.json
npmyargs^18.0.0package.json
All dependencies 34

Full resolved dependency set from the GitHub dependency graph: 24 direct and 10 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
npm@inquirer/prompts^7.4.1direct
npm@listr2/prompt-adapter-enquirer^2.0.12direct
npm@node-core/caritat^1.6.0direct
npm@pkgjs/nv^0.3.0direct
npmbranch-diff^3.1.1direct
npmchalk^5.4.1direct
npmchangelog-maker^4.4.1direct
npmcheerio^1.0.0direct
npmclipboardy^5.0.2direct
npmcore-validate-commit^6.0.0direct
npmfigures^6.1.0direct
npmghauth^7.0.1direct
npmgit-secure-tag^2.3.1direct
npmjs-yaml^5.2.1direct
npmlistr2^9.0.5direct
npmlodash^4.17.21direct
npmlog-symbols^7.0.0direct
npmora^9.0.0direct
npmreplace-in-file^8.3.0direct
npmsemver^7.7.1direct
npmsmol-toml^1.7.0direct
npmundici^8.3.0direct
npmwhich^7.0.0direct
npmyargs^18.0.0direct
npm@eslint/js^9.39.4indirect
npm@reporters/github^1.7.2indirect
npmc8^11.0.0indirect
npmeslint^9.39.4indirect
npmeslint-plugin-import^2.32.0indirect
npmeslint-plugin-n^17.24.0indirect
npmeslint-plugin-promise^7.3.0indirect
npmglobals^17.4.0indirect
npmneostandard^0.13.0indirect
npmsinon^22.0.0indirect
Dependency advisories 1

Installing npm:@node-core/utils@6.4.0 pulls in 425 packages, direct and transitive: 1 carry known advisories, of which 0 are direct dependencies.

PackageVersionRelationSeverityAdvisoriesFixed in
yargs-parser2.4.1indirectmoderate118.1.1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "nodejs",
        "node"
      ],
      "is_fork": false,
      "size_kb": 2796,
      "has_wiki": false,
      "homepage": "https://nodejs.github.io/node-core-utils/",
      "languages": {
        "JavaScript": 653251
      },
      "pushed_at": "2026-07-24T13:39:17Z",
      "created_at": "2017-10-22T12:27:44Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T13:39:03Z",
      "description": "CLI tools for Node.js Core collaborators",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://nodejs.org",
      "name": "Node.js",
      "type": "Organization",
      "login": "nodejs",
      "company": null,
      "location": null,
      "followers": 16225,
      "avatar_url": "https://avatars.githubusercontent.com/u/9950313?v=4",
      "created_at": "2014-11-25T17:10:50Z",
      "is_verified": null,
      "public_repos": 231,
      "account_age_days": 4260
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v6.4.0",
          "kind": "minor",
          "published_at": "2026-05-13T06:44:27Z"
        },
        {
          "tag": "v6.3.3",
          "kind": "patch",
          "published_at": "2026-04-27T08:47:30Z"
        },
        {
          "tag": "v6.3.2",
          "kind": "patch",
          "published_at": "2026-04-14T19:07:06Z"
        },
        {
          "tag": "v6.3.1",
          "kind": "patch",
          "published_at": "2026-04-11T21:40:55Z"
        },
        {
          "tag": "v6.3.0",
          "kind": "minor",
          "published_at": "2026-03-27T22:34:05Z"
        },
        {
          "tag": "v6.2.1",
          "kind": "patch",
          "published_at": "2026-03-20T22:51:03Z"
        },
        {
          "tag": "v6.2.0",
          "kind": "minor",
          "published_at": "2026-03-18T12:47:30Z"
        },
        {
          "tag": "v6.1.1",
          "kind": "patch",
          "published_at": "2026-01-05T17:58:22Z"
        },
        {
          "tag": "v6.1.0",
          "kind": "minor",
          "published_at": "2026-01-02T18:34:21Z"
        },
        {
          "tag": "v6.0.0",
          "kind": "major",
          "published_at": "2025-12-21T11:14:33Z"
        },
        {
          "tag": "v5.16.2",
          "kind": "patch",
          "published_at": "2025-10-12T14:40:39Z"
        },
        {
          "tag": "v5.16.1",
          "kind": "patch",
          "published_at": "2025-09-22T11:59:48Z"
        },
        {
          "tag": "v5.16.0",
          "kind": "minor",
          "published_at": "2025-09-18T15:02:16Z"
        },
        {
          "tag": "v5.15.0",
          "kind": "minor",
          "published_at": "2025-08-09T12:48:02Z"
        },
        {
          "tag": "v5.14.1",
          "kind": "patch",
          "published_at": "2025-07-11T18:05:29Z"
        },
        {
          "tag": "v5.14.0",
          "kind": "minor",
          "published_at": "2025-05-26T18:57:30Z"
        },
        {
          "tag": "v5.13.0",
          "kind": "minor",
          "published_at": "2025-05-01T15:48:49Z"
        },
        {
          "tag": "v5.12.2",
          "kind": "patch",
          "published_at": "2025-04-01T08:42:58Z"
        },
        {
          "tag": "v5.12.1",
          "kind": "patch",
          "published_at": "2025-03-28T12:38:24Z"
        },
        {
          "tag": "v5.12.0",
          "kind": "minor",
          "published_at": "2025-03-28T08:23:01Z"
        },
        {
          "tag": "v5.11.0",
          "kind": "minor",
          "published_at": "2025-01-30T07:29:43Z"
        },
        {
          "tag": "v5.10.0",
          "kind": "minor",
          "published_at": "2025-01-20T13:33:03Z"
        },
        {
          "tag": "v5.9.0",
          "kind": "minor",
          "published_at": "2025-01-15T20:06:36Z"
        },
        {
          "tag": "v5.8.0",
          "kind": "minor",
          "published_at": "2024-12-03T23:31:54Z"
        },
        {
          "tag": "v5.7.0",
          "kind": "minor",
          "published_at": "2024-11-19T18:26:17Z"
        },
        {
          "tag": "v5.6.0",
          "kind": "minor",
          "published_at": "2024-11-08T14:43:02Z"
        },
        {
          "tag": "v5.5.1",
          "kind": "patch",
          "published_at": "2024-09-26T16:12:04Z"
        },
        {
          "tag": "v5.5.0",
          "kind": "minor",
          "published_at": "2024-09-02T15:44:44Z"
        },
        {
          "tag": "v5.4.0",
          "kind": "minor",
          "published_at": "2024-08-07T19:09:24Z"
        },
        {
          "tag": "v5.3.1",
          "kind": "patch",
          "published_at": "2024-07-03T07:58:22Z"
        },
        {
          "tag": "v5.3.0",
          "kind": "minor",
          "published_at": "2024-06-24T16:01:09Z"
        },
        {
          "tag": "v5.2.1",
          "kind": "patch",
          "published_at": "2024-06-21T19:44:27Z"
        },
        {
          "tag": "v5.2.0",
          "kind": "minor",
          "published_at": "2024-06-14T13:09:16Z"
        },
        {
          "tag": "v5.1.0",
          "kind": "minor",
          "published_at": "2024-05-22T07:32:32Z"
        },
        {
          "tag": "v5.0.2",
          "kind": "patch",
          "published_at": "2024-05-11T16:54:28Z"
        },
        {
          "tag": "v5.0.1",
          "kind": "patch",
          "published_at": "2024-04-24T21:17:33Z"
        },
        {
          "tag": "v5.0.0",
          "kind": "major",
          "published_at": "2024-04-24T19:25:52Z"
        },
        {
          "tag": "v4.4.0",
          "kind": "minor",
          "published_at": "2024-04-03T18:07:10Z"
        },
        {
          "tag": "v4.3.0",
          "kind": "minor",
          "published_at": "2024-03-05T14:40:08Z"
        },
        {
          "tag": "v4.2.3",
          "kind": "patch",
          "published_at": "2024-01-04T08:27:59Z"
        },
        {
          "tag": "v4.2.2",
          "kind": "patch",
          "published_at": "2023-12-08T15:14:40Z"
        },
        {
          "tag": "v4.2.1",
          "kind": "patch",
          "published_at": "2023-11-29T09:46:41Z"
        },
        {
          "tag": "v4.2.0",
          "kind": "minor",
          "published_at": "2023-11-15T10:28:44Z"
        },
        {
          "tag": "v4.1.0",
          "kind": "minor",
          "published_at": "2023-10-12T11:55:02Z"
        },
        {
          "tag": "v4.0.0",
          "kind": "major",
          "published_at": "2023-09-24T21:29:50Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2023-09-24T09:06:52Z"
        },
        {
          "tag": "v3.4.2",
          "kind": "patch",
          "published_at": "2023-09-15T14:11:41Z"
        },
        {
          "tag": "v3.4.1",
          "kind": "patch",
          "published_at": "2023-09-12T20:37:23Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2023-09-04T08:04:51Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2023-08-04T20:10:03Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2023-07-04T15:23:38Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2023-06-26T06:12:08Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2023-06-12T06:32:58Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2023-03-08T09:01:27Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2022-12-06T15:36:22Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2022-11-22T14:56:14Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2022-10-27T23:43:43Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2022-10-22T09:33:40Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2022-07-31T12:31:12Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2022-07-12T06:39:03Z"
        },
        {
          "tag": "v1.31.4",
          "kind": "patch",
          "published_at": "2022-04-25T11:20:25Z"
        },
        {
          "tag": "v1.31.3",
          "kind": "patch",
          "published_at": "2022-04-19T16:21:18Z"
        },
        {
          "tag": "v1.31.2",
          "kind": "patch",
          "published_at": "2022-04-08T12:35:30Z"
        },
        {
          "tag": "v1.31.1",
          "kind": "patch",
          "published_at": "2022-03-17T12:24:33Z"
        },
        {
          "tag": "v1.31.0",
          "kind": "minor",
          "published_at": "2021-12-21T10:43:42Z"
        },
        {
          "tag": "v1.30.1",
          "kind": "patch",
          "published_at": "2021-11-17T14:27:32Z"
        },
        {
          "tag": "v1.30.0",
          "kind": "minor",
          "published_at": "2021-11-08T18:12:50Z"
        },
        {
          "tag": "v1.29.1",
          "kind": "patch",
          "published_at": "2021-10-31T01:39:15Z"
        },
        {
          "tag": "v1.29.0",
          "kind": "minor",
          "published_at": "2021-10-28T12:08:38Z"
        },
        {
          "tag": "v1.28.2",
          "kind": "patch",
          "published_at": "2021-10-04T10:10:58Z"
        },
        {
          "tag": "v1.28.1",
          "kind": "patch",
          "published_at": "2021-09-25T07:55:07Z"
        },
        {
          "tag": "v1.28.0",
          "kind": "minor",
          "published_at": "2021-09-20T00:44:48Z"
        },
        {
          "tag": "v1.27.2",
          "kind": "patch",
          "published_at": "2021-07-03T09:38:25Z"
        },
        {
          "tag": "v1.27.1",
          "kind": "patch",
          "published_at": "2021-06-10T20:20:04Z"
        },
        {
          "tag": "v1.27.0",
          "kind": "minor",
          "published_at": "2021-02-26T12:27:10Z"
        },
        {
          "tag": "v1.26.0",
          "kind": "minor",
          "published_at": "2021-02-09T10:48:05Z"
        },
        {
          "tag": "v1.25.0",
          "kind": "minor",
          "published_at": "2020-09-30T06:11:17Z"
        },
        {
          "tag": "v1.24.0",
          "kind": "minor",
          "published_at": "2020-08-25T00:05:28Z"
        },
        {
          "tag": "v1.23.0",
          "kind": "minor",
          "published_at": "2020-07-29T20:31:13Z"
        },
        {
          "tag": "v1.22.0",
          "kind": "minor",
          "published_at": "2020-07-13T09:49:04Z"
        },
        {
          "tag": "v1.21.0",
          "kind": "minor",
          "published_at": "2020-05-19T16:54:19Z"
        },
        {
          "tag": "v1.20.0",
          "kind": "minor",
          "published_at": "2020-02-14T19:34:53Z"
        },
        {
          "tag": "v1.18.0",
          "kind": "minor",
          "published_at": "2019-10-10T08:10:46Z"
        },
        {
          "tag": "v1.17.1",
          "kind": "patch",
          "published_at": "2019-10-10T08:11:11Z"
        },
        {
          "tag": "v1.17.0",
          "kind": "minor",
          "published_at": "2019-05-01T06:48:45Z"
        },
        {
          "tag": "v1.16.1",
          "kind": "patch",
          "published_at": "2018-12-03T22:44:58Z"
        },
        {
          "tag": "v1.14.0",
          "kind": "minor",
          "published_at": "2018-09-07T07:27:19Z"
        },
        {
          "tag": "v1.13.0",
          "kind": "minor",
          "published_at": "2018-06-01T09:16:00Z"
        },
        {
          "tag": "v1.12.0",
          "kind": "minor",
          "published_at": "2018-05-14T14:29:51Z"
        },
        {
          "tag": "v1.11.2",
          "kind": "patch",
          "published_at": "2018-03-31T19:47:26Z"
        },
        {
          "tag": "v1.11.1",
          "kind": "patch",
          "published_at": "2018-02-23T13:28:47Z"
        },
        {
          "tag": "v1.10.0",
          "kind": "minor",
          "published_at": "2018-02-08T15:16:16Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "c263c2ae7d9be82feb79766a89a7bdaf5527b86b",
          "body": "* fix: handle affectedVersions as object for post-release\n\nRefs: https://github.com/nodejs-private/nodejs.org-private/pull/567#discussion_r3625265939\nSigned-off-by: RafaelGSS <rafael.nunu@hotmail.com>\n\n* feat: sort by severity on post-release\n\nSigned-off-by: RafaelGSS <rafael.nunu@hotmail.com>\n\n---------\n\nSigned-off-by: RafaelGSS <rafael.nunu@hotmail.com>",
          "is_bot": false,
          "headline": "fix: handle affectedVersions as object for post-release (#1122)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-24T13:38:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b3296a199e94b802c6c9b62bf190a7236378db2",
          "body": null,
          "is_bot": false,
          "headline": "fix: borrow generateAmendedMessage in CherryPick (#1125)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-24T13:38:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72bf75617d38a551788a2540738574524072fc77",
          "body": "…124)\n\n`git node release --prepare --security` now selects the PRs to cherry-pick\nfrom the per-line `affectedVersions` mapping of each report and dependency,\ninstead of scanning open PRs and filtering by label.\n\n- `--security` accepts the path to vulnerabilities.json directly (or the\n  security-rele\n[…]\n- Dependency updates now use the same `affectedVersions` schema as the\n  reports, updating the generator and the `git node security` consumer.\n\nRemoved the `--filterLabel` option and the open PR scan.",
          "is_bot": false,
          "headline": "feat(git-node): select security release PRs from affectedVersions (#1…",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-23T19:23:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2f4ac59adba509c18f64276e479ae0f81502138",
          "body": "It no longer asks for every report, I have used for the next security release\nand it's working pretty smooth\n\nSigned-off-by: RafaelGSS <rafael.nunu@hotmail.com>",
          "is_bot": false,
          "headline": "feat: improve DX of request-cves (#1120)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-23T12:27:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4a7c7dea4529235ecb8e028377e961d66bab0b7",
          "body": "Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>",
          "is_bot": false,
          "headline": "feat(security): add include-all report selection mode (#1111)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-21T20:14:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67fbf883ad4234626d4ca1c5dd5226b7e663fc0a",
          "body": "Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>",
          "is_bot": false,
          "headline": "fix: remove the separator for dep update (#1112)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-21T20:14:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3017208dc95e56f2381a9a4abf32336942f803c6",
          "body": null,
          "is_bot": false,
          "headline": "fix: add announcement ref to top-level vuln json (#1119)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-21T19:51:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78e1dbb7f0c5bddc3db820bd9d0feaa0a3490a9c",
          "body": null,
          "is_bot": false,
          "headline": "feat(v8)!: synchronize Rust crates with major updates (#1117)",
          "author_name": "René",
          "author_login": "Renegade334",
          "committed_at": "2026-07-21T18:03:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3b9dc659b0433b5d92e3a6bd72ec998a24289fa",
          "body": "Due to a recent update on the vulnerabilities.json\nschema, this needs to be adjusted.",
          "is_bot": false,
          "headline": "feat: support affectedVersions as object (#1118)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-21T12:07:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09c8ff9a42fbf9db4af40ecaa5cf7e96f1be4db2",
          "body": "After updating the V8 tree, we currently re-fetch the new V8 version\nfrom the filesystem several times during various tasks.\nInstead, we can cache it in the same way that we do the existing\nversion.\n\nUpdates `getCurrentV8Version()` to a generic task that accepts a label\nfor the version, either 'current' or 'new', from which the context\nproperty name is derived.",
          "is_bot": false,
          "headline": "refactor(v8): cache new V8 version during major update (#1116)",
          "author_name": "René",
          "author_login": "Renegade334",
          "committed_at": "2026-07-14T08:58:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10c6f35d8fde535f676d526c8ffe1eeb35951d9b",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): fix SSH passphrase input when promoting a release (#1097)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-07-14T07:30:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb405a170d741d5fdb2f7cbc4f7e413ad9570c40",
          "body": null,
          "is_bot": false,
          "headline": "feat(git-node): add `git node benchmark` (#1114)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-07-13T08:13:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ead0a1a213fb67a43aec3ba2353613ec718dca3",
          "body": "…CVEs (#1095)",
          "is_bot": false,
          "headline": "fix(git-node): prefill both patch and minor versions when requesting …",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-07-09T20:05:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ad397f9075cbcf7f741c4990629d1ff223ad5fb",
          "body": "…1096)",
          "is_bot": false,
          "headline": "fix(git-node): security release preparation should not use staging (#…",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-07-09T16:34:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a22e127565e86238cc9d0b378cbbe297cdc58ea6",
          "body": "Expose stable PR readiness reason codes from `PRChecker` and add\n`git node metadata --json` for machine-readable metadata readiness\nresults.\n\nThe JSON output includes readiness classification, reserved exit-code\ncategories, generated metadata, unique reason codes, and detailed\nreasons.\n\nSigned-off-by: Filip Skokan <panva.ip@gmail.com>",
          "is_bot": false,
          "headline": "feat: add metadata JSON readiness output (#1113)",
          "author_name": "Filip Skokan",
          "author_login": "panva",
          "committed_at": "2026-07-09T10:25:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9250fba633a4ab2c74b1478dc2ee325f34f66e98",
          "body": "Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 5.2.1.\n- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.1...5.2.1)\n\n---\nupdated-dependencies:\n- dependency-name: js-yaml\n  dependency-version: 5.2.0\n  d\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump js-yaml from 4.1.1 to 5.2.1 (#1106)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T15:24:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e2c2ab85e53c68c117c5bf8a339270d7015a8bc",
          "body": "Bumps [sinon](https://github.com/sinonjs/sinon) from 21.0.0 to 22.0.0.\n- [Release notes](https://github.com/sinonjs/sinon/releases)\n- [Changelog](https://github.com/sinonjs/sinon/blob/main/CHANGES.md)\n- [Commits](https://github.com/sinonjs/sinon/compare/v21.0.0...v22.0.0)\n\n---\nupdated-dependencies:\n\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump sinon from 21.0.0 to 22.0.0 (#1105)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T15:18:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5bc79855b3fc4ef798b5cacea234fbe1b7a3f85a",
          "body": "Bumps [semver](https://github.com/npm/node-semver) from 7.7.3 to 7.8.5.\n- [Release notes](https://github.com/npm/node-semver/releases)\n- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/npm/node-semver/compare/v7.7.3...v7.8.5)\n\n---\nupdated-depende\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump semver from 7.7.3 to 7.8.5 (#1104)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T15:17:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6bc85eb2af6290e86124e2ff09c9f20166b6054",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6 to 7 (#1102)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-07T15:16:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f46846c29b6e21962beb7d15b9f94eb5781c5d3",
          "body": "Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>",
          "is_bot": false,
          "headline": "feat(security): offer Tuesday release date choices (#1110)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-07-07T14:44:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce38c70db2eaee1d8ebd523fb2ff6d809e525d9c",
          "body": "Signed-off-by: Stewart X Addison <sxa@ibm.com>",
          "is_bot": false,
          "headline": "docs: refer to \"squash\" in help screen for git node land (#1108)",
          "author_name": "Stewart X Addison",
          "author_login": "sxa",
          "committed_at": "2026-07-01T13:51:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b970144338ff0e4c5fa34c00c0d7d0b7ad750f7c",
          "body": "Signed-off-by: Stewart X Addison <sxa@ibm.com>",
          "is_bot": false,
          "headline": "docs: remove \"npm test-all\" from CONTRIBUTING.md\" (#1109)",
          "author_name": "Stewart X Addison",
          "author_login": "sxa",
          "committed_at": "2026-07-01T13:03:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d1085f5824c76f9fe7261cefc6ccd74c9ce4035",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): add missing exit loop condition (#1101)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-06-29T17:59:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf990ac8fdc9d92567a3b2e084c37051bfcff904",
          "body": null,
          "is_bot": false,
          "headline": "feat(git-node): add `git node security --apply-patches` (#1050)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-06-29T17:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "254ebaa09fee108c152352845c9a54cb42786dc6",
          "body": null,
          "is_bot": false,
          "headline": "chore(git-node): clarify prompt message in promotion script (#1100)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-06-24T12:23:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "383db9687417c4e7a6a83e039371c27601369ac8",
          "body": null,
          "is_bot": false,
          "headline": "chore(git-node): remove abort error in case of fixable error (#1099)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-06-23T20:20:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "07d5ba0c2c2800ebf7cd7f14c826c0a43ca65894",
          "body": null,
          "is_bot": false,
          "headline": "feat: add confirmation steps to any write operation (#1092)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-06-18T21:50:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9fff73877c8cffdfb03b1cd8132bd6c640fc137",
          "body": "Signed-off-by: Filip Skokan <panva.ip@gmail.com>",
          "is_bot": false,
          "headline": "fix(wpt): avoid test/fixtures/wpt/README.md conflicts",
          "author_name": "Filip Skokan",
          "author_login": "panva",
          "committed_at": "2026-06-16T08:53:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea22b8a7c2917d052f4a46fee02bdd6c64ce929",
          "body": null,
          "is_bot": false,
          "headline": "chore: replace `process.exit` calls with actual error thrown (#1089)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-06-01T15:59:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e084f7a0fee703f79747755a7de6cbde66cf34cb",
          "body": "When we announce a security release, we used to say we'll be\nfixing X High, X Medium, and so on. By communicating only the\nexpected highest vulnerability, the ecosystem can still prepare\naccordingly, while maintainers can drop lower vuln if needed.\n\nCo-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com>",
          "is_bot": false,
          "headline": "update: drop number of vulnerabilities on --pre-release (#1080)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-06-01T14:31:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd0b6887725b6b926772b8a114550e0eef66a6e8",
          "body": "Bumps [branch-diff](https://github.com/nodejs/branch-diff) from 3.1.1 to 3.1.4.\n- [Release notes](https://github.com/nodejs/branch-diff/releases)\n- [Changelog](https://github.com/nodejs/branch-diff/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/nodejs/branch-diff/compare/v3.1.1...v3.1.4)\n\n--\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump branch-diff from 3.1.1 to 3.1.4 (#1086)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T10:39:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "edd339008dd2cf32f845ffed1fa934eae896f74b",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): bump `which` from version 6 to 7 (#1083)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-06-01T10:38:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbc5452a55d4f9a3901aa729704962416c111eb4",
          "body": "Co-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump eslint packages (#1088)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T10:34:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa13cdb67abe42fd5301d9a1d8b65be8f9552a07",
          "body": "Bumps [ghauth](https://github.com/rvagg/ghauth) from 7.0.1 to 7.0.4.\n- [Release notes](https://github.com/rvagg/ghauth/releases)\n- [Changelog](https://github.com/rvagg/ghauth/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/rvagg/ghauth/compare/v7.0.1...v7.0.4)\n\n---\nupdated-dependencies:\n- d\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ghauth from 7.0.1 to 7.0.4 (#1087)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T08:34:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e045c6b8cd9251a21019cecd340d789dd3a475e",
          "body": "Bumps [changelog-maker](https://github.com/nodejs/changelog-maker) from 4.4.4 to 4.4.32.\n- [Release notes](https://github.com/nodejs/changelog-maker/releases)\n- [Changelog](https://github.com/nodejs/changelog-maker/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/nodejs/changelog-maker/compare\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump changelog-maker from 4.4.4 to 4.4.32 (#1085)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T08:33:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "31236c962dd844ae876c28ae2a8357cc29d41b0f",
          "body": "Bumps [neostandard](https://github.com/neostandard/neostandard) from 0.12.2 to 0.13.0.\n- [Release notes](https://github.com/neostandard/neostandard/releases)\n- [Changelog](https://github.com/neostandard/neostandard/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/neostandard/neostandard/compar\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump neostandard from 0.12.2 to 0.13.0 (#1084)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T08:30:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6c1ff48a3de6c09b0e3b5a5226cc562468f4bb5",
          "body": "Bumps [undici](https://github.com/nodejs/undici) from 7.24.6 to 8.3.0.\n- [Release notes](https://github.com/nodejs/undici/releases)\n- [Commits](https://github.com/nodejs/undici/compare/v7.24.6...v8.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: undici\n  dependency-version: 8.1.0\n  dependency-typ\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump undici from 7.24.6 to 8.3.0 (#1067)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-27T09:56:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c564d818fb55f7cdd3159708a65584db64fd43b6",
          "body": null,
          "is_bot": false,
          "headline": "chore!: drop support for Node.js 20 and 25 (#1072)",
          "author_name": "Michaël Zasso",
          "author_login": "targos",
          "committed_at": "2026-05-27T09:50:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a4439b6346013d531280de1e53176b273a278c8",
          "body": "Bumps [googleapis/release-please-action](https://github.com/googleapis/release-please-action)\nfrom 4 to 5.\n- [Release notes](https://github.com/googleapis/release-please-action/releases)\n- [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md)\n- [Commits](https://git\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump googleapis/release-please-action from 4 to 5 (#1066)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-27T08:13:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9270115d1722c39fa1f5e5d5de13ee8d394ee56",
          "body": "Bumps [eslint-plugin-promise](https://github.com/eslint-community/eslint-plugin-promise) from 7.2.1 to 7.3.0.\n- [Release notes](https://github.com/eslint-community/eslint-plugin-promise/releases)\n- [Changelog](https://github.com/eslint-community/eslint-plugin-promise/blob/main/CHANGELOG.md)\n- [Commi\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump eslint-plugin-promise to 7.3.0 (#1068)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-27T08:01:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16bc56dcd1feb0e79adfd0003bbe30c50a152fb2",
          "body": "Bumps [replace-in-file](https://github.com/adamreisnz/replace-in-file) from 8.3.0 to 8.4.0.\n- [Release notes](https://github.com/adamreisnz/replace-in-file/releases)\n- [Changelog](https://github.com/adamreisnz/replace-in-file/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/adamreisnz/replace-\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump replace-in-file from 8.3.0 to 8.4.0 (#1070)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-27T08:00:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e9be444653e99ab736d30322d327e493b35c2a4",
          "body": "Bumps [@node-core/caritat](https://github.com/nodejs/caritat) from 1.6.0 to 1.7.0.\n- [Release notes](https://github.com/nodejs/caritat/releases)\n- [Changelog](https://github.com/nodejs/caritat/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/nodejs/caritat/compare/v1.6.0...v1.7.0)\n\n---\nupdated\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump @node-core/caritat from 1.6.0 to 1.7.0 (#1071)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-27T07:45:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f857c25b9934b24a4668a5753d00ff830cdad502",
          "body": "Bumps [globals](https://github.com/sindresorhus/globals) from 17.4.0 to 17.6.0.\n- [Release notes](https://github.com/sindresorhus/globals/releases)\n- [Commits](https://github.com/sindresorhus/globals/compare/v17.4.0...v17.6.0)\n\n---\nupdated-dependencies:\n- dependency-name: globals\n  dependency-versio\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump globals from 17.4.0 to 17.6.0 (#1069)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-27T07:42:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0395a93fdd001c36e50174ff7c04e77a66858ae",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): force bump Yargs to fix CI (#1081)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-05-26T14:14:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37cc6f0b01162d8a01899975436b4a5c4576d68c",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.4.0 (#1075)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-05-13T06:44:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54be933b1a86a123c62e19e907e157cb19c58d10",
          "body": "Keep only the folders that are needed at the moment\n\nRefs: https://chromium-review.googlesource.com/c/v8/v8/+/7828379",
          "is_bot": false,
          "headline": "feat(v8): add llvm-libc to V8 deps (#1073)",
          "author_name": "Michaël Zasso",
          "author_login": "targos",
          "committed_at": "2026-05-13T06:41:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20f60af8d8bba56ebaf0bc173957e31633c55cc3",
          "body": null,
          "is_bot": false,
          "headline": "feat: check for reports without PR_URL on H1 (#1074)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-05-11T20:00:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da357518d488f789273de45a453df0be9cfa22ef",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.3.3 (#1064)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-04-27T08:47:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "961fa2dca86709154f9acca90513709fec5b5d9f",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): bump `core-validate-commit` version (#1065)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-04-27T08:44:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f131b097cf99c27af3c0d3de4a451879aa97a72a",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): handle multi-line trailers (#1062)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-04-27T07:52:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0587fa5380f91e7f6237606f4eeb15de02d5406",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.3.2 (#1061)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-04-14T19:06:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7bd24d09c1156af579fd8bb8de648e867747b3b",
          "body": null,
          "is_bot": false,
          "headline": "docs: add ncu-ci run documentation (#1060)",
          "author_name": "Matteo Collina",
          "author_login": "mcollina",
          "committed_at": "2026-04-14T19:05:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f510b8a2031a89912c5da20dd5b3ab7d0fb6f061",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): handle single-line commit messages (#1059)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-04-14T17:12:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9048c85b505b267fc6ccfab743f2301f92a7af5",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.3.1 (#1057)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-04-11T21:40:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d958465c0341dc1e2eb61b93f189ad7234f5e138",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): fix handling of existing trailers (#1056)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-04-11T21:38:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2624c1015349782ef364d1a38109cd5ffad14ccd",
          "body": "Bumps [core-validate-commit](https://github.com/nodejs/core-validate-commit) from 4.1.0 to 5.0.1.\n- [Release notes](https://github.com/nodejs/core-validate-commit/releases)\n- [Changelog](https://github.com/nodejs/core-validate-commit/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/nodejs/core\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump core-validate-commit from 4.1.0 to 5.0.1 (#1055)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T14:24:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ea5c9560be6e63b3d29bf16e6fccc239f721eb1",
          "body": "Bumps [globals](https://github.com/sindresorhus/globals) from 16.2.0 to 17.4.0.\n- [Release notes](https://github.com/sindresorhus/globals/releases)\n- [Commits](https://github.com/sindresorhus/globals/compare/v16.2.0...v17.4.0)\n\n---\nupdated-dependencies:\n- dependency-name: globals\n  dependency-versio\n[…]\nrect:development\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump globals from 16.2.0 to 17.4.0 (#1054)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T14:22:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f724cc8a74e0460dca7ef90f5bee57fe246fce4b",
          "body": "Bumps `eslint-plugin-n` from 17.23.1 to 17.24.0.\n- [Release notes](https://github.com/eslint-community/eslint-plugin-n/releases)\n- [Changelog](https://github.com/eslint-community/eslint-plugin-n/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/eslint-community/eslint-plugin-n/compare/v17.23.\n[…]\nrect:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump eslint-plugin-n from 17.23.1 to 17.24.0 (#1053)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T14:21:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "936c0219399e6387f52c17192c283ad23fd7a365",
          "body": "Bumps [cheerio](https://github.com/cheeriojs/cheerio) from 1.1.2 to 1.2.0.\n- [Release notes](https://github.com/cheeriojs/cheerio/releases)\n- [Commits](https://github.com/cheeriojs/cheerio/compare/v1.1.2...v1.2.0)\n\n---\nupdated-dependencies:\n- dependency-name: cheerio\n  dependency-version: 1.2.0\n  de\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump cheerio from 1.1.2 to 1.2.0 (#1052)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T14:20:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ae85e8e6406641a8a19a3f6b9b7060b1163171c4",
          "body": "Bumps [ghauth](https://github.com/rvagg/ghauth) from 6.0.19 to 7.0.1.\n- [Release notes](https://github.com/rvagg/ghauth/releases)\n- [Changelog](https://github.com/rvagg/ghauth/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/rvagg/ghauth/compare/v6.0.19...v7.0.1)\n\n---\nupdated-dependencies:\n-\n[…]\ndependency-name: ghauth\n  dependency-version: 7.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nCo-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ghauth from 6.0.19 to 7.0.1 (#1051)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T14:19:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72e8772e6404abef43f1cba35e15b647c7ba516a",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.3.0 (#1049)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-03-27T22:33:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a427eed683eeec5cb9e951c05e5b40b2463744d",
          "body": null,
          "is_bot": false,
          "headline": "feat(git-node): suggest abort previous session (#1042)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-27T16:10:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25082a4b7daca47396f462e7ccde676c84fb1294",
          "body": null,
          "is_bot": false,
          "headline": "fix(*): throw `Error` objects to help with debugging (#1045)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-27T16:10:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "673476fe4585f1c16ae5cde267bc31083f73495d",
          "body": "Security releases preparation follow the same steps as regular releases,\nhaving duplicated steps is only cumbersome AFAICT.",
          "is_bot": false,
          "headline": "fix(git-node): remove duplicated code in `prepare_release.js` (#1047)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-27T16:09:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dec276d20ce889eed28cd77d3679bae427165a3e",
          "body": null,
          "is_bot": false,
          "headline": "chore(request): mutualize GH API headers (#1046)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-27T16:08:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3070852c189db34ca86f2c7d36a66d1567699d15",
          "body": "…EOL (#1044)",
          "is_bot": false,
          "headline": "fix(git-node): simplify `vulnerabilities.json` creation, add missing …",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-27T13:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be846eb411ce38eb894a2f73f5f5ee9adb31de8a",
          "body": null,
          "is_bot": false,
          "headline": "feat(git-node): do not trust user input metadata",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-24T10:38:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fc91ad31fc6b13f84d054ae2511c7882e3ae906",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): do not parse `PR-URL` from backport PR description",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-24T10:38:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22f1f7165433fd566fbc2ffec2f70ddd3e970cb5",
          "body": null,
          "is_bot": false,
          "headline": "feat(git-node): add backport reviewers to metadata",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-24T10:38:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f70b2f5a4a455e5fa3f3fcf93e7e292c7f1c29b6",
          "body": "Node.js security patches are prepared on a separate repo, it can be\nuseful to be able to run `git node land` without needing to touch the\nlocal config.",
          "is_bot": false,
          "headline": "feat(git-node): add limited support for cross-repo PRs (#1043)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-24T10:26:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d22f66444174b6fa00aa93fd13d60bcfc252df20",
          "body": null,
          "is_bot": false,
          "headline": "chore(git-node): remove code duplication in `security.js` (#1048)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-24T10:20:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a789fd16cb9a2e49ef85090e899570a222cdd8e",
          "body": null,
          "is_bot": false,
          "headline": "feat(ncu-ci): add `--check-for-duplicates` flag (#1035)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-23T10:53:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5034b4f5b12b92b785004854cf8fc2959178f27f",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.2.1 (#1040)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-03-20T22:50:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9dc16980fe0ab26e9bdcc07f176458a3c20fe09",
          "body": null,
          "is_bot": false,
          "headline": "chore(deps): bump core-validate-commit (#1034)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-20T18:01:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82241222c4b03f4d19b558664a4f7b3a5ad685f6",
          "body": null,
          "is_bot": false,
          "headline": "fix(git-node): pass `argv` to `LandingSession` constructor (#1039)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-20T18:01:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2f4194b2bc00e4c8a734df74fbf354e80d64bca",
          "body": "…es (#1030)\n\nIf a value is defined locally, it should make no difference whether the\nassociated key is present or not in the global config.\n\nAlso fix a bug where the `additional` being ignored if config was\npreviously merged.",
          "is_bot": false,
          "headline": "fix(ncu-config): allow overriding global encrypted keys with local on…",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-20T18:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "478250b2c430fa2c578e378b641e83f724d1f167",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.2.0",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-03-18T12:47:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6ef8b543191bc5e0e8ae6b7c0d693670affecf0",
          "body": null,
          "is_bot": false,
          "headline": "fix: ensure all webcrypto idls are downloaded",
          "author_name": "Filip Skokan",
          "author_login": "panva",
          "committed_at": "2026-03-18T08:16:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc7645fa3d24f4dc941c40004231848241d8dfc6",
          "body": null,
          "is_bot": false,
          "headline": "fix: improve --request-cve (#1037)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-03-17T17:36:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7520eb9cc14c1fea783729de7cdd927303fa827a",
          "body": "Bumps [clipboardy](https://github.com/sindresorhus/clipboardy) from 4.0.0 to 5.0.2.\n- [Release notes](https://github.com/sindresorhus/clipboardy/releases)\n- [Commits](https://github.com/sindresorhus/clipboardy/compare/v4.0.0...v5.0.2)\n\n---\nupdated-dependencies:\n- dependency-name: clipboardy\n  depend\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump clipboardy from 4.0.0 to 5.0.2 (#1018)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-16T18:57:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ea7b22724c3c507c5ed9a790ee278b66d99dcf0",
          "body": "Bumps [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js) from 9.39.1 to 9.39.2.\n- [Release notes](https://github.com/eslint/eslint/releases)\n- [Commits](https://github.com/eslint/eslint/commits/v9.39.2/packages/js)\n\n---\nupdated-dependencies:\n- dependency-name: \"@eslint/js\"\n  depend\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump @eslint/js from 9.39.1 to 9.39.2 (#1017)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-13T21:41:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4df0f5436257c400972fa877b6e0549362c29269",
          "body": "Bumps [eslint](https://github.com/eslint/eslint) from 9.39.0 to 9.39.2.\n- [Release notes](https://github.com/eslint/eslint/releases)\n- [Commits](https://github.com/eslint/eslint/compare/v9.39.0...v9.39.2)\n\n---\nupdated-dependencies:\n- dependency-name: eslint\n  dependency-version: 9.39.2\n  dependency-\n[…]\nrect:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps-dev): bump eslint from 9.39.0 to 9.39.2 (#1020)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-13T21:41:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "48276fe763b5fd115f04e81d874ef1782fb46e6a",
          "body": "Bumps [ghauth](https://github.com/rvagg/ghauth) from 6.0.13 to 6.0.19.\n- [Release notes](https://github.com/rvagg/ghauth/releases)\n- [Changelog](https://github.com/rvagg/ghauth/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/rvagg/ghauth/compare/v6.0.13...v6.0.19)\n\n---\nupdated-dependencies:\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ghauth from 6.0.13 to 6.0.19 (#1021)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-13T21:40:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b8686072ce6628ddca80d32913555ba1f7d54bb",
          "body": "Bumps [semver](https://github.com/npm/node-semver) from 7.7.2 to 7.7.3.\n- [Release notes](https://github.com/npm/node-semver/releases)\n- [Changelog](https://github.com/npm/node-semver/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/npm/node-semver/compare/v7.7.2...v7.7.3)\n\n---\nupdated-depende\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump semver from 7.7.2 to 7.7.3 (#1019)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-13T21:39:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "45861633306db130a587174d6abda676694f1447",
          "body": "… (#1032)",
          "is_bot": false,
          "headline": "fix(git-node): do not enforce minimum wait time for release proposals…",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-13T14:28:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21fe4732ba20cf57332341941de448a93d107319",
          "body": "…033)",
          "is_bot": false,
          "headline": "fix(git-node): use stash and detached head for release operations (#1…",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-03-13T13:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63171d7553ced640393476346d28a82fd9e4ccce",
          "body": null,
          "is_bot": false,
          "headline": "chore: optimize the Conventional Commit Linter workflow (#1031)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-02-04T15:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19b468ad088a8200eabdc94a96f58a6027e2fc11",
          "body": null,
          "is_bot": false,
          "headline": "feat: add list detail of failed GHA jobs (#960)",
          "author_name": "Alex Yang",
          "author_login": "himself65",
          "committed_at": "2026-01-15T22:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37604ef61465a614f2a645e170db57d6a041eb34",
          "body": "Using the full URL should be preferred as that's the path to the least\nsurprise, but passing only PR number should not error.",
          "is_bot": false,
          "headline": "fix(git-node): promoting a release using only PR number (#1028)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-01-10T13:59:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6ab4fc9a374752f10ad4977995e12c4583d92e0",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.1.1 (#1027)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-01-05T17:58:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cc0b130f0b64dd7644c22c03a38c6ff6c180229",
          "body": null,
          "is_bot": false,
          "headline": "fix(auth): validation of H1 tokens (#1026)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2026-01-05T09:01:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "219ead464d38edf383298891ea9b20cec8b4c8ca",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.1.0 (#1023)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2026-01-02T18:34:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89df0538426b32826db9f8e39a3d1f687d42abaa",
          "body": "Fixes: https://github.com/nodejs-private/security-release/issues/47",
          "is_bot": false,
          "headline": "feat: automatically include cveId trailling (#1022)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-01-02T15:55:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f15adf903d91213e0042bdc108ddd8dab356769a",
          "body": null,
          "is_bot": false,
          "headline": "fix: improve suggestion next patch or next minor version (#1014)",
          "author_name": "Rafael Gonzaga",
          "author_login": "RafaelGSS",
          "committed_at": "2026-01-02T15:55:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ced7c25d32df5f2ef0dd540d1ed1cd352eb43e5",
          "body": null,
          "is_bot": false,
          "headline": "chore(main): release 6.0.0 (#992)",
          "author_name": "Node.js GitHub Bot",
          "author_login": "nodejs-github-bot",
          "committed_at": "2025-12-21T11:14:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ed551c94e5f733d5e8533ea53b69faad1ff04c2",
          "body": "Bumps [listr2](https://github.com/listr2/listr2) from 8.3.3 to 9.0.5.\n- [Release notes](https://github.com/listr2/listr2/releases)\n- [Changelog](https://github.com/listr2/listr2/blob/master/release.config.js)\n- [Commits](https://github.com/listr2/listr2/compare/listr2@8.3.3...listr2@9.0.5)\n\n---\nupda\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump listr2 from 8.3.3 to 9.0.5 (#1012)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-21T11:11:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aadc4fcb9c8d889424ddf51bd38a0dca1a8ec375",
          "body": "Add `git node v8 deps` to (re)sync V8 dependencies from V8's `DEPS`\nfile.",
          "is_bot": false,
          "headline": "feat(v8): add command to sync V8 deps (#1016)",
          "author_name": "Richard Lau",
          "author_login": "richardlau",
          "committed_at": "2025-12-20T22:07:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d05ef11a1501cecd4243f97eeb5b1517b88e777b",
          "body": null,
          "is_bot": false,
          "headline": "docs: nudge users into using partially encrypted config files (#1005)",
          "author_name": "Antoine du Hamel",
          "author_login": "aduh95",
          "committed_at": "2025-12-16T15:06:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2588b0c472b3788dd035f2132e3fe180d0927f5d",
          "body": null,
          "is_bot": false,
          "headline": "chore: update `@pkgjs/nv` to v0.3.0 (#1015)",
          "author_name": "Michaël Zasso",
          "author_login": "targos",
          "committed_at": "2025-12-15T14:57:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13dbcaf4980b27ff6b57c4c148661d29dd6a413d",
          "body": "Bumps [cheerio](https://github.com/cheeriojs/cheerio) from 1.1.0 to 1.1.2.\n- [Release notes](https://github.com/cheeriojs/cheerio/releases)\n- [Commits](https://github.com/cheeriojs/cheerio/compare/v1.1.0...v1.1.2)\n\n---\nupdated-dependencies:\n- dependency-name: cheerio\n  dependency-version: 1.1.2\n  de\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump cheerio from 1.1.0 to 1.1.2 (#1010)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-11T22:38:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 92,
      "commits_last_year": 147,
      "latest_release_at": "2026-05-13T06:44:27Z",
      "latest_release_tag": "v6.4.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 33,
      "days_since_latest_release": 73,
      "mean_days_between_releases": 15.9
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@node-core/utils",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@node-core/utils",
          "is_deprecated": false,
          "latest_version": "6.4.0",
          "repository_url": "https://github.com/nodejs/node-core-utils",
          "versions_count": 45,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 3333,
          "first_published_at": "2023-09-24T21:30:09.734000Z",
          "latest_published_at": "2026-05-13T06:44:48.878000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 73
        }
      ]
    },
    "popularity": {
      "forks": 131,
      "stars": 313,
      "watchers": 17,
      "fork_history": {
        "days": [
          {
            "date": "2017-10-23",
            "count": 1
          },
          {
            "date": "2017-10-26",
            "count": 1
          },
          {
            "date": "2017-10-30",
            "count": 2
          },
          {
            "date": "2017-10-31",
            "count": 1
          },
          {
            "date": "2017-11-01",
            "count": 1
          },
          {
            "date": "2017-11-02",
            "count": 2
          },
          {
            "date": "2017-11-04",
            "count": 1
          },
          {
            "date": "2017-11-10",
            "count": 2
          },
          {
            "date": "2017-11-11",
            "count": 1
          },
          {
            "date": "2017-11-13",
            "count": 1
          },
          {
            "date": "2017-11-20",
            "count": 1
          },
          {
            "date": "2017-11-25",
            "count": 1
          },
          {
            "date": "2018-01-07",
            "count": 2
          },
          {
            "date": "2018-01-18",
            "count": 1
          },
          {
            "date": "2018-01-29",
            "count": 1
          },
          {
            "date": "2018-02-16",
            "count": 1
          },
          {
            "date": "2018-03-05",
            "count": 2
          },
          {
            "date": "2018-03-08",
            "count": 1
          },
          {
            "date": "2018-03-12",
            "count": 1
          },
          {
            "date": "2018-03-16",
            "count": 1
          },
          {
            "date": "2018-04-17",
            "count": 1
          },
          {
            "date": "2018-07-06",
            "count": 1
          },
          {
            "date": "2018-07-16",
            "count": 1
          },
          {
            "date": "2018-08-09",
            "count": 1
          },
          {
            "date": "2018-09-13",
            "count": 1
          },
          {
            "date": "2018-10-05",
            "count": 1
          },
          {
            "date": "2018-10-12",
            "count": 1
          },
          {
            "date": "2018-10-13",
            "count": 1
          },
          {
            "date": "2018-11-06",
            "count": 1
          },
          {
            "date": "2018-11-13",
            "count": 1
          },
          {
            "date": "2018-11-19",
            "count": 1
          },
          {
            "date": "2018-12-11",
            "count": 1
          },
          {
            "date": "2019-01-10",
            "count": 1
          },
          {
            "date": "2019-02-07",
            "count": 1
          },
          {
            "date": "2019-04-18",
            "count": 1
          },
          {
            "date": "2019-04-19",
            "count": 1
          },
          {
            "date": "2019-06-26",
            "count": 1
          },
          {
            "date": "2019-08-01",
            "count": 1
          },
          {
            "date": "2019-08-11",
            "count": 1
          },
          {
            "date": "2019-09-07",
            "count": 1
          },
          {
            "date": "2019-09-11",
            "count": 1
          },
          {
            "date": "2019-11-27",
            "count": 1
          },
          {
            "date": "2020-02-19",
            "count": 1
          },
          {
            "date": "2020-03-11",
            "count": 1
          },
          {
            "date": "2020-04-28",
            "count": 1
          },
          {
            "date": "2020-05-18",
            "count": 1
          },
          {
            "date": "2020-05-30",
            "count": 1
          },
          {
            "date": "2020-06-04",
            "count": 2
          },
          {
            "date": "2020-07-13",
            "count": 1
          },
          {
            "date": "2020-08-14",
            "count": 2
          },
          {
            "date": "2020-09-01",
            "count": 2
          },
          {
            "date": "2020-12-01",
            "count": 1
          },
          {
            "date": "2021-01-31",
            "count": 1
          },
          {
            "date": "2021-02-12",
            "count": 1
          },
          {
            "date": "2021-03-04",
            "count": 3
          },
          {
            "date": "2021-03-28",
            "count": 1
          },
          {
            "date": "2021-04-16",
            "count": 1
          },
          {
            "date": "2021-05-10",
            "count": 1
          },
          {
            "date": "2021-07-14",
            "count": 1
          },
          {
            "date": "2021-07-20",
            "count": 1
          },
          {
            "date": "2021-07-28",
            "count": 1
          },
          {
            "date": "2021-09-11",
            "count": 1
          },
          {
            "date": "2021-09-21",
            "count": 1
          },
          {
            "date": "2022-01-08",
            "count": 1
          },
          {
            "date": "2022-02-02",
            "count": 1
          },
          {
            "date": "2022-03-21",
            "count": 1
          },
          {
            "date": "2022-04-25",
            "count": 1
          },
          {
            "date": "2022-04-26",
            "count": 1
          },
          {
            "date": "2022-05-15",
            "count": 1
          },
          {
            "date": "2022-06-06",
            "count": 1
          },
          {
            "date": "2022-06-22",
            "count": 1
          },
          {
            "date": "2022-07-04",
            "count": 1
          },
          {
            "date": "2022-07-19",
            "count": 1
          },
          {
            "date": "2022-08-11",
            "count": 1
          },
          {
            "date": "2022-09-15",
            "count": 1
          },
          {
            "date": "2022-10-20",
            "count": 1
          },
          {
            "date": "2022-11-06",
            "count": 1
          },
          {
            "date": "2023-02-08",
            "count": 1
          },
          {
            "date": "2023-02-21",
            "count": 1
          },
          {
            "date": "2023-02-24",
            "count": 1
          },
          {
            "date": "2023-02-27",
            "count": 1
          },
          {
            "date": "2023-03-10",
            "count": 1
          },
          {
            "date": "2023-05-19",
            "count": 1
          },
          {
            "date": "2023-05-31",
            "count": 1
          },
          {
            "date": "2023-06-18",
            "count": 1
          },
          {
            "date": "2023-08-01",
            "count": 1
          },
          {
            "date": "2023-08-16",
            "count": 1
          },
          {
            "date": "2023-12-04",
            "count": 1
          },
          {
            "date": "2024-01-31",
            "count": 1
          },
          {
            "date": "2024-04-16",
            "count": 1
          },
          {
            "date": "2024-05-13",
            "count": 1
          },
          {
            "date": "2024-05-31",
            "count": 1
          },
          {
            "date": "2024-06-19",
            "count": 1
          },
          {
            "date": "2024-08-09",
            "count": 1
          },
          {
            "date": "2024-08-26",
            "count": 1
          },
          {
            "date": "2024-09-19",
            "count": 1
          },
          {
            "date": "2024-09-26",
            "count": 1
          },
          {
            "date": "2024-12-22",
            "count": 1
          },
          {
            "date": "2025-06-07",
            "count": 1
          },
          {
            "date": "2025-07-23",
            "count": 1
          },
          {
            "date": "2025-08-09",
            "count": 1
          },
          {
            "date": "2025-08-11",
            "count": 1
          },
          {
            "date": "2025-09-07",
            "count": 1
          },
          {
            "date": "2025-10-06",
            "count": 1
          },
          {
            "date": "2025-11-01",
            "count": 1
          },
          {
            "date": "2026-02-23",
            "count": 1
          },
          {
            "date": "2026-03-01",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          },
          {
            "date": "2026-04-29",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-05-14",
            "count": 1
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-06-10",
            "count": 1
          },
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-07-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 127,
        "total_forks": 131
      },
      "star_history": null,
      "open_issues_and_prs": 86
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 80496,
      "source_files_sampled": 128,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "2.4.1",
            "severity": "moderate",
            "ecosystem": "npm",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-p9pc-299p-vxgp"
            ],
            "fixed_version": "18.1.1",
            "advisory_count": 1,
            "oldest_advisory_days": 2150
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "moderate": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 425,
        "malicious_count": 0,
        "assessed_package": "npm:@node-core/utils@6.4.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@inquirer/prompts",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.4.1"
        },
        {
          "name": "@listr2/prompt-adapter-enquirer",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.12"
        },
        {
          "name": "@node-core/caritat",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@pkgjs/nv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "branch-diff",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.1.1"
        },
        {
          "name": "chalk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.1"
        },
        {
          "name": "changelog-maker",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.4.1"
        },
        {
          "name": "cheerio",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.0"
        },
        {
          "name": "clipboardy",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.2"
        },
        {
          "name": "core-validate-commit",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "figures",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.1.0"
        },
        {
          "name": "ghauth",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.1"
        },
        {
          "name": "git-secure-tag",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.3.1"
        },
        {
          "name": "js-yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.1"
        },
        {
          "name": "listr2",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.5"
        },
        {
          "name": "lodash",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.17.21"
        },
        {
          "name": "log-symbols",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "ora",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "replace-in-file",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.3.0"
        },
        {
          "name": "semver",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.7.1"
        },
        {
          "name": "smol-toml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.7.0"
        },
        {
          "name": "undici",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.3.0"
        },
        {
          "name": "which",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.0.0"
        },
        {
          "name": "yargs",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^18.0.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "@inquirer/prompts",
            "direct": true,
            "version": "^7.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@listr2/prompt-adapter-enquirer",
            "direct": true,
            "version": "^2.0.12",
            "ecosystem": "npm"
          },
          {
            "name": "@node-core/caritat",
            "direct": true,
            "version": "^1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/nv",
            "direct": true,
            "version": "^0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "branch-diff",
            "direct": true,
            "version": "^3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": true,
            "version": "^5.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "changelog-maker",
            "direct": true,
            "version": "^4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "cheerio",
            "direct": true,
            "version": "^1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "clipboardy",
            "direct": true,
            "version": "^5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "core-validate-commit",
            "direct": true,
            "version": "^6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "figures",
            "direct": true,
            "version": "^6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ghauth",
            "direct": true,
            "version": "^7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "git-secure-tag",
            "direct": true,
            "version": "^2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "^5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "listr2",
            "direct": true,
            "version": "^9.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "lodash",
            "direct": true,
            "version": "^4.17.21",
            "ecosystem": "npm"
          },
          {
            "name": "log-symbols",
            "direct": true,
            "version": "^7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ora",
            "direct": true,
            "version": "^9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "replace-in-file",
            "direct": true,
            "version": "^8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": true,
            "version": "^7.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "smol-toml",
            "direct": true,
            "version": "^1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici",
            "direct": true,
            "version": "^8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": true,
            "version": "^7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": true,
            "version": "^18.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "^9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "@reporters/github",
            "direct": false,
            "version": "^1.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "c8",
            "direct": false,
            "version": "^11.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "^9.39.4",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-import",
            "direct": false,
            "version": "^2.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-n",
            "direct": false,
            "version": "^17.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-promise",
            "direct": false,
            "version": "^7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "^17.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "neostandard",
            "direct": false,
            "version": "^0.13.0",
            "ecosystem": "npm"
          },
          {
            "name": "sinon",
            "direct": false,
            "version": "^22.0.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 34,
        "direct_count": 24,
        "indirect_count": 10
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 23,
        "merged_prs": 772,
        "open_issues": 63,
        "closed_ratio": 0.761,
        "closed_issues": 201,
        "closed_unmerged_prs": 66
      },
      "bus_factor": 3,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "joyeecheung",
          "commits": 212,
          "avatar_url": "https://avatars.githubusercontent.com/u/4299420?v=4"
        },
        {
          "type": "User",
          "login": "targos",
          "commits": 110,
          "avatar_url": "https://avatars.githubusercontent.com/u/2352663?v=4"
        },
        {
          "type": "User",
          "login": "aduh95",
          "commits": 109,
          "avatar_url": "https://avatars.githubusercontent.com/u/14309773?v=4"
        },
        {
          "type": "User",
          "login": "RafaelGSS",
          "commits": 68,
          "avatar_url": "https://avatars.githubusercontent.com/u/26234614?v=4"
        },
        {
          "type": "User",
          "login": "codebytere",
          "commits": 39,
          "avatar_url": "https://avatars.githubusercontent.com/u/2036040?v=4"
        },
        {
          "type": "User",
          "login": "nodejs-github-bot",
          "commits": 28,
          "avatar_url": "https://avatars.githubusercontent.com/u/18269663?v=4"
        },
        {
          "type": "User",
          "login": "priyank-p",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/23620441?v=4"
        },
        {
          "type": "User",
          "login": "VoltrexKeyva",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/62040526?v=4"
        },
        {
          "type": "User",
          "login": "mmarchini",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/4048656?v=4"
        },
        {
          "type": "User",
          "login": "marco-ippolito",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/36735501?v=4"
        }
      ],
      "contributors_sampled": 67,
      "top_contributor_share": 0.262
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "commitlint.yml",
        "nodejs.yml",
        "release-please.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 5,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 73 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "21 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "c263c2ae7d9be82feb79766a89a7bdaf5527b86b",
        "ran_at": "2026-07-25T21:04:31Z",
        "aggregate_score": 6.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T13:39:51Z",
      "oldest_open_prs": [
        {
          "number": 390,
          "created_at": "2020-03-07T04:07:32Z",
          "last_comment_at": "2020-08-15T00:27:56Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 475,
          "created_at": "2020-08-15T04:41:55Z",
          "last_comment_at": "2020-12-28T00:47:25Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 546,
          "created_at": "2021-05-10T19:14:25Z",
          "last_comment_at": "2021-05-11T13:45:52Z",
          "last_comment_author": "DeeDeeG"
        },
        {
          "number": 642,
          "created_at": "2022-07-19T13:59:48Z",
          "last_comment_at": "2023-02-23T09:18:42Z",
          "last_comment_author": "aduh95"
        },
        {
          "number": 759,
          "created_at": "2023-12-04T16:47:47Z",
          "last_comment_at": "2024-04-26T12:30:34Z",
          "last_comment_author": "joyeecheung"
        },
        {
          "number": 760,
          "created_at": "2023-12-04T16:58:42Z",
          "last_comment_at": "2025-11-15T11:08:41Z",
          "last_comment_author": "aduh95"
        },
        {
          "number": 865,
          "created_at": "2024-11-02T21:35:45Z",
          "last_comment_at": "2024-11-04T10:05:46Z",
          "last_comment_author": "VoltrexKeyva"
        },
        {
          "number": 875,
          "created_at": "2024-11-27T17:37:59Z",
          "last_comment_at": "2025-04-08T21:34:38Z",
          "last_comment_author": "ruyadorno"
        },
        {
          "number": 881,
          "created_at": "2024-12-23T22:51:07Z",
          "last_comment_at": "2025-01-09T01:28:25Z",
          "last_comment_author": "joyeecheung"
        },
        {
          "number": 883,
          "created_at": "2025-01-08T15:54:23Z",
          "last_comment_at": "2025-01-08T16:17:28Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 920,
          "created_at": "2025-04-05T16:39:13Z",
          "last_comment_at": "2025-04-09T15:33:58Z",
          "last_comment_author": "aduh95"
        },
        {
          "number": 940,
          "created_at": "2025-06-15T17:54:07Z",
          "last_comment_at": "2025-06-15T21:01:53Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1076,
          "created_at": "2026-05-12T15:36:19Z",
          "last_comment_at": "2026-05-12T15:38:18Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1077,
          "created_at": "2026-05-14T06:14:59Z",
          "last_comment_at": "2026-07-21T19:53:47Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1079,
          "created_at": "2026-05-22T14:09:17Z",
          "last_comment_at": "2026-05-27T19:41:57Z",
          "last_comment_author": "RafaelGSS"
        },
        {
          "number": 1082,
          "created_at": "2026-05-27T09:51:04Z",
          "last_comment_at": "2026-05-27T09:52:03Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1090,
          "created_at": "2026-06-07T09:31:44Z",
          "last_comment_at": "2026-06-07T09:32:38Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1091,
          "created_at": "2026-06-07T10:08:12Z",
          "last_comment_at": "2026-06-07T10:09:03Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1093,
          "created_at": "2026-06-13T19:46:48Z",
          "last_comment_at": "2026-06-13T19:48:05Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 1098,
          "created_at": "2026-06-20T19:46:45Z",
          "last_comment_at": "2026-07-01T20:05:12Z",
          "last_comment_author": "avivkeller"
        }
      ],
      "last_merged_pr_at": "2026-07-24T13:38:49Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 97,
          "created_at": "2017-11-09T10:13:00Z",
          "last_comment_at": "2020-08-18T00:28:28Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 204,
          "created_at": "2018-03-07T12:32:38Z",
          "last_comment_at": "2021-02-16T00:33:53Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 211,
          "created_at": "2018-03-09T15:38:23Z",
          "last_comment_at": "2020-11-16T00:29:22Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 230,
          "created_at": "2018-04-06T08:01:12Z",
          "last_comment_at": "2021-02-22T00:34:55Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 233,
          "created_at": "2018-04-08T14:02:55Z",
          "last_comment_at": "2020-11-15T00:29:27Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 258,
          "created_at": "2018-06-20T18:52:16Z",
          "last_comment_at": "2020-08-16T00:29:39Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 268,
          "created_at": "2018-08-06T08:32:23Z",
          "last_comment_at": "2020-11-15T00:29:25Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 313,
          "created_at": "2018-11-22T07:52:57Z",
          "last_comment_at": "2020-08-17T00:30:05Z",
          "last_comment_author": "priyank-p"
        },
        {
          "number": 321,
          "created_at": "2018-12-04T09:43:12Z",
          "last_comment_at": "2020-08-16T00:29:31Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 343,
          "created_at": "2019-04-29T02:51:56Z",
          "last_comment_at": "2020-08-15T00:28:10Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 356,
          "created_at": "2019-06-19T07:42:35Z",
          "last_comment_at": "2020-08-15T00:28:06Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 357,
          "created_at": "2019-06-19T07:46:59Z",
          "last_comment_at": "2021-02-22T00:34:54Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 382,
          "created_at": "2019-12-13T16:44:38Z",
          "last_comment_at": "2020-08-15T00:27:58Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 391,
          "created_at": "2020-03-11T15:58:15Z",
          "last_comment_at": "2020-08-15T00:27:55Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 394,
          "created_at": "2020-03-12T02:51:08Z",
          "last_comment_at": "2020-08-15T00:27:53Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 396,
          "created_at": "2020-03-16T21:15:52Z",
          "last_comment_at": "2020-08-15T00:27:51Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 398,
          "created_at": "2020-03-25T22:28:34Z",
          "last_comment_at": "2020-08-15T00:27:49Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 425,
          "created_at": "2020-05-24T01:29:51Z",
          "last_comment_at": "2020-11-11T00:23:30Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 428,
          "created_at": "2020-05-30T02:53:10Z",
          "last_comment_at": "2020-12-02T00:34:10Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 442,
          "created_at": "2020-06-27T01:23:59Z",
          "last_comment_at": "2020-09-27T00:37:37Z",
          "last_comment_author": "github-actions"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/nodejs/node-core-utils",
    "host": "github.com",
    "name": "node-core-utils",
    "owner": "nodejs"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 82,
      "inputs": {
        "security": 67,
        "vitality": 92,
        "community": 70,
        "governance": 84,
        "engineering": 90
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 92,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "commits_last_year": 147,
              "human_commit_share": 0.73,
              "days_since_last_push": 1,
              "active_weeks_last_year": 33
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "33/52 weeks with commits",
                "points": 22.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 33
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "147 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 147
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 92,
              "latest_release_tag": "v6.4.0",
              "releases_from_tags": false,
              "days_since_latest_release": 73,
              "mean_days_between_releases": 15.9
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "92 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 92
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 73 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 73
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~15.9 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 15.9
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 70,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "forks": 131,
              "stars": 313,
              "watchers": 17,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "313 stars",
                "points": 40.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 313
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "131 forks",
                "points": 17.6,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 131
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "17 watchers",
                "points": 6.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 59,
            "inputs": {
              "packages": [
                "@node-core/utils"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 3333
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,333 downloads/month across npm",
                "points": 47,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3333,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 84,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "bus_factor": 3,
              "contributors_sampled": 67,
              "top_contributor_share": 0.262
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "3 contributor(s) cover half of all commits",
                "points": 36,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 26% of commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 26
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "67 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 67
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 73 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "merged_prs": 772,
              "open_issues": 63,
              "closed_issues": 201,
              "issue_closed_ratio": 0.761,
              "closed_unmerged_prs": 66
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "76% of issues closed",
                "points": 35.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 76
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "772/838 decided PRs merged",
                "points": 35.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 772,
                      "decided": 838
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "followers": 16225,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "nodejs",
              "public_repos": 231,
              "account_age_days": 4260
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "16,225 followers of nodejs",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 16225,
                      "login": "nodejs"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "231 public repos, account ~11 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 231
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@node-core/utils"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 73
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 73 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 73
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "45 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 45
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 90,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "nodejs",
                "node"
              ],
              "has_wiki": false,
              "homepage": "https://nodejs.github.io/node-core-utils/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://nodejs.github.io/node-core-utils/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "2 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 67,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 73 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "21 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Matched the npm:@node-core/utils@6.4.0 runtime dependency closure — what installing the published package pulls in — 425 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@node-core/utils@6.4.0",
                  "assessed": 425
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 85,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 425,
              "unassessed_packages": 0,
              "affected_by_severity": "moderate 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: yargs-parser 2.4.1 (moderate 5.3)",
                "points": 14.4,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "yargs-parser 2.4.1 (moderate 5.3)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 2150 days ago",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 2150
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 425,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 20
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 43,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "73 of 73 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 73,
                      "sampled": 73
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.27
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "27 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 27,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 80496,
              "source_files_sampled": 128,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/128 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 128,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T21:04:59.157532Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/nodejs/node-core-utils.svg",
  "full_name": "nodejs/node-core-utils",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsnpm.