Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-28 22:08 UTC

pitabwire / frame

A simple bootstrap for quickly starting a server based on gocloud framework

GoApache-2.0★ 5 stars⑂ 2 forkssince Jan 2021View on GitHub ↗

pitabwire/frame holds a health index of 71 out of 100, placing it in the Good band. It scores highest on Vitality (98/100) and lowest on Community & Adoption (38/100). It was last updated 1 day ago. A single contributor accounts for most of its recent work.

71
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

71
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Peter BwirePersonal account
8 followers30 public repossince May 2013@antinvestor

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/pitabwire/frame/v2v2.1.3-211 day ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

98Excellent · 22% of overall
How it's scored
36/36Push recency — last push 1 days ago
33.2/36Commit cadence — 48/52 weeks with commits
18/18Commit volume — 664 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year664
human_commit_share0.87
days_since_last_push1
active_weeks_last_year48

Release discipline

100Excellent
How it's scored
27/27Ships releases — 100 releases published
36/36Release recency — latest release 1 days ago
27/27Release cadence — a release every ~0.7 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count100
latest_release_tagv2.1.2
releases_from_tagsno
days_since_latest_release1
mean_days_between_releases0.7
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

38At risk · 18% of overall
How it's scored
9.8/60Stars — 5 stars
0/25Forks — 2 forks
0/15Watchers — 1 watchers
Inputs used
forks2
stars5
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

57Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
3/10OpenSSF Scorecard: Contributors — project has 1 contributing companies or organizations -- score normalized to 3
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
37.2/38.3PR acceptance — 663/681 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/23 approved changesets -- score normalized to 0
Inputs used
merged_prs663
open_issues0
closed_issues5
issue_closed_ratio1
closed_unmerged_prs18
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
6.9/25Owner reach — 8 followers of pitabwire
22.9/25Track record — 30 public repos, account ~13 yr old
Inputs used
followers8
owner_typeUser
is_verified
owner_loginpitabwire
public_repos30
account_age_days4,830
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 1 days ago
20/20Version history — 21 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/pitabwire/frame/v2
ecosystemsgo
any_deprecatedno
min_days_since_publish1

Engineering Quality

Are baseline engineering and documentation practices in place?

96Excellent · 20% of overall
How it's scored
24/24CI workflows — 9 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yaml
9.6/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configyes
has_precommit_configyes

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://pitabwire.github.io/frame/
10/10Repository description
10/10Topics — 7 topics
10/10Wiki
Inputs used
topicsgo, golang, boilerplate, gocloud, microservice, postgresql, message-queue
has_wikiyes
homepagehttps://pitabwire.github.io/frame/
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/23 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5.2
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.
How it's scored
35/35Direct dependencies free of known advisories — no direct dependency carries a known advisory
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
0/40No advisories left outstanding — no advisory carries a publication date
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages149
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 149 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

71Good · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 86 of 87 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.989
agent_instruction_files
agent_instruction_max_bytes
How it's scored
18/18One-command bootstrap — Makefile
22/22Automated tests
11/11Lint / format config — .golangci.yaml
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — lockfile
0/10Demonstrated agent practice — no agent-authored commits among the last 100
8/8Automated maintenance — 13 of the last 100 commits are automated dependency updates
1/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileno
typed_languageyes
bootstrap_filesMakefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0.13
How it's scored
45/45Type-checkable code — Go (statically typed)
54.8/55Manageable file sizes — 1/297 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes96,081
source_files_sampled297
oversized_source_files1
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — frametests/rpcservice/ping/v1/ping.proto
0/20MCP server
40/40Runnable examples — examples
Inputs used
example_dirsexamples
has_mcp_signalno
api_schema_filesframetests/rpcservice/ping/v1/ping.proto

Key facts

5GitHub stars
1contributors
664commits, last 12 months
1days since last push
100releases
1bus factor
0open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

Star and fork history 0 ★ / 2 ⇿
0Stars
2Forks

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

111222212021-092022-112023-12

Each point covers 3 days.

OpenSSF Scorecard 5.2 / 10
5.2aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-28 22:07 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/23 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 47
RegistryPackageVersion constraintManifest
Gobuf.build/go/protovalidatev1.2.0go.mod
Goconnectrpc.com/connectv1.20.0go.mod
Goconnectrpc.com/otelconnectv0.9.0go.mod
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/caarlos0/env/v11v11.4.1go.mod
Gogithub.com/exaring/otelpgxv0.11.1go.mod
Gogithub.com/go-jose/go-jose/v4v4.1.4go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/jackc/pgx/v5v5.10.0go.mod
Gogithub.com/lmittmann/tintv1.2.0go.mod
Gogithub.com/moby/moby/apiv1.55.0go.mod
Gogithub.com/nats-io/nats.gov1.52.0go.mod
Gogithub.com/nicksnyder/go-i18n/v2v2.6.1go.mod
Gogithub.com/ory/keto/protov0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0go.mod
Gogithub.com/panjf2000/ants/v2v2.12.1go.mod
Gogithub.com/pitabwire/natspubsubv0.8.4go.mod
Gogithub.com/pitabwire/utilv0.9.1go.mod
Gogithub.com/redis/go-redis/v9v9.21.0go.mod
Gogithub.com/rs/xidv1.6.0go.mod
Gogithub.com/spiffe/go-spiffe/v2v2.8.1go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/testcontainers/testcontainers-gov0.43.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/natsv0.43.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/postgresv0.43.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/valkeyv0.43.0go.mod
Gogithub.com/valkey-io/valkey-gov1.0.76go.mod
Gogo.opentelemetry.io/contrib/bridges/otelslogv0.19.0go.mod
Gogo.opentelemetry.io/contrib/exporters/autoexportv0.69.0go.mod
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0go.mod
Gogo.opentelemetry.io/contrib/propagators/autopropv0.69.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/logv0.20.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/logv0.20.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogocloud.devv0.46.0go.mod
Gogolang.org/x/netv0.57.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/textv0.40.0go.mod
Gogoogle.golang.org/apiv0.290.0go.mod
Gogoogle.golang.org/grpcv1.82.1go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gogorm.io/driver/postgresv1.6.0go.mod
Gogorm.io/gormv1.31.2go.mod
All dependencies 149

Full resolved dependency set from the GitHub dependency graph: 47 direct and 102 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gobuf.build/go/protovalidatev1.2.0direct
Goconnectrpc.com/connectv1.20.0direct
Goconnectrpc.com/otelconnectv0.9.0direct
Gogithub.com/burntsushi/tomlv1.6.0direct
Gogithub.com/caarlos0/env/v11v11.4.1direct
Gogithub.com/exaring/otelpgxv0.11.1direct
Gogithub.com/go-jose/go-jose/v4v4.1.4direct
Gogithub.com/golang-jwt/jwt/v5v5.3.1direct
Gogithub.com/jackc/pgx/v5v5.10.0direct
Gogithub.com/lmittmann/tintv1.2.0direct
Gogithub.com/moby/moby/apiv1.55.0direct
Gogithub.com/nats-io/nats.gov1.52.0direct
Gogithub.com/nicksnyder/go-i18n/v2v2.6.1direct
Gogithub.com/ory/keto/protov0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0direct
Gogithub.com/panjf2000/ants/v2v2.12.1direct
Gogithub.com/pitabwire/natspubsubv0.8.4direct
Gogithub.com/pitabwire/utilv0.9.1direct
Gogithub.com/redis/go-redis/v9v9.21.0direct
Gogithub.com/rs/xidv1.6.0direct
Gogithub.com/spiffe/go-spiffe/v2v2.8.1direct
Gogithub.com/stretchr/testifyv1.11.1direct
Gogithub.com/testcontainers/testcontainers-gov0.43.0direct
Gogithub.com/testcontainers/testcontainers-go/modules/natsv0.43.0direct
Gogithub.com/testcontainers/testcontainers-go/modules/postgresv0.43.0direct
Gogithub.com/testcontainers/testcontainers-go/modules/valkeyv0.43.0direct
Gogithub.com/valkey-io/valkey-gov1.0.76direct
Gogo.opentelemetry.io/contrib/bridges/otelslogv0.19.0direct
Gogo.opentelemetry.io/contrib/exporters/autoexportv0.69.0direct
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0direct
Gogo.opentelemetry.io/contrib/propagators/autopropv0.69.0direct
Gogo.opentelemetry.io/otelv1.44.0direct
Gogo.opentelemetry.io/otel/logv0.20.0direct
Gogo.opentelemetry.io/otel/metricv1.44.0direct
Gogo.opentelemetry.io/otel/sdkv1.44.0direct
Gogo.opentelemetry.io/otel/sdk/logv0.20.0direct
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0direct
Gogo.opentelemetry.io/otel/tracev1.44.0direct
Gogocloud.devv0.46.0direct
Gogolang.org/x/netv0.57.0direct
Gogolang.org/x/oauth2v0.36.0direct
Gogolang.org/x/textv0.40.0direct
Gogoogle.golang.org/apiv0.290.0direct
Gogoogle.golang.org/grpcv1.82.1direct
Gogoogle.golang.org/protobufv1.36.11direct
Gogopkg.in/yaml.v3v3.0.1direct
Gogorm.io/driver/postgresv1.6.0direct
Gogorm.io/gormv1.31.2direct
Gobuf.build/gen/go/bufbuild/protovalidate/protocolbuffers/gov1.36.11-20260709200747-435963d16310.1indirect
Gocel.dev/exprv0.25.2indirect
Gocloud.google.com/go/authv0.22.0indirect
Gocloud.google.com/go/auth/oauth2adaptv0.2.8indirect
Gocloud.google.com/go/compute/metadatav0.9.0indirect
Gocloud.google.com/go/iamv1.12.0indirect
Gocloud.google.com/go/pubsubv1.51.0indirect
Gocloud.google.com/go/pubsub/v2v2.6.1indirect
Godario.cat/mergov1.0.2indirect
Gogithub.com/antlr4-go/antlr/v4v4.13.1indirect
Gogithub.com/azure/go-ansitermv0.0.0-20250102033503-faa5f7b0171cindirect
Gogithub.com/beorn7/perksv1.0.1indirect
Gogithub.com/cenkalti/backoff/v4v4.3.0indirect
Gogithub.com/cenkalti/backoff/v5v5.0.3indirect
Gogithub.com/cespare/xxhash/v2v2.3.0indirect
Gogithub.com/containerd/errdefsv1.0.0indirect
Gogithub.com/containerd/errdefs/pkgv0.3.0indirect
Gogithub.com/containerd/logv0.1.0indirect
Gogithub.com/containerd/platformsv0.2.1indirect
Gogithub.com/cpuguy83/dockercfgv0.3.2indirect
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirect
Gogithub.com/distribution/referencev0.6.0indirect
Gogithub.com/docker/go-connectionsv0.8.0indirect
Gogithub.com/docker/go-unitsv0.5.0indirect
Gogithub.com/ebitengine/puregov0.10.2indirect
Gogithub.com/felixge/httpsnoopv1.1.0indirect
Gogithub.com/go-logr/logrv1.4.4indirect
Gogithub.com/go-logr/stdrv1.2.2indirect
Gogithub.com/go-ole/go-olev1.3.0indirect
Gogithub.com/google/cel-gov0.30.0indirect
Gogithub.com/google/s2a-gov0.1.9indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/google/wirev0.7.0indirect
Gogithub.com/googleapis/enterprise-certificate-proxyv0.3.19indirect
Gogithub.com/googleapis/gax-go/v2v2.23.0indirect
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0indirect
Gogithub.com/jackc/pgpassfilev1.0.0indirect
Gogithub.com/jackc/pgservicefilev0.0.0-20240606120523-5a60cdf6a761indirect
Gogithub.com/jackc/puddle/v2v2.2.2indirect
Gogithub.com/jinzhu/inflectionv1.0.0indirect
Gogithub.com/jinzhu/nowv1.1.5indirect
Gogithub.com/klauspost/compressv1.19.1indirect
Gogithub.com/lufia/plan9statsv0.0.0-20260627054121-477a66015f15indirect
Gogithub.com/magiconair/propertiesv1.18.11indirect
Gogithub.com/mdelapenya/tlscertv0.2.0indirect
Gogithub.com/microsoft/go-winiov0.6.2indirect
Gogithub.com/moby/docker-image-specv1.3.1indirect
Gogithub.com/moby/go-archivev0.2.1indirect
Gogithub.com/moby/moby/clientv0.5.0indirect
Gogithub.com/moby/patternmatcherv0.6.1indirect
Gogithub.com/moby/sys/sequentialv0.7.0indirect
Gogithub.com/moby/sys/userv0.4.1indirect
Gogithub.com/moby/sys/usernsv0.1.0indirect
Gogithub.com/moby/termv0.5.2indirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/nats-io/nkeysv0.4.16indirect
Gogithub.com/nats-io/nuidv1.0.1indirect
Gogithub.com/opencontainers/go-digestv1.0.0indirect
Gogithub.com/opencontainers/image-specv1.1.1indirect
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirect
Gogithub.com/power-devops/perfstatv0.0.0-20240221224432-82ca36839d55indirect
Gogithub.com/prometheus/client_golangv1.24.1indirect
Gogithub.com/prometheus/client_modelv0.6.2indirect
Gogithub.com/prometheus/commonv0.70.1indirect
Gogithub.com/prometheus/otlptranslatorv1.0.0indirect
Gogithub.com/prometheus/procfsv0.21.1indirect
Gogithub.com/shirou/gopsutil/v4v4.26.6indirect
Gogithub.com/sirupsen/logrusv1.9.4indirect
Gogithub.com/tklauser/go-sysconfv0.4.0indirect
Gogithub.com/tklauser/numcpusv0.12.0indirect
Gogithub.com/yusufpapurcu/wmiv1.2.4indirect
Gogo.opentelemetry.io/auto/sdkv1.2.1indirect
Gogo.opentelemetry.io/contrib/bridges/prometheusv0.69.0indirect
Gogo.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpcv0.69.0indirect
Gogo.opentelemetry.io/contrib/propagators/awsv1.44.0indirect
Gogo.opentelemetry.io/contrib/propagators/b3v1.44.0indirect
Gogo.opentelemetry.io/contrib/propagators/jaegerv1.44.0indirect
Gogo.opentelemetry.io/contrib/propagators/otv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpcv0.20.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpv0.20.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0indirect
Gogo.opentelemetry.io/otel/exporters/stdout/stdoutlogv0.20.0indirect
Gogo.opentelemetry.io/otel/exporters/stdout/stdoutmetricv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0indirect
Gogo.opentelemetry.io/proto/otlpv1.11.0indirect
Gogo.uber.org/atomicv1.11.0indirect
Gogo.uber.org/multierrv1.11.0indirect
Gogo.yaml.in/yaml/v3v3.0.5indirect
Gogolang.org/x/cryptov0.54.0indirect
Gogolang.org/x/expv0.0.0-20260718201538-764159d718efindirect
Gogolang.org/x/syncv0.22.0indirect
Gogolang.org/x/sysv0.47.0indirect
Gogolang.org/x/timev0.15.0indirect
Gogolang.org/x/xerrorsv0.0.0-20240903120638-7835f813f4daindirect
Gogoogle.golang.org/genprotov0.0.0-20260724162435-b2f20204f0dfindirect
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260724162435-b2f20204f0dfindirect
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260724162435-b2f20204f0dfindirect
Dependency advisories 1

This repository publishes no package the index resolves, so its own dependency graph was assessed — 149 packages, which also include development and test pins that never ship: 1 carry known advisories, of which 0 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
golang.org/x/cryptov0.54.0indirectunknown1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "go",
        "golang",
        "boilerplate",
        "gocloud",
        "microservice",
        "postgresql",
        "message-queue"
      ],
      "is_fork": false,
      "size_kb": 3665,
      "has_wiki": true,
      "homepage": "https://pitabwire.github.io/frame/",
      "languages": {
        "Go": 1427227,
        "Makefile": 2722
      },
      "pushed_at": "2026-07-27T10:22:43Z",
      "created_at": "2021-01-01T16:57:43Z",
      "owner_type": "User",
      "updated_at": "2026-07-27T10:23:40Z",
      "description": "A simple bootstrap for quickly starting a server based on gocloud framework",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://www.linkedin.com/in/pitabwire",
      "name": "Peter Bwire",
      "type": "User",
      "login": "pitabwire",
      "company": "@antinvestor ",
      "location": "Busia",
      "followers": 8,
      "avatar_url": "https://avatars.githubusercontent.com/u/4368681?v=4",
      "created_at": "2013-05-07T19:30:52Z",
      "is_verified": null,
      "public_repos": 30,
      "account_age_days": 4830
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2026-07-27T10:09:49Z"
        },
        {
          "tag": "v2.0.14",
          "kind": "patch",
          "published_at": "2026-07-25T09:56:02Z"
        },
        {
          "tag": "v2.0.13",
          "kind": "patch",
          "published_at": "2026-07-25T09:51:25Z"
        },
        {
          "tag": "v2.0.12",
          "kind": "patch",
          "published_at": "2026-07-24T16:34:08Z"
        },
        {
          "tag": "v2.0.11",
          "kind": "patch",
          "published_at": "2026-07-24T16:27:20Z"
        },
        {
          "tag": "v2.0.10",
          "kind": "patch",
          "published_at": "2026-07-24T16:26:43Z"
        },
        {
          "tag": "v2.0.9",
          "kind": "patch",
          "published_at": "2026-07-24T16:16:19Z"
        },
        {
          "tag": "v2.0.8",
          "kind": "patch",
          "published_at": "2026-07-24T16:16:26Z"
        },
        {
          "tag": "v2.0.7",
          "kind": "patch",
          "published_at": "2026-07-21T18:34:18Z"
        },
        {
          "tag": "v2.0.5",
          "kind": "patch",
          "published_at": "2026-07-21T02:22:26Z"
        },
        {
          "tag": "v2.0.4",
          "kind": "patch",
          "published_at": "2026-07-11T02:21:38Z"
        },
        {
          "tag": "v2.0.3",
          "kind": "patch",
          "published_at": "2026-07-09T20:00:08Z"
        },
        {
          "tag": "v2.0.2",
          "kind": "patch",
          "published_at": "2026-07-06T00:38:27Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-06-29T00:43:50Z"
        },
        {
          "tag": "v1.98.4",
          "kind": "patch",
          "published_at": "2026-06-10T21:40:07Z"
        },
        {
          "tag": "v1.98.3",
          "kind": "patch",
          "published_at": "2026-06-10T17:13:37Z"
        },
        {
          "tag": "v1.98.2",
          "kind": "patch",
          "published_at": "2026-06-10T15:58:55Z"
        },
        {
          "tag": "v1.98.1",
          "kind": "patch",
          "published_at": "2026-06-10T09:47:29Z"
        },
        {
          "tag": "v1.98.0",
          "kind": "minor",
          "published_at": "2026-06-08T13:58:47Z"
        },
        {
          "tag": "v1.94.11",
          "kind": "patch",
          "published_at": "2026-06-06T00:44:57Z"
        },
        {
          "tag": "v1.94.10",
          "kind": "patch",
          "published_at": "2026-05-26T00:42:56Z"
        },
        {
          "tag": "v1.94.9",
          "kind": "patch",
          "published_at": "2026-05-21T00:44:59Z"
        },
        {
          "tag": "v1.94.8",
          "kind": "patch",
          "published_at": "2026-05-16T00:37:39Z"
        },
        {
          "tag": "v1.94.7",
          "kind": "patch",
          "published_at": "2026-05-10T08:21:00Z"
        },
        {
          "tag": "v1.94.6",
          "kind": "patch",
          "published_at": "2026-04-20T18:08:05Z"
        },
        {
          "tag": "v1.94.5",
          "kind": "patch",
          "published_at": "2026-04-20T17:55:00Z"
        },
        {
          "tag": "v1.94.4",
          "kind": "patch",
          "published_at": "2026-04-20T15:44:41Z"
        },
        {
          "tag": "v1.94.3",
          "kind": "patch",
          "published_at": "2026-04-20T14:51:28Z"
        },
        {
          "tag": "v1.94.2",
          "kind": "patch",
          "published_at": "2026-04-20T14:02:20Z"
        },
        {
          "tag": "v1.94.1",
          "kind": "patch",
          "published_at": "2026-04-14T12:11:28Z"
        },
        {
          "tag": "v1.94.0",
          "kind": "minor",
          "published_at": "2026-04-14T11:27:22Z"
        },
        {
          "tag": "v1.93.6",
          "kind": "patch",
          "published_at": "2026-04-11T00:26:47Z"
        },
        {
          "tag": "v1.93.5",
          "kind": "patch",
          "published_at": "2026-04-06T00:28:10Z"
        },
        {
          "tag": "v1.93.4",
          "kind": "patch",
          "published_at": "2026-04-03T09:19:24Z"
        },
        {
          "tag": "v1.93.3",
          "kind": "patch",
          "published_at": "2026-04-03T08:57:46Z"
        },
        {
          "tag": "v1.93.2",
          "kind": "patch",
          "published_at": "2026-04-03T08:52:47Z"
        },
        {
          "tag": "v1.93.1",
          "kind": "patch",
          "published_at": "2026-04-03T08:45:48Z"
        },
        {
          "tag": "v1.93.0",
          "kind": "minor",
          "published_at": "2026-03-31T10:11:26Z"
        },
        {
          "tag": "v1.90.2",
          "kind": "patch",
          "published_at": "2026-04-01T00:30:25Z"
        },
        {
          "tag": "v1.90.1",
          "kind": "patch",
          "published_at": "2026-03-31T00:27:19Z"
        },
        {
          "tag": "v1.90.0",
          "kind": "minor",
          "published_at": "2026-03-29T07:24:38Z"
        },
        {
          "tag": "v1.89.0",
          "kind": "minor",
          "published_at": "2026-03-29T06:59:12Z"
        },
        {
          "tag": "v1.88.0",
          "kind": "minor",
          "published_at": "2026-03-28T16:39:01Z"
        },
        {
          "tag": "v1.87.0",
          "kind": "minor",
          "published_at": "2026-03-28T16:05:15Z"
        },
        {
          "tag": "v1.86.0",
          "kind": "minor",
          "published_at": "2026-03-28T15:31:42Z"
        },
        {
          "tag": "v1.85.0",
          "kind": "minor",
          "published_at": "2026-03-28T15:19:54Z"
        },
        {
          "tag": "v1.84.0",
          "kind": "minor",
          "published_at": "2026-03-28T14:54:29Z"
        },
        {
          "tag": "v1.82.2",
          "kind": "patch",
          "published_at": "2026-03-26T00:26:59Z"
        },
        {
          "tag": "v1.82.1",
          "kind": "patch",
          "published_at": "2026-03-25T02:51:19Z"
        },
        {
          "tag": "v1.81.1",
          "kind": "patch",
          "published_at": "2026-03-22T11:04:42Z"
        },
        {
          "tag": "v1.81.0",
          "kind": "minor",
          "published_at": "2026-03-22T10:35:29Z"
        },
        {
          "tag": "v1.80.1",
          "kind": "patch",
          "published_at": "2026-03-19T11:06:44Z"
        },
        {
          "tag": "v1.79.2",
          "kind": "patch",
          "published_at": "2026-03-16T00:27:32Z"
        },
        {
          "tag": "v1.79.1",
          "kind": "patch",
          "published_at": "2026-03-13T18:58:52Z"
        },
        {
          "tag": "v1.78.2",
          "kind": "patch",
          "published_at": "2026-03-12T19:52:56Z"
        },
        {
          "tag": "v1.78.1",
          "kind": "patch",
          "published_at": "2026-03-12T19:25:49Z"
        },
        {
          "tag": "v1.78.0",
          "kind": "minor",
          "published_at": "2026-03-12T16:50:48Z"
        },
        {
          "tag": "v1.77.3",
          "kind": "patch",
          "published_at": "2026-03-12T16:47:15Z"
        },
        {
          "tag": "v1.77.2",
          "kind": "patch",
          "published_at": "2026-03-09T19:07:47Z"
        },
        {
          "tag": "v1.77.1",
          "kind": "patch",
          "published_at": "2026-03-08T11:30:57Z"
        },
        {
          "tag": "v1.77.0",
          "kind": "minor",
          "published_at": "2026-03-07T15:14:32Z"
        },
        {
          "tag": "v1.76.6",
          "kind": "patch",
          "published_at": "2026-03-05T19:12:28Z"
        },
        {
          "tag": "v1.76.5",
          "kind": "patch",
          "published_at": "2026-03-05T02:23:33Z"
        },
        {
          "tag": "v1.76.4",
          "kind": "patch",
          "published_at": "2026-03-01T00:25:53Z"
        },
        {
          "tag": "v1.76.3",
          "kind": "patch",
          "published_at": "2026-02-28T08:39:09Z"
        },
        {
          "tag": "v1.76.2",
          "kind": "patch",
          "published_at": "2026-02-28T08:28:44Z"
        },
        {
          "tag": "v1.76.1",
          "kind": "patch",
          "published_at": "2026-02-27T20:51:19Z"
        },
        {
          "tag": "v1.76.0",
          "kind": "minor",
          "published_at": "2026-02-27T15:20:28Z"
        },
        {
          "tag": "v1.75.0",
          "kind": "minor",
          "published_at": "2026-02-25T16:07:12Z"
        },
        {
          "tag": "v1.74.1",
          "kind": "patch",
          "published_at": "2026-02-26T00:21:36Z"
        },
        {
          "tag": "v1.74.0",
          "kind": "minor",
          "published_at": "2026-02-25T13:39:02Z"
        },
        {
          "tag": "v1.73.0",
          "kind": "minor",
          "published_at": "2026-02-25T11:27:53Z"
        },
        {
          "tag": "v1.72.1",
          "kind": "patch",
          "published_at": "2026-02-11T00:28:31Z"
        },
        {
          "tag": "v1.72.0",
          "kind": "minor",
          "published_at": "2026-02-06T08:02:49Z"
        },
        {
          "tag": "v1.71.1",
          "kind": "patch",
          "published_at": "2026-02-05T04:09:04Z"
        },
        {
          "tag": "v1.71.0",
          "kind": "minor",
          "published_at": "2026-02-04T13:31:03Z"
        },
        {
          "tag": "v1.70.2",
          "kind": "patch",
          "published_at": "2026-01-27T11:22:34Z"
        },
        {
          "tag": "v1.70.1",
          "kind": "patch",
          "published_at": "2026-01-26T13:00:17Z"
        },
        {
          "tag": "v1.70.0",
          "kind": "minor",
          "published_at": "2026-01-25T11:05:00Z"
        },
        {
          "tag": "v1.69.14",
          "kind": "patch",
          "published_at": "2026-01-25T10:13:39Z"
        },
        {
          "tag": "v1.69.13",
          "kind": "patch",
          "published_at": "2025-12-27T06:22:10Z"
        },
        {
          "tag": "v1.69.12",
          "kind": "patch",
          "published_at": "2025-12-19T19:15:37Z"
        },
        {
          "tag": "v1.69.11",
          "kind": "patch",
          "published_at": "2025-12-19T15:56:22Z"
        },
        {
          "tag": "v1.69.10",
          "kind": "patch",
          "published_at": "2025-12-19T09:43:18Z"
        },
        {
          "tag": "v1.69.9",
          "kind": "patch",
          "published_at": "2025-12-19T08:34:49Z"
        },
        {
          "tag": "v1.69.8",
          "kind": "patch",
          "published_at": "2025-12-19T07:34:49Z"
        },
        {
          "tag": "v1.69.7",
          "kind": "patch",
          "published_at": "2025-12-19T05:26:09Z"
        },
        {
          "tag": "v1.69.6",
          "kind": "patch",
          "published_at": "2025-12-19T05:22:02Z"
        },
        {
          "tag": "v1.69.5",
          "kind": "patch",
          "published_at": "2025-12-18T08:46:38Z"
        },
        {
          "tag": "v1.69.4",
          "kind": "patch",
          "published_at": "2025-12-18T08:02:06Z"
        },
        {
          "tag": "v1.69.3",
          "kind": "patch",
          "published_at": "2025-12-17T07:30:26Z"
        },
        {
          "tag": "v1.69.2",
          "kind": "patch",
          "published_at": "2025-12-17T06:57:44Z"
        },
        {
          "tag": "v1.69.1",
          "kind": "patch",
          "published_at": "2025-12-16T08:21:05Z"
        },
        {
          "tag": "v1.69.0",
          "kind": "minor",
          "published_at": "2025-12-13T05:32:08Z"
        },
        {
          "tag": "v1.68.15",
          "kind": "patch",
          "published_at": "2025-12-11T00:18:24Z"
        },
        {
          "tag": "v1.68.14",
          "kind": "patch",
          "published_at": "2025-12-08T09:32:27Z"
        },
        {
          "tag": "v1.68.13",
          "kind": "patch",
          "published_at": "2025-12-06T12:38:32Z"
        },
        {
          "tag": "v1.68.12",
          "kind": "patch",
          "published_at": "2025-12-04T19:08:27Z"
        },
        {
          "tag": "v1.68.11",
          "kind": "patch",
          "published_at": "2025-12-04T18:30:50Z"
        },
        {
          "tag": "v1.68.10",
          "kind": "patch",
          "published_at": "2025-12-04T12:25:04Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2e77d14b44836599674ac7cb8f05b57826a62664",
          "body": "WithDatastore only created DefaultMigrationPoolName when DO_MIGRATION was\ntrue. Job argv [\"setup\"] / DO_SETUP therefore failed migrate steps with\n\"datastore pool is not initialised\". Open the migration pool whenever\nsetup mode is active as well as for legacy migrate.",
          "is_bot": false,
          "headline": "fix(datastore): open migration pool for setup plan jobs",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T10:22:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3d41fd993f92878960cbf21e5f179374bf74339",
          "body": "Support subdomain-style audiences such as https://profile.stawi.org\n(empty path) in addition to legacy path form under an API host.",
          "is_bot": false,
          "headline": "feat(config): allow host-only OAuth resource audiences",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T10:08:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e785e68f7b62c50f25193bd79384dcc9493aef2",
          "body": "Document Job argv [\"setup\"] (all registered steps) and DO_SETUP as the\ncanonical one-shot path. Legacy migrate / DO_MIGRATION remains supported\nbut is no longer the recommended default for deploys.",
          "is_bot": false,
          "headline": "docs(setup): prefer full setup plan over legacy migrate argv",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T09:55:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1aa8df036c9a215fd4f84a8ef6cd3e65f3d6080",
          "body": "GetRoles only accepted comma-separated strings under ext.roles, so Hydra\nsession extras shaped as [\"internal\"] left IsInternalSystem false. Service\nbots then checked tenancy_access#member instead of #service and permission\nregistration rejected internal SA tokens.\n\nAlso attach X-Serverless-Authorization (Google ID token) on HTTPS HTTP\nclient calls so product OAuth and Cloud Run invoker can both succeed when\nregistering permission manifests against IAM-authenticated tenancy hosts.",
          "is_bot": false,
          "headline": "fix(security): parse JWT roles arrays; dual-auth Cloud Run HTTP",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T09:15:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5824b66b3076752d1914c095e7874162fed7fd33",
          "body": "Fix relative link in multi-tenant isolation spec that broke\nmkdocs build --strict. Update direct/indirect Go modules\n(google.golang.org/api and transitive deps) to latest.",
          "is_bot": false,
          "headline": "fix(docs): repair mkdocs strict link; bump go deps",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T22:17:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49269b5592ccaa001d4f952f706b9a7f2d81feb9",
          "body": "The setup plan / no-PreStart contract is released as minor v2.1.0.",
          "is_bot": false,
          "headline": "docs(setup): prefer frame v2.1.0 over v2.0.17 patch series",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T19:20:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1b547c27bcd839879457daaf27d74e779a498ba",
          "body": "Permission manifests publish only via the setup plan (setup.NamePermissions).\nThis keeps Cloud Run cold starts fast and makes deploy-time registration\nfail-closed on the Job.\n\n- Drop PreStart path from WithPermissionRegistration\n- Add ShouldRunSetup + RunSetupForProcess for setup and legacy migrate\n- PERMISSIONS_REGISTER_ON_START deprecated/ignored (default false)\n- Docs: SETUP_JOB.md",
          "is_bot": false,
          "headline": "fix(setup): remove runtime PreStart permission registration",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20ebb153d5626d7c461e09e8b685661d3d6c3fc2",
          "body": "feat(setup): multi-task setup job (migrate, permissions, bootstrap)",
          "is_bot": false,
          "headline": "Merge pull request #688 from pitabwire/feat/setup-job",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:27:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f558c118f99b2826f43e57a11a6bdc94cc150c6",
          "body": "Move setup out of Frame-specific task funcs into package setup:\n\n- setup.Step / setup.Func — pure Name + Run contract\n- setup.Registry — register + bulk Run / RunAll (fail-closed, ordered)\n- setup.Selection / Select — argv and env without Service coupling\n\nFrame keeps thin adapters (Service.Setup, W\n[…]\netupStep/Func/Task,\nRunSetup, IsSetupMode). WithPermissionRegistration registers an abstract\npermissions Step on the registry.\n\nDocument fully in docs/SETUP_JOB.md, setup/README.md, service.md, index.",
          "is_bot": false,
          "headline": "refactor(setup): abstract Step interface and bulk Registry",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:26:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d369765aecc4fe07026098e70e097872a73d71eb",
          "body": "Add Service.RunSetup / WithSetupTask / IsSetupMode so Cloud Run Jobs can\nrun ordered one-shot steps (schema migrate, permission manifest publish,\nroot/bot bootstrap) instead of relying on every runtime PreStart.\n\nWithPermissionRegistration now:\n- always registers SetupTaskPermissions (fail-closed sy\n[…]\nsync PreStart when PERMISSIONS_REGISTER_ON_START=true\n  (default, Colony parity); set false on CR replicas once setup owns it\n\nLegacy argv migrate alone is unchanged. Prefer setup migrate permissions.",
          "is_bot": false,
          "headline": "feat(setup): multi-task setup job for migrate, permissions, bootstrap",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:20:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f26ca5694efa49cc769b5c6d7b14df6e84bb038",
          "body": "Plaintext insecure credentials broke https AUTHORIZATION_SERVICE_* URIs\non Cloud Run (unexpected EOF on server preface). Use TLS for https and\nattach a Google ID token when ADC can mint one so IAM-authenticated\nKeto services accept invoker calls. Keep insecure for http:// cluster\nURLs.",
          "is_bot": false,
          "headline": "fix(authorizer): TLS + Cloud Run ID token for Keto gRPC",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T07:06:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6508c0c9d8a99b84b20f7961a61c12acb45090a2",
          "body": "configWithoutHTTPServer only stubbed two events methods, so Run failed\non ConfigurationEvents before reaching ErrHTTPServerConfigRequired.",
          "is_bot": false,
          "headline": "test(service): implement full ConfigurationEvents in HTTP config test",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T09:55:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2472051cfd17e8230c1f4f4b1116c9b51626b81b",
          "body": "Stamp membership on create from JWT claims, keep access_id immutable on\nrepository updates (with tenant/partition), and prefer profile_id for\ncreated_by/modified_by. Document that access_id is not RLS or Keto scope.",
          "is_bot": false,
          "headline": "fix(data): treat access_id as write attribution only",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T08:55:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a566961a9ac5988a40034873ddc61ea7bb15762",
          "body": "Add Service.ConnectDefaultInterceptors so handlers pick up the service\nClaimsBinder automatically (RequireClaims + no internal Skip under\nHybrid), making transparent isolation one call for Connect stacks.",
          "is_bot": false,
          "headline": "feat(service): wire Secure Profile into Connect default interceptors",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T06:59:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fe7fa916f620f3967edd3e9f5adced0179ce17b",
          "body": "Implement mode-driven multi-tenant isolation so services can opt into\ntransparent RLS enforcement without hand-written tenant filters.\n\n- Security modes: fail_open (default), hybrid, fail_closed\n- SystemPrincipal with scoped bind; AllowGlobal only via allowlist or\n  unforgeable framework migration m\n[…]\nds on untrusted push\n- Tenant-aware cache prefixes (t/ sys/ g/ unset/)\n- Enrollment strict + readiness arming for non-BYPASSRLS roles\n- WithSecureProfile() and design spec under docs/superpowers/specs",
          "is_bot": false,
          "headline": "feat(tenancy): Secure Profile isolation with fail-closed modes",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T06:57:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fd41dfc501a2c42f1acaaffdf5f923bc9030d88",
          "body": "Normalize and validate tenant/partition IDs, preserve multi-partition\nsets across queue AsMetadata/ClaimsFromMap round-trips, and stop\nblanket-skipping RLS in queue consumers so published tenancy is enforced.",
          "is_bot": false,
          "headline": "fix(tenancy): harden claims validation and auth mapping",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T05:34:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "277b56540f13dc2a966e2e92371f952fcb317993",
          "body": "Register the three standard Kubernetes health endpoints with correct\nsemantics: /livez stays shallow and healthy during drain, /readyz\nreflects startup, termination, and dependency checks, and /healthz\nremains a deprecated readiness alias for compatibility.",
          "is_bot": false,
          "headline": "feat(service): add Kubernetes livez, readyz, and healthz probes",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T05:28:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6fc74e26e2a9ee3d8495e839ca796f262f991bb",
          "body": "Frame already registers the GCP Pub/Sub driver; importing frame/v2 is enough.\nAlso fix govet shadow in GCP push envelope Decode.",
          "is_bot": false,
          "headline": "docs(queue): apps need not blank-import gcppubsub",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:33:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7eefd05c0074b17e1df5d15fea4ec1fc82da069",
          "body": "Document and test that FRAME_QUEUE_PUSH_OIDC_ALLOWED_EMAILS matches either\nJWT email or sub (both claims always considered). Note that apps should\nstill blank-import gcppubsub for durable GCP linkage.",
          "is_bot": false,
          "headline": "fix(queue): check OIDC allowlist against both email and sub",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:25:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36d319a824d830cca0fcb6dbf1cd002dd62c76df",
          "body": "- EVENTS_QUEUE_PUBLISH_URL / EVENTS_QUEUE_SUBSCRIBE_URL override the\n  single EVENTS_QUEUE_URL so Cloud Run can publish via gcppubsub://\n  and receive via push:// (POST /_frame/queue/{ref})\n- Decode Google Pub/Sub push envelopes (base64 data + attributes)\n- Document the regional Pub/Sub push pattern for Cloud Run",
          "is_bot": false,
          "headline": "feat(queue): dual events URLs + GCP Pub/Sub push codec",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:23:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a69a59194b5700aeb8e13ac1fe26508eeafa57de",
          "body": "Register gocloud gcppubsub by default so gcppubsub:// topics and\nsubscriptions work without app-level blank imports. Classify the scheme\nas pull/Go Cloud. Add FRAME_QUEUE_PUSH_OIDC_ALLOWED_EMAILS so push OIDC\ncan restrict callers to known service-account email or sub claims.",
          "is_bot": false,
          "headline": "feat(queue): default GCP Pub/Sub driver and OIDC SA allowlist",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:13:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "426e052c550eb0cd9ea11acd3fb05bac17174875",
          "body": "Queue work is background processing: it should run until the handler\nreturns. Default FRAME_QUEUE_PUSH_HANDLER_TIMEOUT is now 0 (disabled),\nNewHandler no longer forces 25s, and HTTP write timeout auto-unbounds\nwhen push has no handler deadline so long events are not killed mid-flight.",
          "is_bot": false,
          "headline": "fix(queue): no default timeout for push consumers",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-22T05:37:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ab21460693b67966ffd4fcfab9f7644aa75afca",
          "body": "…ntics (#687)\n\nPreserve the design that missing claims does not error and does not filter.\nWhen claims are set, bind session GUCs so RLS applies by default; Skip and\nempty claims clear scope (match-all). Always clear session vars on acquire\nfor unscoped paths and on release so prior principal scope \n[…]\n.\n\nAlso reject partition IDs containing ',' (CSV encoding), document PgBouncer\nsession-mode requirements, and expand provider integration tests for\nreuse, WITH CHECK, and unscoped match-all behaviour.",
          "is_bot": false,
          "headline": "fix(tenancy): harden RLS session binding without changing opt-in sema…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-21T18:33:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04f3426ea592fc5877c2cf4e3542d60b3582eb58",
          "body": "Bumps the production-dependencies group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.82.0` | `1.82.1` |\n| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.0` | `1.19.1` |\n| [github.com/prom\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 5 updates (#686)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T13:30:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7b8e740881e6836b6aac198652015876f833869",
          "body": "Add URL-scheme transport modes so the same SubscribeWorker API works for\nlocal pull (mem/nats), Knative CloudEvents, and Google Cloud Tasks.\n\n- Shared processDelivery path for pull and push\n- Always-mounted POST /_frame/queue/{ref} demux handler\n- Protocol codecs: raw, CloudEvents binary/structured,\n[…]\nlishers: ce+http(s) binary egress and cloudtasks CreateTask REST\n- Push auth: bearer + dedicated Google OIDC; secure-by-default require-auth\n- Fix background-consumer vs NoopDriver terminal error race",
          "is_bot": false,
          "headline": "feat(queue): HTTP push multiplexing for Knative Events and Cloud Tasks",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-20T09:39:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "736f13f64ab8d996a7fb17814b922045306f398d",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-go\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/setup-go from 6 to 7 (#684)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T09:19:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab750ac5ca8515bc9094a826791d7dc6b99f693f",
          "body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-python\n  dependency-\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/setup-python from 6 to 7 (#685)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T09:12:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc6cf4d3e49f2d15f73b26b58bde4829221e369e",
          "body": "…17 updates (#682)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/lmittmann/tint\n  dependency-version: 1.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: production-dependencies\n- dependency-name: golang.org/x/net\n  dependency-version:\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group across 1 directory with …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T13:36:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2799797c60b120d26009365f488d879eb31c0c06",
          "body": "… (#683)\n\n---\nupdated-dependencies:\n- dependency-name: buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go\n  dependency-version: 1.36.11-20260709200747-435963d16310.1\n  dependency-type: indirect\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T13:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0e3ba41f4cbe9bf6973fa801b9e3fee4da9aa0e",
          "body": "…#681)\n\nPlatform invariant: subject is always the profile. Hydra may leave wire\nsub=client_id for client_credentials; after JWT validation we rewrite\nSubject from the profile_id claim so GetSubject/GetProfileID and ReBAC\ncheckers always see the acting profile.",
          "is_bot": false,
          "headline": "fix(security): enforce JWT sub === profile_id via NormalizeIdentity (…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-10T21:54:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e3b4038d8c8adb3ce7729c367b9f2595e748dc3",
          "body": "Profile is the acting principal for ReBAC. Hydra client_credentials\ntokens keep sub=client_id; profile_id is carried in claims. GetProfileID\nnow prefers profile_id, and tenancy/function/resource checkers use it so\nKeto grants remain keyed by profile — never OAuth client_id.",
          "is_bot": false,
          "headline": "fix(security): authorize with profile_id, not JWT sub/client_id (#680)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-10T21:22:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "caf863743bf5e1c5ceac2b98d64e91595be8e1f5",
          "body": "* fix: restore NoopDriver contract so svc.Run returns after start\n\nsendStopError ignored nil after the first-error sync.Once change, so\nWithNoopDriver / WithHTTPTestDriver never woke Run after ListenAndServe\nreturned. Tests then needed go func() { svc.Run(...) } workarounds.\n\nNil is a valid clean ex\n[…]\n invalid queue URLs make Run return an error\ninstead of a false success under NoopDriver.\n\nAlso register a publisher alongside mem:// subscribers in queue tests\n(topic must exist before subscription).",
          "is_bot": false,
          "headline": "fix: restore NoopDriver contract so svc.Run returns after start (#679)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-09T19:59:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82c225edcc8e86b5b8f604fd756970a5a9349994",
          "body": "…tBackGroundConsumer\n\n- Run svc.Run() in goroutine with error channel to avoid blocking\n- Use test driver getter after brief delay to let server start\n- Explicitly stop service and wait for graceful shutdown (context.Canceled)\n- Fix TestBackGroundConsumer to properly handle service stop lifecycle",
          "is_bot": false,
          "headline": "fix: resolve hanging tests in service_http_middleware_test.go and Tes…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-02T20:16:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4255c2af92cff81b2bb4fa8ee40e94cf9741ee0",
          "body": null,
          "is_bot": false,
          "headline": "resolve merge conflicts from migrating to v2",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-02T11:17:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47c3887f3683e193f0759e25b9111f78cd7bdc14",
          "body": "…ility\n\nSecurity fixes (P0):\n- TokenAuthenticator: JWKS refresh now uses service context with 10s timeout, proper shutdown via WaitGroup\n- OIDC discovery: replaced http.DefaultClient with timed http.Client (10s)\n- JWT validation: added WithExpirationRequired() parser option\n\nResilience & correctness\n[…]\n Updated docs for new config options\n- Fixed lint issues (goimports, golines, govet, exhaustive)\n\nTesting:\n- All security tests pass\n- Service tests pass\n- Cache tests pass\n- Lint passes with 0 issues",
          "is_bot": false,
          "headline": "security/resilience: fix critical issues and improve framework reliab…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-30T19:14:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c10bb5b02913ed03b341380631858b2c83f5292a",
          "body": "Bumps the production-dependencies group with 4 updates: [gorm.io/gorm](https://github.com/go-gorm/gorm), [github.com/moby/sys/user](https://github.com/moby/sys), [github.com/prometheus/procfs](https://github.com/prometheus/procfs) and [google.golang.org/api](https://github.com/googleapis/google-api-\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 4 updates (#677)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T13:29:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f4cf2e40f8368378ebbad628bd94b90507824f9",
          "body": "Refs #675",
          "is_bot": false,
          "headline": "feat!: adopt Frame v2 semantic import path (#676)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-29T00:41:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f34e6f2c8019575b512ea9da3c5aedd2a394564",
          "body": "…#674)\n\nRefs #673",
          "is_bot": false,
          "headline": "feat!: standardize typed authentication and authorization contracts (…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-29T00:29:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f84d832a396fcee87c47d21fa45f323b1e52c0b",
          "body": "Bumps the production-dependencies group with 12 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/moby/moby/api](https://github.com/moby/moby) | `1.54.2` | `1.55.0` |\n| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.20.1` | `9.21.0` |\n| [github.com/spiffe/go\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 12 updates (#672)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T13:29:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "726c889a38945386c3d802ac73af279abfd8d23e",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/checkout from 6 to 7 (#671)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T09:12:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b20eec52789565dedf96f24bbfd7467f928c9c9b",
          "body": "Bumps the production-dependencies group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.20.0` | `9.20.1` |\n| [golang.org/x/net](https://github.com/golang/net) | `0.55.0` | `0.56.0` |\n| [golang.org/x/text](https://g\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 6 updates (#670)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-15T13:37:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d965fed3e9c66002079ed3bf7ed4ec3349ae035",
          "body": "…ments (#669)\n\nThe standard factory for product/business metrics. Counter/FloatCounter/\nHistogram/Gauge/FloatGauge wrappers merge TenantAttributes(ctx) into\nevery measurement, so call sites cannot forget tenant attribution —\nthe existing opt-in WithTenantAttributes pattern proved forgettable\n(23 fin\n[…]\nrd without tenant attributes; explicit per-call attributes are\npreserved. Instrument-creation errors fall back to noop instruments\n(metrics never break the service), matching LatencyMeasure behaviour.",
          "is_bot": false,
          "headline": "feat(telemetry): BusinessMetrics — transparently tenant-scoped instru…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T20:27:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f15a12cc233417e00a24a3fbcb6885aac1a433a3",
          "body": "Tenanted/Unscoped have pointer receivers, so a migrate list passing\nmodels BY VALUE silently failed the interface assertions and the\ntables were skipped during RLS install — no error, no policy. Four\nservices shipped that way (settings refs/vals/audits in profile,\nproperty tables in files, the entir\n[…]\nct values to\npointers before checking, so registration style cannot change\nenforcement. Regression test proves value and pointer registration\nenroll identically (fails on the previous implementation).",
          "is_bot": false,
          "headline": "fix(tenancy): enroll models registered by value (#668)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T17:13:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe4745e492ebd3b9037772b938b887ef6f0d9090",
          "body": "…est suites (#667)\n\nPromoted from service-fintech apps/limits/tests/rlstest. Wraps the\npostgres tenancy provider with Enable-gated SET ROLE hooks so test\nqueries run under an unprivileged role: testcontainer users are\nsuperusers and bypass FORCE ROW LEVEL SECURITY, so without this no\nsuite actually \n[…]\nr\nlate-created tables).\n\nPackage test proves the gate: superuser sees cross-tenant rows before\nEnable, the scoped role sees none after, own-tenant and claim-less\n(system match-all) reads keep working.",
          "is_bot": false,
          "headline": "feat(frametests): add rlstest — RLS-exercising tenancy provider for t…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T15:58:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca7e497939c05110fbe854199146b4d1d85ccb27",
          "body": "util v0.9.1 fixes MultiHandler fan-out so LOG_LEVEL takes effect on\nstdout even with the OTel telemetry log handler attached.\n\nretract v1.94.12: published accidentally from a stale release draft on\n2026-06-10 — the tag pointed at post-v1.98.0 main and was cached by the\nmodule proxy before deletion.",
          "is_bot": false,
          "headline": "deps: bump pitabwire/util v0.9.0 → v0.9.1; retract v1.94.12 (#666)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T09:46:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58dfe7717e38856b672a853adc829cdf25b71323",
          "body": "…11 updates (#665)\n\nBumps the production-dependencies group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) | `5.9.2` | `5.10.0` |\n| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.19.0`\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group across 1 directory with …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-08T14:05:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fcecf051c259f5baea98677b4ca2a711f7f5064c",
          "body": "…ocloud v0.46 (#664)\n\nOTel SDK v1.44 moves its default resource to semconv schema 1.41.0. Frame's\ntelemetry resource was pinned to semconv v1.40.0, so resource.Merge of the\nSDK default with Frame's resource failed with \"conflicting Schema URL\"\n(1.41.0 vs 1.40.0) — breaking service/telemetry init (an\n[…]\nb v0.69, otelpgx\n  v0.11.1) and gocloud.dev v0.45->v0.46.\n\nVerified: resource.Merge(resource.Default(), frame-resource) now succeeds\nwith a unified 1.41.0 schema; build, vet, and telemetry tests pass.",
          "is_bot": false,
          "headline": "feat(telemetry): upgrade to OpenTelemetry v1.44 / semconv v1.41 and g…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-08T13:57:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0436080a544c939882c15b9b39f71f7b18323b72",
          "body": "…rer (#662)\n\nHTTPClientManager auto-attaches the service's outbound OAuth bearer (resolved\nfrom the OAuth config in ctx) to every client it builds, with no per-call\nopt-out — clobbering an external API's own Authorization header (e.g. an API\nkey). Services had to fall back to a bare stdlib client an\n[…]\nlogging) but attaches NO bearer. The OAuth application is extracted to\napplyOutboundOAuth to keep the guard flat. shouldCreateRequestScopedClient\nhonours the flag so InvokeRestService respects it too.",
          "is_bot": false,
          "headline": "feat(client): WithHTTPNoAuth() — manager client without the OAuth bea…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-04T11:10:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f2269d4cf9fd34b3b3cf1ca4f7b3cd19c0c82b8",
          "body": "Bumps the production-dependencies group with 8 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [connectrpc.com/connect](https://github.com/connectrpc/connect-go) | `1.19.2` | `1.20.0` |\n| [github.com/exaring/otelpgx](https://github.com/exaring/otelpgx) | `0.10.0` | `0.11.1` |\n| [github.com/p\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 8 updates (#660)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-25T19:43:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c0707b540772e17476d197f05459ee5d182af1a",
          "body": "… failure\n\nWhen a service's permission registration fails — Hydra unreachable, the\nsigner endpoint not yet up, tenancy briefly unavailable — the option was\nFatal-ing the process. That is too aggressive: it deadlocks the auth\nservice during a cold rollout, because the auth pod's signer is *itself*.\nW\n[…]\nhe documented invariant (every service's namespace\nreaches tenancy.service_namespaces on every pod start) while making\npod startup tolerant of transient peer unavailability and self-bootstrap\nwindows.",
          "is_bot": false,
          "headline": "fix(permissions): retry-with-backoff instead of Fatal on registration…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-21T22:52:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df294fa783657a77a7b30072c561c4b52f383134",
          "body": "publishManifest pre-marshalled the manifest to JSON bytes and then\npassed those bytes to HTTPClientManager().Invoke — which json.Marshal's\nits payload again. Marshalling []byte yields a base64-encoded JSON\nstring, not the original object, so the tenancy registration endpoint\nsaw a literal string wit\n[…]\nspace/permissions fields and returned\n400 Bad Request.\n\nPass the manifest map directly. Invoke handles JSON encoding once.\nThe drop of the redundant json.Marshal also removes the encoding/json\nimport.",
          "is_bot": false,
          "headline": "fix(permissions): pass manifest map to Invoke, drop double JSON marshal",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-21T21:19:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30846eef4c32a7c1ed29bdfcb69208f23122c09d",
          "body": "…y pod start\n\nWithPermissionRegistration only added its PreStartMethod when\nDoDatabaseMigrate() returned true. The intent was \"register from the\nmigration job, not from the main pod\", but in practice services'\ncmd/main.go runs the migration synchronously *before* svc.Init and\nreturns early — the Pre\n[…]\nhatever the running binary\ndeclares.\n\nConsumers no longer need to invent glue (short-circuit-then-Run-with-\ntimeout, or out-of-band POST helpers) around svc.Run to make this fire\nfrom a migration job.",
          "is_bot": false,
          "headline": "fix(permissions): drop DO_MIGRATION gate so registration runs on ever…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-21T20:13:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07995fb69e2d8ddb36fcd3be06ee1286d67ca9eb",
          "body": "Bumps the production-dependencies group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/valkey-io/valkey-go](https://github.com/valkey-io/valkey-go) | `1.0.74` | `1.0.75` |\n| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.81.0` | `1.81.1` |\n| [github.com/go\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 6 updates (#659)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T23:25:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b35fbbdc8cf801aca58da39532e98df24b819b2",
          "body": "…658)\n\nBumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 3.1.1 to 3.2.0.\n- [Release notes](https://github.com/actions/create-github-app-token/releases)\n- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)\n- [Commits](\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/create-github-app-token from 3.1.1 to 3.2.0 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T16:17:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "962054057189bb65bd83aa8d806cef1c38a47652",
          "body": "…ic Noop handlers\n\nCatch-all-subject consumers (e.g. NATS subscription on\nsvc.X.events.>) previously had to register a NoopHandler for every\nevent type the service intentionally ignored. Forgetting one entry\nturned the message into a permanent retry-storm; remembering all of\nthem risked silently dro\n[…]\nr arrays.\n\nTests cover both modes (existing events_test.go suite remains green;\nnew shared-stream behaviour is exercised by integration tests in the\nopportunities service after the loose-mode opt-in).",
          "is_bot": false,
          "headline": "feat(events): loose-mode manager — ack unknown events without per-top…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-18T05:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f073429940ade4c6f3e585ef2c66b551ca31df2a",
          "body": "http.DefaultTransport's MaxIdleConnsPerHost=2 forces every caller past\nthe second concurrent in-flight to open a new TCP connection per\nrequest. At service-to-service concurrency the upstream's accept queue\nfloods with TIME_WAITs and most requests return \"read: connection reset\nby peer\".\n\nLive trace\n[…]\no: nolint the existing crypto/elliptic X/Y deprecations in the JWT\ntest fixture so the pre-commit lint passes; those are unrelated and\nthe rewrite to crypto/ecdh would touch too much test scaffolding.",
          "is_bot": false,
          "headline": "fix(client): bump MaxIdleConnsPerHost from stdlib default (2) to 64",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-17T20:31:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbde0c25b0d9619d819ef328a07f0723e7af755e",
          "body": "Services typically talk to multiple downstreams with different latency\nprofiles in the same binary — an LLM inference endpoint that wants 5min\nof patience alongside an identity API that should fail fast at 3s. A\nsingle HTTP_CLIENT_TIMEOUT env var sets the service-wide default but\ncannot differentiat\n[…]\n now reachable from .Client):\n  per-call option > env-var / context config > 30s default\n\nTests cover the shared-client identity, the scoped-client divergence,\nand the precedence vs in-context config.",
          "is_bot": false,
          "headline": "feat(client): Manager.Client accepts per-call HTTPOptions",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-17T18:56:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0706a6c82c60d61b458b157b49f3c212f37291a",
          "body": "Outbound http.Client.Timeout was hard-pinned to 30s with no env-var or\nyaml override, leaving callers no path to extend it for slow downstreams\n(e.g. in-cluster LLM inference whose response time exceeds 30s). The\nonly knob was the code-level WithHTTPTimeout option, which is not\nreachable from deploy\n[…]\n vs invalid/empty fallback to defaults\n- context-seeded timeout flows into the constructed client\n- explicit WithHTTPTimeout overrides the context default\n- absence of any config keeps the 30s default",
          "is_bot": false,
          "headline": "feat(client): env-driven HTTP_CLIENT_TIMEOUT / HTTP_CLIENT_IDLE_TIMEOUT",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-17T18:24:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "412380e139007d410383fba11e57ff652d01b3ff",
          "body": null,
          "is_bot": false,
          "headline": "deps: bump pitabwire/natspubsub to v0.8.4",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:59:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adb0bfe4459fe6d83f8e75a2c8a7d178a9bdab79",
          "body": "…t cleanup\n\n- DefaultList now appends tenancy.NewClaimsInterceptor after auth so\n  downstream services get tenancy claims bound automatically.\n- AdvisoryLock doc-comment notes that the pinned conn fires acquire\n  hooks (safe: migrations are typically claim-less; AfterRelease\n  resets any state).\n- NewPool panic comment clarified — only nil-hook contract violation\n  can trip it; structurally unreachable for concrete providers.\n- Test asserts MaxIdleConns=0 invariant on the *sql.DB.",
          "is_bot": false,
          "headline": "feat(security): include tenancy interceptor in DefaultList; misc audi…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f952b5d2a4591ead184f47821600ef356973e67",
          "body": "…terns",
          "is_bot": false,
          "headline": "feat(tenancy): WithSkipEnforcement helper; document worker + perf pat…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6cf6d140aa34c2d9865bfa0a4ea34c25f02840c",
          "body": "…eConnections\n\nThe dialect adapter forces sql.DB MaxIdleConns=0 regardless of the\npool Option, because tenancy hook correctness requires every release\nto flow through pgxpool (and through the hook chain). WithMaxIdle has\nbeen silently ineffective; mark it Deprecated and turn the body into\na no-op so callers immediately see it has no effect. Drop the\nMaxIdle field from Options (it was unread) and stop forwarding\nconfig.GetMaxIdleConnections via WithMaxIdle in datastoreOptsFromConfig.",
          "is_bot": false,
          "headline": "chore(pool): document WithMaxIdle as no-op; stop forwarding GetMaxIdl…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f7a04525158b451ec79c4d29a9401f142a140cb",
          "body": "…entifier quoter\n\nStash the wired adapter on the Provider so Install can delegate\nidentifier quoting back to the adapter (matching whatever dialect\nrules are in force) instead of duplicating the canonical Postgres\ndouble-quote implementation in a file-local pgQuoteIdent. Falls back\nto the canonical rule when the provider is used without WireAdapter\n(e.g. tests that drive Install directly). Receivers on Install and\napplyTenancyPolicy promoted to pointer so they can read p.adapter.",
          "is_bot": false,
          "headline": "refactor(tenancy/postgres): provider holds adapter; drop duplicate id…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c4063eb0896adebdc293e8ea2d71e4b75d925a2",
          "body": "…k snapshot; log hook failures\n\n* tenancy/postgres: collapse the two set_config / RESET round trips in\n  beforeAcquire / afterRelease into a single Exec each, halving the\n  hook overhead on every conn acquire and release. afterRelease now\n  uses `set_config(..., '', false)` so both vars reset in one\n[…]\nrace-detected with the\n  earlier per-acquire RLock pattern).\n* dialect/postgres: log hook failures at WARN before pgxpool drops or\n  destroys the conn, so silent acquire/release errors are observable.",
          "is_bot": false,
          "headline": "perf(tenancy/postgres,dialect/postgres): batch hook SQL; per-pool hoo…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "943f364c44768b2d023d9a5f76a2c161863c176a",
          "body": "…test\n\nWithDatastoreConnectionWithOptions was calling pool.NewPool(ctx) with no\noptions, so WithTenancyProvider and WithDialectAdapter were silently\ndropped — only the pool's internal default Postgres-RLS provider ever\nreceived WireAdapter. Custom providers got only WireGorm (a no-op for\nthe Postgre\n[…]\nes:\n  - WithTenancyProvider(custom) -> WireAdapter called once, override\n    reachable via svc.TenancyProvider()\n  - WithTenancyProvider(nil)    -> svc.TenancyProvider() is nil, no\n    hooks installed",
          "is_bot": false,
          "headline": "fix(frame): WithTenancyProvider now reaches pool.NewPool; regression …",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "87d807ca0f219e56581f7293ad16f4ec9b0866f5",
          "body": "…n *sql.DB\n\nreflect.DeepEqual reaches into pgxpool's mutable state and races with\nbackground acquire/release goroutines; identity is the only meaningful\ncheck anyway.",
          "is_bot": false,
          "headline": "test(datastore): use pointer identity instead of reflect deep-equal o…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "057e5eea4913ec2c85aa44cb9a8878b9e855ef96",
          "body": "Pull the GORM AutoMigrate + tenancy provider install branch out of\nMigrate into a dedicated helper so the top-level flow reads as a\nlinear sequence of early-return steps. Resolves the `nestif`\ncomplaint on the post-Task-16 Migrate function without changing\nbehaviour.",
          "is_bot": false,
          "headline": "refactor(pool): extract applyAutoMigrations to flatten Migrate nesting",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b707c92a5e9e2399ae908aefbc2ba1bfffee4f7",
          "body": "The legacy `package pool` declaration was originally needed because\nthe test reached into the unexported `isRelationAlreadyExistsErr`\nhelper. After Task 16 that helper moved to the dialect adapter and\nthe surviving test only exercises the public Pool API, so flip the\npackage to `pool_test` and silence the `testpackage` linter.",
          "is_bot": false,
          "headline": "refactor(pool): move Migrate sanity test to pool_test package",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f765e4e84e7836bcb02976ae2e1fa9c1dd9db48",
          "body": "Run the project's `make format` hook to normalise import grouping in\nservice.go and tenancy/postgres/provider.go after the Task 1-21\nrefactor. Pure formatting; no behaviour change.",
          "is_bot": false,
          "headline": "chore(lint): goimports sweep across refactored packages",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f9d210d4889dd4c0b306e2e3a3835c1d37be426",
          "body": "…ser caveat",
          "is_bot": false,
          "headline": "docs(datastore): document tenancy package, one-shot model, RLS superu…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dae45882530802e5c96e50caa1378edc99d591db",
          "body": null,
          "is_bot": false,
          "headline": "test(tenancy): end-to-end claims interceptor (testcontainers)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9ba47bb1e394d5f82f1a2d2c3ace0f80745a914",
          "body": "…the right session",
          "is_bot": false,
          "headline": "fix(dialect/postgres): pin connection in AdvisoryLock so unlock hits …",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50c29da75f2bf4ee50202d57617a941e500e1c14",
          "body": null,
          "is_bot": false,
          "headline": "feat(frame): WithTenancyProvider option + svc.TenancyProvider() accessor",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff3cd718593613ce7287ed718cf20890e7d6cd55",
          "body": null,
          "is_bot": false,
          "headline": "refactor(datastore): delete scopes package (redundant with RLS)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae892e5fef3048127091e413b6b6a32d2eb93190",
          "body": "…ncy.NewClaimsInterceptor",
          "is_bot": false,
          "headline": "refactor(security): remove tenancy-tx interceptor; superseded by tena…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e76114e9cb1705ba20d6005393d134ed60d3405",
          "body": "… nolint markers)",
          "is_bot": false,
          "headline": "chore(tenancy/postgres): post-Task-11 lint cleanup (errors.New + drop…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45a9f2cd1fb4e08793f22462d68dd5b00e444020",
          "body": "…op tx-in-context\n\nStrip all tenancy methods (WithTenancy, WithRequestTx, ContextWithTx,\nTxFromContext) from the Pool interface. Tenancy is now enforced at the\nconnection-acquire level by the configured tenancy.Provider's adapter\nhook -- application code no longer threads transaction-bound contexts.\n[…]\nks at security/interceptors/connect/tenancy_tx.go which still\nreferences pool.WithRequestTx. Task 17 removes that file to restore\nthe build. Pre-commit hook bypassed (--no-verify) for the same reason.",
          "is_bot": false,
          "headline": "refactor(pool): compose dialect.DialectAdapter + tenancy.Provider; dr…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffd994690cb0022faed9d0880eecba72d177a706",
          "body": null,
          "is_bot": false,
          "headline": "feat(pool): WithDialectAdapter + WithTenancyProvider options",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "858f1ef5bea0d5671391596bd2d9b60f6e71a1b6",
          "body": "…ntainers)",
          "is_bot": false,
          "headline": "test(tenancy/postgres): RLS install + per-acquire enforcement (testco…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3126c40f6df00f4fa468e573d23ff9813115d91",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): Connect claims interceptor (no transactions)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c3962ab338cd38833b68a09cc1c48a5c95dc259",
          "body": null,
          "is_bot": false,
          "headline": "chore(tenancy): simplify test assertion",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c62fc52f5d44daff7b8a4099f9a8a976c624f98d",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): claims context binding, auth derivation, extension helper",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c01fd5f4a4ae0ee9306887a7eb5bae9d1f4b9958",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy/postgres): Install (RLS) + WireAdapter hooks",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98fb9a9bb6a604df28c902128146c8447e78fcf9",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy/postgres): embed RLS DDL fragments",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6762cf64356ef64e6689d24cff9f5d6efe0bcfc0",
          "body": "…oured",
          "is_bot": false,
          "headline": "fix(tenancy): use gorm.Statement.Parse so TableName overrides are hon…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e0380478f61a1b6b6cfa91d0e75ceb229fb5a9f",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): structural enrollment via Tenanted / Unscoped",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b5e66dc4d18392b6ef7654979fec2488acb3492",
          "body": "…test green",
          "is_bot": false,
          "headline": "fix(dialect): close pgxpool via OpenConnection close-fn; integration …",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d17d13990273e4998b1c8933fcaea81a4256f28",
          "body": "…ts; wrap lock errors",
          "is_bot": false,
          "headline": "fix(dialect/postgres): bound release hook timeout; correct doc-commen…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad25d75afbff0a6dbbea416e04efcdafb42fb759",
          "body": null,
          "is_bot": false,
          "headline": "feat(dialect/postgres): Adapter with pgxpool hook plumbing",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85e7e36574d96fa55c1fa5993f865dc0d7c68c89",
          "body": "… caveats",
          "is_bot": false,
          "headline": "docs(dialect/postgres): document NormalizeDSN heuristic and inherited…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9512b8753b4d242c5c649beb3ce9d39ac967eec",
          "body": null,
          "is_bot": false,
          "headline": "feat(dialect/postgres): port DSN normalisation",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "903f9ebec91edb0ea9cee443c319b07a98e71cf8",
          "body": "…ontract",
          "is_bot": false,
          "headline": "refactor(dialect,tenancy): drop gorm-logger leak; clarify ModelInfo c…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25621e2293102e027b2ab2c81d6a1167f0a74e92",
          "body": null,
          "is_bot": false,
          "headline": "feat(dialect): introduce DialectAdapter abstraction",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "018589ff2a5239dd87bdc41932a782c205558df9",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): declare Provider interface (forward-references dialect)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf47d20e2ce1b37071d4f5c47876de445ebfb480",
          "body": null,
          "is_bot": false,
          "headline": "test(data): cover overwrite + clear-to-empty; document mirror sync",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b4693e9b0d0a4cb2f2b6ac43422105fd443e6cb",
          "body": null,
          "is_bot": false,
          "headline": "feat(data): BaseModel implements tenancy.Tenanted via setters",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45afd40de10379359b3d7c2c3fa43e860d28df72",
          "body": null,
          "is_bot": false,
          "headline": "test(tenancy): cover nil-receiver contract for Claims",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4771b268448df4c39039f02d26b04afc37782238",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): add immutable Claims with additive ExtendPartitions",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0518cb7ada8e86aabb754f910a520a5b353c228b",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): add compile-time guard for UnscopedMarker",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2289c57d624dc071146f3be76f7187473c3522cc",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): introduce Tenanted and Unscoped markers",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 664,
      "latest_release_at": "2026-07-27T10:09:49Z",
      "latest_release_tag": "v2.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 48,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/pitabwire/frame/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/pitabwire/frame/v2",
          "is_deprecated": false,
          "latest_version": "v2.1.3",
          "repository_url": "https://github.com/pitabwire/frame",
          "versions_count": 21,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-27T10:22:03Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 5,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2021-09-24",
            "count": 1
          },
          {
            "date": "2023-12-20",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "frametests/rpcservice/ping/v1/ping.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 96081,
      "source_files_sampled": 297,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 20
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 149,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "buf.build/go/protovalidate",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "connectrpc.com/connect",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.20.0"
        },
        {
          "name": "connectrpc.com/otelconnect",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.0"
        },
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/caarlos0/env/v11",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v11.4.1"
        },
        {
          "name": "github.com/exaring/otelpgx",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.11.1"
        },
        {
          "name": "github.com/go-jose/go-jose/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.1.4"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.10.0"
        },
        {
          "name": "github.com/lmittmann/tint",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/moby/moby/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.55.0"
        },
        {
          "name": "github.com/nats-io/nats.go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.52.0"
        },
        {
          "name": "github.com/nicksnyder/go-i18n/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.6.1"
        },
        {
          "name": "github.com/ory/keto/proto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0"
        },
        {
          "name": "github.com/panjf2000/ants/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.12.1"
        },
        {
          "name": "github.com/pitabwire/natspubsub",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.8.4"
        },
        {
          "name": "github.com/pitabwire/util",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/redis/go-redis/v9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.21.0"
        },
        {
          "name": "github.com/rs/xid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/spiffe/go-spiffe/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.8.1"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/nats",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/postgres",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/valkey",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/valkey-io/valkey-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.76"
        },
        {
          "name": "go.opentelemetry.io/contrib/bridges/otelslog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.19.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/exporters/autoexport",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/propagators/autoprop",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "gocloud.dev",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.46.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.57.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "google.golang.org/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.290.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.82.1"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "gorm.io/driver/postgres",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "gorm.io/gorm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.31.2"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "buf.build/go/protovalidate",
            "direct": true,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "connectrpc.com/connect",
            "direct": true,
            "version": "v1.20.0",
            "ecosystem": "go"
          },
          {
            "name": "connectrpc.com/otelconnect",
            "direct": true,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/caarlos0/env/v11",
            "direct": true,
            "version": "v11.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/exaring/otelpgx",
            "direct": true,
            "version": "v0.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": true,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgx/v5",
            "direct": true,
            "version": "v5.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lmittmann/tint",
            "direct": true,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/moby/api",
            "direct": true,
            "version": "v1.55.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nats.go",
            "direct": true,
            "version": "v1.52.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nicksnyder/go-i18n/v2",
            "direct": true,
            "version": "v2.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ory/keto/proto",
            "direct": true,
            "version": "v0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/panjf2000/ants/v2",
            "direct": true,
            "version": "v2.12.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pitabwire/natspubsub",
            "direct": true,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pitabwire/util",
            "direct": true,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/v9",
            "direct": true,
            "version": "v9.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rs/xid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spiffe/go-spiffe/v2",
            "direct": true,
            "version": "v2.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/nats",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/postgres",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/valkey",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/valkey-io/valkey-go",
            "direct": true,
            "version": "v1.0.76",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/bridges/otelslog",
            "direct": true,
            "version": "v0.19.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/exporters/autoexport",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/autoprop",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/log",
            "direct": true,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/log",
            "direct": true,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "gocloud.dev",
            "direct": true,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": true,
            "version": "v0.57.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/api",
            "direct": true,
            "version": "v0.290.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.82.1",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/driver/postgres",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/gorm",
            "direct": true,
            "version": "v1.31.2",
            "ecosystem": "go"
          },
          {
            "name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
            "direct": false,
            "version": "v1.36.11-20260709200747-435963d16310.1",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.2",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/auth",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/auth/oauth2adapt",
            "direct": false,
            "version": "v0.2.8",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/compute/metadata",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/iam",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/pubsub",
            "direct": false,
            "version": "v1.51.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/pubsub/v2",
            "direct": false,
            "version": "v2.6.1",
            "ecosystem": "go"
          },
          {
            "name": "dario.cat/mergo",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr4-go/antlr/v4",
            "direct": false,
            "version": "v4.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/go-ansiterm",
            "direct": false,
            "version": "v0.0.0-20250102033503-faa5f7b0171c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs/pkg",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/log",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/platforms",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cpuguy83/dockercfg",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/distribution/reference",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-connections",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-units",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ebitengine/purego",
            "direct": false,
            "version": "v0.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ole/go-ole",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/cel-go",
            "direct": false,
            "version": "v0.30.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/s2a-go",
            "direct": false,
            "version": "v0.1.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/wire",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googleapis/enterprise-certificate-proxy",
            "direct": false,
            "version": "v0.3.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googleapis/gax-go/v2",
            "direct": false,
            "version": "v2.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgpassfile",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgservicefile",
            "direct": false,
            "version": "v0.0.0-20240606120523-5a60cdf6a761",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/puddle/v2",
            "direct": false,
            "version": "v2.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/inflection",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/now",
            "direct": false,
            "version": "v1.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.19.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lufia/plan9stats",
            "direct": false,
            "version": "v0.0.0-20260627054121-477a66015f15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/magiconair/properties",
            "direct": false,
            "version": "v1.18.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mdelapenya/tlscert",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/docker-image-spec",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/go-archive",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/moby/client",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/patternmatcher",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/sequential",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/user",
            "direct": false,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/userns",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/term",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nkeys",
            "direct": false,
            "version": "v0.4.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nuid",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/go-digest",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/image-spec",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/power-devops/perfstat",
            "direct": false,
            "version": "v0.0.0-20240221224432-82ca36839d55",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.24.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.70.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.21.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shirou/gopsutil/v4",
            "direct": false,
            "version": "v4.26.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.9.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/go-sysconf",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/numcpus",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yusufpapurcu/wmi",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/bridges/prometheus",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/aws",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/b3",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/jaeger",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/ot",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": false,
            "version": "v0.66.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdoutlog",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdoutmetric",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.5",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260718201538-764159d718ef",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/xerrors",
            "direct": false,
            "version": "v0.0.0-20240903120638-7835f813f4da",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto",
            "direct": false,
            "version": "v0.0.0-20260724162435-b2f20204f0df",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": false,
            "version": "v0.0.0-20260724162435-b2f20204f0df",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260724162435-b2f20204f0df",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 149,
        "direct_count": 47,
        "indirect_count": 102
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 663,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 5,
        "closed_unmerged_prs": 18
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "pitabwire",
          "commits": 1127,
          "avatar_url": "https://avatars.githubusercontent.com/u/4368681?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "changelog.yml",
        "dependabot-auto-merge.yml",
        "docs.yml",
        "draft_release.yml",
        "gemini-cli.yml",
        "gemini-pr-review.yml",
        "golangci-lint.yml",
        "publish-release.yml",
        "run_tests.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/23 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 1,
            "reason": "dependency not pinned by hash detected -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2e77d14b44836599674ac7cb8f05b57826a62664",
        "ran_at": "2026-07-28T22:07:57Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T13:25:20Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T18:27:36Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/pitabwire/frame",
    "host": "github.com",
    "name": "frame",
    "owner": "pitabwire"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 71,
      "inputs": {
        "security": 62,
        "vitality": 98,
        "community": 38,
        "governance": 57,
        "engineering": 96
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 98,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "commits_last_year": 664,
              "human_commit_share": 0.87,
              "days_since_last_push": 1,
              "active_weeks_last_year": 48
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "48/52 weeks with commits",
                "points": 33.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 48
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "664 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 664
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v2.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 38,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 2,
              "stars": 5,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 663,
              "open_issues": 0,
              "closed_issues": 5,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 18
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "663/681 decided PRs merged",
                "points": 37.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 663,
                      "decided": 681
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/23 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "followers": 8,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "pitabwire",
              "public_repos": 30,
              "account_age_days": 4830
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "8 followers of pitabwire",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 8,
                      "login": "pitabwire"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "30 public repos, account ~13 yr old",
                "points": 22.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 30
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/pitabwire/frame/v2"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 1
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "21 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 96,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "go",
                "golang",
                "boilerplate",
                "gocloud",
                "microservice",
                "postgresql",
                "message-queue"
              ],
              "has_wiki": true,
              "homepage": "https://pitabwire.github.io/frame/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://pitabwire.github.io/frame/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/23 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 0.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 149 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 149
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 149,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 149,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 71,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.989,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "86 of 87 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 86,
                      "sampled": 87
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 96081,
              "source_files_sampled": 297,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/297 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 297,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "frametests/rpcservice/ping/v1/ping.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "frametests/rpcservice/ping/v1/ping.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "frametests/rpcservice/ping/v1/ping.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T22:08:12.267371Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/pitabwire/frame.svg",
  "full_name": "pitabwire/frame",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.