Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-26 17:03 UTC

rushteam / beauty

beauty is a kit for build micro service

GoApache-2.0★ 5 stars⑂ 1 forksince Jul 2020View on GitHub ↗

rushteam/beauty holds a health index of 57 out of 100, placing it in the Moderate band. It scores highest on Vitality (78/100) and lowest on Community & Adoption (29/100). It was last updated today. A single contributor accounts for most of its recent work.

57
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

57
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

RushTeamOrganization
1 follower18 public repossince Jan 2019

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/rushteam/beautyv0.2.0-25 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

78Good · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
6.9/36Commit cadence — 10/52 weeks with commits
18/18Commit volume — 191 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year191
human_commit_share1
days_since_last_push0
active_weeks_last_year10
How it's scored
16.2/27Ships releases — 2 version tags (no GitHub releases)
36/36Release recency — latest release 5 days ago
27/27Release cadence — a release every ~1.3 days
0/10OpenSSF Scorecard: Signed-Releases — no data
Inputs used
releases_count2
latest_release_tagv0.2.0
releases_from_tagsyes
days_since_latest_release5
mean_days_between_releases1.3
Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

29Critical · 18% of overall
How it's scored
9.8/60Stars — 5 stars
0/25Forks — 1 forks
0/15Watchers — 1 watchers
Inputs used
forks1
stars5
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

56Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0.5/22.5Commit distribution — top contributor authored 98% of commits
2.7/13.5Contributor breadth — 2 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled2
top_contributor_share0.979
How it's scored
46.8/46.8Issue resolution — 100% of issues closed
36.3/38.3PR acceptance — 19/20 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/9 approved changesets -- score normalized to 0
Inputs used
merged_prs19
open_issues0
closed_issues1
issue_closed_ratio1
closed_unmerged_prs1
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
2.2/25Owner reach — 1 followers of rushteam
21.3/25Track record — 18 public repos, account ~7 yr old
Inputs used
followers1
owner_typeOrganization
is_verified
owner_loginrushteam
public_repos18
account_age_days2,745
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 5 days ago
12/20Version history — 2 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/rushteam/beauty
ecosystemsgo
any_deprecatedno
min_days_since_publish5

Engineering Quality

Are baseline engineering and documentation practices in place?

65Moderate · 20% of overall
How it's scored
24/24CI workflows — 1 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 5 merged PRs checked by a CI test -- score normalized to 0
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

90Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — go microservice framework grpc websocket webrtc
10/10Repository description
10/10Topics — 8 topics
0/10Wiki
Inputs used
topicsframework, game, golang, grpc, live, microservice, webrtc, websocket
has_wikino
homepagego microservice framework grpc websocket webrtc
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

50Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 5 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/9 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — no data
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 19 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.6
Excluded from scoring (no data or not applicable): packaging, signed_releases. Remaining weights renormalized.
How it's scored
9.5/35Direct dependencies free of known advisories — 1 affected: google.golang.org/grpc v1.81.1 (critical 9.1)
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories37
affected_packages9
assessed_packages264
unassessed_packages0
affected_by_severitycritical 2, high 1, low 1, unknown 5
direct_affected_packages1
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 264 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

65Moderate · 0% of overall
How it's scored
0/45Agent instructions — no CLAUDE.md / AGENTS.md / editor rules
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 100 of 100 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
How it's scored
12.6/18One-command bootstrap — contrib/casbin/go.mod, contrib/elasticsearch/go.mod, contrib/gorm/go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 90 of the last 100 commits agent-authored or agent-credited
0/8Automated maintenance — no automated dependency updates observed
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.9
toolchain_manifestscontrib/casbin/go.mod, contrib/elasticsearch/go.mod, contrib/gorm/go.mod, contrib/kafka/go.mod, contrib/llm/go.mod, contrib/mcp/go.mod, contrib/mcpagent/go.mod, contrib/nats/go.mod, contrib/natsjs/go.mod, contrib/openfga/go.mod, contrib/sqldb/go.mod, contrib/vector/go.mod, contrib/wasm/go.mod, contrib/wasmagent/go.mod, contrib/wasmopa/go.mod, examples/agentservice/go.mod, go.mod, tools/go.mod
dependency_bot_commit_share0
How it's scored
45/45Type-checkable code — Go (statically typed)
55/55Manageable file sizes — 0/553 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes32,687
source_files_sampled553
oversized_source_files0
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — examples/complete/example/api/service.proto, examples/protobuf-example/api/service.proto
0/20MCP server
40/40Runnable examples — example, examples
Inputs used
example_dirsexample, examples
has_mcp_signalno
api_schema_filesexamples/complete/example/api/service.proto, examples/protobuf-example/api/service.proto

Key facts

5GitHub stars
2contributors
191commits, last 12 months
0days since last push
2releases
1bus factor
0open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

OpenSSF Scorecard 4.6 / 10
4.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-26 17:03 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 5 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/9 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
n/aSigned-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities19 existing vulnerabilities detected
Direct dependencies 51
RegistryPackageVersion constraintManifest
Gogithub.com/bluenviron/gohlslib/v2v2.4.0go.mod
Gogithub.com/bluenviron/mediacommon/v2v2.9.1go.mod
Gogithub.com/coder/websocketv1.8.14go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/hashicorp/consul/apiv1.34.3go.mod
Gogithub.com/pion/interceptorv0.1.45go.mod
Gogithub.com/pion/rtpv1.10.4go.mod
Gogithub.com/pion/webrtc/v4v4.2.17go.mod
Gogithub.com/polarismesh/polaris-gov1.7.0go.mod
Gogithub.com/quic-go/quic-gov0.60.0go.mod
Gogithub.com/redis/go-redis/extra/redisotel/v9v9.21.0go.mod
Gogithub.com/redis/go-redis/v9v9.21.0go.mod
Gogithub.com/spf13/viperv1.20.1go.mod
Gogithub.com/yutopp/go-rtmpv0.0.7go.mod
Gogo.etcd.io/etcd/client/v3v3.6.2go.mod
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0go.mod
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.34.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogolang.org/x/syncv0.22.0go.mod
Gogoogle.golang.org/grpcv1.81.1go.mod
Gok8s.io/apiv0.34.0go.mod
Gok8s.io/apimachineryv0.34.0go.mod
Gok8s.io/client-gov0.34.0go.mod
Gogithub.com/dubonzi/otelrestyv1.5.0go.mod
Gogithub.com/fsnotify/fsnotifyv1.9.0go.mod
Gogithub.com/go-resty/resty/v2v2.16.5go.mod
Gogithub.com/gofrs/uuid/v5v5.3.2go.mod
Gogithub.com/gorilla/schemav1.4.1go.mod
Gogithub.com/grpc-ecosystem/go-grpc-middlewarev1.4.0go.mod
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0go.mod
Gogithub.com/nacos-group/nacos-sdk-go/v2v2.3.3go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogo.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpcv0.59.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/prometheusv0.56.0go.mod
Gogo.opentelemetry.io/otel/exporters/stdout/stdoutmetricv1.34.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogolang.org/x/timev0.14.0go.mod
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaago.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogithub.com/gobuffalo/herev0.6.7tools/go.mod
Gogithub.com/urfave/cli/v3v3.4.1tools/go.mod
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20250826171959-ef028d996bc1tools/go.mod
Gogoogle.golang.org/protobufv1.36.8tools/go.mod
All dependencies 264

Full resolved dependency set from the GitHub dependency graph: 59 direct and 205 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/bluenviron/gohlslib/v2v2.4.0direct
Gogithub.com/bluenviron/mediacommon/v2v2.9.1direct
Gogithub.com/coder/websocketv1.8.14direct
Gogithub.com/dubonzi/otelrestyv1.5.0direct
Gogithub.com/fsnotify/fsnotifyv1.10.1direct
Gogithub.com/fsnotify/fsnotifyv1.9.0direct
Gogithub.com/go-resty/resty/v2v2.16.5direct
Gogithub.com/gobuffalo/herev0.6.7direct
Gogithub.com/gofrs/uuid/v5v5.3.2direct
Gogithub.com/golang-jwt/jwt/v5v5.3.1direct
Gogithub.com/gorilla/schemav1.4.1direct
Gogithub.com/grpc-ecosystem/go-grpc-middlewarev1.4.0direct
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0direct
Gogithub.com/hashicorp/consul/apiv1.34.3direct
Gogithub.com/nacos-group/nacos-sdk-go/v2v2.3.3direct
Gogithub.com/pion/interceptorv0.1.45direct
Gogithub.com/pion/rtpv1.10.4direct
Gogithub.com/pion/webrtc/v4v4.2.17direct
Gogithub.com/polarismesh/polaris-gov1.7.0direct
Gogithub.com/quic-go/quic-gov0.60.0direct
Gogithub.com/redis/go-redis/extra/redisotel/v9v9.21.0direct
Gogithub.com/redis/go-redis/v9v9.21.0direct
Gogithub.com/robfig/cron/v3v3.0.1direct
Gogithub.com/spf13/viperv1.20.1direct
Gogithub.com/urfave/cli/v3v3.4.1direct
Gogithub.com/yutopp/go-rtmpv0.0.7direct
Gogo.etcd.io/etcd/client/v3v3.6.2direct
Gogo.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpcv0.59.0direct
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0direct
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0direct
Gogo.opentelemetry.io/otelv1.29.0direct
Gogo.opentelemetry.io/otelv1.30.0direct
Gogo.opentelemetry.io/otelv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/prometheusv0.56.0direct
Gogo.opentelemetry.io/otel/exporters/stdout/stdoutmetricv1.34.0direct
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.34.0direct
Gogo.opentelemetry.io/otel/metricv1.29.0direct
Gogo.opentelemetry.io/otel/metricv1.30.0direct
Gogo.opentelemetry.io/otel/metricv1.44.0direct
Gogo.opentelemetry.io/otel/sdkv1.44.0direct
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0direct
Gogo.opentelemetry.io/otel/tracev1.29.0direct
Gogo.opentelemetry.io/otel/tracev1.30.0direct
Gogo.opentelemetry.io/otel/tracev1.44.0direct
Gogolang.org/x/syncv0.22.0direct
Gogolang.org/x/timev0.14.0direct
Gogolang.org/x/timev0.15.0direct
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20250826171959-ef028d996bc1direct
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaadirect
Gogoogle.golang.org/grpcv1.81.1direct
Gogoogle.golang.org/protobufv1.36.11direct
Gogoogle.golang.org/protobufv1.36.8direct
Gok8s.io/apiv0.34.0direct
Gok8s.io/apimachineryv0.34.0direct
Gok8s.io/client-gov0.34.0direct
Gocel.dev/exprv0.25.1indirect
Gocloud.google.com/go/compute/metadatav0.9.0indirect
Gofilippo.io/edwards25519v1.1.0indirect
Gogithub.com/abema/go-mp4v1.7.1indirect
Gogithub.com/alibabacloud-go/alibabacloud-gateway-popv0.0.7indirect
Gogithub.com/alibabacloud-go/alibabacloud-gateway-spiv0.0.5indirect
Gogithub.com/alibabacloud-go/darabonba-arrayv0.1.0indirect
Gogithub.com/alibabacloud-go/darabonba-encode-utilv0.0.2indirect
Gogithub.com/alibabacloud-go/darabonba-mapv0.0.2indirect
Gogithub.com/alibabacloud-go/darabonba-openapi/v2v2.0.10indirect
Gogithub.com/alibabacloud-go/darabonba-signature-utilv0.0.7indirect
Gogithub.com/alibabacloud-go/darabonba-stringv1.0.2indirect
Gogithub.com/alibabacloud-go/debugv1.0.1indirect
Gogithub.com/alibabacloud-go/endpoint-utilv1.1.1indirect
Gogithub.com/alibabacloud-go/kms-20160120/v3v3.2.3indirect
Gogithub.com/alibabacloud-go/openapi-utilv0.1.1indirect
Gogithub.com/alibabacloud-go/teav1.2.2indirect
Gogithub.com/alibabacloud-go/tea-utils/v2v2.0.7indirect
Gogithub.com/alibabacloud-go/tea-xmlv1.1.3indirect
Gogithub.com/aliyun/alibaba-cloud-sdk-gov1.63.84indirect
Gogithub.com/aliyun/alibabacloud-dkms-gcs-go-sdkv0.5.1indirect
Gogithub.com/aliyun/alibabacloud-dkms-transfer-go-sdkv0.1.9indirect
Gogithub.com/aliyun/aliyun-secretsmanager-client-gov1.1.5indirect
Gogithub.com/aliyun/credentials-gov1.4.3indirect
Gogithub.com/antithesishq/antithesis-sdk-gov0.7.0-default-no-opindirect
Gogithub.com/armon/go-metricsv0.4.1indirect
Gogithub.com/asticode/go-astikitv0.30.0indirect
Gogithub.com/asticode/go-astitsv1.15.0indirect
Gogithub.com/beorn7/perksv1.0.1indirect
Gogithub.com/bmatcuk/doublestar/v4v4.6.1indirect
Gogithub.com/buger/jsonparserv1.1.2indirect
Gogithub.com/casbin/casbin/v2v2.135.0indirect
Gogithub.com/casbin/govaluatev1.3.0indirect
Gogithub.com/cenkalti/backoff/v5v5.0.3indirect
Gogithub.com/cespare/xxhash/v2v2.3.0indirect
Gogithub.com/clbanning/mxj/v2v2.7.0indirect
Gogithub.com/cncf/xds/gov0.0.0-20260202195803-dba9d589def2indirect
Gogithub.com/coreos/go-semverv0.3.1indirect
Gogithub.com/coreos/go-systemd/v22v22.5.0indirect
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirect
Gogithub.com/deckarep/golang-setv1.7.1indirect
Gogithub.com/dlclark/regexp2v1.7.0indirect
Gogithub.com/dustin/go-humanizev1.0.1indirect
Gogithub.com/elastic/elastic-transport-go/v8v8.9.0indirect
Gogithub.com/elastic/go-elasticsearch/v8v8.19.6indirect
Gogithub.com/emicklei/go-restful/v3v3.12.2indirect
Gogithub.com/envoyproxy/go-control-plane/envoyv1.37.0indirect
Gogithub.com/envoyproxy/protoc-gen-validatev1.3.3indirect
Gogithub.com/fatih/colorv1.16.0indirect
Gogithub.com/felixge/httpsnoopv1.0.4indirect
Gogithub.com/fxamacker/cbor/v2v2.9.0indirect
Gogithub.com/glebarez/go-sqlitev1.21.2indirect
Gogithub.com/glebarez/sqlitev1.11.0indirect
Gogithub.com/go-jose/go-jose/v4v4.1.4indirect
Gogithub.com/go-logr/logrv1.4.2indirect
Gogithub.com/go-logr/logrv1.4.3indirect
Gogithub.com/go-logr/stdrv1.2.2indirect
Gogithub.com/go-openapi/jsonpointerv0.21.0indirect
Gogithub.com/go-openapi/jsonreferencev0.20.2indirect
Gogithub.com/go-openapi/swagv0.23.0indirect
Gogithub.com/go-sql-driver/mysqlv1.8.1indirect
Gogithub.com/go-viper/mapstructure/v2v2.4.0indirect
Gogithub.com/gogo/protobufv1.3.2indirect
Gogithub.com/golang/mockv1.6.0indirect
Gogithub.com/golang/protobufv1.5.4indirect
Gogithub.com/google/gnostic-modelsv0.7.0indirect
Gogithub.com/google/go-cmpv0.7.0indirect
Gogithub.com/google/go-tpmv0.9.8indirect
Gogithub.com/google/jsonschema-gov0.4.3indirect
Gogithub.com/google/uuidv1.3.0indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/hashicorp/errwrapv1.1.0indirect
Gogithub.com/hashicorp/go-cleanhttpv0.5.2indirect
Gogithub.com/hashicorp/go-hclogv1.5.0indirect
Gogithub.com/hashicorp/go-immutable-radixv1.3.1indirect
Gogithub.com/hashicorp/go-multierrorv1.1.1indirect
Gogithub.com/hashicorp/go-rootcertsv1.0.2indirect
Gogithub.com/hashicorp/golang-lruv0.5.4indirect
Gogithub.com/hashicorp/serfv0.10.1indirect
Gogithub.com/jinzhu/inflectionv1.0.0indirect
Gogithub.com/jinzhu/nowv1.1.5indirect
Gogithub.com/jmespath/go-jmespathv0.4.0indirect
Gogithub.com/josharian/internv1.0.0indirect
Gogithub.com/json-iterator/gov1.1.12indirect
Gogithub.com/klauspost/compressv1.17.9indirect
Gogithub.com/klauspost/compressv1.18.6indirect
Gogithub.com/mailru/easyjsonv0.7.7indirect
Gogithub.com/mattn/go-colorablev0.1.13indirect
Gogithub.com/mattn/go-isattyv0.0.17indirect
Gogithub.com/mattn/go-isattyv0.0.20indirect
Gogithub.com/minio/highwayhashv1.0.4indirect
Gogithub.com/mitchellh/go-homedirv1.1.0indirect
Gogithub.com/mitchellh/mapstructurev1.4.1indirect
Gogithub.com/modelcontextprotocol/go-sdkv1.6.1indirect
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirect
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31eeindirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/natefinch/lumberjackv2.0.0+incompatibleindirect
Gogithub.com/nats-io/jwt/v2v2.8.2indirect
Gogithub.com/nats-io/nats-server/v2v2.14.3indirect
Gogithub.com/nats-io/nats.gov1.52.0indirect
Gogithub.com/nats-io/nkeysv0.4.16indirect
Gogithub.com/nats-io/nuidv1.0.1indirect
Gogithub.com/ncruces/go-strftimev1.0.0indirect
Gogithub.com/openfga/go-sdkv0.8.2indirect
Gogithub.com/opentracing/opentracing-gov1.2.1-0.20220228012449-10b1cf09e00bindirect
Gogithub.com/orcaman/concurrent-mapv0.0.0-20210501183033-44dafcb38eccindirect
Gogithub.com/pelletier/go-toml/v2v2.2.4indirect
Gogithub.com/pierrec/lz4/v4v4.1.15indirect
Gogithub.com/pion/datachannelv1.6.2indirect
Gogithub.com/pion/dtls/v3v3.1.5indirect
Gogithub.com/pion/ice/v4v4.3.0indirect
Gogithub.com/pion/loggingv0.2.4indirect
Gogithub.com/pion/mdns/v2v2.1.0indirect
Gogithub.com/pion/randutilv0.1.0indirect
Gogithub.com/pion/rtcpv1.2.17indirect
Gogithub.com/pion/sctpv1.11.0indirect
Gogithub.com/pion/sdp/v3v3.0.19indirect
Gogithub.com/pion/srtp/v3v3.0.12indirect
Gogithub.com/pion/stun/v3v3.1.6indirect
Gogithub.com/pion/transport/v4v4.0.2indirect
Gogithub.com/pion/turn/v5v5.0.12indirect
Gogithub.com/pkg/errorsv0.9.1indirect
Gogithub.com/planetscale/vtprotobufv0.6.1-0.20240319094008-0393e58bdf10indirect
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirect
Gogithub.com/polarismesh/specificationv1.7.0indirect
Gogithub.com/prometheus/client_golangv1.20.5indirect
Gogithub.com/prometheus/client_modelv0.6.2indirect
Gogithub.com/prometheus/commonv0.62.0indirect
Gogithub.com/prometheus/procfsv0.15.1indirect
Gogithub.com/redis/go-redis/extra/rediscmd/v9v9.21.0indirect
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daecindirect
Gogithub.com/rushteam/beautyv0.1.0indirect
Gogithub.com/rushteam/beautyv0.2.0indirect
Gogithub.com/sagikazarmark/locaferov0.9.0indirect
Gogithub.com/segmentio/asmv1.1.3indirect
Gogithub.com/segmentio/encodingv0.5.4indirect
Gogithub.com/segmentio/kafka-gov0.4.51indirect
Gogithub.com/sirupsen/logrusv1.7.0indirect
Gogithub.com/sourcegraph/concv0.3.0indirect
Gogithub.com/spaolacci/murmur3v1.1.0indirect
Gogithub.com/spf13/aferov1.15.0indirect
Gogithub.com/spf13/castv1.9.2indirect
Gogithub.com/spf13/pflagv1.0.7indirect
Gogithub.com/spiffe/go-spiffe/v2v2.6.0indirect
Gogithub.com/subosito/gotenvv1.6.0indirect
Gogithub.com/tetratelabs/wazerov1.12.0indirect
Gogithub.com/tjfoc/gmsmv1.4.1indirect
Gogithub.com/uptrace/opentelemetry-go-extra/otelgormv0.3.2indirect
Gogithub.com/uptrace/opentelemetry-go-extra/otelsqlv0.3.2indirect
Gogithub.com/wlynxg/anetv0.0.5indirect
Gogithub.com/x448/float16v0.8.4indirect
Gogithub.com/xsam/otelsqlv0.43.0indirect
Gogithub.com/yosida95/uritemplate/v3v3.0.2indirect
Gogithub.com/yutopp/go-amf0v0.1.0indirect
Gogo.etcd.io/etcd/api/v3v3.6.2indirect
Gogo.etcd.io/etcd/client/pkg/v3v3.6.2indirect
Gogo.opentelemetry.io/auto/sdkv1.2.1indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0indirect
Gogo.opentelemetry.io/proto/otlpv1.10.0indirect
Gogo.uber.org/atomicv1.11.0indirect
Gogo.uber.org/multierrv1.11.0indirect
Gogo.uber.org/zapv1.27.0indirect
Gogo.yaml.in/yaml/v2v2.4.2indirect
Gogo.yaml.in/yaml/v3v3.0.4indirect
Gogolang.org/x/cryptov0.51.0indirect
Gogolang.org/x/cryptov0.53.0indirect
Gogolang.org/x/expv0.0.0-20260218203240-3dfff04db8faindirect
Gogolang.org/x/netv0.55.0indirect
Gogolang.org/x/oauth2v0.35.0indirect
Gogolang.org/x/oauth2v0.36.0indirect
Gogolang.org/x/sysv0.31.0indirect
Gogolang.org/x/sysv0.41.0indirect
Gogolang.org/x/sysv0.44.0indirect
Gogolang.org/x/sysv0.45.0indirect
Gogolang.org/x/sysv0.46.0indirect
Gogolang.org/x/sysv0.47.0indirect
Gogolang.org/x/sysv0.7.0indirect
Gogolang.org/x/termv0.43.0indirect
Gogolang.org/x/textv0.39.0indirect
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260526163538-3dc84a4a5aaaindirect
Gogopkg.in/evanphx/json-patch.v4v4.12.0indirect
Gogopkg.in/inf.v0v0.9.1indirect
Gogopkg.in/ini.v1v1.67.0indirect
Gogopkg.in/natefinch/lumberjack.v2v2.2.1indirect
Gogopkg.in/yaml.v2v2.4.0indirect
Gogopkg.in/yaml.v3v3.0.1indirect
Gogorm.io/driver/mysqlv1.6.0indirect
Gogorm.io/gormv1.31.2indirect
Gogorm.io/plugin/dbresolverv1.6.2indirect
Gok8s.io/klog/v2v2.130.1indirect
Gok8s.io/kube-openapiv0.0.0-20250710124328-f3f2b991d03bindirect
Gok8s.io/utilsv0.0.0-20250604170112-4c0f3b243397indirect
Gomodernc.org/libcv1.22.5indirect
Gomodernc.org/libcv1.74.1indirect
Gomodernc.org/mathutilv1.5.0indirect
Gomodernc.org/mathutilv1.7.1indirect
Gomodernc.org/memoryv1.11.0indirect
Gomodernc.org/memoryv1.5.0indirect
Gomodernc.org/sqlitev1.23.1indirect
Gomodernc.org/sqlitev1.54.0indirect
Gosigs.k8s.io/jsonv0.0.0-20241014173422-cfa47c3a1cc8indirect
Gosigs.k8s.io/randfillv1.0.0indirect
Gosigs.k8s.io/structured-merge-diff/v6v6.3.0indirect
Gosigs.k8s.io/yamlv1.6.0indirect
Dependency advisories 9

This repository publishes no package the index resolves, so its own dependency graph was assessed — 264 packages, which also include development and test pins that never ship: 9 carry known advisories, of which 1 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
google.golang.org/grpcv1.81.1directcritical11.82.1
golang.org/x/cryptov0.51.0indirectcritical270.52.0
github.com/sirupsen/logrusv1.7.0indirecthigh21.9.3
filippo.io/edwards25519v1.1.0indirectlow21.1.1
golang.org/x/cryptov0.53.0indirectunknown1
golang.org/x/netv0.55.0indirectunknown10.56.0
golang.org/x/sysv0.31.0indirectunknown10.44.0
golang.org/x/sysv0.41.0indirectunknown10.44.0
golang.org/x/sysv0.7.0indirectunknown10.44.0

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "framework",
        "game",
        "golang",
        "grpc",
        "live",
        "microservice",
        "webrtc",
        "websocket"
      ],
      "is_fork": false,
      "size_kb": 8690,
      "has_wiki": false,
      "homepage": "go microservice framework grpc websocket webrtc",
      "languages": {
        "Go": 2082758,
        "Yacc": 2519,
        "Shell": 619,
        "Smarty": 46077,
        "Go Template": 51264
      },
      "pushed_at": "2026-07-26T16:25:21Z",
      "created_at": "2020-07-03T00:36:03Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T16:28:34Z",
      "description": "beauty is a kit for build micro service",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "RushTeam",
      "type": "Organization",
      "login": "rushteam",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/46830347?v=4",
      "created_at": "2019-01-18T22:59:27Z",
      "is_verified": null,
      "public_repos": 18,
      "account_age_days": 2745
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-20T17:04:18Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-19T10:55:31Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "70a6d3b2b4e9203dbba6087fe9c7bac965f87fd9",
          "body": "Feat/wasm",
          "is_bot": false,
          "headline": "Merge pull request #25 from rushteam/feat/wasm",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-26T16:25:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4551e8f5d534b9c8ee9694d4aaab5e3dfab63656",
          "body": "补齐高收益小改动:WithCacheDir 磁盘 JIT 缓存、Pool.Warm/WithWarm 冷启动预热、\nWithHandlerObserver、Router.Stats(Hits/Misses/Functions)。",
          "is_bot": false,
          "headline": "feat(wasm): 编译缓存、池预热、Handler 可观测与 Router 指标",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-26T16:24:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b887550066434dc6be8a6141534c19e0ac5b2d0",
          "body": null,
          "is_bot": false,
          "headline": "docs(wasm): 补充 FaaS-lite Handler/Router 使用文档",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-25T22:51:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "535ad3fc8a8e548c9b4f898cc657bfc6012cf7ee",
          "body": "新增 Handler/Router 把用户上传的 wasm 模块直接暴露为 HTTP 端点:\n- Handler(mod): 单模块包装成 http.Handler(alloc/handle ABI, 输出 Response)\n- Router: 路径注册/注销/热替换, 精确匹配>最长前缀, 并发安全\n- 支持实例池/超时/请求体透传\n\n同时修复 wasmopa 并发 panic: 实例池改为 channel + semaphore 限制并发实例化。",
          "is_bot": false,
          "headline": "feat(wasm): FaaS-lite — wasm 函数即 HTTP Handler + 路由热插拔",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-25T22:47:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1abf1c8db2faf8cd2e3b7e815366ddaae68bd4d",
          "body": "新增 contrib/wasmopa:用 wazero 直接执行 OPA 编译出的 wasm 策略模块,\n实现 pkg/authz.Enforcer,无需完整 OPA SDK(纯 Go、无 CGo)。\n\n- OPA wasm ABI 1.2+ 协议(opa_eval 一次性求值);\n- Policy.Eval: 通用策略求值(governance / 任意 Rego 决策);\n- Policy.Authorize: 实现 authz.Enforcer(input 自动构造);\n- 每个并发槽位独立 Runtime+memory,race-free 池化复用;\n- SetData 运行时热更新外部数据;\n- 自动构造最小 env wasm 模块(导出 memory + OPA host stubs)。\n\n同步更新 wasm-roadmap.md(Tier 2/3 状态)与 contrib/README.md。",
          "is_bot": false,
          "headline": "feat(wasmopa): 策略即 wasm —— OPA Rego 编译的 wasm 实现 authz.Enforcer",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-25T20:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2665e548fb6509ff43edda04d3845b41b4cffe91",
          "body": "把 contrib/wasm 的沙箱执行能力接到 contrib/llm/agent 的工具循环上:\n\n- NewWasmExecutor: 适配 skills.ScriptExecutor,让技能脚本在 wazero\n  沙箱内运行(替代 EnableExec 的本地进程执行);按 path+mtime 编译缓存,\n  实例池复用,超时中断;\n- ToolFrom: 直接把预编译 wasm 模块包装成 agent.Tool(模型调用→wasm\n  handle→结果文本),支持并发池化与超时;\n- skills.ScriptExecutor 类型 + WithScriptExecutor 注入口(contrib/llm\n  侧变更),默认仍走本地进程,向后兼容。\n\n独立胶水模块:同时依赖 wasm 与 llm/agent,让那两个模块彼此零耦合。",
          "is_bot": false,
          "headline": "feat(wasmagent): 新增 contrib/wasmagent —— wasm×agent 胶水模块",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-25T12:24:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "664f97b01d39764ef461fed34b2d02b6fc6fed6b",
          "body": "中间件默认不读请求体(零成本);WithBody(maxBytes) 显式启用后,guest 可见请求体前\nmaxBytes(Request.Body 为 base64,超长置 BodyTruncated=true),且**完整 body 还原给下游**——\nguest 可见部分受限于内存有界,下游不受影响。适合 WAF/签名校验等需看 body 的过滤器,\n按需开启,不必每次都有成本。\n\n测试:WithBody 启用时 guest 见前 N 字节而下游收到完整 body;未启用时 body 不被读取、\n下游完整可读。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(wasm): 请求体访问 WithBody(opt-in 限长,下游不受影响)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-24T14:04:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4a81ad6801ea7dc0a6e208140b47e84a489ffc41",
          "body": "- WithPool(size):实例池复用(非阻塞 free-list,并发安全),降低重运行时 guest 的实例化开销;\n  复用实例状态会保留(guest 需自行重置),出错/超时实例不放回而丢弃;\n- WithLog(logger)/WithClock():内置但需显式授予的 host functions(env.log / env.now_unix_milli);\n- WithObserver(fn):每次执行后回调 Event(action/err/duration),接指标/日志/追踪由使用方定。\n\n测试(-race)覆盖:池化并发正确性、WithLog 记录 guest 日志、WithClock 返回时间戳、observer 回调。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(wasm): 实例池 + 内置 host functions + 可观测",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-23T19:59:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ca4e51a90931fc82a53cc3d4c70495e02e1c58d1",
          "body": "Feat/wasm",
          "is_bot": false,
          "headline": "Merge pull request #24 from rushteam/feat/wasm",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-23T18:46:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f329c75138a75d2e9162868dbee0c609ef921639",
          "body": "用 wazero(纯 Go、零 CGo)把逻辑/策略写成沙箱化、可热插拔的 wasm 模块:\n- Runtime:编译/实例化/调用/内存读写/受控 host functions;默认不启用 WASI(无 fs/net/env/clock);\n- 资源上限:内存(WithMemoryLimitPages)+ 执行超时中断(WithTimeout + CloseOnContextDone,挡死循环);\n- \"HTTP 中间件即 wasm\":请求元数据→handle→决策(放行/拒绝/改写请求头(Set/Add/Remove)/状态码),\n  fail-open/closed 可配;可经 handler.WithMiddleware 声明式绑定。\n测试用手工编码的极小 wasm(无需工具链/WASI)覆盖 Runtime/host func/内存/超时/中间件全链路。\n含 docs/wasm-roadmap.md(Tier1 已落地,Tier2 排期)。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(wasm): 新增 contrib/wasm —— WebAssembly 插件运行时(wazero)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-23T18:44:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ade33155ed36b207805fe85f430b6c2f69237e8e",
          "body": "pkg/handler 增加 WithMiddleware(mw ...func(http.Handler) http.Handler),挂在包装链最外层\n(先于 ratelimit/afterwork/auth,可提前短路;靠前者在更外层)。核心不依赖 contrib,\n故任意标准中间件即插即用——例如声明式绑定 contrib/wasm 的过滤器。\n顺带把 ServeHTTP 包装链改用 http.Handler 类型变量,去掉 .(http.HandlerFunc) 断言。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(handler): 新增通用中间件口 WithMiddleware",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-23T18:44:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ff27d049c0849fba0513700bff5db9924e8f2e1f",
          "body": "Feat/web primitives",
          "is_bot": false,
          "headline": "Merge pull request #23 from rushteam/feat/web-primitives",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T11:22:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c7d044176162eed200f90b5a37391efc320f4d3",
          "body": "golang.org/x/text 存在可对无效输入触发死循环的漏洞(GO-2026-5970),\n经 contrib/gorm 的 gorm.init → norm.Form.Properties 可达,govulncheck 报 exit 3。\n把各模块的 x/text 升到修复版 v0.39.0:\n- contrib/gorm: v0.20.0 → v0.39.0(此前可达,现 0 可达漏洞);\n- 根模块 / contrib/casbin / contrib/openfga / examples/agentservice: v0.37.0 → v0.39.0(未被调用,一并升级)。\n\n均为间接依赖版本提升,不改代码;各模块 build/test 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): 升级 golang.org/x/text 到 v0.39.0(GO-2026-5970)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T11:21:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c761c874635920aaa8ed48e9ba36294a702eafe9",
          "body": "- Jump(Google Jump Consistent Hash):key→[0,buckets),几乎无内存,增桶迁移约 1/(n+1);\n- Rendezvous(HRW):选加权得分最高的成员,无需虚拟节点、天然支持权重,\n  增删成员只影响其自身的 key;Pick/PickN/Update。\n环形一致性哈希之外的两个更小巧的补充。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(shard): Jump 一致性哈希 + Rendezvous(加权 HRW)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T09:04:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b21468b914a24e23fde43eaa18b507d37a63dc30",
          "body": "为 GET 200 响应算强 ETag(FNV-1a),客户端带 If-None-Match 命中即回 304,省带宽。\n支持 *、逗号多值、W/ 弱校验器前缀;尊重下游已设 ETag;非 GET 透传。需缓冲响应体,\n适合中小 JSON 响应按需接入。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(middleware/etag): ETag 条件请求中间件",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T09:04:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e88823328394e80c290f82810dc3f5bb2a6f5d02",
          "body": "gRPC retry-throttling 模型:用令牌余额约束\"重试/请求\"比率,防重试风暴。\nAllow 为一次重试花 1 token(仅当余额 > maxTokens/2),Deposit 在请求完成时归还 tokenRatio。\n下游持续失败会迅速耗尽余额、抑制重试。补齐 retry+熔断之外的比率闸。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ratelimit): 重试预算(RetryBudget)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T09:04:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b78fceaca888f32afa3200b3369f6d947c1d3c63",
          "body": "Encode/Decode[T] 把\"下一页起点\"编码成 URL 安全的不透明游标(base64url·json);\nBuild 收尾 keyset 分页(\"多取一条\"判断是否有下一页)。深翻页高效、结果稳定。\n注:游标仅不透明非防篡改,敏感场景请另加 HMAC 签名。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(pagination): 不透明游标(keyset 分页)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T09:04:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a019ec6a5d665f684a63f18bc5b9a6a9f1e42838",
          "body": "监控/风控常用的近似原语,常量级内存:\n- HyperLogLog:基数估计(UV/去重 IP),p=14 约 16KB、误差 ~0.81%,支持 Merge;\n- CountMin:频率/热点估计(热 key/Top-N/限流分桶),只高估不低估;\n- Reservoir[T]:蓄水池采样(算法 R),从未知长度流等概率抽 K,可并发。\n哈希用固定 FNV-1a + splitmix64(确定性,支持跨实例 Merge)。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(sketch): 概率数据结构(HyperLogLog / CountMin / Reservoir)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T09:04:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "24c51005f9938c0be8c388855c466d6e27c4a20d",
          "body": "Feat/web primitives",
          "is_bot": false,
          "headline": "Merge pull request #22 from rushteam/feat/web-primitives",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T06:53:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "378181429772b86626eb084d7565a4113e657752",
          "body": "传输无关的 Power-of-Two-Choices + EWMA:随机取两节点选实时负载更低者\n(load = sqrt(lag+1)*(inflight+1),EWMA 带时间衰减),压长尾、避慢/出错节点。\n反馈式 API:Pick 返回 node + done 回调,done(err) 上报耗时/成败更新 EWMA;\nforcePick 防饥饿,健康度阈值,Update 按 ID 保留统计。\n\n补齐 pkg/loadbalance 的动态负载均衡(此前仅 RR/加权/一致性哈希);\n数学参考自 gRPC 专用的 pkg/client/grpcclient 的 p2c_ewma balancer。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(loadbalance): 新增通用 P2C + EWMA",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T06:48:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f26d51d0e9cf191032ca4d1713784970dfc0e78f",
          "body": "- Cache[K,V] 接口 + LRU(container/list);\n- W-TinyLFU:窗口 LRU + 主 SLRU + Count-Min 频率准入(4-bit 计数带老化),抗扫描,\n  泛型键用 hash/maphash.Comparable;\n- Loader:Cache + syncx.singleflight + TTL + 负缓存,一站式化解穿透/击穿/雪崩;\n  NewLRULoader 便捷构造,WithTTL/WithNegativeTTL/WithClock、Forget。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cache): 有界缓存(LRU / W-TinyLFU)+ 防击穿加载器",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T06:48:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d5d04eda86f83e3be831005330804d44bc8c88cf",
          "body": "Do[T](ctx, delay, maxHedge, fn):primary 发出后 delay 内未返回则并发补发副本\n(最多 maxHedge 个),取最先成功者、取消其余(《The Tail at Scale》削尾延迟)。\ndelay<=0 为请求竞速,maxHedge=0 退化为单发;副本共享可取消 ctx。纯标准库。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hedge): 新增对冲请求(hedged requests)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T06:48:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fb5af98b5f7d0b78378a33b7a2d3eb0abbfd3aa5",
          "body": "漏桶的精巧实现:每 key 只维护一个理论到达时间(TAT),放行=一次时间算术,\n无后台补令牌、无时间戳队列,输出平滑且支持突发。实现现有 Limiter 接口,可直接接 Middleware;\n复用现有 Option/gc 模式。补在令牌桶/滑动窗口之外,适合\"精确无锯齿\"场景。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(ratelimit): 新增 GCRA 限流器",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-22T06:48:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "57054046cc8057cd86d18ecb87e43d75c314aa09",
          "body": "Claude Code 的本地权限配置属机器本地(含本机路径),不应入库。只忽略 settings.local.json,\n保留将来提交共享 .claude/settings.json 的可能。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: gitignore .claude/settings.local.json",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-21T19:57:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b4e4e7032e6b8359dbac2c536f63ace68e988181",
          "body": "feat(llm): agent 能力栈——工具调用/循环/护栏/会话/技能 + MCP 桥接 + 示例",
          "is_bot": false,
          "headline": "Merge pull request #21 from rushteam/feat/llm-agent-stack",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-21T19:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5523a1188b42586dd2534f7caef20ca44e7e961",
          "body": "panic handler 在 worker goroutine 执行,且发生在 wg.Done 之后(Done 在 task.fn 的\ndefer 里、先于 executeTask 的 recover 运行),故 wg.Wait() 返回时 handler 可能尚未跑完。\n原测试用共享变量 + time.Sleep 凑时序,无 happens-before,-race 必报。\n\n改用带缓冲 channel 把 panic 值送出来做同步,去掉共享变量与 sleep:既消除数据竞争,\n也不再依赖时序。-race 下重复 20 次 + 全包均通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(xgo): 修复 TestPanicHandling 的数据竞争(-race)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-21T19:45:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2790a79edd1dff49a97c5ea8af0013516ce7c2cf",
          "body": "在 contrib/llm(零依赖)上补齐从 agno 借鉴的核心 agent 能力,全部机制而非策略:\n\n- 工具调用(function calling):中立 ToolDef/ToolCall + Request.Tools/ToolChoice\n  + Response.ToolCalls;OpenAI/Anthropic 各自翻译线格式,纯文本请求体保持不变\n- llm/agent.Runner:模型→调工具→喂回→再生成的循环;未知工具/出错喂回自愈\n- 人工审批:Tool.Approval + Runner.Approve(拒绝喂回、审批失败中止)\n- llm.Guard 护栏中间\n[…]\nt:把 MCP 远程工具桥接成 agent.Tool(独立胶水模块)\n- examples/agentservice:整条链路跑成 beauty 服务(HTTP + SSE),离线 stub 可跑\n\n测试均以 httptest/假 client 打桩,go test -race 全绿。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(llm): agent 能力栈——工具调用/循环/护栏/会话/技能 + MCP 桥接 + 示例",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-21T19:27:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "af09055799cc7d604a7df12d68fef99c5f2ee89a",
          "body": "均实现核心 pkg/authz.Enforcer,应用面向 Enforcer 编程可无缝替换(内置 RBAC ↔ casbin ↔ openfga)。\n独立模块,require github.com/rushteam/beauty v0.2.0(核心自 v0.2.0 起含 authz)。\n\n- contrib/casbin:薄封装 casbin/v2,支持 RBAC(域/继承)/ABAC/策略文件/DB adapter。默认按 Subject\n  每个角色 Enforce(role,resource,action),WithSubjectID/WithMapper 可调。进程内 model+p\n[…]\nenfga/go-sdk,Zanzibar 式 ReBAC,经 Check API 判定关系权限;默认映射\n  user:<id>/relation/object,WithMapper 可调。httptest 打桩单测。\n\n两者 -race 通过、govulncheck 0 可达漏洞。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib): casbin + openfga —— pkg/authz 的两个授权引擎",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T17:41:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c5f68f856f9c78f37ff22c077ca9eac684d251d",
          "body": "补齐\"只认证不授权\"的空白。Subject(id/角色/属性,放 context)+ Enforcer 接口\n(Authorize(sub,action,resource)→nil/ErrDenied)+ 内置 RBAC(Grant + 通配 */前缀,\n零依赖)+ HTTP 中间件 / gRPC 一元拦截器(无主体→401/Unauthenticated,拒绝→403/\nPermissionDenied,action/resource 由 mapper 推导)。\n\n复杂策略(ABAC/动态/ReBAC)由实现同一 Enforcer 的 contrib 提供(casbin/openfga),\n调用点不变。-race 单测覆盖 RBAC 通配/context 往返/HTTP/gRPC。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(authz): 新增授权机制 pkg/authz(接口 + 内置 RBAC + HTTP/gRPC 中间件)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T17:04:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6c393fbc8d4277f5a06538b7c67777277967dae3",
          "body": ".github/workflows/ci.yml:\n- core:gofmt / vet / build / go test -race + 校验核心不 import contrib + govulncheck;\n- contrib:9 个模块矩阵,各自 gofmt / vet / test -race / govulncheck;\n- tools:build / vet。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: 新增 GitHub Actions(测试矩阵 + govulncheck + 反污染校验)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T16:12:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "17b06c90dc2edd8a61938065b1f057218c52d483",
          "body": "对历史上未格式化的文件做一次 gofmt(纯格式化,无逻辑改动),使仓库 gofmt-clean,\n以便 CI 强制 gofmt 门禁。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: 全仓 gofmt 统一",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T16:12:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3f25595d43d916c762e24fc27d06a692061a89ab",
          "body": "govulncheck 显示各 contrib 模块存在可达的标准库漏洞——因 go.mod 只写 go 1.26.0、\n未固定工具链。统一固定 toolchain go1.26.5(与核心一致)后,全部 contrib 与核心\ngovulncheck 可达漏洞归零;GitHub 的 14 个依赖告警经核实均为不可达噪音。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): contrib 模块固定 toolchain go1.26.5,可达漏洞归零",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T16:09:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ef4fc35bcc3d94c085369a79beb478e07466a870",
          "body": "去掉顶部\"单测只验证结构、没验证真机\"说明、末尾\"本清单只验证可被消费\"免责,以及\n\"验证服务端重协商生效\"旁白;保留命令与检查点等操作方法。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(media-validation): 只留验证方法,去掉\"未验证/只验证结构\"等说明",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T15:29:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4a853d501f12d748f3be713e095391623d1b6038",
          "body": "在 contrib/sqldb/example/outbox 演示\"改库+发消息\"的原子性:业务事务同一个 tx 里\n顺带 INSERT 到 outbox 表,relay 轮询投递+删除。刻意做成可照抄的 demo(enqueue/relayOnce\n约 40 行),不做成 pkg/模块,避免为一个模式引入耦合。\n\n耦合极薄:写入只用 *sql.Tx.ExecContext(不绑 ORM/驱动),投递用 *sql.DB + 一个 Publisher\n接口(不绑 broker)。纯 database/sql + 内存 sqlite,自包含可 go run;演示提交(原子入箱)、\n回滚(发件箱一并丢弃,证原子性)、relay 投递三步。生产化(换 pkg/mq、relay 放 leader、\n幂等、DLQ)在 README 注明。无新依赖。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(sqldb): 加事务性发件箱(outbox)示例(应用层模式,非库)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T15:24:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "60ed3eda8cdf717b16147be9fe4112378e36b771",
          "body": "泛型、仅依赖 stdlib + golang.org/x/sync,补齐常被手搓易写错的并发模式:\n\n- Map/ForEach:对一批元素并发处理,带并发上限 + 错误聚合(首错经 ctx 取消其余);\n- SingleFlight:相同 key 并发调用去重合并,防缓存击穿/惊群;\n- Batcher:攒够 N 条或到时间就 flush,批量写库/推送/调用;\n- Debounce/Throttle:事件去抖 / 前沿限频;\n- Future/Async:异步执行 + Await(ctx) 取结果,panic 转错误。\n\n全部 -race 单测通过;README 能力表加\"并发\"行。x/sync 提为直接依赖。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(syncx): 新增并发便捷原语包 pkg/syncx",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T14:14:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8b4f394b3a24752fcff6a293747c16168eede754",
          "body": "英文/中文 README 加居中标题块、pkg.go.dev / Go Report / Go 版本 / License 徽章、\n分隔线与语言切换,更符合主流 Go 项目 README 观感。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): 美化头部——居中标题 + 徽章 + 语言切换",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T13:44:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "abead0484de9217deb1cf5c52ded53a32aabcab9",
          "body": "旧 README 中英混杂、且未反映近期新增能力(媒体/实时/mq/shard/contrib/AI)。重写为\n干净的英文 README.md(能力总览 + contrib 模块表 + 精简上手),并新增对应的中文\nREADME-CN.md,双语互相链接。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(readme): 重写 README(默认英文)+ 新增 README-CN 中文版",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T13:37:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "63725f26e2268c8e846f6b52954bdc441388e535",
          "body": "薄封装官方 modelcontextprotocol/go-sdk(路线 A),把 beauty 服务暴露成 AI 可调用的\nMCP 工具,也可作 MCP 客户端消费别的 server。独立模块,不 import 核心。\n\n- Server:AddTool[In,Out] 由 SDK 泛型自动反射 In/Out 的 JSON Schema(struct→schema);\n- 部署:HTTPHandler(Streamable HTTP,挂 beauty.WithWebServer)+ NewStdioService\n  (结构上满足 beauty.Service,本地工具场景);\n- Clie\n[…]\nect + ListTools/CallTool;\n- Text() 构造文本结果;工具业务/鉴权/OAuth/schema 细节留 policy。\n\nInMemory 传输 + httptest 端到端单测(注册/列举/调用 + struct→schema 反射),-race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib/mcp): 新增 Model Context Protocol 集成",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T13:02:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e330bbede0b99af60985b211022839e33265b1aa",
          "body": "去掉 CHANGELOG、示例、文档、包注释里\"mediamtx 同款库\"\"参考了 grpc-go-polaris\n设计理念\"\"类似 Polaris 风格\"等来源/借鉴措辞,只保留功能与实际依赖名(如\nbluenviron/gohlslib 是真实 import 的依赖,属事实陈述)。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: 文档只描述功能,移除来源/借鉴归因",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T11:34:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "868cfa20c2658dfb08a3cba2a9d5cab6889e48eb",
          "body": "澄清:智谱/Kimi/MiniMax/通义千问(DashScope)/DeepSeek 等都提供 OpenAI 兼容端点,\n换 BaseURL 即用同一 openai provider,无需专门适配——新增 BaseURL* 预设常量。\n\n微软 Azure OpenAI 认证/URL 不同(api-key 头 + deployment 路径 + api-version),\n新增 openai.NewAzure 便捷构造 + WithAzure/WithAPIKeyHeader 选项(仍纯 stdlib)。\n\nAWS Bedrock 用 SigV4 签名 + 按模型报文,机制完全不同,需独立适配\n[…]\ntdlib\n的 openai),文档标注可另起 llm/bedrock。\n\nhttptest 单测新增 Azure(校验 api-key 头 + deployment/api-version URL)与兼容厂商\n(Bearer 认证路径),-race 通过。向后兼容(仅新增 API)。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib/llm): 多厂商适配(兼容厂商 BaseURL 预设 + Azure OpenAI)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T08:04:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "81ae726f1d187da927e2a548b42e997d2274277a",
          "body": "对齐 2026 AI 原生热点,补上框架此前完全空白的 AI 基建。两者均为独立模块、纯标准库、\n零外部依赖、不 import 核心。\n\ncontrib/llm:provider 无关 LLM 客户端(HTTP 直连 REST,不引 SDK)。\n- Client(Generate/Stream 流式 token)+ Embedder 接口;\n- 子包 llm/openai(chat + embeddings,BaseURL 可对接兼容网关)、llm/anthropic(messages);\n- 中间件 Fallback(跨 provider 切换)/Retry/Metered(用量+延迟回调,\n[…]\n contrib/llm 的 Embedder 搭 RAG,大规模换 pgvector/qdrant 实现同接口;\n- 单测覆盖余弦与增查删/降序/混维健壮。\n\nprompt/模型/成本表/分块/rerank 等 policy 留给使用方。-race 通过,核心 go.mod 零污染。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib): 新增 llm(LLM 客户端)与 vector(向量/RAG)模块",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-20T07:09:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c74a1b8441fdc16eea607a1a58f7a0d883c74def",
          "body": "核心已打 v0.1.0,contrib/nats、contrib/kafka、contrib/natsjs 从\nrequire v0.0.0 + replace => ../.. 切换为 require github.com/rushteam/beauty v0.1.0\n(去掉 replace),从而可对外 go get。三者 build/test 对已发布核心通过。\n\n不引入根 go.work(各 contrib 与核心的间接依赖版本不一致,合并工作区会 ambiguous import);\n本地协同开发按需对\"核心+单个 contrib\"加临时 replace。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "build(contrib): mq 模块改为 require beauty v0.1.0 并去掉 replace",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T12:05:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2ee92c95ad39876b2308755c85647ebfd5c9726d",
          "body": "contrib/sqldb/example:sqlc 生成的类型安全查询 + contrib/sqldb 读写分离,sqlite 免真库\n即可 go run。演示 Writer()(写)/Reader()(读)/RW()(自动路由,含 RETURNING 被嗅探为写\n自动落主库)/Primary(ctx)(读己之写)。含 schema.sql/query.sql/sqlc.yaml + 已提交的\nsqlc 生成代码(appdb/,便于免装 sqlc 直接跑)+ README(重新生成步骤)。\n\n样例置于 sqldb 模块内(核心不能 import contrib);sqldb 库包本身不拉 sqlite 驱动\n(仅 example/test 引入),库使用者仍零驱动依赖。整模块 -race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(contrib/sqldb): 加 sqlc 端到端可运行样例",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T10:55:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "705cf14f3fb7262567e5e0029e60827da3c494a2",
          "body": "纯按方法(Exec/Query)路由无法正确处理 INSERT...RETURNING(走 QueryRow 却是写)与\nSELECT...FOR UPDATE(读却要走主),会静默路错。改为 Query/QueryRow 先按 SQL 意图判定:\n写动词开头、RETURNING、FOR UPDATE/SHARE、数据修改 CTE → 主库,否则副本。偏保守——拿不准\n偏向主库(读误判只是少分流,方向安全;避免\"写→副本\"的危险失败)。Primary(ctx) 仍可显式强制。\n\n如实标注:SQL 启发式无法 100% 覆盖(字符串/注释里的关键字会误判为主库,方向安全);\n确定性保证仍用显式 \n[…]\neader()。\n\n单测:hasWriteIntent 覆盖写/RETURNING/FOR UPDATE/数据修改 CTE/只读 CTE/前导括号;\nE2E 验证 INSERT...RETURNING 经 RW() 自动落主库(sqlite 真实执行、副本不受影响),-race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib/sqldb): RW() 自动路由加 SQL 意图嗅探,自动挡写误落副本",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T08:04:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "35fbececb4ca99b8def039cddb6f69b1dee5be64",
          "body": "独立模块,给 database/sql 提供主从读写分离与 otelsql 埋点,和 sqlc 生成的代码天然\n配合(sqlc 的 Queries 吃 DBTX,本模块 Writer()/Reader() 即 DBTX),也可用于 sqlx/手写。\n\n- Open(主 + 多副本,otelsql 命令级 trace/DB stats metrics、连接池);\n- Writer()(主)/Reader()(副本轮询,无副本回退主)/Primary()(开事务/迁移)/Ping/Close;\n- RW() 自动路由(Exec→主、Query→从)+ Primary(ctx) 逃生口——如实标注 \n[…]\n优先用显式 Writer()/Reader();\n- 不 import 数据库驱动(使用方空导入)与核心。\n\n双内存 sqlite 库单测验证路由落点(Writer→主/Reader→副本/RW 自动+Primary 强制/无副本回退),\n-race 通过;核心 go.mod 零污染。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib/sqldb): database/sql 读写分离 + OTel(配合 sqlc)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T07:35:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4c0dce4da60fff2e2740ab9cd37f107555a81eb4",
          "body": "给现有 redis.NewClient 加 WithTracing()/WithMetrics() 选项,基于 redisotel 让每条\nredis 命令产生 span 与命令级 metrics(用 beauty telemetry 的全局 Provider,未配 no-op)。\nConfig 补 PoolSize/MinIdleConns/DialTimeout/ReadTimeout/WriteTimeout(零值用 go-redis\n默认)。分布式锁/KV 共用的客户端从此可观测。\n\n选项无参、不泄漏 redisotel 类型到公共 API。新增 redisotel 依赖(其依赖 go-redis/otel\n核心已有),go-redis 升至 v9.21;整核心 build 与 kvstore/dlock 编译通过。\n多集群 ClientManager 属应用级策略,不进框架。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(infra/redis): NewClient 支持 OTel 埋点 + 连接池/超时配置",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T04:33:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fe323af424027b3212f3e6117ebfe2037dfe9a53",
          "body": "pkg/buildinfo(核心,零依赖):运行时暴露 版本/commit/构建时间/Go版本/模块/dirty,\n用于 /version、启动日志。ldflags 注入变量优先,runtime/debug 的 VCS 元数据回退;\nGet()/String()/Handler()。单测覆盖默认/ldflags 覆盖/Handler。核心 go.mod 零改动。\n\ncontrib/natsjs(独立模块):pkg/mq 的 NATS JetStream 绑定,持久化 + at-least-once。\nEnsureStream 建流、Publish 落盘、mq.WithGroup→durable\n[…]\nak 重投)。是 contrib/nats(core,\nat-most-once)的可靠版。内嵌开启 JetStream 的 nats-server 真实往返单测(先发后订的\n持久化、Nak 重投),-race 通过;实现核心 mq 接口故 replace => ../.. 本仓解析。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: pkg/buildinfo(运行时构建信息)+ contrib/natsjs(JetStream 持久 MQ)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T04:06:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "10a195908ebf3d7ca06a49d98c2bbb5d99b1f78a",
          "body": "按\"重依赖实现独立成模块\"继续补齐,均为独立 Go 模块、核心 go.mod 零污染:\n\n- contrib/nats:pkg/mq 的 NATS broker 绑定,实现 Publisher/Subscriber。topic→subject、\n  mq.WithGroup→NATS queue group(竞争)/不设组扇出、Headers 与 Key 透传、订阅随 ctx 退订;\n  at-most-once(持久化用 JetStream)。内嵌 nats-server 真实往返单测(扇出/队列组/退订)。\n- contrib/kafka:pkg/mq 的 Kafka broker 绑定(\n[…]\n 头)。\n\nnats/kafka 实现核心 pkg/mq 接口故 import 核心(replace => ../.. 本仓解析);gorm/elasticsearch 独立。\n全部 -race 通过;核心 go build ./... 不编译 contrib,依赖与 CI 不受影响。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib): 新增 nats/kafka(mq broker 绑定)与 elasticsearch 模块",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-19T03:24:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4246cd1f1a41a21dbc523d47a8ff8ba02634f9ba",
          "body": "结合 social-infra 补齐持久层能力,但按\"重依赖实现独立成模块\"的方式:contrib/ 下每个\n子目录是独立 Go 模块(github.com/rushteam/beauty/contrib/<name>,自带 go.mod,与\ntools/ 同套路)。核心只留轻量机制/接口,重依赖进 contrib——不 import 就零负担、可自己\n照接口实现、可独立钉版本;核心 go build ./... 不编译 contrib,依赖与 CI 不受影响。\n\n首个模块 contrib/gorm:\n- 读写分离(dbresolver 主写从读)、otelgorm 链路、gorm→slog \n[…]\n;\n- 不 import beauty 核心,仅依赖 stdlib slog + OTel 全局 Provider,可脱离框架单用。\n\nsqlite 内存 + 合成错误单测覆盖 CRUD/读写句柄/唯一键判定,-race 通过。\n核心 go.mod 零改动(gorm 未进核心依赖图)。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(contrib): 新增 contrib 多模块区 + contrib/gorm(GORM 集成)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T18:25:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8d8d583899a719a6a160c5c77c649d551baf135f",
          "body": "此前只有服务发现版客户端接了节点级熔断+重试,直连/普通客户端裸奔。现复用已有的\nbackoff.Policy 与 middleware/circuitbreaker,接到 pkg/client:\n\nHTTP(resty.NewHTTPClient):\n- WithRetry(policy):重试瞬时失败,默认只重试幂等方法(网络错误/429/502/503/504),\n  遵守 Retry-After,请求体自动重放;\n- WithRetryable(fn):自定义重试判定;\n- WithCircuitBreaker(cb):复用 middleware/circuitbreaker 的 Ro\n[…]\nInterceptor(cb):请求级熔断拦截器,直连与发现模式均生效,\n  与发现版节点级 WithCircuitBreaker 互补;重试默认已由 service config 开启。\n\n单测覆盖重试/幂等不重试/体重放/ctx 取消打断退避/熔断短路,-race 通过,无新依赖。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(client): 把熔断/重试接进直连/普通客户端(客户端韧性闭环)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T17:52:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ab7e6dfbe998734406ec8f94189a1cd36cdf65ad",
          "body": "补齐框架跨服务异步的空白(此前只有进程内 eventbus 扇出 + webhook HTTP 推)。\n\n- Publisher/Subscriber 接口:订阅按 ctx 绑定生命周期,同时适配 NATS(push)与\n  Kafka(pull)语义;\n- Consumer:把一组 (topic, handler) 订阅包成 beauty.Service(Start/String/Ready),\n  随 app 优雅停机,链式 Handle 登记;\n- 处理中间件 Chain/Recover(吞 panic)/Retry(瞬时错误重试);\n- 队列组 WithGroup 竞争消费(多副本水平\n[…]\n-most-once(用\nRetry 兜瞬时错误),可靠\"改库+发消息\"的 Outbox 依赖持久层暂未做。\n\n示例 examples/mq。单测覆盖扇出/队列组负载均衡/订阅随 ctx 解除/Consumer 生命周期/\nRetry/Recover/关闭,-race 通过,无新依赖。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(mq): 传输无关消息队列抽象 + 消费者即 Service",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T17:15:12Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7d680889fac39dd5ef55d281b38c14857f20881b",
          "body": "pkg/shard:一致性哈希(复用 loadbalance.ConsistentHash)把 key(streamKey/roomID/\nuserID)确定性归属到某实例,Sharder.Owner/IsLocal + 动态 SetMembers;Router 是\nhttp.Handler,按 key 把非本地请求反代给归属实例(WebSocket 可,带防环标记头),本地\nkey 走本地 handler。让 media.Hub、webrtc/sfu 房间、gameloop 房间、presence 这些进程内\n单实例服务无需改造即可水平扩多副本(分片层坐在前面)。成员来源/ key 提取/权\n[…]\nwner、防环、成员变更迁移,-race 通过,无新依赖。\n\ndocs/media-validation.md:媒体链路真机验证清单——单测只验证产出结构,本清单给可照抄的\nffmpeg 命令 + 真实播放器(Safari/hls.js/ffplay)检查点 + 延迟/断流/泄漏红线。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(shard): 有状态服务多副本分片路由 + 媒体真机验证清单",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T15:27:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7458e3cb1d7637c50fa46aa84d7f4bd3097ff2f9",
          "body": "删除自研的 pkg/media/remux(FLV→TS):其招牌活儿 RTMP→HLS 已被 pkg/media/hlsmux\n(gohlslib,LL-HLS/fMP4)取代且更全。go-astits 由我们的直接依赖降为 gohlslib 的\n间接依赖。同时删除被取代的 examples/live-hls(并入 live-hls-gohlslib)。\n\nHub 泛化为 Hub[S media.Stream](Stream = http.Handler + Finish()),不再绑死\n*hls.Stream:同一套多路管理/路由/生命周期现可承载 *hlsmux.Bridge(gohls\n[…]\n现成分片)、跨码率 ABR\n主清单、可插拔对象存储 Store 仍由 pkg/hls 提供。gohlslib 的存储是 WithDirectory\n(磁盘),不迁移 hls 的 Store 接口。\n\n新增 Hub[*Bridge] + Master(ABR)集成单测,-race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(media): 删 remux,Hub 泛化,hlsmux 接进 Hub/ABR",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T08:03:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ed781632d04cb353b541b7e72317dc4dde5afa88",
          "body": "把 RTMP 采集的 FLV(H.264+AAC)喂给 bluenviron/gohlslib(mediamtx 同款库),\n产出产线级 HLS:MPEG-TS / fMP4 / LL-HLS。相比自研 pkg/media/remux(仅 FLV→TS +\n手搓播放列表),由 gohlslib 负责分片、播放列表(含 LL-HLS EXT-X-PART/PRELOAD-HINT\n与阻塞式刷新)、fMP4 init 段等全部细节。\n\nBridge 同时实现 rtmp.Handler(收流)与 http.Handler(播放):拿到 SPS/PPS+首关键帧\n后惰性起 muxer(关键帧前置带内 \n[…]\nib。单测覆盖 FLV 解析纯函数 + 用真实 SPS/PPS/ASC 喂帧、\n由 gohlslib 自身校验产出 MPEG-TS/LL-HLS 播放列表,-race 通过。\n\n新增依赖:bluenviron/gohlslib/v2、bluenviron/mediacommon/v2。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(media/hlsmux): 新增 RTMP FLV→gohlslib 的 LL-HLS 桥接",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T07:33:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e728027f7461f200da8f56066b2e0fecbe7a6d9c",
          "body": "在 pkg/media/webrtc 之上补齐 WHIP/WHEP 覆盖不到的 N↔N 动态成员那一档:每人推\n自己的轨道、订阅其他所有人,服务端做选择性转发(不混流不转码),成员进出由服务\n端重协商。\n\n无 glare 模型:客户端只在加入时发一次 offer,此后所有重协商一律由服务端作为\nofferer 发起;resync 在信令未落定(非 stable)时自动推迟、answer 到达后重试。\n\n信令传输无关:Room.Join(id, send) 经 send 回调推信令、Participant.HandleSignal\n吃客户端信令,承载(WebSocket 等)由上层决定。鉴权、房\n[…]\n\n(MCU)、主讲人检测、STUN/TURN、录制全留 policy。\n\n示例 examples/webrtc-voice-room(pkg/ws 信令 + 浏览器多人语音)。进程内多方单测\n覆盖真实 ICE + 双向收流 + 服务端重协商 + 离开回收,-race 通过。无新增依赖。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(media/webrtc/sfu): 新增多人实时音视频会议室 SFU 原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T03:02:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b7841baefcbe8565f0996a72b326e6ce85d73735",
          "body": "面向亚秒级、交互式实时媒体(连麦/云游戏/实时协作),和 pkg/hls(多秒级、可过\nCDN 分发)互补,与 pkg/quic+pkg/gameloop 同属「实时」家族。\n\nWHIP/WHEP 本质同为「HTTP 一发一答 SDP 协商、服务端做 answerer」:\n- NewWHIP/NewWHEP 是 http.Handler(挂 beauty.WithWebServer 即可,不自起监听),\n  做 SDP/ICE 协商 + 资源生命周期(Location/DELETE/断连自动回收);\n- Answer 暴露协商原语;Pipe 做 RTP 纯包转发(不转码,SFU 最小原语);\n\n[…]\nN、编解码档位、CORS 全留 policy。\n示例 examples/webrtc-whip-whep(一推多播最小 SFU)。端到端单测覆盖真实 ICE\n环回 + RTP 转发 + DELETE 拆除,-race 通过。\n\n新增依赖:pion/webrtc/v4、pion/rtp。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(media/webrtc): 新增 WHIP/WHEP 薄机制(pion,纯 Go 零 cgo)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T02:24:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "20f175208f9d9d305f9080c05be2478ae3fbbe92",
          "body": "go-rtmp 的 ConnConfig.normalize() 在 Logger==nil 时会自建一个输出到\nDiscard 的 logger,所以我们无需自己引 logrus——移除 Server 的 logger 字段、\nWithLogger Option 与 discard logger 构造,logrus 降为纯间接依赖。slog 已够用。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(rtmp): 移除 logrus,go-rtmp Logger 留 nil 默认静默",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-18T01:25:58Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2eab0c0735d71890bcaa5513682dfc3ecd7d14dd",
          "body": "新增 pkg/media 编排薄机制:\n- Hub:streamKey→Session 注册表 + 生命周期 + 按 key 路由(http.Handler)+ 防重复推流;\n  Session.Context() 在 Release 时取消,供 ffmpeg Supervisor 等后台任务随流停机。\n- Supervisor:监督子进程(ffmpeg 等),非正常退出按 pkg/backoff 退避重启,ctx 取消\n  优雅停(SIGTERM→宽限→Kill);命令构造(ffmpeg 参数)留 policy。\n- Metrics:基于 OTel 全局 Meter 上报 streams.a\n[…]\n,按 streamKey 各自成流/分发 + 指标。\n边界:Supervisor 的崩溃重启适合\"拉流/读文件\"式输入;stdin 管道式转码崩溃应结束重推\n(README 已说明)。单测覆盖 Acquire/拒绝/Release/路由/并发抢流唯一性/重启/优雅停,-race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(media): 多路流 Hub + 进程 Supervisor + OTel 指标",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-17T08:37:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7155c68dc2cdf5bb4fd90d92963f74de279b6ee0",
          "body": "examples/live-transcode:beauty 收 RTMP、把流重建成 FLV 管道喂给 ffmpeg 转成 720p/360p\n两档,再用 pkg/hls.Master(FileServer 变体)组主清单分发自适应码率。转码交给 ffmpeg,\n框架负责采集/鉴权/编排/分发。CHANGELOG 同步补齐 hls 的 ABR/LL-HLS 条目。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(examples): 拓扑A ffmpeg 转码(ABR)示例",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-17T08:05:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "32e4d3b2f1a1cf9f7e8a015d257da5d815404815",
          "body": "ABR 多码率:Master/Variant 生成 #EXT-X-STREAM-INF 主清单并按变体名路由;Variant.Handler\n用 http.Handler 解耦,可接进程内 *Stream 或 ffmpeg 转码产物目录的 FileServer,故同一个\nMaster 覆盖\"进程内\"与\"外部转码\"两种产源。\n\nLL-HLS 低延迟:WithPartTarget 开启部分分片,AppendPart/CompleteSegment 驱动;播放列表带\nEXT-X-PART / PART-INF / SERVER-CONTROL(CAN-BLOCK-RELOAD)/ PRELOAD-H\n[…]\nS_msn=&_HLS_part=,基于 sync.Cond + 超时)。part 按 part{seq}_{idx} 分发。\n\n单测覆盖主清单生成/路由、LL 指令生成、part 分发、阻塞刷新唤醒,-race 通过。真机播放器\n的 ABR 切换与 LL-HLS 亚秒延迟需另行验证。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hls): 补 master playlist(ABR)+ LL-HLS 低延迟",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-17T08:05:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f93e24f0ce2d54640f4044f64cb544036411e029",
          "body": "pkg/media/remux:把 FLV(H.264/AAC)重封装成 MPEG-TS 分片(纯 Go go-astits),按视频\n关键帧切片 Append 到 hls.Stream,不转码——只做 AVCC→AnnexB、AAC→ADTS 格式转换与容器\n重封装。FLVToHLS 实现 rtmp.Handler,把采集(rtmp)与分发(hls)串成完整直播链路。\nexamples/live-hls 端到端示例:ffmpeg 推 RTMP → HLS 播放。\n\n单测覆盖 AVCC→AnnexB / SPS-PPS 解析 / AudioSpecificConfig+ADTS / 关键帧切片,并校验\n产出合法 TS(0x47 同步字、188 对齐)。仅支持 H.264+AAC;真机播放器互操作未在此验证。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(remux): FLV→MPEG-TS remux 打通 RTMP→HLS 端到端",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T20:14:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bc8b6b38c5c9f6deac6f315b10ca7e8349a3b1ef",
          "body": "薄封装 yutopp/go-rtmp:接受 OBS/ffmpeg 推流,把每路流 metadata/audio/video\n(FLV tag body)交给业务 Handler。Server 结构上满足 beauty.Service。鉴权两级:\n连接级 WithConnectAuth(按 connect 的 app/tcUrl 校验)+ 推流级 PublishFunc 返回 nil\n拒绝。只负责收流,不转码、不封装。loopback 测试:go-rtmp client 推流→收到音视频帧\n+ 流名,-race 通过。\n\n新增依赖 github.com/yutopp/go-rtmp、github.com/sirupsen/logrus。go.mod 同时纳入\n后续 remux 用到的 github.com/asticode/go-astits。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(rtmp): 新增 pkg/media/rtmp 采集服务端(含鉴权)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T20:13:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "90a7fedf658de630a89e837c23102be41ce4b5c3",
          "body": "纯 Go HLS origin:滚动分片窗口 + m3u8 播放列表(live EVENT / VOD)+ http.Handler\n挂 webserver 分发。不做编解码/切片,分片由上游 Append 进来,支持 TS 与 fMP4\n(EXT-X-MAP init 分片)。分片存储可插拔:Store 接口 + 内存/磁盘实现(WithStore),\n对象存储可自实现;Append 返回 error 以反映存储失败。示例 examples/hls 用合成分片\n演示,curl 可拉 m3u8。单测覆盖窗口淘汰/media-sequence/Finish 转 VOD/磁盘存储/ServeHTTP。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(hls): 新增 pkg/hls 直播/点播 origin(可插拔存储)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T20:13:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7d01a2a030df558cc2cfd8af8baeccdee08267cd",
          "body": "examples/statesync-quic:与 examples/statesync 同样的权威模拟 + AOI 逻辑,传输换成\npkg/quic 并按可靠性分流——指令(Hello 握手 + Cmd)走可靠有序流,高频状态(AOI View)\n走不可靠数据报。复用 pkg/gameloop + pkg/spatial,3 个 QUIC bot 端到端自校验 AOI 一致。\nstatesync README 的生产化提示与 CHANGELOG 的 quic 条目同步补齐。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(examples): 补 statesync-over-QUIC 端到端示例",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T14:59:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "76fb45af6fd887eaac9adf77129a90da1d6b3baf",
          "body": "基于 quic-go v0.60,作为 pkg/ws(WebSocket/TCP)之外面向实时/游戏同步的可选传输\n(opt-in 子包)。一条连接两种通道:可靠有序流(OpenStream/AcceptStream,多路复用、\n跨流无队头阻塞——关键指令)+ 不可靠数据报(SendDatagram/ReceiveDatagram,RFC 9221\n——高频状态更新,丢了不重传不阻塞)。Server 结构上满足 beauty.Service,可直接\nWithService 挂进框架;Dial 客户端;DevTLSConfig 开发用自签证书。\n\n性能:ListenUDP 建 socket 时尽\n[…]\n\nsocket 与 quic.Transport 复用(一条 socket 同承载监听+拨号);包注释附 sysctl 提示。\n封装热路径零额外开销(fmt.Errorf 仅在出错时执行)。loopback 测试覆盖可靠流回显、\n数据报回显、自备 socket 路径,-race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(quic): 新增 pkg/quic 传输层(可靠流 + 不可靠数据报)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T14:51:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "105df6061f48531d0795d4f59f44fc98aba3c67c",
          "body": "新增 examples/statesync:与 examples/gameloop 共用同一个 pkg/gameloop.Room,只换\nOnTick 策略,即从帧同步(下发输入)切到状态同步(服务器权威模拟 + 下发状态)。\n用 pkg/spatial 每帧建网格索引、在连接出口按视野半径 Nearby 做 AOI 过滤;3 个\n进程内 bot 自校验「只收到视野内实体」(alice↔bob 互见、carol 远处隔离)。\n\ngameloop README 交叉链接两个示例;CHANGELOG 的 gameloop 条目补上 statesync。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(examples): 补状态同步 AOI 示例,与帧同步对照",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T14:07:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4273cb3b833fdad63a7f4339402647ab3c1a6bd9",
          "body": "「机制而非策略」的瘦包:定步长 tick、并发输入聚合(每帧原子取走)、经\nstream.Broadcaster 扇出下发、结构上满足 beauty.Service(Start/String)+\nReadyNotifier,可直接 WithService 挂进框架随 app 优雅停机。帧同步/状态同步的\n服务端骨架——同步策略(确定性/序列化/快照/AOI)全在 Handler.OnTick 里,不进\n框架。仅依赖 pkg/stream,零框架耦合。\n\nexamples/gameloop 给出可运行的 lockstep demo:pkg/ws 接连接(读循环 Push 输入、\n写循环写回每帧)+ 3 个进程内 bot 自校验「逐帧输入全端一致」(lockstep 传输不变量)。\n单测覆盖 tick 推进/输入聚合/扇出一致/优雅停,-race 通过。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gameloop): 新增 pkg/gameloop 定步长游戏循环原语 + lockstep 示例",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T13:56:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f5b00e1cda040997d4f3dc4a57fccd77008dbf87",
          "body": "govulncheck 判定为可达的 8 个漏洞全部来自 Go 标准库(crypto/tls、crypto/x509、\nnet/http HTTP/2 无限循环 DoS、html/template XSS、net、mime、net/textproto),\n升级工具链一并修掉,无需改动任何依赖。修复后 govulncheck ./... 可达漏洞归零。\n其余 dependabot 告警为不可达的间接依赖噪音(代码未调用到)。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(security): 固定 toolchain go1.26.5,修掉 8 个可达的 stdlib 漏洞",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T08:59:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ab697de9b7089c7cf08d11d63d363137637d299d",
          "body": "README 给基建适配层一个 overview:能力矩阵(conf/dlock/kvstore/discover ×\netcd/consul/k8s/redis/nacos/polaris)+ 各后端 DSN 与最小用法。CHANGELOG 补\ndlock URL 工厂、etcd kvstore 两条 Added。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(infra): 新增 pkg/infra 总览 README + CHANGELOG 条目",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T07:06:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "29ce54bf77301803d11da7c8be51430139c4d6f7",
          "body": "用 etcd lease 做 TTL(可精确查剩余)、事务/CAS 做原子 SetNX/Incr,实现\nkvstore.Store,给 counter/cooldown/idempotency 一个跨实例后端。与 redis\n实现互补:etcd 秒级 TTL、已有 etcd 免再引 Redis;redis 毫秒级 TTL、Incr\n原生原子。集成测试(build tag + BEAUTY_TEST_ETCD_ENDPOINTS)覆盖 roundtrip、\nlease 到期、并发 Incr 精确性,已对真实 etcd + -race 验证。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(kvstore): 补 etcd 后端(pkg/infra/etcd.Store)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T07:05:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a1fecc1f93f9d0152ea2f669df8d6478d529f167",
          "body": "dlock.New(dsn) 构造 Locker、dlock.NewElector(dsn) 构造 Elector,各 infra\n子包空导入即注册:etcd/etcdv3、consul、redis 注册两者;k8s 只注册 Elector\n(基于 Lease 的选主,无互斥锁原语)。选后端只看 DSN,免在业务里硬编码实现,\ncron 的 WithLeaderElector 也能直接吃 DSN 构造的 elector。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dlock): 补 URL/DSN 工厂,与 conf.New 的 scheme 工厂对齐",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-16T07:05:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "254227545127477a38abd368505d44f096cb13a2",
          "body": "…omConfig\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(changelog): 记录 consul/redis dlock、redis kvstore、client 收敛、k8s Fr…",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-15T17:39:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6debff198ce800ef135a2646541563e8422e611b",
          "body": "- consul(pkg/infra/consul/dlock.go,零新依赖):session + KV Acquire 实现\n  Locker(真非阻塞 TryLock)+ Elector,RenewPeriodic 续期,LockDelay=0 对齐\n  etcd 的快速 failover;NewDLock / NewDLockFromConfig 构造。\n- redis(pkg/infra/redis,新增 go-redis/v9):单节点 SET NX PX + Lua CAS\n  释放/续期实现 Locker + Elector,如实标注非 Redlock 的单节点语义。\n- re\n[…]\nre,给 counter/cooldown/idempotency 一个跨实例后端。\n- 两家均配 build-tag + 环境变量守卫的集成测试(仿 etcd),已在真实\n  consul/redis 容器里跑通互斥/单主/failover 与 kvstore 往返,含 -race。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dlock): 新增 consul、redis 分布式锁后端 + redis kvstore",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-15T17:38:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b8a70fcabdefb243770aca3ea3a80f2304a94b0",
          "body": "pkg/infra/{etcd,consul} 暴露 NewClient、k8s 暴露 NewClientset,配置中心/分布式锁\n与 pkg/service/discover/{etcdv3,consul,k8s} 共用同一处连接构造,消除各写一遍的\n重复(对齐 nacos 早已复用 infra/nacos 的做法)。\n\n副作用:discover 子包因此 import 对应 infra 包,连带触发其 init() 注册 conf\nscheme(Go 保证每包 init 只执行一次,不会重复注册),无害。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(infra): 收敛 etcd/consul/k8s 的 client 构造,discover 复用",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-15T17:37:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b0eb47ad06c542560c8e2dba15ed27ab6a62aca8",
          "body": "- pkg/infra/k8s 实现 conf.ConfigCenter,空导入注册 configmap/secret scheme,\n  纯 k8s 部署无需额外配置中心即可热更新:按 metadata.name watch 目标资源、\n  断线指数退避重连、按值去重避免无谓重载,删除源资源时保留 last-good。\n- 新增 NewClientset(in-cluster/kubeconfig 判定的公共构造)与 Elector 的\n  NewElectorFromConfig,后者填上此前注释指向的缺失便捷构造。\n- fake clientset 单测覆盖 Get/BinaryData/Secret 解码/缺 key/坏格式/Watch 去重。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(conf): 新增 k8s ConfigMap/Secret 配置中心后端 + Elector FromConfig",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-15T17:36:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a701e304e588d6e1ac27b9f9793fcc2cb08caf2f",
          "body": "NewElectorFromConfig 从未实现,注释误导。改为说明生产用法自行构造\nclientset 后传入即可,可参考 pkg/service/discover/k8s 的判定模式。\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(dlock): 修正 k8s.NewElector 注释里指向不存在函数的文档漂移",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-14T12:31:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7c76f90c3889e036f6d6a4feb2059baa4f9623a2",
          "body": "部署在 k8s 里不想额外运维一套 etcd 时,可直接用集群自带的选主能力实现\npkg/dlock.Elector——基于 client-go 的 leaderelection + coordination.k8s.io/v1\nLease 资源(kube-scheduler 等控制面组件用的同一套机制),不重新发明选主算法。\nclientset 构造复用 pkg/service/discover/k8s 已有的 in-cluster/kubeconfig 判定\n模式的思路。\n\n只实现 Elector,不实现 Locker:client-go 的 leaderelection 语义是\"持续参选\n[…]\ntx 级联取消)。如实标注验证强度边界:fake clientset 不做\nresourceVersion 乐观锁仲裁,验证不了真实互斥,所以没做\"多 Elector 竞选同一 Lease\"\n的断言——这和 etcd 后端那轮\"真实 etcd 集成测试\"的验证标准不一致,留给真实集群。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dlock): 补 k8s 原生选主后端(pkg/infra/k8s.Elector)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-14T02:59:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e80a7fff77240e97b1b2d63e7a0148eae21fccab",
          "body": "补齐框架级生产化缺口:多实例部署下 Cron 会每个实例各跑一遍定时任务(重复\n发奖/重复扣款/重复生成报表),框架此前没有解法。\n\n- pkg/dlock: 定义后端无关的 Locker(Lock/TryLock)+ Elector(Run 持续选主,\n  onElected 收到的 leaderCtx 是\"仍是 leader\"的唯一凭证)接口 + 内存实现\n  Memory(单进程多 goroutine 竞争,供开发/测试/单实例用)。\n- pkg/infra/etcd.DLock: 基于 etcd 官方 client/v3/concurrency 包(Session+\n  Mutex/E\n[…]\n。\n\n用 dlock.Memory 模拟两个 Cron 实例竞选同一 key 的测试验证了互斥语义。\nexamples/cron-leader 演示效果(生产换 etcd.NewDLock 即可,业务代码不变)。\ndocs 新增 pkg/dlock 速查 + \"④ 需跨实例协调\"一档。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(dlock): 分布式锁/选主 + Cron 只在 leader 上跑",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-14T00:56:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dbfe11a4dc1b117580e7f1212c8c2464fab6ba92",
          "body": "wrapper.go 用 span.(sdktrace.ReadOnlySpan) 断言算耗时;未显式调用\nbeauty.WithTrace() 时全局 tracer 是 otel 的 noop 实现,产生的 span 不满足该\n接口,断言必然 panic(被 recover 兜住,但每次 tick 都产生一次堆栈 + ERROR\n日志)。改用 time.Now()/time.Since 计算耗时,不依赖具体 span 实现。\n\n影响范围:任何未显式配置 trace 的 Cron 使用者(多数简单场景、全部现有 example/\n测试)。此 bug 与本次 dlock/选主改动无关,在改动前的 main 分支上已验证复现\n(git stash 对照),顺手修掉。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cron): 修复未配置真实 TracerProvider 时每次任务触发都 panic-recover",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-14T00:56:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "136615935d258f6482c06de0389072ed8d9ef650",
          "body": "回答\"内存原语能否上多实例生产\":给类三(需跨实例共享状态)的三个原语抽出统一的\n带 TTL 原子 KV 存储接口 pkg/kvstore.Store,配置 WithStore 后状态存到共享后端\n(Redis 等),从单机升级为多实例一致。\n\n- pkg/kvstore: 定义 Store 接口(Incr/GetInt/Get/Set/SetNX/TTL/Delete,均原子、\n  context 感知、每方法标注对应 Redis 命令)+ 纯标准库内存实现 Memory。不引任何后端 SDK。\n- counter.WithStore: 固定窗口(每 window 一个 TTL 计数键),A\n[…]\nhOnStoreError 上报。各含 store 模式 -race 测试(含\"两实例共享\n同一 Store\"的跨实例一致性验证)。附 examples/kvstore-shared 演示。\ndocs 新增\"生产多实例:内存 vs Store\"章节,按状态性质三档说明哪些能直接上生产。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(kvstore): 抽出 TTL-KV Store 接口,counter/cooldown/idempotency 支持跨实例",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-10T11:18:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d3785c1fc0cf36a809633a1610b586cf316c8c0",
          "body": "补齐任务成就、等级、红点三个高频系统,均纯标准库 + 泛型 + 函数式 Option:\n\n- questlog: 任务/成就进度追踪。朝目标累加进度、达标可领(幂等)、前置依赖门控、\n  周期重置;四态状态机(Locked→InProgress→Achieved→Claimed)。与 counter(窗口\n  计数、会过期)区分:进度不随时间减少。每日任务/成就/通行证/新手引导。\n- leveling: 经验/等级曲线换算。Gain 返回新等级/升几级/级内进度/满级溢出;三种\n  曲线 Linear/Poly/Table(对接策划数值)。纯计算无状态,经验由调用方持久化。\n- reddot\n[…]\n红点未读聚合树。叶子设未读、父节点自动汇总(Count 精确 / Dot 布尔)、\n  清零沿父链传播;路径式节点惰性建树。App\"我的\"页红点汇总。\n\n各含 -race 测试与可运行 example。README 原语表补 3 行、docs 补 3 个速查块、\n组件计数 48→51。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: 新增 questlog / leveling / reddot 三个游戏&社交原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-03T01:32:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a96453274ae2b2b3b1ff8f69aaa60dfc5507ec44",
          "body": "一致性审计发现:fsm 是唯一用\"带字段的错误类型\"而非 var ErrXxx = errors.New\n哨兵值的包。这是有意设计(携带 From/Event 供 errors.As 取用),补一段 doc\n说明理由与用法,使其看起来是刻意选择而非偏离。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(fsm): 说明 ErrInvalidTransition 用错误类型而非哨兵值的理由",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-03T00:56:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "055dd2ab5caa4456a68feb5451b79458a9cb72fe",
          "body": "补齐游戏/直播场景的常用件,均纯标准库 + 泛型 + 函数式 Option:\n\n- loot: 加权随机抽取(抽卡/开宝箱/掉落/直播抽奖)。Vose's Alias Method 建表后\n  抽取 O(1);Puller 支持保底(pity:连续 N 次未出目标稀有度则强制出);DrawDistinct\n  不放回抽 N 个(十连去重)。含分布统计测试。\n- cooldown: per-key 冷却,Ready/Remaining/TryTrigger(原子检查+触发)。与 ratelimit\n  (速率)、counter(窗口累计)互补——控两次动作最小间隔。分片锁 + gc。\n- rin\n[…]\nAnd/Or/AndNot + 连续签到统计。1000 万用户/天 ~1.25MB;\n  与 bloom(概率型)互补——精确、可 Count/枚举。\n\n各含 -race 测试与可运行 example。README 原语表补 4 行、docs 补 4 个速查块、\n组件计数 44→48。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: 新增 loot / cooldown / ringbuffer / bitmap 四个游戏原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T17:57:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b5e17d3fdcf5e7743611c696f095046cbcb809d9",
          "body": "给 idgen/counter/spatial/keyedmutex/backoff 加基准,验证设计假设 + 回归防线:\n- counter: 分片锁生效——多 key 并行(97ns)优于单热点 key(156ns);\n- spatial: 网格收益随规模显现——10k 实体与全表扫描相当,250k 时网格 ~10µs\n  vs 全表 ~171µs(~17×),印证查询耗时取决于局部密度而非 N;\n- idgen: Next ~243ns 零分配(time.Now 主导),Parse ~2ns;\n- backoff: Duration 7~11ns 零分配;\n- keyedmutex: 无争用 ~65ns(entry+闭包 3 allocs),热点 key 退化为普通互斥。\n\n均为独立 bench_test.go,不影响常规 go test。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: 给性能敏感原语加 benchmark",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T17:29:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ef073d84097d54d6eb855bd2204bfa5a741b26de",
          "body": "docs/realtime-components.md 此前只有老原语有\"速查\"块(API 示例 + 要点),\n15 个新原语仅在概览表格里。补齐:每个原语一段速查(典型用法代码 + 3~5 条\n要点/坑 + 互补关系),与老原语格式一致。新增\"扩展原语速查\"分节,按\n并发&可靠性 / 调度&计数 / 状态机&玩法 / 空间&地理 归类。\n\nAPI 示例均对照真实签名核对。README 文档索引条目同步更新。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: 补 15 个扩展原语的速查块",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T17:29:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "343dd0036dcb54132df02546e9dd666db06ec69c",
          "body": "从\"同时只一局\"改为多房间并行:roomID→Match 的 map 支持多局,keyedmutex\n按房间串行化 start/结算等结构性操作(不同房间互不阻塞),各接口带 room 参数,\n新增 /rooms 列出进行中的房间。送礼幂等键改为含房间维度(gift:<room>:<id>),\n跨房间独立计分。接入 eventbus 广播全局 PK 生命周期事件(pk.started/pk.ended),\n演示榜单/通知等下游模块如何解耦订阅。\n\n端到端验证:两局并行比分独立(R1 A=100/B=130、R2 A=50),同 giftID 跨房间\n各自计一次、房间内重复 replayed=true。README/docs 同步更新组合说明。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(examples): live-pk 升级为多房间 + keyedmutex + eventbus",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T16:56:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5833c822c324a229d4ab90349fcece7dbe1c2e9f",
          "body": "- docs/realtime-components.md:新增\"扩展原语\"章节,把 15 个新原语按\n  并发&可靠性 / 调度&计数 / 状态机&玩法 / 空间&地理 四组归类,附一句话 +\n  典型场景;补一张\"互补关系速记\"表(idempotency vs keyedmutex、counter vs\n  ratelimit、txn vs saga、spatial vs geohash、stream vs eventbus 等)帮选件;\n  组合范式补\"直播 PK 房间\"一节。\n- examples/live-pk:可运行的直播 PK 后端 demo,组合 versus(对抗计分+SSE)+\n  idempotency(送礼幂等去重)+ counter(送礼配额防刷)+ tally(点赞高频聚合)+\n  idgen(房间 ID),端到端演示原语协作。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: 扩展原语归类文档 + 直播 PK 组合 demo",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T13:32:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7fd076adc20ebcdb2ff6aaec47c505f6a141852d",
          "body": "消除三处各自手写的指数退避,统一到 pkg/backoff,行为保持不变:\n- webhook.deliver:base=backoff、factor=2、无抖动、不封顶(原 delay*=2 等价);\n- saga 补偿重试:base=compRetryDelay、factor=2、无抖动(原 delay<<(attempt-1) 等价);\n- grpcclient 失败换节点:base=retryDelay、factor=2、±25% 比例抖动\n  (原 base*2^i ± base/4 等价)。\n\n为精确保留 grpcclient 的 ±25% 语义,给 pkg/backoff 新增 JitterProportional\n抖动模式(WithJitterRatio,默认 0.25),补充边界测试。三处调用点对外 API\n与时序行为均不变,各自测试全绿。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: webhook/saga/grpcclient 复用 pkg/backoff 统一退避",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T13:31:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "66f4862ef1da7070019357b044961e5a24f4b608",
          "body": "- backoff: 指数退避 + 抖动(Full/Equal/None,对齐 AWS jitter),Duration(n) 计算\n  退避序列、Retry/RetryIf 包住可重试操作(ctx 取消即停、支持不可重试判定)。\n  收敛 webhook/grpcclient/saga 各自手写的 \"delay*=2+jitter\"(本次仅新增独立包,\n  不改现有调用点,迁移另行进行)。\n- eventbus: 泛型进程内事件总线,按 topic 订阅 + 回调分发,同步/异步(WithAsync)\n  可选,panic 经 pkg/safe 恢复。与 stream(channel 单源扇\n[…]\n + Haversine 距离。\n  前缀相邻性让\"附近的人\"退化为字符串前缀检索,可直接落库/Redis。与 spatial\n  (平面网格)互补,面向真实地球坐标的 LBS。\n\n各包含 -race 测试与可运行 example。README 原语表补 3 行、组件计数 41→44。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: 新增 backoff / eventbus / geohash 三个原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T12:12:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6b6fcfd433d4142a2ad3246d38aefb63c33c4f42",
          "body": "补齐并发控制与直播/游戏空间维度的常用件,均纯标准库 + 泛型 + 函数式 Option:\n\n- keyedmutex: 按 key 的细粒度锁,同 key 串行、不同 key 并行,引用计数归零自动\n  回收 entry(不随 key 增长泄漏)。Lock 返回 unlock 闭包(sync.Once 防 double-unlock)。\n  同账户/房间/订单串行,替代\"一把大锁锁全表\"。与 idempotency(同 key 只执行一次)区分。\n- momentum: 连击 + 热度时间衰减。连击窗口内递增、断连重置(保留 maxCombo);\n  热度按半衰期指数惰性衰减(读时结算,无后\n[…]\n: 网格空间索引,实体分桶,Nearby(范围查询)/ KNN(最近 N 个)只扫描\n  近邻单元 + 精确距离过滤,避免全表遍历。附近的人 / MMO AOI / 大地图分区。\n\n各包含 -race 测试与可运行 example。README 原语表补 3 行、组件计数 38→41。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: 新增 keyedmutex / momentum / spatial 三个原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T11:37:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8bcf29f13e11e6e75fdc413625095ccde0f87af3",
          "body": "面向直播/游戏场景补齐常用原语,均纯标准库 + 泛型 + 函数式 Option:\n\n- counter: 按 key 的滑动窗口计数与时间窗配额(环形桶 + 分片锁)。与 ratelimit\n  互补——ratelimit 控速率,counter 控\"窗口内总量\"(每日抽卡上限/分钟弹幕限频/防刷)。\n- tally: 高频累计聚合 + 批量刷写。海量小额 +1 在内存合并,定时/攒够阈值一次性\n  flush,削平写放大。直播点赞/刷礼物量级(与 wallet 逐笔账本互补)。\n- versus: 限时多方对抗计分(直播 PK)。组合复用 fsm(状态机)+ stream(事件广播)\n  +\n[…]\n网格 A* 寻路,支持障碍/移动代价/对角(含禁止穿墙角),octile 启发\n  保证最优。纯计算,同一 Grid 可并发 FindPath。塔防/SLG/点击移动/怪物追击。\n\n各包含 -race 测试与可运行 example。README 原语表补 4 行、组件计数 34→38。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: 新增 counter / tally / versus / pathfind 四个直播&游戏原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T07:16:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d2384b16536c7167e8918cfed1a45deb89b9072",
          "body": "明确纯内存版的崩溃恢复模型:依赖可重投触发源(MQ at-least-once)+ 幂等\nAction/Compensate,协调器崩溃后消息重投、saga 从头重跑即恢复。强调幂等键\n须来自触发消息、跨重投稳定,不可用 idgen/uuid 现场生成(否则每次重投键不同、\n幂等失效致重复扣款)。触发源不可重投的场景需外部持久化,本包不覆盖。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(saga): 补充崩溃恢复说明与幂等键约束",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T06:47:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c58b6b9af8e8fe2653e5a5889325d59d4f6770b0",
          "body": "补齐游戏/社交实时框架的几个常用空档,均纯标准库 + 泛型 + 函数式 Option:\n\n- delayqueue: 定点单次延迟触发(最小堆 + 单 goroutine 驱动),Schedule/Cancel/\n  改期。填 scheduler(即时)与 cron(周期)之间缺的一次性触发:开局倒计时/\n  buff 到期/订单超时/匹配兜底。回调经 pkg/safe 恢复 panic。\n- fsm: 泛型有限状态机 FSM[S,E] + 链式 Builder,声明式转移表,非法转移报错而非\n  静默改状态,OnLeave/OnTransition/OnEnter 钩子(可否决)。对局/房间\n[…]\nion_failed)。补偿用 WithoutCancel 不受原 ctx\n  取消影响。MVP 纯内存(不持久化/无隔离性,doc 已标注),与 txn(同进程 2PC)互补。\n\n各包含 -race 测试与可运行 example。README 原语表补 6 行、组件计数 29→34。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: 新增 delayqueue / fsm / idgen / saga 四个原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T06:16:32Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "774c7ca22a6178d4212184029ffcc743cfbb3e18",
          "body": "新增 pkg/idempotency:泛型 Store[T],去重(同 key 复用首次结果)+ singleflight\n(并发同 key 只执行一次、其余共享结果)两语义合一,TTL 过期、可选缓存错误、\npanic 可重试。解决网络重试/客户端重发导致的重复扣款、重复发奖。\n\nwallet 新增 ApplyTx(txID, ...):同 txID 重复调用只应用一次,后续返回首次结果\n且余额不再变动;首次失败不记录 txID,允许重试。不动老 Apply,内建 append-only\ntxIndex 保持 wallet 无后台 goroutine 的自包含契约。\n\n含 -race 测试(并发单飞、TTL、panic 重试;wallet 并发同 txID 只扣一次)与\nexample。二者天然咬合:正向 ApplyTx(txID) + 补偿 ApplyTx(refundID) 可安全重试。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(idempotency): 幂等执行原语 + wallet.ApplyTx txID 幂等",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T06:15:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6a480f2a7aef0b607ae7ede8d49eb7915c2a4570",
          "body": "连续错误达 errThreshold 后,Acquire 直接拒绝且不创建 Token、不加 inFlight,\n但 consecutiveErrors 只在 OnResponse 里清零——被拒的请求永远不会触发\nOnResponse,导致计数冻结在阈值、节点永久拒绝、无法恢复(不重启/不 Reset)。\n兄弟包 circuitbreaker 有 Open→HalfOpen 冷却探测,本包这条路径却是死路。\n\n参照熔断器加错误锁定态的冷却探测:每隔 errRecovInterval(默认 5s,可用\nWithErrorRecoveryInterval 配)放行一个探测,探测成功清零解锁、失败续锁一轮;\nerrProbeInflight 保证并发只放一个探测。补 3 个恢复语义回归测试。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(overloadctrl): 错误锁定态加冷却探测,消除节点永久锁死",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T06:13:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5438cda56d83e42854c7e4a8e1988573c20ee79e",
          "body": "RoundRobin 无锁,但包注释与服务发现客户端用法都假设它并发安全:\nselectService 在 t.mu 锁外调 Next() 读 r.nodes,而 Watch 回调经\nrebuildBalancers 调 Update() 替换 r.nodes(slice header 写),二者并发\n即 data race——轻则读到错乱 slice,重则 nodes[idx%len] 越界 panic。\n兄弟原语 WeightedRoundRobin 本就有 Mutex,RoundRobin 漏了。\n\n加 sync.RWMutex:Update 写锁替换、Next/Nodes 读锁取快照,读路径仍基本\n无锁保留高吞吐。新增 Update/Next 并发回归测试(-race 下能稳定复现原竞争)。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(loadbalance): RoundRobin 加锁消除 Update/Next 数据竞争",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-07-02T06:13:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d519dd9c849e94455c74d664f57bc69e06066824",
          "body": "借鉴 trpc-go naming/{circuitbreaker,servicerouter,bannednodes} + overloadctrl\n的接口形态,落地到 pkg/governance 下四个子包,接入 grpcclient 与 http transport\n的 selectService,补齐客户端服务治理的\"节点级\"维度。\n\n- bannednodes: 单次请求内节点禁用(ctx 传递),重试链内失败节点不重复选\n- circuitbreaker: 节点级熔断(Available/Report 分离,三态机,per-node)\n- router: 服务发现与负载均衡之间的\n[…]\n router→banned→Available 过滤,\nCall/RoundTrip 失败自动 Ban + Report。修了 RR/WRR 选节点 maxAttempts 用候选集\n长度导致漏选的 bug(改用全量长度)。另附 http-client-discovery 用法文档。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(governance): 节点级熔断/路由过滤/节点禁用 + 自适应限流原语",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-06-30T16:22:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0c2ddf46241a23adb4184e6fdb7ebb36ce1d9524",
          "body": "新增 pkg/client/http/discovery_transport.go:discoveryTransport 实现\nhttp.RoundTripper,把\"服务名 + 相对路径\"透明路由到服务发现选出的实例——\n改写 req.URL.Host/Scheme/Host(Clone 避免并发改写),转发给 base transport\n(otelhttp)。复用 pkg/loadbalance(RR/WRR)+ pkg/service/discover +\npkg/utils/selector。重试:5xx/网络错误触发,指数退避 ±25% jitter,\n可配换节点;body 优先用\n[…]\nient,差异:无 LeastConnections(HTTP 无\nconn 状态)、无 drainTimeout、5xx 重试 4xx 不重试、URL 拼接(scheme 从\nMetadata 读)。15 个测试全过(含 -race),example 验证 WRR 1:2:3 分布。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(http-client): 服务发现 HTTP 客户端(RoundTripper 实现 + 薄包装层)",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-06-30T13:44:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5e78325c03bbb32edaa342f90e8768c76ee6b3cf",
          "body": "pkg/loadbalance 新增三个纯算法原语,不绑 RPC/服务发现:\n- ConsistentHash:虚拟节点 + maphash + sort.Search 二分,按 key 稳定路由,\n  支持权重放大与 GetReplicas 主+副本(会话粘性 / 有状态分片)\n- WeightedRoundRobin:nginx 平滑加权轮询(current+=weight; 选 max; selected-=total),\n  避免低权重节点连续命中;新增 Update 支持服务列表变化重建\n- RoundRobin:atomic 游标无锁轮询\n\ngrpcclient 解耦:RR/WRR\n[…]\nnce(修掉原\"名 SWRR 实配额式\"实现,\n修掉服务列表长度不变但内容变化不重建的 bug),LeastConnections 因依赖 grpc conn 状态保留。\n新增 serviceNode adapter 从 Metadata[\"weight\"] 解析权重(默认 100)。\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(loadbalance): 负载均衡算法原语(一致性哈希 + SWRR + 轮询)+ grpcclient 复用解耦",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-06-30T06:50:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e7a63acb20379b233abb64a58adb42f1191a9c36",
          "body": "解决\"提交后副作用\"竞态:在 body 里直接发通知/webhook,若事务回滚,\n通知却已发出。OnCommit 把这类副作用推迟到全部 Participant Commit 成功后。\n\n- OnCommit(fn) 注册钩子(可在 Run 前或 body 内注册)\n- 全部 Commit 成功后,safe.Go 异步执行(WithoutCancel ctx,注册顺序)\n- 任一 Prepare/body/Commit 失败则清空不执行,失败不残留\n- 钩子 panic 被恢复,不影响 Run 返回值\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(txn): OnCommit 钩子——提交成功后异步触发副作用",
          "author_name": "mlboy",
          "author_login": "mlboy",
          "committed_at": "2026-06-29T11:45:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 2,
      "commits_last_year": 191,
      "latest_release_at": "2026-07-20T17:04:18Z",
      "latest_release_tag": "v0.2.0",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 10,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 1.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/rushteam/beauty",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/rushteam/beauty",
          "is_deprecated": false,
          "latest_version": "v0.2.0",
          "repository_url": "https://github.com/rushteam/beauty",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T17:04:18Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 5,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2024-04-12",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "example",
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "examples/complete/example/api/service.proto",
        "examples/protobuf-example/api/service.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "contrib/casbin/go.mod",
        "contrib/elasticsearch/go.mod",
        "contrib/gorm/go.mod",
        "contrib/kafka/go.mod",
        "contrib/llm/go.mod",
        "contrib/mcp/go.mod",
        "contrib/mcpagent/go.mod",
        "contrib/nats/go.mod",
        "contrib/natsjs/go.mod",
        "contrib/openfga/go.mod",
        "contrib/sqldb/go.mod",
        "contrib/vector/go.mod",
        "contrib/wasm/go.mod",
        "contrib/wasmagent/go.mod",
        "contrib/wasmopa/go.mod",
        "examples/agentservice/go.mod",
        "go.mod",
        "tools/go.mod"
      ],
      "largest_source_bytes": 32687,
      "source_files_sampled": 553,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "tools/go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.81.1",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 1,
            "oldest_advisory_days": 4
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.51.0",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 10,
            "advisory_ids": [
              "GHSA-45gg-vh54-h5m9",
              "GHSA-5cgq-3rg8-m6cv",
              "GHSA-78mq-xcr3-xm33",
              "GHSA-89gr-r52h-f8rx",
              "GHSA-9m57-25v3-79x9",
              "GHSA-f5wc-c3c7-36mc",
              "GHSA-jppx-rxg9-jmrx",
              "GHSA-q4h4-gmj2-qvw2",
              "GHSA-qpw4-5x99-6vjp",
              "GHSA-rm3j-f69w-wqmq"
            ],
            "fixed_version": "0.52.0",
            "advisory_count": 27,
            "oldest_advisory_days": 65
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.7.0",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-4f99-4q7p-p3gh",
              "GO-2025-4188"
            ],
            "fixed_version": "1.9.3",
            "advisory_count": 2,
            "oldest_advisory_days": 233
          },
          {
            "name": "filippo.io/edwards25519",
            "direct": false,
            "version": "v1.1.0",
            "severity": "low",
            "ecosystem": "go",
            "cvss_score": 3.7,
            "advisory_ids": [
              "GHSA-fw7p-63qq-7hpr",
              "GO-2026-4503"
            ],
            "fixed_version": "1.1.1",
            "advisory_count": 2,
            "oldest_advisory_days": 158
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 18
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5942"
            ],
            "fixed_version": "0.56.0",
            "advisory_count": 1,
            "oldest_advisory_days": 11
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.31.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5024"
            ],
            "fixed_version": "0.44.0",
            "advisory_count": 1,
            "oldest_advisory_days": 64
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.41.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5024"
            ],
            "fixed_version": "0.44.0",
            "advisory_count": 1,
            "oldest_advisory_days": 64
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.7.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5024"
            ],
            "fixed_version": "0.44.0",
            "advisory_count": 1,
            "oldest_advisory_days": 64
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 1,
          "high": 1,
          "unknown": 5,
          "critical": 2
        },
        "advisory_count": 37,
        "affected_count": 9,
        "assessed_count": 264,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/bluenviron/gohlslib/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.4.0"
        },
        {
          "name": "github.com/bluenviron/mediacommon/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.9.1"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/hashicorp/consul/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.34.3"
        },
        {
          "name": "github.com/pion/interceptor",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.45"
        },
        {
          "name": "github.com/pion/rtp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.4"
        },
        {
          "name": "github.com/pion/webrtc/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.2.17"
        },
        {
          "name": "github.com/polarismesh/polaris-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.0"
        },
        {
          "name": "github.com/quic-go/quic-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.60.0"
        },
        {
          "name": "github.com/redis/go-redis/extra/redisotel/v9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.21.0"
        },
        {
          "name": "github.com/redis/go-redis/v9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.21.0"
        },
        {
          "name": "github.com/spf13/viper",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.20.1"
        },
        {
          "name": "github.com/yutopp/go-rtmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.7"
        },
        {
          "name": "go.etcd.io/etcd/client/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.6.2"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.34.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.81.1"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "github.com/dubonzi/otelresty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.0"
        },
        {
          "name": "github.com/go-resty/resty/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.16.5"
        },
        {
          "name": "github.com/gofrs/uuid/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.2"
        },
        {
          "name": "github.com/gorilla/schema",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.1"
        },
        {
          "name": "github.com/grpc-ecosystem/go-grpc-middleware",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.29.0"
        },
        {
          "name": "github.com/nacos-group/nacos-sdk-go/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.3.3"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.59.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/prometheus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.56.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/stdout/stdoutmetric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.34.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "golang.org/x/time",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.14.0"
        },
        {
          "name": "google.golang.org/genproto/googleapis/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260526163538-3dc84a4a5aaa"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "github.com/gobuffalo/here",
          "manifest": "tools/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.7"
        },
        {
          "name": "github.com/urfave/cli/v3",
          "manifest": "tools/go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.4.1"
        },
        {
          "name": "google.golang.org/genproto/googleapis/api",
          "manifest": "tools/go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250826171959-ef028d996bc1"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "tools/go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.8"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/bluenviron/gohlslib/v2",
            "direct": true,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bluenviron/mediacommon/v2",
            "direct": true,
            "version": "v2.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coder/websocket",
            "direct": true,
            "version": "v1.8.14",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dubonzi/otelresty",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": true,
            "version": "v1.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": true,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-resty/resty/v2",
            "direct": true,
            "version": "v2.16.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobuffalo/here",
            "direct": true,
            "version": "v0.6.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gofrs/uuid/v5",
            "direct": true,
            "version": "v5.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/schema",
            "direct": true,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/go-grpc-middleware",
            "direct": true,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": true,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/consul/api",
            "direct": true,
            "version": "v1.34.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nacos-group/nacos-sdk-go/v2",
            "direct": true,
            "version": "v2.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/interceptor",
            "direct": true,
            "version": "v0.1.45",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/rtp",
            "direct": true,
            "version": "v1.10.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/webrtc/v4",
            "direct": true,
            "version": "v4.2.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/polarismesh/polaris-go",
            "direct": true,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/quic-go/quic-go",
            "direct": true,
            "version": "v0.60.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/extra/redisotel/v9",
            "direct": true,
            "version": "v9.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/v9",
            "direct": true,
            "version": "v9.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/robfig/cron/v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/viper",
            "direct": true,
            "version": "v1.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/urfave/cli/v3",
            "direct": true,
            "version": "v3.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yutopp/go-rtmp",
            "direct": true,
            "version": "v0.0.7",
            "ecosystem": "go"
          },
          {
            "name": "go.etcd.io/etcd/client/v3",
            "direct": true,
            "version": "v3.6.2",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
            "direct": true,
            "version": "v0.59.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.29.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.30.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": true,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdoutmetric",
            "direct": true,
            "version": "v1.34.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": true,
            "version": "v1.34.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.29.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.30.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.29.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.30.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": true,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": true,
            "version": "v0.14.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": true,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": true,
            "version": "v0.0.0-20250826171959-ef028d996bc1",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": true,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.81.1",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.8",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.34.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.34.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.34.0",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.1",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/compute/metadata",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "filippo.io/edwards25519",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/abema/go-mp4",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/alibabacloud-gateway-pop",
            "direct": false,
            "version": "v0.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/alibabacloud-gateway-spi",
            "direct": false,
            "version": "v0.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-array",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-encode-util",
            "direct": false,
            "version": "v0.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-map",
            "direct": false,
            "version": "v0.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-openapi/v2",
            "direct": false,
            "version": "v2.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-signature-util",
            "direct": false,
            "version": "v0.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/darabonba-string",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/debug",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/endpoint-util",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/kms-20160120/v3",
            "direct": false,
            "version": "v3.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/openapi-util",
            "direct": false,
            "version": "v0.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea-utils/v2",
            "direct": false,
            "version": "v2.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alibabacloud-go/tea-xml",
            "direct": false,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/alibaba-cloud-sdk-go",
            "direct": false,
            "version": "v1.63.84",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/alibabacloud-dkms-gcs-go-sdk",
            "direct": false,
            "version": "v0.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/alibabacloud-dkms-transfer-go-sdk",
            "direct": false,
            "version": "v0.1.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/aliyun-secretsmanager-client-go",
            "direct": false,
            "version": "v1.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aliyun/credentials-go",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antithesishq/antithesis-sdk-go",
            "direct": false,
            "version": "v0.7.0-default-no-op",
            "ecosystem": "go"
          },
          {
            "name": "github.com/armon/go-metrics",
            "direct": false,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/asticode/go-astikit",
            "direct": false,
            "version": "v0.30.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/asticode/go-astits",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bmatcuk/doublestar/v4",
            "direct": false,
            "version": "v4.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/buger/jsonparser",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/casbin/casbin/v2",
            "direct": false,
            "version": "v2.135.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/casbin/govaluate",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clbanning/mxj/v2",
            "direct": false,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cncf/xds/go",
            "direct": false,
            "version": "v0.0.0-20260202195803-dba9d589def2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-semver",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-systemd/v22",
            "direct": false,
            "version": "v22.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/deckarep/golang-set",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dlclark/regexp2",
            "direct": false,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/elastic/elastic-transport-go/v8",
            "direct": false,
            "version": "v8.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/elastic/go-elasticsearch/v8",
            "direct": false,
            "version": "v8.19.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.12.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/envoyproxy/go-control-plane/envoy",
            "direct": false,
            "version": "v1.37.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/envoyproxy/protoc-gen-validate",
            "direct": false,
            "version": "v1.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fatih/color",
            "direct": false,
            "version": "v1.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/glebarez/go-sqlite",
            "direct": false,
            "version": "v1.21.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/glebarez/sqlite",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": false,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.20.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-sql-driver/mysql",
            "direct": false,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gogo/protobuf",
            "direct": false,
            "version": "v1.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/mock",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/protobuf",
            "direct": false,
            "version": "v1.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-tpm",
            "direct": false,
            "version": "v0.9.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/jsonschema-go",
            "direct": false,
            "version": "v0.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/errwrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-cleanhttp",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-hclog",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-immutable-radix",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-multierror",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-rootcerts",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/golang-lru",
            "direct": false,
            "version": "v0.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/serf",
            "direct": false,
            "version": "v0.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/inflection",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/now",
            "direct": false,
            "version": "v1.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jmespath/go-jmespath",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.17.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.7.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": false,
            "version": "v0.1.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/minio/highwayhash",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/go-homedir",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modelcontextprotocol/go-sdk",
            "direct": false,
            "version": "v1.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/natefinch/lumberjack",
            "direct": false,
            "version": "v2.0.0+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/jwt/v2",
            "direct": false,
            "version": "v2.8.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nats-server/v2",
            "direct": false,
            "version": "v2.14.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nats.go",
            "direct": false,
            "version": "v1.52.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nkeys",
            "direct": false,
            "version": "v0.4.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nuid",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openfga/go-sdk",
            "direct": false,
            "version": "v0.8.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opentracing/opentracing-go",
            "direct": false,
            "version": "v1.2.1-0.20220228012449-10b1cf09e00b",
            "ecosystem": "go"
          },
          {
            "name": "github.com/orcaman/concurrent-map",
            "direct": false,
            "version": "v0.0.0-20210501183033-44dafcb38ecc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml/v2",
            "direct": false,
            "version": "v2.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pierrec/lz4/v4",
            "direct": false,
            "version": "v4.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/datachannel",
            "direct": false,
            "version": "v1.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/dtls/v3",
            "direct": false,
            "version": "v3.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/ice/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/logging",
            "direct": false,
            "version": "v0.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/mdns/v2",
            "direct": false,
            "version": "v2.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/randutil",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/rtcp",
            "direct": false,
            "version": "v1.2.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/sctp",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/sdp/v3",
            "direct": false,
            "version": "v3.0.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/srtp/v3",
            "direct": false,
            "version": "v3.0.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/stun/v3",
            "direct": false,
            "version": "v3.1.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/transport/v4",
            "direct": false,
            "version": "v4.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pion/turn/v5",
            "direct": false,
            "version": "v5.0.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/planetscale/vtprotobuf",
            "direct": false,
            "version": "v0.6.1-0.20240319094008-0393e58bdf10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/polarismesh/specification",
            "direct": false,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.20.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.62.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.15.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/extra/rediscmd/v9",
            "direct": false,
            "version": "v9.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rushteam/beauty",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rushteam/beauty",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sagikazarmark/locafero",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/segmentio/asm",
            "direct": false,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/segmentio/encoding",
            "direct": false,
            "version": "v0.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/segmentio/kafka-go",
            "direct": false,
            "version": "v0.4.51",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sourcegraph/conc",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spaolacci/murmur3",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/afero",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.9.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spiffe/go-spiffe/v2",
            "direct": false,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/subosito/gotenv",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tetratelabs/wazero",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tjfoc/gmsm",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uptrace/opentelemetry-go-extra/otelgorm",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uptrace/opentelemetry-go-extra/otelsql",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/wlynxg/anet",
            "direct": false,
            "version": "v0.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xsam/otelsql",
            "direct": false,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yosida95/uritemplate/v3",
            "direct": false,
            "version": "v3.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yutopp/go-amf0",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "go.etcd.io/etcd/api/v3",
            "direct": false,
            "version": "v3.6.2",
            "ecosystem": "go"
          },
          {
            "name": "go.etcd.io/etcd/client/pkg/v3",
            "direct": false,
            "version": "v3.6.2",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": false,
            "version": "v1.27.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.2",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.51.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260218203240-3dfff04db8fa",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.31.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.41.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.39.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.12.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/ini.v1",
            "direct": false,
            "version": "v1.67.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/natefinch/lumberjack.v2",
            "direct": false,
            "version": "v2.2.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/driver/mysql",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/gorm",
            "direct": false,
            "version": "v1.31.2",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/plugin/dbresolver",
            "direct": false,
            "version": "v1.6.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": false,
            "version": "v2.130.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20250710124328-f3f2b991d03b",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": false,
            "version": "v0.0.0-20250604170112-4c0f3b243397",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.22.5",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.74.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": false,
            "version": "v1.23.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": false,
            "version": "v1.54.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20241014173422-cfa47c3a1cc8",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 264,
        "direct_count": 59,
        "indirect_count": 205
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 19,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 1,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "mlboy",
          "commits": 417,
          "avatar_url": "https://avatars.githubusercontent.com/u/1733903?v=4"
        },
        {
          "type": "User",
          "login": "Thxzzzzz",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/22448000?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.979
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 5 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/9 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "19 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "70a6d3b2b4e9203dbba6087fe9c7bac965f87fd9",
        "ran_at": "2026-07-26T17:03:06Z",
        "aggregate_score": 4.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-26T16:25:57Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T16:25:22Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/rushteam/beauty",
    "host": "github.com",
    "name": "beauty",
    "owner": "rushteam"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 57,
      "inputs": {
        "security": 50,
        "vitality": 78,
        "community": 29,
        "governance": 56,
        "engineering": 65
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 78,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "commits_last_year": 191,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 10
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "10/52 weeks with commits",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "191 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 191
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v0.2.0",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 1.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 29,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 1,
              "stars": 5,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 12,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.979
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 98% of commits",
                "points": 0.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 98
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 83,
            "inputs": {
              "merged_prs": 19,
              "open_issues": 0,
              "closed_issues": 1,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "19/20 decided PRs merged",
                "points": 36.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 19,
                      "decided": 20
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/9 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "rushteam",
              "public_repos": 18,
              "account_age_days": 2745
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of rushteam",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "rushteam"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "18 public repos, account ~7 yr old",
                "points": 21.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 18
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "github.com/rushteam/beauty"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "2 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 65,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 5 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "framework",
                "game",
                "golang",
                "grpc",
                "live",
                "microservice",
                "webrtc",
                "websocket"
              ],
              "has_wiki": false,
              "homepage": "go microservice framework grpc websocket webrtc",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "go microservice framework grpc websocket webrtc",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 50,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 46,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 5 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/9 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "19 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 264 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 264
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "source": "osv",
              "advisories": 37,
              "affected_packages": 9,
              "assessed_packages": 264,
              "unassessed_packages": 0,
              "affected_by_severity": "critical 2, high 1, low 1, unknown 5",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: google.golang.org/grpc v1.81.1 (critical 9.1)",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "google.golang.org/grpc v1.81.1 (critical 9.1)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 264,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 65,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.9,
              "toolchain_manifests": [
                "contrib/casbin/go.mod",
                "contrib/elasticsearch/go.mod",
                "contrib/gorm/go.mod",
                "contrib/kafka/go.mod",
                "contrib/llm/go.mod",
                "contrib/mcp/go.mod",
                "contrib/mcpagent/go.mod",
                "contrib/nats/go.mod",
                "contrib/natsjs/go.mod",
                "contrib/openfga/go.mod",
                "contrib/sqldb/go.mod",
                "contrib/vector/go.mod",
                "contrib/wasm/go.mod",
                "contrib/wasmagent/go.mod",
                "contrib/wasmopa/go.mod",
                "examples/agentservice/go.mod",
                "go.mod",
                "tools/go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "contrib/casbin/go.mod, contrib/elasticsearch/go.mod, contrib/gorm/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "contrib/casbin/go.mod, contrib/elasticsearch/go.mod, contrib/gorm/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "90 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 90,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 32687,
              "source_files_sampled": 553,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/553 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 553,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "example",
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "examples/complete/example/api/service.proto",
                "examples/protobuf-example/api/service.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "examples/complete/example/api/service.proto, examples/protobuf-example/api/service.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples/complete/example/api/service.proto, examples/protobuf-example/api/service.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "example, examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "example, examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T17:03:20.016142Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/rushteam/beauty.svg",
  "full_name": "rushteam/beauty",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.