Public record
Software health reportschema 0.27.0 · metrics 2.5.0 · 2026-07-29 16:54 UTC

openziti / sdk-golang

Ziti SDK for Golang

GoApache-2.0★ 130 stars⑂ 33 forkssince Nov 2019View on GitHub ↗

openziti/sdk-golang holds a health index of 91 out of 100, placing it in the Excellent band. It scores highest on Vitality (90/100) and lowest on AI Readiness (69/100). It was last updated 8 days ago. 2 contributors account for most of its recent work.

91
overall / 100
Excellent

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean, calibrated against the distribution of the public record so bands carry percentile meaning; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At Risk ceiling of 34.

91
Exceptional93-100The record's top tier (≈ top 5%); essentially all checked criteria met
Excellent80-92Strong across the board; minor gaps
Good65-79Healthy; gaps are limited and manageable
Moderate50-64Acceptable with notable gaps; review recommended
Weak35-49Material weaknesses across several areas
At Risk20-34Significant weaknesses; adoption warrants caution
Critical1-19Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

The weighted overall 77 is calibrated to 91 on the published index scale (record calibration 2026-08-02).

Ownership

OpenZitiOrganization
990 followers89 public repossince May 2020

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/openziti/sdk-golang/v2v2.0.0-pre3-39 days ago
Gogithub.com/openziti/sdk-golangv1.9.0-78846 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

90Excellent · 21% of overall
How it's scored
28.8/36Push recency — last push 8 days ago
27/36Commit cadence — 39/52 weeks with commits
18/18Commit volume — 180 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year180
human_commit_share0.93
days_since_last_push8
active_weeks_last_year39

Release discipline

100Exceptional
How it's scored
27/27Ships releases — 30 releases published
36/36Release recency — latest release 46 days ago
27/27Release cadence — a release every ~12.5 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count30
latest_release_tagv1.9.0
releases_from_tagsno
days_since_latest_release46
mean_days_between_releases12.5
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

71Good · 17% of overall
How it's scored
34.2/60Stars — 130 stars
12.5/25Forks — 33 forks
5.3/15Watchers — 10 watchers
Inputs used
forks33
stars130
watchers10
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Community health

93Exceptional
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
7.2/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
readme_badges
has_contributingyes
has_issue_templateyes
has_code_of_conductyes
readme_badge_services
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

77Good · 23% of overall
How it's scored
25.2/54Bus factor — 2 contributor(s) cover half of all commits
13.3/22.5Commit distribution — top contributor authored 41% of commits
13.5/13.5Contributor breadth — 20 contributors
10/10OpenSSF Scorecard: Contributors — project has 6 contributing companies or organizations
Inputs used
bus_factor2
contributors_sampled20
top_contributor_share0.408
How it's scored
34.6/42Issue resolution — 82% of issues closed
17.9/30PR acceptance — 478/800 decided PRs merged
0/13Newcomer PR acceptance — no first-time contributor's PR decided in 30d
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Inputs used
merged_prs478
open_issues31
closed_issues146
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0.825
closed_unmerged_prs322
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Excluded from scoring (no data or not applicable): newcomer_pr_acceptance. Remaining weights renormalized.
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
21.5/25Owner reach — 990 followers of openziti
25/25Track record — 89 public repos, account ~6 yr old
Inputs used
followers990
owner_typeOrganization
is_verified
owner_loginopenziti
public_repos89
account_age_days2,260

Package maintenance

100Exceptional
How it's scored
25/25Published & resolvable — 2 package(s) on go
35/35Publish recency — latest publish 9 days ago
20/20Version history — 788 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/openziti/sdk-golang/v2, github.com/openziti/sdk-golang
ecosystemsgo
any_deprecatedno
min_days_since_publish9

Engineering Quality

Are baseline engineering and documentation practices in place?

74Good · 19% of overall
How it's scored
24/24CI workflows — 7 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yml
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configno

Documentation

60Moderate
How it's scored
30/30README
0/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
10/10Topics — 15 topics
10/10Wiki
Inputs used
topicsgolang, networking, sdk, zero-trust, appsec, netsec, openziti, secure-networking, ztaa, ztna, security, zerotrust, zero-trust-network, zero-trust-network-access, zero-trust-security
has_wikiyes
homepage
has_readmeyes
has_docs_dirno
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

71Good · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 6 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
4.5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate6.4
Excluded from scoring (no data or not applicable): branch_protection, packaging, signed_releases. Remaining weights renormalized.

Dependency advisories

100Exceptional
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories13
affected_packages8
assessed_packages186
unassessed_packages0
affected_by_severitycritical 1, high 3, moderate 1, unknown 3
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 186 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight (4%): agent tooling is a real maintenance signal, but a repository with none can still reach 100/100.

69Good · 4% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 81 of 93 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.871
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — acceptance/go.mod, example/go.mod, example/influxdb-client-go/go.mod (toolchain convention, no task runner)
22/22Automated tests
11/11Lint / format config — .golangci.yml
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 7 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifestsacceptance/go.mod, example/go.mod, example/influxdb-client-go/go.mod, go.mod
dependency_bot_commit_share0.07
How it's scored
45/45Type-checkable code — Go (statically typed)
54.4/55Manageable file sizes — 2/192 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes147,249
source_files_sampled192
oversized_source_files2
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — pb/edge_client_pb/edge_client.proto
0/20MCP server
40/40Runnable examples — example
Inputs used
example_dirsexample
has_mcp_signalno
api_schema_filespb/edge_client_pb/edge_client.proto

Key facts

130GitHub stars
20contributors
180commits, last 12 months
8days since last push
30releases
2bus factor
31open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 33 ⇿
0Stars
33Forks
30Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

01325383322020-092023-082026-06
Major 0Minor 8Patch 20

Each point covers 6 days.

OpenSSF Scorecard 6.4 / 10
6.4aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-29 16:53 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 6 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
9Security-Policysecurity policy file detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
3Vulnerabilities7 existing vulnerabilities detected
Direct dependencies 38
RegistryPackageVersion constraintManifest
Gogithub.com/golang-jwt/jwt/v5v5.3.1acceptance/go.mod
Gogithub.com/michaelquigley/pfxlogv0.6.10acceptance/go.mod
Gogithub.com/openziti/edge-apiv0.35.0acceptance/go.mod
Gogithub.com/sirupsen/logrusv1.9.4acceptance/go.mod
Gogithub.com/stretchr/testifyv1.11.1acceptance/go.mod
Gogolang.org/x/modv0.37.0acceptance/go.mod
Gogopkg.in/yaml.v3v3.0.1acceptance/go.mod
Gogithub.com/openziti/sdk-golang/v2v2.0.0acceptance/go.mod
Gogithub.com/Jeffail/gabsv1.4.0go.mod
Gogithub.com/cenkalti/backoff/v4v4.3.0go.mod
Gogithub.com/emirpasic/godsv1.18.1go.mod
Gogithub.com/fullsailor/pkcs7v0.0.0-20190404230743-d7302db945fago.mod
Gogithub.com/go-openapi/runtimev0.32.3go.mod
Gogithub.com/go-openapi/strfmtv0.26.3go.mod
Gogithub.com/go-resty/resty/v2v2.17.2go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/kataras/go-eventsv0.0.3go.mod
Gogithub.com/michaelquigley/pfxlogv0.6.10go.mod
Gogithub.com/mitchellh/mapstructurev1.5.0go.mod
Gogithub.com/openziti/channel/v5v5.0.10go.mod
Gogithub.com/openziti/edge-apiv0.35.0go.mod
Gogithub.com/openziti/foundation/v2v2.0.95go.mod
Gogithub.com/openziti/identityv1.0.133go.mod
Gogithub.com/openziti/metricsv1.4.5go.mod
Gogithub.com/openziti/secretstreamv0.1.51go.mod
Gogithub.com/openziti/transport/v2v2.0.216go.mod
Gogithub.com/orcaman/concurrent-map/v2v2.0.1go.mod
Gogithub.com/pkg/errorsv0.9.1go.mod
Gogithub.com/rcrowley/go-metricsv0.0.0-20250401214520-65e299d6c5c9go.mod
Gogithub.com/shirou/gopsutil/v4v4.26.5go.mod
Gogithub.com/sirupsen/logrusv1.9.4go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/zitadel/oidc/v3v3.47.5go.mod
Gogo.mozilla.org/pkcs7v0.9.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/sysv0.46.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
All dependencies 186

Full resolved dependency set from the GitHub dependency graph: 33 direct and 153 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/cenkalti/backoff/v4v4.3.0direct
Gogithub.com/emirpasic/godsv1.18.1direct
Gogithub.com/fullsailor/pkcs7v0.0.0-20190404230743-d7302db945fadirect
Gogithub.com/go-openapi/runtimev0.32.3direct
Gogithub.com/go-openapi/strfmtv0.26.3direct
Gogithub.com/go-resty/resty/v2v2.17.2direct
Gogithub.com/golang-jwt/jwt/v5v5.3.1direct
Gogithub.com/google/uuidv1.6.0direct
Gogithub.com/jeffail/gabsv1.4.0direct
Gogithub.com/kataras/go-eventsv0.0.3direct
Gogithub.com/michaelquigley/pfxlogv0.6.10direct
Gogithub.com/mitchellh/mapstructurev1.5.0direct
Gogithub.com/openziti/channel/v5v5.0.10direct
Gogithub.com/openziti/edge-apiv0.34.1-0.20260703041337-e7f938dcaa70direct
Gogithub.com/openziti/edge-apiv0.35.0direct
Gogithub.com/openziti/foundation/v2v2.0.95direct
Gogithub.com/openziti/identityv1.0.133direct
Gogithub.com/openziti/metricsv1.4.5direct
Gogithub.com/openziti/secretstreamv0.1.51direct
Gogithub.com/openziti/transport/v2v2.0.216direct
Gogithub.com/orcaman/concurrent-map/v2v2.0.1direct
Gogithub.com/pkg/errorsv0.9.1direct
Gogithub.com/rcrowley/go-metricsv0.0.0-20250401214520-65e299d6c5c9direct
Gogithub.com/shirou/gopsutil/v4v4.26.5direct
Gogithub.com/sirupsen/logrusv1.9.4direct
Gogithub.com/stretchr/testifyv1.11.1direct
Gogithub.com/zitadel/oidc/v3v3.47.5direct
Gogo.mozilla.org/pkcs7v0.9.0direct
Gogolang.org/x/modv0.37.0direct
Gogolang.org/x/oauth2v0.36.0direct
Gogolang.org/x/sysv0.46.0direct
Gogoogle.golang.org/protobufv1.36.11direct
Gogopkg.in/yaml.v3v3.0.1direct
Gogithub.com/alecthomas/chromav0.10.0indirect
Gogithub.com/andybalholm/brotliv1.0.5indirect
Gogithub.com/apapsch/go-jsonmerge/v2v2.0.0indirect
Gogithub.com/aymerick/douceurv0.2.0indirect
Gogithub.com/burntsushi/tomlv1.3.2indirect
Gogithub.com/bytedance/sonicv1.10.1indirect
Gogithub.com/cespare/xxhash/v2v2.3.0indirect
Gogithub.com/chenzhuoyu/base64xv0.0.0-20230717121745-296ad89f973dindirect
Gogithub.com/chenzhuoyu/iasmv0.9.0indirect
Gogithub.com/clipperhouse/uax29/v2v2.2.0indirect
Gogithub.com/cloudykit/fastprinterv0.0.0-20200109182630-33d98a066a53indirect
Gogithub.com/cloudykit/jet/v6v6.2.0indirect
Gogithub.com/davecgh/go-spewv1.1.1indirect
Gogithub.com/deepmap/oapi-codegenv1.15.0indirect
Gogithub.com/dgrijalva/jwt-gov3.2.0+incompatibleindirect
Gogithub.com/dlclark/regexp2v1.11.5indirect
Gogithub.com/ebitengine/puregov0.10.1indirect
Gogithub.com/fatih/colorv1.18.0indirect
Gogithub.com/fatih/structsv1.1.0indirect
Gogithub.com/flosch/pongo2/v4v4.0.2indirect
Gogithub.com/fsnotify/fsnotifyv1.10.1indirect
Gogithub.com/gabriel-vasile/mimetypev1.4.2indirect
Gogithub.com/gin-contrib/ssev0.1.0indirect
Gogithub.com/gin-gonic/ginv1.9.1indirect
Gogithub.com/go-jose/go-jose/v4v4.1.4indirect
Gogithub.com/go-logr/logrv1.4.3indirect
Gogithub.com/go-logr/stdrv1.2.2indirect
Gogithub.com/go-ole/go-olev1.3.0indirect
Gogithub.com/go-openapi/analysisv0.25.2indirect
Gogithub.com/go-openapi/errorsv0.22.8indirect
Gogithub.com/go-openapi/jsonpointerv0.23.1indirect
Gogithub.com/go-openapi/jsonreferencev0.21.6indirect
Gogithub.com/go-openapi/loadsv0.24.0indirect
Gogithub.com/go-openapi/runtime/server-middlewarev0.32.3indirect
Gogithub.com/go-openapi/specv0.22.5indirect
Gogithub.com/go-openapi/swagv0.26.1indirect
Gogithub.com/go-openapi/swag/cmdutilsv0.26.1indirect
Gogithub.com/go-openapi/swag/convv0.26.1indirect
Gogithub.com/go-openapi/swag/fileutilsv0.26.1indirect
Gogithub.com/go-openapi/swag/jsonnamev0.26.1indirect
Gogithub.com/go-openapi/swag/jsonutilsv0.26.1indirect
Gogithub.com/go-openapi/swag/loadingv0.26.1indirect
Gogithub.com/go-openapi/swag/manglingv0.26.1indirect
Gogithub.com/go-openapi/swag/netutilsv0.26.1indirect
Gogithub.com/go-openapi/swag/stringutilsv0.26.1indirect
Gogithub.com/go-openapi/swag/typeutilsv0.26.1indirect
Gogithub.com/go-openapi/swag/yamlutilsv0.26.1indirect
Gogithub.com/go-openapi/validatev0.26.0indirect
Gogithub.com/go-playground/localesv0.14.1indirect
Gogithub.com/go-playground/universal-translatorv0.18.1indirect
Gogithub.com/go-playground/validator/v10v10.15.4indirect
Gogithub.com/go-viper/mapstructure/v2v2.5.0indirect
Gogithub.com/goccy/go-jsonv0.10.2indirect
Gogithub.com/golang/snappyv0.0.4indirect
Gogithub.com/gomarkdown/markdownv0.0.0-20250311123330-531bef5e742bindirect
Gogithub.com/gomarkdown/markdownv0.0.0-20250810172220-2e2c11897d1aindirect
Gogithub.com/gorilla/cssv1.0.0indirect
Gogithub.com/gorilla/muxv1.8.1indirect
Gogithub.com/gorilla/schemav1.4.1indirect
Gogithub.com/gorilla/securecookiev1.1.2indirect
Gogithub.com/gorilla/websocketv1.5.3indirect
Gogithub.com/hashicorp/hclv1.0.0indirect
Gogithub.com/inconshreveable/mousetrapv1.1.0indirect
Gogithub.com/influxdata/influxdb-client-go/v2v2.12.3indirect
Gogithub.com/influxdata/line-protocolv0.0.0-20210922203350-b1ad95c89adfindirect
Gogithub.com/iris-contrib/schemav0.0.6indirect
Gogithub.com/jeffail/gabs/v2v2.7.0indirect
Gogithub.com/joker/jadev1.1.3indirect
Gogithub.com/josharian/internv1.0.0indirect
Gogithub.com/json-iterator/gov1.1.12indirect
Gogithub.com/kataras/blocksv0.0.8indirect
Gogithub.com/kataras/gologv0.1.9indirect
Gogithub.com/kataras/iris/v12v12.2.7indirect
Gogithub.com/kataras/piov0.0.12indirect
Gogithub.com/kataras/sitemapv0.0.6indirect
Gogithub.com/kataras/tunnelv0.0.4indirect
Gogithub.com/klauspost/compressv1.17.0indirect
Gogithub.com/klauspost/cpuid/v2v2.2.5indirect
Gogithub.com/kyokomi/emoji/v2v2.2.13indirect
Gogithub.com/labstack/echo/v4v4.11.1indirect
Gogithub.com/labstack/gommonv0.4.0indirect
Gogithub.com/leodido/go-urnv1.2.4indirect
Gogithub.com/lufia/plan9statsv0.0.0-20260330125221-c963978e514eindirect
Gogithub.com/magiconair/propertiesv1.8.7indirect
Gogithub.com/mailgun/raymond/v2v2.0.48indirect
Gogithub.com/mailru/easyjsonv0.7.7indirect
Gogithub.com/mattn/go-colorablev0.1.15indirect
Gogithub.com/mattn/go-isattyv0.0.22indirect
Gogithub.com/mattn/go-runewidthv0.0.19indirect
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957dindirect
Gogithub.com/michaelmure/go-term-textv0.3.1indirect
Gogithub.com/microcosm-cc/bluemondayv1.0.25indirect
Gogithub.com/miekg/pkcs11v1.1.2indirect
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirect
Gogithub.com/modern-go/reflect2v1.0.2indirect
Gogithub.com/muhlemmer/guv0.3.1indirect
Gogithub.com/oklog/ulid/v2v2.1.1indirect
Gogithub.com/openziti/go-term-markdownv1.0.1indirect
Gogithub.com/openziti/runzmdv1.0.83indirect
Gogithub.com/parallaxsecond/parsec-client-gov0.0.0-20221025095442-f0a77d263cf9indirect
Gogithub.com/pelletier/go-toml/v2v2.1.0indirect
Gogithub.com/pmezard/go-difflibv1.0.0indirect
Gogithub.com/power-devops/perfstatv0.0.0-20240221224432-82ca36839d55indirect
Gogithub.com/rs/corsv1.11.1indirect
Gogithub.com/russross/blackfriday/v2v2.1.0indirect
Gogithub.com/sagikazarmark/locaferov0.3.0indirect
Gogithub.com/sagikazarmark/slog-shimv0.1.0indirect
Gogithub.com/schollz/closestmatchv2.1.0+incompatibleindirect
Gogithub.com/shopify/goreferrerv0.0.0-20220729165902-8cddb4f5de06indirect
Gogithub.com/sourcegraph/concv0.3.0indirect
Gogithub.com/speps/go-hashidsv2.0.0+incompatibleindirect
Gogithub.com/spf13/aferov1.10.0indirect
Gogithub.com/spf13/castv1.5.1indirect
Gogithub.com/spf13/cobrav1.10.2indirect
Gogithub.com/spf13/pflagv1.0.9indirect
Gogithub.com/spf13/viperv1.17.0indirect
Gogithub.com/subosito/gotenvv1.6.0indirect
Gogithub.com/tdewolff/minify/v2v2.12.9indirect
Gogithub.com/tdewolff/parse/v2v2.6.8indirect
Gogithub.com/tklauser/go-sysconfv0.4.0indirect
Gogithub.com/tklauser/numcpusv0.12.0indirect
Gogithub.com/twitchyliquid64/golang-asmv0.15.1indirect
Gogithub.com/ugorji/go/codecv1.2.11indirect
Gogithub.com/valyala/bytebufferpoolv1.0.0indirect
Gogithub.com/valyala/fasttemplatev1.2.2indirect
Gogithub.com/vmihailenco/msgpack/v5v5.3.5indirect
Gogithub.com/vmihailenco/tagparser/v2v2.0.0indirect
Gogithub.com/yosssi/acev0.0.5indirect
Gogithub.com/yusufpapurcu/wmiv1.2.4indirect
Gogithub.com/zitadel/loggingv0.7.0indirect
Gogithub.com/zitadel/oidcv1.13.5indirect
Gogithub.com/zitadel/schemav1.3.2indirect
Gogo.opentelemetry.io/auto/sdkv1.2.1indirect
Gogo.opentelemetry.io/otelv1.44.0indirect
Gogo.opentelemetry.io/otel/metricv1.44.0indirect
Gogo.opentelemetry.io/otel/tracev1.44.0indirect
Gogo.uber.org/multierrv1.11.0indirect
Gogo.yaml.in/yaml/v3v3.0.4indirect
Gogolang.org/x/archv0.5.0indirect
Gogolang.org/x/cryptov0.53.0indirect
Gogolang.org/x/expv0.0.0-20240506185415-9bf2ced13842indirect
Gogolang.org/x/netv0.56.0indirect
Gogolang.org/x/syncv0.21.0indirect
Gogolang.org/x/termv0.44.0indirect
Gogolang.org/x/textv0.38.0indirect
Gogolang.org/x/timev0.12.0indirect
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20251202230838-ff82c1b0f217indirect
Gogoogle.golang.org/grpcv1.79.3indirect
Gogoogle.golang.org/grpc/examplesv0.0.0-20231107231549-482de2224942indirect
Gogopkg.in/ini.v1v1.67.0indirect
Gogopkg.in/resty.v1v1.12.0indirect
Gogopkg.in/square/go-jose.v2v2.6.0indirect
Gonhooyr.io/websocketv1.8.17indirect
Dependency advisories 8

This repository publishes no package the index resolves, so its own dependency graph was assessed — 186 packages, which also include development and test pins that never ship: 8 carry known advisories, of which 0 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
google.golang.org/grpcv1.79.3indirectcritical21.82.1
github.com/dgrijalva/jwt-gov3.2.0+incompatibleindirecthigh24.0.0-preview1
github.com/gomarkdown/markdownv0.0.0-20250311123330-531bef5e742bindirecthigh20.0.0-20260411013819-759bbc3e3207
github.com/gomarkdown/markdownv0.0.0-20250810172220-2e2c11897d1aindirecthigh20.0.0-20260411013819-759bbc3e3207
gopkg.in/square/go-jose.v2v2.6.0indirectmoderate24.0.1
github.com/klauspost/compressv1.17.0indirectunknown11.18.7
golang.org/x/cryptov0.53.0indirectunknown1
golang.org/x/textv0.38.0indirectunknown10.39.0

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "golang",
        "networking",
        "sdk",
        "zero-trust",
        "appsec",
        "netsec",
        "openziti",
        "secure-networking",
        "ztaa",
        "ztna",
        "security",
        "zerotrust",
        "zero-trust-network",
        "zero-trust-network-access",
        "zero-trust-security"
      ],
      "is_fork": false,
      "size_kb": 18782,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1148053,
        "Shell": 391,
        "Dockerfile": 567
      },
      "pushed_at": "2026-07-20T18:46:39Z",
      "created_at": "2019-11-19T15:38:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-29T11:42:46Z",
      "description": "Ziti SDK for Golang",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://openziti.io",
      "name": "OpenZiti",
      "type": "Organization",
      "login": "openziti",
      "company": null,
      "location": null,
      "followers": 990,
      "avatar_url": "https://avatars.githubusercontent.com/u/65675559?v=4",
      "created_at": "2020-05-20T17:10:36Z",
      "is_verified": null,
      "public_repos": 89,
      "account_age_days": 2260
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.9.0",
          "kind": "minor",
          "published_at": "2026-06-12T19:15:37Z"
        },
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-05-28T14:31:26Z"
        },
        {
          "tag": "v1.7.0",
          "kind": "minor",
          "published_at": "2026-04-14T14:14:49Z"
        },
        {
          "tag": "v1.5.4",
          "kind": "patch",
          "published_at": "2026-03-21T03:08:23Z"
        },
        {
          "tag": "v1.2.4-patch1",
          "kind": "prerelease",
          "published_at": "2026-03-11T19:57:43Z"
        },
        {
          "tag": "v1.5.3",
          "kind": "patch",
          "published_at": "2026-03-11T13:45:23Z"
        },
        {
          "tag": "v1.5.2",
          "kind": "patch",
          "published_at": "2026-03-07T00:53:45Z"
        },
        {
          "tag": "v1.5.1",
          "kind": "patch",
          "published_at": "2026-03-06T13:43:53Z"
        },
        {
          "tag": "v1.5.0",
          "kind": "minor",
          "published_at": "2026-03-04T16:23:18Z"
        },
        {
          "tag": "v1.4.2",
          "kind": "patch",
          "published_at": "2026-02-20T17:53:22Z"
        },
        {
          "tag": "v1.3.1",
          "kind": "patch",
          "published_at": "2025-12-15T19:41:34Z"
        },
        {
          "tag": "v1.3.0",
          "kind": "minor",
          "published_at": "2025-11-13T15:19:37Z"
        },
        {
          "tag": "v1.2.10",
          "kind": "patch",
          "published_at": "2025-10-15T13:40:09Z"
        },
        {
          "tag": "v1.2.9",
          "kind": "patch",
          "published_at": "2025-10-14T14:11:32Z"
        },
        {
          "tag": "v1.2.8",
          "kind": "patch",
          "published_at": "2025-10-02T20:01:34Z"
        },
        {
          "tag": "v1.2.7",
          "kind": "patch",
          "published_at": "2025-10-02T13:36:46Z"
        },
        {
          "tag": "v1.2.6",
          "kind": "patch",
          "published_at": "2025-09-30T18:09:14Z"
        },
        {
          "tag": "v1.2.5",
          "kind": "patch",
          "published_at": "2025-09-25T14:50:08Z"
        },
        {
          "tag": "v1.2.4",
          "kind": "patch",
          "published_at": "2025-09-09T19:17:14Z"
        },
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2025-08-14T07:28:57Z"
        },
        {
          "tag": "v1.2.2",
          "kind": "patch",
          "published_at": "2025-08-09T15:14:08Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2025-07-25T15:52:32Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2025-07-18T16:43:09Z"
        },
        {
          "tag": "v1.1.2",
          "kind": "patch",
          "published_at": "2025-06-16T17:51:31Z"
        },
        {
          "tag": "v1.1.1",
          "kind": "patch",
          "published_at": "2025-05-29T15:08:40Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2025-07-31T16:19:34Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2025-01-23T18:03:17Z"
        },
        {
          "tag": "v0.23.42",
          "kind": "patch",
          "published_at": "2024-09-16T18:42:43Z"
        },
        {
          "tag": "v0.23.40",
          "kind": "patch",
          "published_at": "2024-08-01T19:49:44Z"
        },
        {
          "tag": "v0.21.0-alpha-1",
          "kind": "prerelease",
          "published_at": "2023-11-14T01:38:58Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "c505373bc6ac48c5711edce200282bde6ca45b41",
          "body": "…… (#969)\n\n* for openziti/ziti#3990 receive service and posture state pushed by edge routers\n\n- adds ServiceChangeSet and PostureStateChange protobuf messages plus the Subscribe/Unsubscribe/ResyncPostureState controls: indexed atomic structural envelopes (services, policies, posture check definition\n[…]\nthe router capability bitmask\n- stops serializing the structured error's Cause, which broke unmarshaling on receipt and silently discarded denials\n- remove RDM capability, it is router/controller only",
          "is_bot": false,
          "headline": "for openziti/ziti#3990 subscribe to router-pushed service and posture…",
          "author_name": "Andrew Martinez",
          "author_login": "andrewpmartinez",
          "committed_at": "2026-07-20T14:53:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "317dc7c6aaacfb1fdd5921ad6af34aa1ca76fc4d",
          "body": "…… (#972)\n\n* for openziti/ziti#4071 unify router capabilities into one shared namespace\n\n- makes RouterCapability a single bit namespace shared by the control and edge channels\n- adds MultiChannel at bit 1; moves ConnectV2 to bit 2\n- adds the RouterCapabilityMultiChannel alias alongside RouterCapabi\n[…]\nrs\n- documents the SupportsPostureChecks/SupportsBindSuccess headers as superseded by\n  the capability bits, kept for backwards compatibility\n- adds RouterCapabilityPostureChecks/BindSuccess constants",
          "is_bot": false,
          "headline": "for openziti/ziti#4071 unify router capabilities into one shared name…",
          "author_name": "Andrew Martinez",
          "author_login": "andrewpmartinez",
          "committed_at": "2026-07-02T20:20:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4879cb9d8c169b06109866f3a5f82633bfbae51",
          "body": "…ess-conn-close-on-teardown\n\nMark xgress conn closed on router-initiated teardown",
          "is_bot": false,
          "headline": "Merge pull request #959 from openziti/fix.openziti.sdk-golang.958.xgr…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-29T15:50:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8640dedbe0f263be8c5a19ba6e474c594c327833",
          "body": "Add acceptance test suite",
          "is_bot": false,
          "headline": "Merge pull request #966 from openziti/add-acceptance-tests",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-29T15:50:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d2497d8a83088e2a3917257b9b320516ec7b0b4",
          "body": "Move RouterCapabilityConnectV2 into edge_client.proto",
          "is_bot": false,
          "headline": "Merge pull request #968 from openziti/move-router-capability-to-proto",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-29T14:33:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1dfbec48f89aaeb8821c4b5e9f816fba924f81b",
          "body": "- adds a RouterCapability enum to edge_client.proto so router capability bit positions are part of the protocol definition and accessible to other language SDKs\n- regenerates edge_client.pb.go\n- derives the RouterCapabilityConnectV2 Go constant from the generated enum",
          "is_bot": false,
          "headline": "Move RouterCapabilityConnectV2 into edge_client.proto. Fixes #967",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6ed75ecc8020f54648244930431fda527a9d897",
          "body": "- adds Test_Revocation_IdentityDelete: after a dialing identity is deleted,\n  the SDK can no longer dial the service; enforcement is asserted as\n  eventual within a bounded window since a freshly revoked identity may\n  briefly dial on cached state\n- reaper-driven teardown of an already-established circuit is left as a\n  follow-up",
          "is_bot": false,
          "headline": "Add acceptance test for revocation enforcement",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "afb9f68aa97ce2bbd06e7f542b71ea638602c117",
          "body": "- adds Test_TokenRefresh_DialContinuity: across several api-session\n  refreshes the client keeps dialing, and on OIDC each refresh rotates the\n  access token (the rotated token propagates to the edge routers)\n- adds Test_HostingContinuity_AcrossRefresh: a hosted terminator survives\n  the host's api-session refresh and keeps accepting dials",
          "is_bot": false,
          "headline": "Add acceptance tests for token refresh and hosting continuity",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c170034edccd95a2365d98a055e42f305a64499",
          "body": "Covers the tunneler-style addressing entry point. With an intercept.v1\nconfig, GetServiceForAddr scores an exact host:port match and DialAddr\nresolves the address and round-trips. A service carrying only a\nziti-tunneler-client.v1 config is still addressable via the SDK's\nclient-config-to-intercept conversion.\n\n- adds harness CreateConfig, CreateServiceWithConfigs, and\n  NewSdkContextWithConfigTypes\n- adds Test_InterceptDial and Test_InterceptDial_ClientConfigConversion",
          "is_bot": false,
          "headline": "Add acceptance tests for address-based (intercept) dialing",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df862a8e5e2d79697c7e56e46ea0e17e72889682",
          "body": "Asserts the SDK reflects service-access edits made after an initial dial:\nthe service changed/removed/added events fire on a refresh, and cached\nstate is invalidated rather than dialing stale data (a dial fails once\naccess is revoked and succeeds again once re-granted).\n\n- adds a deletable Policy handle returned by GrantDial/GrantBind so a test\n  can revoke access mid-run\n- adds Test_ServiceUpdatePropagation",
          "is_bot": false,
          "headline": "Add acceptance test for service-access update propagation",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:22:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35d99162f2671ff5b4eba33a622a6727888c10ff",
          "body": "Adds username/password (UPDB) login through the SDK plus an api-session\ntoken refresh: a UPDB identity dials a service, then refreshes its session\nand dials again.\n\n- adds harness CreateUpdbIdentity and NewUpdbSdkContext\n- generalizes the policy grant helpers to a NamedEntity interface so they\n  work for both cert and UPDB identities\n- adds Test_AuthModes_Updb",
          "is_bot": false,
          "headline": "Add acceptance test for UPDB auth mode",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:21:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a409a5d50434081700c9075b2e932de9186e426",
          "body": "Asserts a host's accepted connection sees the dialer-supplied metadata:\nthe caller id (the dialing identity's name), the app data passed on dial,\nand the dialer identity (asserted only on controller versions that\npopulate it). The assertions ride on a verified write/half-close/\nread-to-EOF data plane.",
          "is_bot": false,
          "headline": "Add acceptance test for dialer connection metadata",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-26T20:21:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "689b62cefe3f9a0cc2a681b6d96ced2a7c4e84fd",
          "body": "- marks the owning edgeConnXgress closed in XgAdapter.HandleXgressClose,\n  the single point every teardown that ends at the xgress passes through\n  (app-initiated close, peer end-of-circuit, or a StateClosed that drains\n  then closes), so IsClosed reflects the closed xgress regardless of which\n  sid\n[…]\nostClose, an acceptance regression that\n  dials over the xgress path, lets the host close after an echo, and\n  asserts the client conn reports closed (not merely EOF on read).\n\nFor openziti/ziti#3884.",
          "is_bot": false,
          "headline": "Mark xgress conn closed on router-initiated teardown. Fixes #958",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-25T13:54:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7942e032828e79362502be4bfa5db0aca1b8c0dc",
          "body": "…tags\n\nSkip GitHub release for pre-release and build-metadata tags",
          "is_bot": false,
          "headline": "Merge pull request #957 from openziti/ci-skip-release-for-prerelease-…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-23T17:19:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04fb7b7f7d6df07274b0824b7bc684bc68fdb039",
          "body": "- restricts the release-builds workflow trigger to exclude tags containing a semver pre-release qualifier (-) or build metadata (+)\n- allows v2.0.0-pre style tags to be pushed for consumption by downstream projects without producing a public GitHub release",
          "is_bot": false,
          "headline": "Skip GitHub release for pre-release and build-metadata tags",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-23T17:15:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a7afe8136e7c898190a0b3778e0ec1726b530ff",
          "body": "Connect-V2, SDK acceptance-test framework, and the 2.0/v2 migration",
          "is_bot": false,
          "headline": "Merge pull request #943 from openziti/connect-v2",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-22T19:13:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "853b23f0f019624bd7eb252b3a889596133f4cbf",
          "body": "The SDK moved to channel/v5 (the 2.0 line) and shares the sdk-golang/xgress\npackage with ziti, so the co-development build cannot compile ziti connect-v2,\nwhich is still on channel/v4, against the SDK under test. ziti's channel/v5\nmigration is in progress but not yet landed or merged with connect-v2.\n\n- disables the connect-v2 V2-coverage job with `if: false`, documenting how and\n  when to re-enable it",
          "is_bot": false,
          "headline": "Gate the connect-v2 acceptance job until ziti adopts channel/v5",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b80fc4f6fc3172561b7656ace1075d97ca9e4fe7",
          "body": "- changes the module path to github.com/openziti/sdk-golang/v2 and rewrites all\n  import paths accordingly, per Go semantic import versioning\n- repoints the acceptance and example modules' SDK require/replace and the\n  acceptance co-development build to the /v2 path\n- regenerates edge_client.pb.go f\n[…]\npackage option\n- bumps the version file to 2.0\n- records the /v2 path change as a breaking change and lists the connect-v2,\n  acceptance-framework (#951), and half-close (#952) issues in the changelog",
          "is_bot": false,
          "headline": "Migrate module to github.com/openziti/sdk-golang/v2 for the 2.0 release",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5ff4aaf61c95cfe1a730159fca63e5c58c83cba",
          "body": "- adds .github/workflows/acceptance.yml, running the SDK acceptance suite on\n  pull requests and pushes to main\n- runs a compatibility matrix over the active-lts, maint-lts, latest, and main\n  selectors in adaptive mode, guaranteeing V1 compatibility across the supported\n  lines; the label-to-versio\n[…]\n\n- caches acquired ziti binaries by their immutable id and serializes package\n  test binaries so they share one acquisition\n- records the V2 job's co-development build rationale in acceptance-tests.md",
          "is_bot": false,
          "headline": "Add the acceptance suite CI workflow",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "933705422675190ec751493b441b71b78ad7589b",
          "body": "… Fixes #952\n\nMoving half-close into xgress replaced the edge FIN flag with the native\nxgress EOF flag. Peers that don't honor native EOF, an older router bridging\nto a legacy edge host or an older SDK, never see the half-close, so a host\nthat reads to EOF starves and the circuit stalls.\n\n- restores\n[…]\ning the\n  native EOF that would tear the whole circuit down\n- adds Test_HalfClose_XgressClientToLegacyHost, an acceptance regression for an\n  xgress client half-closing to a router-bridged legacy host",
          "is_bot": false,
          "headline": "Restore legacy edge FIN half-close for xgress clients to older peers.…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fcc7852fcbbd85ae0245ea1ac653ef0f88a8df3",
          "body": "- splits startEchoServerFC out of startEchoServer with an explicit sdkXgress\n  parameter, so tests can host a legacy (non-xgress) terminator the router\n  bridges to\n- keeps startEchoServer defaulting to SDK-hosted xgress, the path the suite\n  primarily exercises",
          "is_bot": false,
          "headline": "Parameterize the echo host's SDK-xgress bind flag",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7d46532aa541ce9c5ae914608a17ebbbcc9026c",
          "body": "- adds Test_DialProtocolNegotiation: the SDK must take ConnectV2 exactly when the router advertises the capability and the session is OIDC, else legacy V1, asserted against the observed dial event (never inferred from a version), with the ForceConnectV1 escape hatch checked too\n- adds ZITI_ACCEPTANC\n[…]\n-doc shorthand in test comments with descriptions of the actual behavior\n- verified against latest and maint-lts (full suite, legacy terminator fallback) and source-built connect-v2 (required-V2 mode)",
          "is_bot": false,
          "headline": "Add the dial-protocol negotiation test and V2 coverage controls",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "502d7d8d99db17a17a606ddf5df6d037bc7fa310",
          "body": "- resolves branch/tag refs to a full commit SHA via git ls-remote before any cache interaction, then shallow-fetches exactly that SHA so a moving branch cannot change what gets built\n- builds the ziti binary from the checkout and installs it into the cache keyed by SHA\n- adds co-development mode (ZI\n[…]\nugh ResolvedID and Version (short-SHA display; source builds satisfy every version minimum)\n- verified live: built openziti/ziti@connect-v2 against the local SDK and ran the bring-up canary against it",
          "is_bot": false,
          "headline": "Add source builds for git-ref selectors with a co-development mode",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d73d95704ae9e0e8d5812ca0564ff1281b3b6413",
          "body": "- adds acceptance/tests with TestMain bringing up one shared environment per package via StartShared, per the design's Layer 5 model; per-test cost drops from a controller boot each to under a few seconds\n- StartShared now materializes the default topology (controller plus the edge1 router); AddRout\n[…]\nm the harness package, which keeps only the per-version bring-up canary\n- verified live against latest (v2.0.0) and maint-lts (v1.6.17); both lines negotiate OIDC by default and force legacy correctly",
          "is_bot": false,
          "headline": "Add the shared-environment tests package with the P0 suite",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f72398215c306dc68e77fb1bf174fc2f08e70f59",
          "body": "- skips the API entirely for selectors that pin a concrete tag (explicit versions and non-wildcard label values) when the binary is already cached; the cache entry is proof the release exists, so warm pinned runs make zero API calls\n- adds acquire.ZitiMemoized, used by the harness: one resolution pe\n[…]\ns GITHUB_TOKEN as the fix\n- documents the rate-limit behavior in the README\n- tests the shortcut and memo against an all-erroring source (proving zero API calls) and the 403 hint against a fake server",
          "is_bot": false,
          "headline": "Reduce GitHub API usage in acceptance version resolution",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e8cd74f40bcb4f941eb6a20f1afbee986bf4738",
          "body": "- adds AddRouter: creates, enrolls, and runs an edge router as its own child process via the version-stable CLI sequence, with config generation driven by ZITI_* env vars verified identical on 1.6 and main\n- gates router readiness on TCP listen plus controller-reported online status, and supports St\n[…]\ning half-close and EOF propagation in both directions\n- verified live against latest (v2.0.0) and maint-lts (v1.6.17); full-matrix runs surfaced an intermittent SDK data-plane race, tracked separately",
          "is_bot": false,
          "headline": "Add router bring-up, policy helpers, and the dial/host echo smoke",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "263cc7647b64b2714af97de01ff9ef1514000b8d",
          "body": "- documents quick start, version selection, the matrix runner, the binary cache, opt-in live tests, module layout, and platform notes\n- links the acceptance module from the top-level README package list",
          "is_bot": false,
          "headline": "Add acceptance test README",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd861c34db24fd74cf6fb4fe72df3eaeea6c0e78",
          "body": "- adds cmd/matrix: runs the tagged acceptance suite once per version selector with a per-version pass/fail summary and non-zero exit on any failure\n- defaults the selector list to the versions.yaml labels plus latest, so the matrix has a single source of truth; arguments select a subset and anything\n[…]\ns)\n- forces -count=1 since go test's cache cannot see controller-side state\n- supports -fail-fast to stop at the first failing version\n- exports acquire.FindVersionsFile and reuses it from the harness",
          "is_bot": false,
          "headline": "Add matrix runner for multi-version local test runs",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5094ae80ef93d071c67b55b0ee52ca3582e7cad0",
          "body": "- adds CreateIdentity: creates and enrolls identities via the versioned CLI per the setup contract, with per-test unique names and best-effort cleanup per the isolation contract\n- adds NewSdkContext: builds an authenticated ziti.Context from a CLI-enrolled identity using the SDK in this tree via the module replace directive\n- adds the first SDK smoke test: authenticate, list services, and current-identity round trip; verified live against latest (v2.0.0) and maint-lts (v1.6.17)",
          "is_bot": false,
          "headline": "Add identity creation and SDK context bridge to the acceptance harness",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c716850fb0a4bc19f0c014e33e92e43a0fb334fb",
          "body": "- adds an open item to source LTS labels from the ziti repo's lts-versions.json once openziti/ziti#3962 merges, keeping our own resolution logic and versions.yaml for source/repo and overrides",
          "is_bot": false,
          "headline": "Note lts-versions.json as future label source",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4e94f6eb95afe13f25a2e0d50431881daeaff4b",
          "body": "- adds the ziticli exec wrapper: every invocation runs with an isolated ZITI_CONFIG_DIR and a scrubbed ZITI_* environment, so harness logins never collide with the developer's own CLI state\n- launches `ziti edge quickstart --no-router` as a long-lived controller-only child process with dynamic port \n[…]\neMinVersion\n- tags the bring-up test with the acceptance build tag so the default suite stays network-free; verified live against latest (v2.0.0), active-lts (v2.0.x wildcard), and maint-lts (v1.6.17)",
          "is_bot": false,
          "headline": "Add controller bring-up harness with admin-usable readiness probe",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ceba5aac69cce171066ddf7dd1d342f5d8c809a",
          "body": "- adds an open item: promote internal/acquire to a sibling nested module (acquire/vX.Y.Z tag line) once the harness and source-build phases prove its API, so ziti/zititest can replace stageziti's GH-release fetch core with it\n- records the hard rule that acquire imports no SDK packages, keeping the extraction mechanical",
          "is_bot": false,
          "headline": "Document plan to promote acquire for zititest reuse",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70bd0ad6b82a04faa28bdcd3822ac8fd3b133470",
          "body": "- extends the GitHub client with release-by-tag asset lookup and download, resolving asset URLs from the API rather than constructing filenames\n- extracts the ziti binary from release tar.gz archives at any path depth\n- caches binaries keyed by immutable id (tag or SHA) with atomic install; ZITI_ACC\n[…]\nrting zip-only matches distinctly\n- tests download/extract/cache behavior against a counting fake release server\n- adds an opt-in live test against the real GitHub API, gated on ZITI_ACCEPTANCE_LIVE=1",
          "is_bot": false,
          "headline": "Add release binary acquisition with caching to the acceptance framework",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7ba282bf4aaf9f06a3768032f72b627b080ee2ec",
          "body": "- adds acceptance-tests.md, the design for correctness-testing the SDK against multiple OpenZiti versions (LTS lines, latest release, branches/commits)\n- adds the acceptance/ module scaffold with its own go.mod and a replace directive targeting the local SDK\n- adds versions.yaml (label -> release po\n[…]\n- uses golang.org/x/mod/semver for version comparison\n- tests resolution against unsorted, prerelease, draft, and paginated release fixtures\n- ignores local review-tooling files (mercurius, .mcp.json)",
          "is_bot": false,
          "headline": "Add SDK acceptance test framework: design doc and version resolution",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "144f081b457b167328694e58ee3ab0cbb7d55771",
          "body": "Implements the Connect-V2 sessionless SDK dial protocol — dials are\nauthorized at the router via RDM instead of requiring a controller-issued\nservice session token.\n\n- Adds `CtrlClient.GetServiceEdgeRouters` wrapping the existing\n  `GET /edge/client/v1/services/{id}/edge-routers` endpoint for\n  sess\n[…]\nge.\n- Removes the `conn.Close()` calls from `setupXgressFlowControl`'s\n  header-validation error paths so the conn no longer NPEs before\n  `xg` / `writeAdapter` are populated.\n\nFor openziti/ziti#3884.",
          "is_bot": false,
          "headline": "Implement Connect-V2. Fixes #936",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-18T20:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6e5f1697a9dc34a41c1ed398d667b349f2b04b4",
          "body": "Fix AddControllerUrlsUpdateListener remover unsubscribing the wrong event",
          "is_bot": false,
          "headline": "Merge pull request #947 from openziti/fix-controller-urls-listener",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-15T16:15:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff096c420df9b60b5f5ff9ae183c85d88b8e5811",
          "body": "Update version, deps and changelog. Also fix flaky test.",
          "is_bot": false,
          "headline": "Merge pull request #950 from openziti/update-deps-and-changelog",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-12T19:13:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9b70f0880a65f64f8b76935be1cbba91877ac03",
          "body": null,
          "is_bot": false,
          "headline": "Update version, deps and changelog. Also fix flaky test.",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-12T16:14:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00691363c48b1c04776f0092669244b0333592fa",
          "body": "Migrate to channel/v5",
          "is_bot": false,
          "headline": "Merge pull request #946 from openziti/channel-v5",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-12T14:06:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98873058fc4cfc098e15cb4864cdd18a36047f16",
          "body": "…vent. Fixes #948\n\n- the returned remover called RemoveListener with EventAuthenticationStateUnauthenticated instead of EventControllerUrlsUpdated, so the urls listener was never unregistered and kept firing after removal\n- adds a regression test that fails against the previous behavior",
          "is_bot": false,
          "headline": "Fix AddControllerUrlsUpdateListener remover unsubscribing the wrong e…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-11T15:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed1a134965563e6d3761d3ab487fa301d3375425",
          "body": "- moves the channel dependency from channel/v4 to channel/v5 and rewrites the import paths\n- decomposes BaseSdkChannel onto the v5 Senders, MessageSourceProvider and UnderlayEventListener interfaces, preserving control-vs-default message routing\n- replaces DialSdkChannel's hand-rolled dial/grouping/\n[…]\ngeTimingBinding wrapper and the NoopTestChannel for the v5 Binding and Channel interfaces\n- adds unit tests for message-source routing, control-available gating, tx-failed requeue and dial constraints",
          "is_bot": false,
          "headline": "Migrate to channel/v5. Fixes #945",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-09T18:39:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d0efa337a3b6eb5a0717c0336c43f51a8775544",
          "body": "Prep for channel v5: explicit receive handler registration, drop send priorities",
          "is_bot": false,
          "headline": "Merge pull request #942 from openziti/channel-v5-prep",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-08T18:24:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42a0f5b68600a8ce079fa48eb2bb9e7a17d60afb",
          "body": "… priorities. Fixes #941\n\n- replaces the typed receive handler registration with explicit content-type registration, since channel v5 removes the self-describing handler pattern\n- replaces the ConnMux embedded channel.TypedReceiveHandler with ContentType() plus an embedded channel.ReceiveHandler\n- removes WithPriority from control-channel sends; priority was already a no-op on grouped channels and channel v5 removes the priority API",
          "is_bot": false,
          "headline": "Prep for channel v5: explicit receive handler registration, drop send…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-06-05T14:06:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cc56224b126141326fccfe55e2d59f3e2a1ad0f",
          "body": "auth fixes",
          "is_bot": false,
          "headline": "Merge pull request #928 from openziti/auth-fixes",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T14:29:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e3f415ee373b9759cb72837c5e9466b25102646",
          "body": null,
          "is_bot": false,
          "headline": "Update deps and changelog",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T14:11:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1631d3652998b168ed3296be01bdb0bcbde06cac",
          "body": "- a 401 on a service-related call within 15s of a successful api-session\n  refresh is almost always a propagation race (server saw the request\n  before processing the new token). Retry with the current session\n  instead of going through Authenticate(), which would needlessly drive\n  the refresh mach\n[…]\ne so\n  recentlyAuthenticated can read it without taking authAttemptLock; also\n  records the refresh time after successful periodic refreshes in\n  runRefreshes, not just on Authenticate-time refreshes.",
          "is_bot": false,
          "headline": "Skip re-authentication on 401 within the refresh race window",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T13:55:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9c3ff6b047827500deb79b2801f9a2cda5297de",
          "body": "- after a failed Authenticate(), subsequent calls within the backoff\n  window return the cached error without retrying. Prevents callers from\n  hammering an unreachable controller.\n- backoff doubles per failure with jitter, capped at AuthBackoffMax.\n  Defaults: AuthBackoffInitial=5s, AuthBackoffMax=\n[…]\ne un-jittered base (authBackoff) from the per-failure\n  wait (currentWait) so jitter doesn't compound into the doubling\n  sequence.\n- exposes Options.AuthBackoffInitial / AuthBackoffMax for embedders.",
          "is_bot": false,
          "headline": "Apply exponential backoff to failed authentication attempts. Fixes #927",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T13:55:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "576338025ab1b5821be37ff60432d65e0cf66676",
          "body": "- replaces the fixed expiresAt - 10s schedule with tokenRefreshTime, which\n  picks a random point between 1/2 and 5/6 of the token's remaining\n  lifetime. The earlier window leaves headroom for slow refreshes and the\n  jitter avoids thundering-herd token exchanges across SDK clients.\n- skips the per\n[…]\nresh doesn't race the expiring\n  token into an unnecessary re-auth on a 401.\n- tokenRefreshTime returns time.Now() when the remaining lifetime is too\n  small to jitter against (avoids rand.Int63n(0)).",
          "is_bot": false,
          "headline": "Refresh access tokens using a C-SDK style window. Fixes #926",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T13:55:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "515516972564e08a1b17c1fa7c0ec6480ecb3053",
          "body": "…ug. Fixes #925\n\n- expands errorIndicatesControllerSwap to recognize HTTP timeouts,\n  context cancellation, EOF / ErrUnexpectedEOF, 5xx responses (via\n  runtime.ClientResponseStatus), and url.Error timeouts so the SDK\n  rotates to a different controller endpoint on transient transport\n  failures ins\n[…]\none.\n- moves the errors.As targets (opError, urlError) from package-level\n  vars into local declarations. errors.As mutates the target, so the\n  shared instances were racing across concurrent callers.",
          "is_bot": false,
          "headline": "Broaden controller-swap error matching, fix shared errors.As target b…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T13:55:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eb5642fd7848816b5605f7bbb49544c424e05334",
          "body": "…s #924\n\n- adds Options.HttpTimeout, plumbed through ApiClientConfig and\n  ComponentsConfig to NewHttpClient.\n- raises the default HTTP client timeout from 10s to 30s, since OIDC\n  token-exchange round trips on slow controllers were exceeding 10s and\n  surfacing as spurious failures that drove the SDK into re-auth retries.\n- exposes DefaultHttpTimeout for callers that want the new default.",
          "is_bot": false,
          "headline": "Make controller HTTP timeout configurable, raise default to 30s. Fixe…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T13:55:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adf817e5221d06bdffbdfdb03561278c1b2fe657",
          "body": "- passes the current API session as the authorization argument so the\n  request is authenticated, matching the rest of the CtrlClient methods.\n  GetService was previously calling ListServices(params, nil), which\n  produced an unauthenticated request and could surface as an unexpected\n  401 on a path that should already be authenticated.",
          "is_bot": false,
          "headline": "Authenticate ListServices call in CtrlClient.GetService",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-05-28T13:55:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1f4c6fa8126244ed64984abac8bc855afda0fc7",
          "body": "* Update github.com/shirou/gopsutil from v3.24.5 to v4.26.4\n\nv4 is the latest version with bug fixes and enhancements, notably the\nremoval of CGO implementations on Darwin in v4.24.9 [1].\n\nNote: Due to the library's versioning policy, v4.24.5 is the first v4\nrelease [2].\n\n[1]: https://github.com/shi\n[…]\nZer Jun <engzerjun@gmail.com>\n\n* Update posture_windows_test.go and include Windows in CI\n\nSigned-off-by: Eng Zer Jun <engzerjun@gmail.com>\n\n---------\n\nSigned-off-by: Eng Zer Jun <engzerjun@gmail.com>",
          "is_bot": false,
          "headline": "Simplify posture process check (#931)",
          "author_name": "Eng Zer Jun",
          "author_login": "Juneezee",
          "committed_at": "2026-05-28T13:38:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "708642af12a91790116538481b775136d3386506",
          "body": "* fixes #932 preserves full API Session certificate chain\n\n- changes CtrlClient.ApiSessionCertificate from *x509.Certificate to []*x509.Certificate\n- stores the full chain returned by the controller in NewApiSessionCertificate instead of only the leaf\n- passes the chain directly to identity.NewClientTokenIdentityWithPool so intermediates are presented during TLS\nhandshakes\n\n* update build info",
          "is_bot": false,
          "headline": "fixes #932 preserves full API Session certificate chain (#933)",
          "author_name": "Andrew Martinez",
          "author_login": "andrewpmartinez",
          "committed_at": "2026-05-08T22:21:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad8706562f9f9f823e228443ce4d2e766feebb6d",
          "body": "Create cla.yml",
          "is_bot": false,
          "headline": "Merge pull request #934 from openziti/add-cla",
          "author_name": "Clint Dovholuk",
          "author_login": "dovholuknf",
          "committed_at": "2026-05-08T19:39:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea4919aa9ea25f96762f9438899454aa562aef50",
          "body": null,
          "is_bot": false,
          "headline": "Create cla.yml",
          "author_name": "Clint Dovholuk",
          "author_login": "dovholuknf",
          "committed_at": "2026-05-08T19:33:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b6a087e92faaf94fcb027e9008bbcf45a325225",
          "body": "Move xgress back to having retransmitter goroutine per-xgress. Fixes …",
          "is_bot": false,
          "headline": "Merge pull request #904 from openziti/rtxer-per-xg",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-14T14:08:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c0ddb4cdefacf656aa0b54e6765bb82c9bca1e9",
          "body": "fix build with go mod tidy",
          "is_bot": false,
          "headline": "Merge pull request #919 from openziti/bugfix/fix_build_with_go_tidy",
          "author_name": "Edward Moscardini",
          "author_login": "emoscardini",
          "committed_at": "2026-04-08T20:04:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f27903672963ded2d7c4235475f7da58b1e3f4c",
          "body": null,
          "is_bot": false,
          "headline": "fix build with go mod tidy",
          "author_name": "Edward Moscardini",
          "author_login": "emoscardini",
          "committed_at": "2026-04-08T19:58:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0acd58b2700f3c403877e352648cd6386e574d06",
          "body": "…piClientWithConfig\n\nmove block to fix nil pointer issue in NewClientApiClientWithConfig",
          "is_bot": false,
          "headline": "Merge pull request #918 from openziti/bufix/nil_pointer_in_NewClientA…",
          "author_name": "Edward Moscardini",
          "author_login": "emoscardini",
          "committed_at": "2026-04-08T19:50:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e2e02f578665f104157852fd6acee85789f21c4",
          "body": null,
          "is_bot": false,
          "headline": "move block to fix nil pointer issue in NewClientApiClientWithConfig",
          "author_name": "Edward Moscardini",
          "author_login": "emoscardini",
          "committed_at": "2026-04-08T19:44:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c814acf9de2ca3f0453ad670bc313bbca3dc12eb",
          "body": "fix URL parsing",
          "is_bot": false,
          "headline": "Merge pull request #916 from openziti/bugfix/apiURL_Parse_issue",
          "author_name": "Edward Moscardini",
          "author_login": "emoscardini",
          "committed_at": "2026-04-08T19:42:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc6c8050f305fe407f9c79d4d91545722c39c45a",
          "body": null,
          "is_bot": false,
          "headline": "fix URL parsing",
          "author_name": "Edward Moscardini",
          "author_login": "emoscardini",
          "committed_at": "2026-04-08T19:29:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5650b19225d74fe21a5f440d33a9e1bf5024e988",
          "body": "Issue-913 - do not add authorization header for empty secondary jwt",
          "is_bot": false,
          "headline": "Merge pull request #914 from openziti/issue-913_malformed-auth-header",
          "author_name": "Tod",
          "author_login": "tburtchell",
          "committed_at": "2026-04-08T18:22:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1922c23aef4bf7580c875d78b6a0f236014a8385",
          "body": "…secondary jwt is empty",
          "is_bot": false,
          "headline": "Issue-913 - do not add authorization header for secondary jwt if the …",
          "author_name": "Tod Burtchell",
          "author_login": "tburtchell",
          "committed_at": "2026-04-08T18:06:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "67172173901fb5c412b2b0ca9fd8ddd48933a0e2",
          "body": "…#901\n\n- replaces shared Retransmitter with a retransmitSender goroutine per LinkSendBuffer,\n  so one slow xgress can't stall retransmissions for others\n- adds intrusive linked list (retxHead/retxTail) to LinkSendBuffer for the retransmit queue\n- switches RetransmitPayload from TrySend (non-blocking\n[…]\ntine\n- adds MarkRetransmission/MarkRetransmissionFailure to Metrics interface\n- removes Retransmitter type, GetRetransmitter from Env/DataPlaneAdapter interfaces,\n  and dummyRetransmitterFaultReporter",
          "is_bot": false,
          "headline": "Move xgress back to having retransmitter goroutine per-xgress. Fixes …",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-03T19:44:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39461d1f7d1484440b5b5c97ccaa7442180c92ba",
          "body": "…-8cc96682b0\n\nBump the non-major group across 1 directory with 2 updates",
          "is_bot": false,
          "headline": "Merge pull request #908 from openziti/dependabot/go_modules/non-major…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-03T19:42:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "136029efa18b4fb2406c90b6a46cde78a6209732",
          "body": "…nfluxdb-client-go/github.com/go-jose/go-jose/v4-4.1.4\n\nBump github.com/go-jose/go-jose/v4 from 4.0.5 to 4.1.4 in /example/influxdb-client-go",
          "is_bot": false,
          "headline": "Merge pull request #910 from openziti/dependabot/go_modules/example/i…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-03T19:41:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42882a3389f36d5d337204277dc09569ebdcfba6",
          "body": "…ithub.com/go-jose/go-jose/v4-4.1.4\n\nBump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /example",
          "is_bot": false,
          "headline": "Merge pull request #911 from openziti/dependabot/go_modules/example/g…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-03T19:41:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c05f8a5168c1ee928ad54340ab42125df06d9c2",
          "body": "…m/go-jose/go-jose/v4-4.1.4\n\nBump github.com/go-jose/go-jose/v4 from 4.0.5 to 4.1.4",
          "is_bot": false,
          "headline": "Merge pull request #909 from openziti/dependabot/go_modules/github.co…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-03T19:41:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0194b1af136718f885cd1f6dc28bf8517342993",
          "body": "Fix potential nil references on session service structs. Fixes #906",
          "is_bot": false,
          "headline": "Merge pull request #907 from openziti/fix-nil-refs",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-04-03T19:37:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97601822f5d1b3645a9b9d3b417e621fd69054c6",
          "body": "Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) from 4.1.3 to 4.1.4.\n- [Release notes](https://github.com/go-jose/go-jose/releases)\n- [Commits](https://github.com/go-jose/go-jose/compare/v4.1.3...v4.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-jose/go-jose/v4\n  dependency-version: 4.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in /example",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-03T03:43:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1ea354e05cbf502ede8bca9b135bfede249fdc5",
          "body": "Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) from 4.0.5 to 4.1.4.\n- [Release notes](https://github.com/go-jose/go-jose/releases)\n- [Commits](https://github.com/go-jose/go-jose/compare/v4.0.5...v4.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-jose/go-jose/v4\n  dependency-version: 4.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump github.com/go-jose/go-jose/v4 in /example/influxdb-client-go",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-03T03:42:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c29aa05f367e8474c7b26c3b67248c961bcc4c8",
          "body": "Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) from 4.0.5 to 4.1.4.\n- [Release notes](https://github.com/go-jose/go-jose/releases)\n- [Commits](https://github.com/go-jose/go-jose/compare/v4.0.5...v4.1.4)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-jose/go-jose/v4\n  dependency-version: 4.1.4\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump github.com/go-jose/go-jose/v4 from 4.0.5 to 4.1.4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-03T03:33:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dee0fe5738cbe4307c6ec1d1658fc28a232ee385",
          "body": "Bumps the non-major group with 2 updates in the / directory: [github.com/go-openapi/strfmt](https://github.com/go-openapi/strfmt) and [github.com/zitadel/oidc/v3](https://github.com/zitadel/oidc).\n\n\nUpdates `github.com/go-openapi/strfmt` from 0.26.0 to 0.26.1\n- [Release notes](https://github.com/go-\n[…]\nc/v3\n  dependency-version: 3.45.6\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump the non-major group across 1 directory with 2 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-31T23:32:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c4419ee845125c8a231290e20f65a217d58ebb2",
          "body": null,
          "is_bot": false,
          "headline": "Fix potential nil references on session service structs. Fixes #906",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-30T19:47:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd83bf352c56fb9d85fa44927456c9993402834a",
          "body": "Allow xgress to use pull model for reads when appropriate. Fixes #897",
          "is_bot": false,
          "headline": "Merge pull request #898 from openziti/xg-pull-model",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-30T19:05:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45c644e61a137ccce7ee976a351d623d078a7d6f",
          "body": "…ies.",
          "is_bot": false,
          "headline": "Update copyright headers. Fix potential deadlock on sending capabilit…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-30T17:21:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36fb49c77a969093b235c2285136a84da6ff52c4",
          "body": "- adds ReadAdapter for pull-based tx path and WriteAdapter for push-based rx path\n- refactors tx() into reusable nextTxPayload/processTxPayload/releasePayloadChunk methods\n- adds deadlineControl backed by LinkSendBuffer's run loop event channel, avoiding\n  per-SetDeadline goroutines (time.AfterFunc)\n[…]\n half-close verification across\n  all four adapter mode combinations (default, writeAdapter, readAdapter, bothAdapters)\n- deletes write_timeout_test.go, moves TestWriteTimeout to write_adapter_test.go",
          "is_bot": false,
          "headline": "Allow xgress to use pull model for reads when appropriate. Fixes #897",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-27T00:38:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46034e0a50a22b91e50c590b554ecb0925d7bdee",
          "body": "Limit effect sudden rtt spikes can have on rtt moving average. Fixes #895",
          "is_bot": false,
          "headline": "Merge pull request #896 from openziti/fix-rtt-spikes",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-26T21:20:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87fd0c9c5deb3ddad9e9aa16d50c20d1f072351a",
          "body": "…#895",
          "is_bot": false,
          "headline": "Limit effect sudden rtt spikes can have on rtt moving average. Fixes …",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-26T21:14:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baf6808f09a4c23d6099ce82a677230e61917a4a",
          "body": "Inspect response message content types are mixed up. Fixes #902",
          "is_bot": false,
          "headline": "Merge pull request #903 from openziti/fix-response-types",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-21T03:03:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98a642358dc453203a328b63a48ab1f3688353e8",
          "body": null,
          "is_bot": false,
          "headline": "Inspect response message content types are mixed up. Fixes #902",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-21T02:03:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5aac7502d66fb477155b88b4d575248e2058a23a",
          "body": "…oogle.golang.org/grpc-1.79.3\n\nBump google.golang.org/grpc from 1.59.0 to 1.79.3 in /example",
          "is_bot": false,
          "headline": "Merge pull request #900 from openziti/dependabot/go_modules/example/g…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-21T02:02:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c744fe8dc88183a75a7ffdf16903387210c4cf0b",
          "body": "…-f0e32ea48c\n\nBump the non-major group across 1 directory with 11 updates",
          "is_bot": false,
          "headline": "Merge pull request #899 from openziti/dependabot/go_modules/non-major…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-21T02:01:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46defa24e05cdfbfb40a23d02bb0d5a5a4a3b72a",
          "body": "Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.59.0 to 1.79.3.\n- [Release notes](https://github.com/grpc/grpc-go/releases)\n- [Commits](https://github.com/grpc/grpc-go/compare/v1.59.0...v1.79.3)\n\n---\nupdated-dependencies:\n- dependency-name: google.golang.org/grpc\n  dependency-version: 1.79.3\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump google.golang.org/grpc from 1.59.0 to 1.79.3 in /example",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-18T23:39:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bae05d6c9c72a57433ea8076649cae530e24029d",
          "body": "Bumps the non-major group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/go-openapi/runtime](https://github.com/go-openapi/runtime) | `0.29.2` | `0.29.3` |\n| [github.com/openziti/channel/v4](https://github.com/openziti/channel) | `4.3.7` | `4.3.9` |\n| [\n[…]\n/sys\n  dependency-version: 0.42.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump the non-major group across 1 directory with 11 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-17T23:33:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "757734f24208844b003b9fcb1d89cd7139ebc741",
          "body": "…(#889)\n\n* for openziti/ziti#3496 adds TOTP enrollment support during OIDC auth\n\n- adds TotpEnrollmentResult, TotpEnrollmentProvider, TotpEnrollmentProviderFunc\n  types to edge-apis/totp.go\n- detects unenrolled TOTP in handlePrimaryAndSecondaryAuth and routes to\n  handleTotpEnrollment in clients_sha\n[…]\nr interface and ContextImpl\n- adds MfaTotpEnrollmentResponse type and wires TotpEnrollmentProviderFunc\n  into ApiClientConfig in contexts.go\n- adds Authorize() for edge oidc initial auth request tests",
          "is_bot": false,
          "headline": "for openziti/ziti#3496 adds TOTP enrollment support during OIDC auth …",
          "author_name": "Andrew Martinez",
          "author_login": "andrewpmartinez",
          "committed_at": "2026-03-11T13:41:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b27b46246403d0abb153713658b30a2f7c9b474",
          "body": "SDK fixes",
          "is_bot": false,
          "headline": "Merge pull request #888 from openziti/sdk-fixes",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-07T00:51:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2c83d3d4cae632511ff286a4b4f7b9b205b0e7a",
          "body": null,
          "is_bot": false,
          "headline": "Update deps and changelog",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-07T00:48:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b128b637835392c6e7fc4bc89e7adf08ed1a85c5",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog and deps",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T20:17:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39d6eae8f2ca6aa03195f8363ebf1b120248dc5e",
          "body": "- uses RemoveCb instead of Remove so the listener manager is only removed if it\n  matches the current instance, preventing a new manager from being inadvertently removed\n- replaces ConnectTimeout-based session creation loop with IsClosed check, allowing\n  retries to continue until the listener is explicitly closed\n- stops immediately on service access denied errors instead of retrying",
          "is_bot": false,
          "headline": "Fixes listener manager cleanup and session creation loop. Fixes #887",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T19:50:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3419be450e088d417c8186b281a01cb80dbb7421",
          "body": "…tead of falling back to full refresh. Fixes #886\n\n- detects ListServiceUpdatesServiceUnavailable error and returns ErrControllerUnavailable\n- adds retry with random backoff in runRefreshes when the controller is unavailable\n- reorders error handling to check unavailable before unauthorized",
          "is_bot": false,
          "headline": "When controller is busy during service refresh, backoff and retry ins…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T19:50:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd44068b60d20fdc2f3ec57946ba7e34495538e1",
          "body": "…#885\n\n- adds serviceDetailsEqual to compare only fields relevant to hosting and dialing\n- ignores metadata fields like timestamps, tags, posture queries, and role attributes\n- prevents unnecessary ServiceChanged events when the controller returns identical\n  service data with different metadata",
          "is_bot": false,
          "headline": "Only compare relevant service fields when looking for changes. Fixes …",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T19:50:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50fc9512d7839c9204b2d037849dfffbe19dde65",
          "body": "- adds a 1-minute deadline for listeners that haven't been established\n- closes the listener if the deadline is exceeded, preventing stale connections",
          "is_bot": false,
          "headline": "Adds establish deadline for listener forwarding. Fixes #884",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T19:50:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "373aa3416b501287deb5753f9e4ecd72240cca10",
          "body": "- moves the closed check after the type assertion so we have access to the listener\n- closes the listener if the multi-listener is already closed, preventing leaked connections",
          "is_bot": false,
          "headline": "closes listener added after multi-listener was closed. Fixes #883",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T19:50:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f31ca01ec8deb9e3ff202872d372572a6bf00e10",
          "body": "…-5b3dc3e909\n\nBump the non-major group across 1 directory with 4 updates",
          "is_bot": false,
          "headline": "Merge pull request #882 from openziti/dependabot/go_modules/non-major…",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-06T19:28:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "684afb522acc57a7eb41a4cd2030d3caba79651a",
          "body": "Bumps the non-major group with 4 updates in the / directory: [github.com/openziti/foundation/v2](https://github.com/openziti/foundation), [github.com/openziti/identity](https://github.com/openziti/identity), [github.com/openziti/transport/v2](https://github.com/openziti/transport) and [github.com/zi\n[…]\nc/v3\n  dependency-version: 3.45.5\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: non-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump the non-major group across 1 directory with 4 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-05T23:33:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a2a548e0afc35a43ed417e40f431646dcbc49c01",
          "body": "Handle differences in xgress eof/end-of-circuit handling by adding a capabilities exchange. Fixes #877",
          "is_bot": false,
          "headline": "Merge pull request #880 from openziti/xg-capabilities-fix-eof",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-04T16:42:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a9686487e9d1a450b88c42366c9b1ce27b88b0bb",
          "body": "…capabilities exchange. Fixes #877",
          "is_bot": false,
          "headline": "Handle differences in xgress eof/end-of-circuit handling by adding a …",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-03-04T16:38:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e874bc46aadbeb11fd556aa0486610775d3e9745",
          "body": "Add a jitter config, which will default to 0.1, for session and service refreshes. Fixes #832",
          "is_bot": false,
          "headline": "Merge pull request #876 from openziti/jitter-refreshes",
          "author_name": "Paul Lorenz",
          "author_login": "plorenz",
          "committed_at": "2026-02-27T20:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 30,
      "commits_last_year": 180,
      "latest_release_at": "2026-06-12T19:15:37Z",
      "latest_release_tag": "v1.9.0",
      "releases_from_tags": false,
      "days_since_last_push": 8,
      "active_weeks_last_year": 39,
      "days_since_latest_release": 46,
      "mean_days_between_releases": 12.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": true,
      "has_code_of_conduct": true,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/openziti/sdk-golang/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/openziti/sdk-golang/v2",
          "is_deprecated": false,
          "latest_version": "v2.0.0-pre3",
          "repository_url": "https://github.com/openziti/sdk-golang",
          "versions_count": 3,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T14:53:30Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "github.com/openziti/sdk-golang",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/openziti/sdk-golang",
          "is_deprecated": false,
          "latest_version": "v1.9.0",
          "repository_url": "https://github.com/openziti/sdk-golang",
          "versions_count": 788,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-12T19:13:49Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 46
        }
      ]
    },
    "popularity": {
      "forks": 33,
      "stars": 130,
      "watchers": 10,
      "fork_history": {
        "days": [
          {
            "date": "2020-09-21",
            "count": 1
          },
          {
            "date": "2020-12-09",
            "count": 1
          },
          {
            "date": "2021-07-27",
            "count": 1
          },
          {
            "date": "2021-08-03",
            "count": 1
          },
          {
            "date": "2021-09-14",
            "count": 1
          },
          {
            "date": "2021-11-23",
            "count": 1
          },
          {
            "date": "2022-01-24",
            "count": 1
          },
          {
            "date": "2022-04-22",
            "count": 1
          },
          {
            "date": "2022-09-14",
            "count": 1
          },
          {
            "date": "2023-02-28",
            "count": 1
          },
          {
            "date": "2023-04-20",
            "count": 1
          },
          {
            "date": "2023-11-22",
            "count": 1
          },
          {
            "date": "2024-03-03",
            "count": 1
          },
          {
            "date": "2024-03-07",
            "count": 1
          },
          {
            "date": "2024-05-22",
            "count": 1
          },
          {
            "date": "2024-11-20",
            "count": 1
          },
          {
            "date": "2025-01-13",
            "count": 1
          },
          {
            "date": "2025-02-21",
            "count": 1
          },
          {
            "date": "2025-03-03",
            "count": 1
          },
          {
            "date": "2025-05-28",
            "count": 1
          },
          {
            "date": "2025-06-04",
            "count": 1
          },
          {
            "date": "2025-06-06",
            "count": 1
          },
          {
            "date": "2025-06-18",
            "count": 1
          },
          {
            "date": "2025-06-27",
            "count": 1
          },
          {
            "date": "2025-08-01",
            "count": 1
          },
          {
            "date": "2025-08-26",
            "count": 1
          },
          {
            "date": "2025-08-27",
            "count": 1
          },
          {
            "date": "2025-10-27",
            "count": 1
          },
          {
            "date": "2025-10-28",
            "count": 1
          },
          {
            "date": "2026-01-21",
            "count": 1
          },
          {
            "date": "2026-04-12",
            "count": 1
          },
          {
            "date": "2026-05-18",
            "count": 1
          },
          {
            "date": "2026-06-26",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 33,
        "total_forks": 33
      },
      "star_history": null,
      "open_issues_and_prs": 39
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "example"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "pb/edge_client_pb/edge_client.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "acceptance/go.mod",
        "example/go.mod",
        "example/influxdb-client-go/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 147249,
      "source_files_sampled": 192,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "acceptance/go.mod",
        "example/go.mod",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.79.3",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf",
              "GO-2026-6061"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 2,
            "oldest_advisory_days": 7
          },
          {
            "name": "github.com/dgrijalva/jwt-go",
            "direct": false,
            "version": "v3.2.0+incompatible",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-w73w-5m7g-f7qc",
              "GO-2020-0017"
            ],
            "fixed_version": "4.0.0-preview1",
            "advisory_count": 2,
            "oldest_advisory_days": 1931
          },
          {
            "name": "github.com/gomarkdown/markdown",
            "direct": false,
            "version": "v0.0.0-20250311123330-531bef5e742b",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-77fj-vx54-gvh7",
              "GO-2026-5208"
            ],
            "fixed_version": "0.0.0-20260411013819-759bbc3e3207",
            "advisory_count": 2,
            "oldest_advisory_days": 105
          },
          {
            "name": "github.com/gomarkdown/markdown",
            "direct": false,
            "version": "v0.0.0-20250810172220-2e2c11897d1a",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-77fj-vx54-gvh7",
              "GO-2026-5208"
            ],
            "fixed_version": "0.0.0-20260411013819-759bbc3e3207",
            "advisory_count": 2,
            "oldest_advisory_days": 105
          },
          {
            "name": "gopkg.in/square/go-jose.v2",
            "direct": false,
            "version": "v2.6.0",
            "severity": "moderate",
            "ecosystem": "go",
            "cvss_score": 4.3,
            "advisory_ids": [
              "GHSA-c5q2-7r4c-mv6g",
              "GO-2024-2631"
            ],
            "fixed_version": "4.0.1",
            "advisory_count": 2,
            "oldest_advisory_days": 873
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.17.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5841"
            ],
            "fixed_version": "1.18.7",
            "advisory_count": 1,
            "oldest_advisory_days": 2
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 21
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.38.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 3,
          "unknown": 3,
          "critical": 1,
          "moderate": 1
        },
        "advisory_count": 13,
        "affected_count": 8,
        "assessed_count": 186,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/michaelquigley/pfxlog",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.10"
        },
        {
          "name": "github.com/openziti/edge-api",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "github.com/sirupsen/logrus",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.4"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.37.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/openziti/sdk-golang/v2",
          "manifest": "acceptance/go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.0"
        },
        {
          "name": "github.com/Jeffail/gabs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/cenkalti/backoff/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.3.0"
        },
        {
          "name": "github.com/emirpasic/gods",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.18.1"
        },
        {
          "name": "github.com/fullsailor/pkcs7",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20190404230743-d7302db945fa"
        },
        {
          "name": "github.com/go-openapi/runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.32.3"
        },
        {
          "name": "github.com/go-openapi/strfmt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.26.3"
        },
        {
          "name": "github.com/go-resty/resty/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.17.2"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/kataras/go-events",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.3"
        },
        {
          "name": "github.com/michaelquigley/pfxlog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.10"
        },
        {
          "name": "github.com/mitchellh/mapstructure",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/openziti/channel/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.0.10"
        },
        {
          "name": "github.com/openziti/edge-api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "github.com/openziti/foundation/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.95"
        },
        {
          "name": "github.com/openziti/identity",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.133"
        },
        {
          "name": "github.com/openziti/metrics",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.5"
        },
        {
          "name": "github.com/openziti/secretstream",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.51"
        },
        {
          "name": "github.com/openziti/transport/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.216"
        },
        {
          "name": "github.com/orcaman/concurrent-map/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.0.1"
        },
        {
          "name": "github.com/pkg/errors",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/rcrowley/go-metrics",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250401214520-65e299d6c5c9"
        },
        {
          "name": "github.com/shirou/gopsutil/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.26.5"
        },
        {
          "name": "github.com/sirupsen/logrus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.4"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/zitadel/oidc/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.47.5"
        },
        {
          "name": "go.mozilla.org/pkcs7",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.46.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/cenkalti/backoff/v4",
            "direct": true,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emirpasic/gods",
            "direct": true,
            "version": "v1.18.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fullsailor/pkcs7",
            "direct": true,
            "version": "v0.0.0-20190404230743-d7302db945fa",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/runtime",
            "direct": true,
            "version": "v0.32.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/strfmt",
            "direct": true,
            "version": "v0.26.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-resty/resty/v2",
            "direct": true,
            "version": "v2.17.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jeffail/gabs",
            "direct": true,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/go-events",
            "direct": true,
            "version": "v0.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/michaelquigley/pfxlog",
            "direct": true,
            "version": "v0.6.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/channel/v5",
            "direct": true,
            "version": "v5.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/edge-api",
            "direct": true,
            "version": "v0.34.1-0.20260703041337-e7f938dcaa70",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/edge-api",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/foundation/v2",
            "direct": true,
            "version": "v2.0.95",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/identity",
            "direct": true,
            "version": "v1.0.133",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/metrics",
            "direct": true,
            "version": "v1.4.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/secretstream",
            "direct": true,
            "version": "v0.1.51",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/transport/v2",
            "direct": true,
            "version": "v2.0.216",
            "ecosystem": "go"
          },
          {
            "name": "github.com/orcaman/concurrent-map/v2",
            "direct": true,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": true,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rcrowley/go-metrics",
            "direct": true,
            "version": "v0.0.0-20250401214520-65e299d6c5c9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shirou/gopsutil/v4",
            "direct": true,
            "version": "v4.26.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": true,
            "version": "v1.9.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zitadel/oidc/v3",
            "direct": true,
            "version": "v3.47.5",
            "ecosystem": "go"
          },
          {
            "name": "go.mozilla.org/pkcs7",
            "direct": true,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": true,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecthomas/chroma",
            "direct": false,
            "version": "v0.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/andybalholm/brotli",
            "direct": false,
            "version": "v1.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/apapsch/go-jsonmerge/v2",
            "direct": false,
            "version": "v2.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymerick/douceur",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": false,
            "version": "v1.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bytedance/sonic",
            "direct": false,
            "version": "v1.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chenzhuoyu/base64x",
            "direct": false,
            "version": "v0.0.0-20230717121745-296ad89f973d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chenzhuoyu/iasm",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/uax29/v2",
            "direct": false,
            "version": "v2.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudykit/fastprinter",
            "direct": false,
            "version": "v0.0.0-20200109182630-33d98a066a53",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudykit/jet/v6",
            "direct": false,
            "version": "v6.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/deepmap/oapi-codegen",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dgrijalva/jwt-go",
            "direct": false,
            "version": "v3.2.0+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dlclark/regexp2",
            "direct": false,
            "version": "v1.11.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ebitengine/purego",
            "direct": false,
            "version": "v0.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fatih/color",
            "direct": false,
            "version": "v1.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fatih/structs",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/flosch/pongo2/v4",
            "direct": false,
            "version": "v4.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": false,
            "version": "v1.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gabriel-vasile/mimetype",
            "direct": false,
            "version": "v1.4.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gin-contrib/sse",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gin-gonic/gin",
            "direct": false,
            "version": "v1.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": false,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ole/go-ole",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/analysis",
            "direct": false,
            "version": "v0.25.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/errors",
            "direct": false,
            "version": "v0.22.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.23.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.21.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/loads",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/runtime/server-middleware",
            "direct": false,
            "version": "v0.32.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/spec",
            "direct": false,
            "version": "v0.22.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/cmdutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/conv",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/fileutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonname",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/loading",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/mangling",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/netutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/stringutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/typeutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/yamlutils",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/validate",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-playground/locales",
            "direct": false,
            "version": "v0.14.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-playground/universal-translator",
            "direct": false,
            "version": "v0.18.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-playground/validator/v10",
            "direct": false,
            "version": "v10.15.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/goccy/go-json",
            "direct": false,
            "version": "v0.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/snappy",
            "direct": false,
            "version": "v0.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gomarkdown/markdown",
            "direct": false,
            "version": "v0.0.0-20250311123330-531bef5e742b",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gomarkdown/markdown",
            "direct": false,
            "version": "v0.0.0-20250810172220-2e2c11897d1a",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/css",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/mux",
            "direct": false,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/schema",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/securecookie",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/websocket",
            "direct": false,
            "version": "v1.5.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/hcl",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/influxdata/influxdb-client-go/v2",
            "direct": false,
            "version": "v2.12.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/influxdata/line-protocol",
            "direct": false,
            "version": "v0.0.0-20210922203350-b1ad95c89adf",
            "ecosystem": "go"
          },
          {
            "name": "github.com/iris-contrib/schema",
            "direct": false,
            "version": "v0.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jeffail/gabs/v2",
            "direct": false,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/joker/jade",
            "direct": false,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/blocks",
            "direct": false,
            "version": "v0.0.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/golog",
            "direct": false,
            "version": "v0.1.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/iris/v12",
            "direct": false,
            "version": "v12.2.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/pio",
            "direct": false,
            "version": "v0.0.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/sitemap",
            "direct": false,
            "version": "v0.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kataras/tunnel",
            "direct": false,
            "version": "v0.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.17.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/cpuid/v2",
            "direct": false,
            "version": "v2.2.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kyokomi/emoji/v2",
            "direct": false,
            "version": "v2.2.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/labstack/echo/v4",
            "direct": false,
            "version": "v4.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/labstack/gommon",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/leodido/go-urn",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lufia/plan9stats",
            "direct": false,
            "version": "v0.0.0-20260330125221-c963978e514e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/magiconair/properties",
            "direct": false,
            "version": "v1.8.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailgun/raymond/v2",
            "direct": false,
            "version": "v2.0.48",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.7.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": false,
            "version": "v0.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.22",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mgutz/ansi",
            "direct": false,
            "version": "v0.0.0-20200706080929-d51e80ef957d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/michaelmure/go-term-text",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microcosm-cc/bluemonday",
            "direct": false,
            "version": "v1.0.25",
            "ecosystem": "go"
          },
          {
            "name": "github.com/miekg/pkcs11",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muhlemmer/gu",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": false,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/go-term-markdown",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openziti/runzmd",
            "direct": false,
            "version": "v1.0.83",
            "ecosystem": "go"
          },
          {
            "name": "github.com/parallaxsecond/parsec-client-go",
            "direct": false,
            "version": "v0.0.0-20221025095442-f0a77d263cf9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/power-devops/perfstat",
            "direct": false,
            "version": "v0.0.0-20240221224432-82ca36839d55",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rs/cors",
            "direct": false,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/russross/blackfriday/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sagikazarmark/locafero",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sagikazarmark/slog-shim",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/schollz/closestmatch",
            "direct": false,
            "version": "v2.1.0+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shopify/goreferrer",
            "direct": false,
            "version": "v0.0.0-20220729165902-8cddb4f5de06",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sourcegraph/conc",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/speps/go-hashids",
            "direct": false,
            "version": "v2.0.0+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/afero",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": false,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/viper",
            "direct": false,
            "version": "v1.17.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/subosito/gotenv",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tdewolff/minify/v2",
            "direct": false,
            "version": "v2.12.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tdewolff/parse/v2",
            "direct": false,
            "version": "v2.6.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/go-sysconf",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/numcpus",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/twitchyliquid64/golang-asm",
            "direct": false,
            "version": "v0.15.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ugorji/go/codec",
            "direct": false,
            "version": "v1.2.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/valyala/bytebufferpool",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/valyala/fasttemplate",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vmihailenco/msgpack/v5",
            "direct": false,
            "version": "v5.3.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vmihailenco/tagparser/v2",
            "direct": false,
            "version": "v2.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yosssi/ace",
            "direct": false,
            "version": "v0.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yusufpapurcu/wmi",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zitadel/logging",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zitadel/oidc",
            "direct": false,
            "version": "v1.13.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zitadel/schema",
            "direct": false,
            "version": "v1.3.2",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/arch",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20240506185415-9bf2ced13842",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20251202230838-ff82c1b0f217",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.79.3",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc/examples",
            "direct": false,
            "version": "v0.0.0-20231107231549-482de2224942",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/ini.v1",
            "direct": false,
            "version": "v1.67.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/resty.v1",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/square/go-jose.v2",
            "direct": false,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "nhooyr.io/websocket",
            "direct": false,
            "version": "v1.8.17",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 186,
        "direct_count": 33,
        "indirect_count": 153
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 8,
        "merged_prs": 478,
        "open_issues": 31,
        "closed_ratio": 0.825,
        "closed_issues": 146,
        "closed_unmerged_prs": 322
      },
      "bus_factor": 2,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "plorenz",
          "commits": 599,
          "avatar_url": "https://avatars.githubusercontent.com/u/777993?v=4"
        },
        {
          "type": "User",
          "login": "ziti-ci",
          "commits": 474,
          "avatar_url": "https://avatars.githubusercontent.com/u/60663654?v=4"
        },
        {
          "type": "User",
          "login": "andrewpmartinez",
          "commits": 195,
          "avatar_url": "https://avatars.githubusercontent.com/u/199856?v=4"
        },
        {
          "type": "User",
          "login": "dovholuknf",
          "commits": 70,
          "avatar_url": "https://avatars.githubusercontent.com/u/46322585?v=4"
        },
        {
          "type": "User",
          "login": "ekoby",
          "commits": 36,
          "avatar_url": "https://avatars.githubusercontent.com/u/7406535?v=4"
        },
        {
          "type": "User",
          "login": "r-caamano",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/59697426?v=4"
        },
        {
          "type": "User",
          "login": "smilindave26",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/19175177?v=4"
        },
        {
          "type": "User",
          "login": "potto007",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/219596?v=4"
        },
        {
          "type": "User",
          "login": "michaelquigley",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/4443091?v=4"
        },
        {
          "type": "User",
          "login": "qrkourier",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/1434400?v=4"
        }
      ],
      "contributors_sampled": 20,
      "top_contributor_share": 0.408
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "acceptance.yml",
        "cla.yml",
        "golangci-lint.yml",
        "main.yml",
        "mattermost-channel-posts.yml",
        "mattermost-webhook.yml",
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 6 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 9,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "c505373bc6ac48c5711edce200282bde6ca45b41",
        "ran_at": "2026-07-29T16:53:49Z",
        "aggregate_score": 6.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-29T11:42:53Z",
      "oldest_open_prs": [
        {
          "number": 558,
          "created_at": "2024-04-29T14:10:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 658,
          "created_at": "2025-01-13T10:56:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 747,
          "created_at": "2025-06-18T13:38:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 937,
          "created_at": "2026-05-28T13:48:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 956,
          "created_at": "2026-06-22T23:32:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 971,
          "created_at": "2026-06-30T17:27:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 973,
          "created_at": "2026-07-01T23:32:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 975,
          "created_at": "2026-07-20T14:42:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-20T14:53:31Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": [
        {
          "number": 111,
          "created_at": "2020-11-13T19:57:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 160,
          "created_at": "2021-06-16T18:06:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 242,
          "created_at": "2022-04-13T03:33:34Z",
          "last_comment_at": "2022-09-19T13:05:44Z",
          "last_comment_author": "dariuszSki"
        },
        {
          "number": 280,
          "created_at": "2022-07-22T18:26:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 288,
          "created_at": "2022-08-31T18:10:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 310,
          "created_at": "2022-10-17T17:24:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 315,
          "created_at": "2022-10-17T17:30:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 316,
          "created_at": "2022-10-17T17:36:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 346,
          "created_at": "2023-01-12T15:38:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 499,
          "created_at": "2024-02-14T20:26:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 504,
          "created_at": "2024-03-01T13:39:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 581,
          "created_at": "2024-06-11T14:42:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 623,
          "created_at": "2024-09-13T14:14:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 780,
          "created_at": "2025-07-30T04:04:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 842,
          "created_at": "2025-11-26T07:04:10Z",
          "last_comment_at": "2025-12-10T12:52:43Z",
          "last_comment_author": "kamrankamilli"
        },
        {
          "number": 870,
          "created_at": "2026-02-15T03:01:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 875,
          "created_at": "2026-02-24T15:45:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 922,
          "created_at": "2026-04-15T21:16:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 935,
          "created_at": "2026-05-20T17:55:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 974,
          "created_at": "2026-07-09T13:57:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/openziti/sdk-golang",
    "host": "github.com",
    "name": "sdk-golang",
    "owner": "openziti"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "excellent",
      "name": "Overall health",
      "note": "The weighted overall 77 is calibrated to 91 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 77,
            "calibrated": 91,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 91,
      "inputs": {
        "security": 71,
        "vitality": 90,
        "community": 71,
        "governance": 77,
        "calibration": "2026-08-02",
        "engineering": 74,
        "ai_readiness": 69,
        "weighted_overall_raw": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 90,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "commits_last_year": 180,
              "human_commit_share": 0.93,
              "days_since_last_push": 8,
              "active_weeks_last_year": 39
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 8 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "39/52 weeks with commits",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 39
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "180 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 180
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 30,
              "latest_release_tag": "v1.9.0",
              "releases_from_tags": false,
              "days_since_latest_release": 46,
              "mean_days_between_releases": 12.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "30 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 46 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 46
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~12.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 12.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 15,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 15 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 15
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 71,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "forks": 33,
              "stars": 130,
              "watchers": 10,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "130 stars",
                "points": 34.2,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 130
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "33 forks",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 33
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "10 watchers",
                "points": 5.3,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "exceptional",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": true,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 7.2,
                "status": "met",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 77,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 20,
              "top_contributor_share": 0.408
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 41% of commits",
                "points": 13.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 41
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "20 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 78,
            "inputs": {
              "merged_prs": 478,
              "open_issues": 31,
              "closed_issues": 146,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.825,
              "closed_unmerged_prs": 322,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "82% of issues closed",
                "points": 34.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 82
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "478/800 decided PRs merged",
                "points": 17.9,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 478,
                      "decided": 800
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "followers": 990,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "openziti",
              "public_repos": 89,
              "account_age_days": 2260
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "990 followers of openziti",
                "points": 21.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 990,
                      "login": "openziti"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "89 public repos, account ~6 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 89
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 6
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/openziti/sdk-golang/v2",
                "github.com/openziti/sdk-golang"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 9
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 9 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "788 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 788
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "topics": [
                "golang",
                "networking",
                "sdk",
                "zero-trust",
                "appsec",
                "netsec",
                "openziti",
                "secure-networking",
                "ztaa",
                "ztna",
                "security",
                "zerotrust",
                "zero-trust-network",
                "zero-trust-network-access",
                "zero-trust-security"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "15 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 71,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 6.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "exceptional",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 186 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 186
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 13,
              "affected_packages": 8,
              "assessed_packages": 186,
              "unassessed_packages": 0,
              "affected_by_severity": "critical 1, high 3, moderate 1, unknown 3",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 186,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 69,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.871,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "81 of 93 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 81,
                      "sampled": 93
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "acceptance/go.mod",
                "example/go.mod",
                "example/influxdb-client-go/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.07
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "acceptance/go.mod, example/go.mod, example/influxdb-client-go/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "acceptance/go.mod, example/go.mod, example/influxdb-client-go/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "7 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 7,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 147249,
              "source_files_sampled": 192,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/192 source files over 60KB",
                "points": 54.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 192,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "excellent",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "example"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "pb/edge_client_pb/edge_client.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "pb/edge_client_pb/edge_client.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "pb/edge_client_pb/edge_client.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "example",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "example"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "library"
      ],
      "labels": [
        "library"
      ],
      "scores": {
        "library": 7,
        "network-service": 3
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 3
        },
        {
          "tier": "structure",
          "label": "network-service",
          "source": "api_schema",
          "weight": 3
        },
        {
          "tier": "description",
          "label": "library",
          "source": "description:library",
          "weight": 2
        },
        {
          "tier": "tags",
          "label": "library",
          "source": "tag:sdk",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": true
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T16:54:14.575064Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/openziti/sdk-golang.svg",
  "full_name": "openziti/sdk-golang",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v2.5.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.