Public record
Software health reportschema 0.26.0 · metrics 1.13.0 · 2026-07-22 02:12 UTC

tektoncd / pipelines-as-code

Pipelines-as-Code for Tekton

GoApache-2.0★ 203 stars⑂ 135 forkssince Apr 2021View on GitHub ↗

tektoncd/pipelines-as-code holds a health index of 79 out of 100, placing it in the Good band. It scores highest on Engineering Quality (96/100) and lowest on Security (62/100). It was last updated today. A single contributor accounts for most of its recent work.

79
overall / 100
Good

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

79
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

TektonOrganization
1,421 followers24 public repossince Feb 2019

This repository is backed by an organization — shared, accountable stewardship that can outlive any single maintainer.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/openshift-pipelines/pipelines-as-codepoints to another repo — not scoredv0.49.0-11315 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

95Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
35.3/36Commit cadence — 51/52 weeks with commits
18/18Commit volume — 575 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year575
human_commit_share0.9
days_since_last_push0
active_weeks_last_year51
How it's scored
27/27Ships releases — 100 releases published
36/36Release recency — latest release 4 days ago
27/27Release cadence — a release every ~5.8 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count100
latest_release_tagv0.48.1
releases_from_tagsno
days_since_latest_release4
mean_days_between_releases5.8

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

75Good · 18% of overall
How it's scored
37.4/60Stars — 203 stars
17.7/25Forks — 135 forks
5/15Watchers — 9 watchers
Inputs used
forks135
stars203
watchers9
growth_stateorganic
growth_factor_pct100

Community health

92Excellent
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
18/18CONTRIBUTING guide
13.5/13.5Code of conduct
0/7.2Issue template
6.3/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingyes
has_issue_templateno
has_code_of_conductyes
has_pull_request_templateyes

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

65Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
5/22.5Commit distribution — top contributor authored 78% of commits
13.5/13.5Contributor breadth — 59 contributors
10/10OpenSSF Scorecard: Contributors — project has 33 contributing companies or organizations
Inputs used
bus_factor1
contributors_sampled59
top_contributor_share0.776
How it's scored
41.1/46.8Issue resolution — 88% of issues closed
34/38.3PR acceptance — 2,014/2,266 decided PRs merged
12/15OpenSSF Scorecard: Code-Review — Found 17/20 approved changesets -- score normalized to 8
Inputs used
merged_prs2,014
open_issues70
closed_issues515
issue_closed_ratio0.88
closed_unmerged_prs252
How it's scored
30/30Ownership backing — organization-owned
0/20Verified domain
22.7/25Owner reach — 1,421 followers of tektoncd
22.2/25Track record — 24 public repos, account ~7 yr old
Inputs used
followers1,421
owner_typeOrganization
is_verified
owner_logintektoncd
public_repos24
account_age_days2,715

Engineering Quality

Are baseline engineering and documentation practices in place?

96Excellent · 20% of overall
How it's scored
24/24CI workflows — 3 workflow(s)
24/24Tests present
16/16Linter config — .golangci.yaml, .golangci.yml, .pylintrc
9.6/9.6Pre-commit hooks
6.4/6.4.editorconfig
14/20OpenSSF Scorecard: CI-Tests — 18 out of 24 merged PRs checked by a CI test -- score normalized to 7
Inputs used
has_ciyes
has_testsyes
has_editorconfigyes
has_linter_configyes
has_precommit_configyes

Documentation

100Excellent
How it's scored
30/30README
25/25Documentation directory
15/15Documentation / homepage site — https://pipelinesascode.com
10/10Repository description
10/10Topics — 11 topics
10/10Wiki
Inputs used
topicstekton-pipelines, tekton, github, pipeline, kubernetes, continuous-delivery, pipelines-as-code, gitlab, ci, bitbucket, gitops
has_wikiyes
homepagehttps://pipelinesascode.com
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

62Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
1.8/2.5CI-Tests — 18 out of 24 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
6/7.5Code-Review — Found 17/20 approved changesets -- score normalized to 8
2.5/2.5Contributors — project has 33 contributing companies or organizations
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — no data
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
6/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.7
Excluded from scoring (no data or not applicable): packaging. Remaining weights renormalized.
How it's scored
26.6/35Direct dependencies free of known advisories — 1 affected: github.com/tektoncd/pipeline v1.14.0 (unknown)
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
37.2/40No advisories left outstanding — 1 advisory-carrying package(s) unaddressed past 90 days; oldest published 700 days ago
Inputs used
sourceosv
advisories4
affected_packages3
assessed_packages156
unassessed_packages7
affected_by_severitycritical 1, unknown 2
direct_affected_packages1
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 156 resolved dependencies against OSV. 7 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

96Excellent · 0% of overall
How it's scored
45/45Agent instructions — AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md
15/15Machine-readable docs (llms.txt) — llms.txt present
40/40Legible commit history — 90 of 90 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtyes
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md
agent_instruction_max_bytes12,245
How it's scored
18/18One-command bootstrap — Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile
22/22Automated tests
11/11Lint / format config — .golangci.yaml, .golangci.yml, .pylintrc
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 26 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 10 of the last 100 commits are automated dependency updates
7/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_filesMakefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile
has_devcontainerno
has_linter_configyes
typecheck_configs
agent_commit_share0.26
toolchain_manifestsdocs/go.mod, go.mod
dependency_bot_commit_share0.1
How it's scored
45/45Type-checkable code — Go (statically typed)
54.7/55Manageable file sizes — 3/518 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes92,818
source_files_sampled518
oversized_source_files3
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto
0/20MCP server
40/40Runnable examples — samples
Inputs used
example_dirssamples
has_mcp_signalno
api_schema_filesvendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto

Key facts

203GitHub stars
59contributors
575commits, last 12 months
0days since last push
100releases
1bus factor
70open issues
Gopackage ecosystems

Data collection warnings

  • go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring

More detail

Star and fork history 203 ★ / 135 ⇿
203Stars
135Forks
100Releases

When each star and fork was added, collected from GitHub and bucketed by day. Cumulative growth sits directly above the daily additions it is made of, so the two read against each other: steady organic accretion looks nothing like an abrupt, short-lived burst. Where that difference is measurable, it is reported as growth authenticity.

0408012016020024020312962021-042023-112026-07
Major 0Minor 34Patch 66

Each point covers 5 days.

OpenSSF Scorecard 5.7 / 10
5.7aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-22 02:12 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
7CI-Tests18 out of 24 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
8Code-ReviewFound 17/20 approved changesets -- score normalized to 8
10Contributorsproject has 33 contributing companies or organizations
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
n/aPackagingpackaging workflow not detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
8Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
Direct dependencies 54
RegistryPackageVersion constraintManifest
Gocodeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3v3.0.0go.mod
Gogithub.com/AlecAivazis/survey/v2v2.3.7go.mod
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.18.0go.mod
Gogithub.com/chzyer/readlinev1.5.1go.mod
Gogithub.com/cloudevents/sdk-go/v2v2.16.2go.mod
Gogithub.com/fvbommel/sortorderv1.1.0go.mod
Gogithub.com/gobwas/globv0.2.3go.mod
Gogithub.com/google/cel-gov0.29.2go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-github/scrapev0.0.0-20260403152401-96a365122246go.mod
Gogithub.com/google/go-github/v84v84.0.0go.mod
Gogithub.com/google/go-github/v85v85.0.0go.mod
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16bgo.mod
Gogithub.com/jenkins-x/go-scmv1.15.31go.mod
Gogithub.com/jonboulle/clockworkv0.5.0go.mod
Gogithub.com/juju/ansitermv1.0.0go.mod
Gogithub.com/ktrysmt/go-bitbucketv0.10.0go.mod
Gogithub.com/mattn/go-colorablev0.1.15go.mod
Gogithub.com/mattn/go-isattyv0.0.23go.mod
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957dgo.mod
Gogithub.com/mitchellh/mapstructurev1.5.0go.mod
Gogithub.com/pkg/errorsv0.9.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tektoncd/pipelinev1.14.0go.mod
Gogitlab.com/gitlab-org/api/client-gov1.46.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogo.uber.org/zapv1.28.0go.mod
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/syncv0.22.0go.mod
Gogolang.org/x/textv0.40.0go.mod
Gogopkg.in/yaml.v2v2.4.0go.mod
Gogotest.tools/v3v3.5.2go.mod
Gok8s.io/apiv0.36.2go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gok8s.io/client-gov0.36.2go.mod
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5go.mod
Goknative.dev/eventingv0.49.2go.mod
Goknative.dev/pkgv0.0.0-20260622140654-39ebae2ee2dcgo.mod
Gosigs.k8s.io/yamlv1.6.0go.mod
Gogithub.com/golang-jwt/jwt/v4v4.5.2go.mod
Gogithub.com/prometheus/client_modelv0.6.2go.mod
Gogithub.com/prometheus/commonv0.69.0go.mod
Gogolang.org/x/termv0.45.0go.mod
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaago.mod
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afgo.mod
Gok8s.io/klog/v2v2.140.0go.mod
All dependencies 163

Full resolved dependency set from the GitHub dependency graph: 54 direct and 109 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gocodeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3v3.0.0direct
Gogithub.com/alecaivazis/survey/v2v2.3.7direct
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.18.0direct
Gogithub.com/chzyer/readlinev1.5.1direct
Gogithub.com/cloudevents/sdk-go/v2v2.16.2direct
Gogithub.com/fvbommel/sortorderv1.1.0direct
Gogithub.com/gobwas/globv0.2.3direct
Gogithub.com/golang-jwt/jwt/v4v4.5.2direct
Gogithub.com/google/cel-gov0.29.2direct
Gogithub.com/google/go-cmpv0.7.0direct
Gogithub.com/google/go-github/scrapev0.0.0-20260403152401-96a365122246direct
Gogithub.com/google/go-github/v84v84.0.0direct
Gogithub.com/google/go-github/v85v85.0.0direct
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16bdirect
Gogithub.com/jenkins-x/go-scmv1.15.31direct
Gogithub.com/jonboulle/clockworkv0.5.0direct
Gogithub.com/juju/ansitermv1.0.0direct
Gogithub.com/ktrysmt/go-bitbucketv0.10.0direct
Gogithub.com/mattn/go-colorablev0.1.15direct
Gogithub.com/mattn/go-isattyv0.0.23direct
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957ddirect
Gogithub.com/mitchellh/mapstructurev1.5.0direct
Gogithub.com/pkg/errorsv0.9.1direct
Gogithub.com/prometheus/client_modelv0.6.2direct
Gogithub.com/prometheus/commonv0.69.0direct
Gogithub.com/spf13/cobrav1.10.2direct
Gogithub.com/stretchr/testifyv1.11.1direct
Gogithub.com/tektoncd/pipelinev1.14.0direct
Gogitlab.com/gitlab-org/api/client-gov1.46.0direct
Gogo.opentelemetry.io/otelv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0direct
Gogo.opentelemetry.io/otel/metricv1.44.0direct
Gogo.opentelemetry.io/otel/sdkv1.44.0direct
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0direct
Gogo.opentelemetry.io/otel/tracev1.44.0direct
Gogo.uber.org/zapv1.28.0direct
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90direct
Gogolang.org/x/oauth2v0.36.0direct
Gogolang.org/x/syncv0.22.0direct
Gogolang.org/x/termv0.45.0direct
Gogolang.org/x/textv0.40.0direct
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaadirect
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afdirect
Gogopkg.in/yaml.v2v2.4.0direct
Gogotest.tools/v3v3.5.2direct
Gok8s.io/apiv0.36.2direct
Gok8s.io/apimachineryv0.36.2direct
Gok8s.io/client-gov0.36.2direct
Gok8s.io/klog/v2v2.140.0direct
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5direct
Goknative.dev/eventingv0.49.2direct
Goknative.dev/pkgv0.0.0-20260622140654-39ebae2ee2dcdirect
Gosigs.k8s.io/yamlv1.6.0direct
Gocel.dev/exprv0.25.1indirect
Gogithub.com/42wim/httpsigv1.2.4indirect
Gogithub.com/andybalholm/cascadiav1.3.3indirect
Gogithub.com/antlr/antlr4/runtime/go/antlrv1.4.10indirect
Gogithub.com/antlr4-go/antlr/v4v4.13.1indirect
Gogithub.com/beorn7/perksv1.0.1indirect
Gogithub.com/blang/semver/v4v4.0.0indirect
Gogithub.com/blendle/zapdriverv1.3.1indirect
Gogithub.com/cenkalti/backoff/v5v5.0.3indirect
Gogithub.com/cert-manager/cert-managerv1.20.1indirect
Gogithub.com/cespare/xxhash/v2v2.3.0indirect
Gogithub.com/cloudevents/sdk-go/observability/opentelemetry/v2v2.16.2indirect
Gogithub.com/cloudevents/sdk-go/sql/v2v2.16.2indirect
Gogithub.com/coreos/go-oidc/v3v3.18.0indirect
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33ccindirect
Gogithub.com/davidmz/go-pageantv1.0.2indirect
Gogithub.com/emicklei/go-restful/v3v3.13.0indirect
Gogithub.com/evanphx/json-patch/v5v5.9.11indirect
Gogithub.com/felixge/httpsnoopv1.0.4indirect
Gogithub.com/fxamacker/cbor/v2v2.9.1indirect
Gogithub.com/go-fed/httpsigv1.1.1-0.20201223112313-55836744818eindirect
Gogithub.com/go-jose/go-jose/v3v3.0.5indirect
Gogithub.com/go-jose/go-jose/v4v4.1.4indirect
Gogithub.com/go-logr/logrv1.4.3indirect
Gogithub.com/go-logr/stdrv1.2.2indirect
Gogithub.com/go-logr/zaprv1.3.0indirect
Gogithub.com/go-openapi/errorsv0.22.7indirect
Gogithub.com/go-openapi/jsonpointerv0.22.5indirect
Gogithub.com/go-openapi/jsonreferencev0.21.5indirect
Gogithub.com/go-openapi/strfmtv0.26.1indirect
Gogithub.com/go-openapi/swagv0.25.5indirect
Gogithub.com/go-openapi/swag/cmdutilsv0.25.5indirect
Gogithub.com/go-openapi/swag/convv0.25.5indirect
Gogithub.com/go-openapi/swag/fileutilsv0.25.5indirect
Gogithub.com/go-openapi/swag/jsonnamev0.25.5indirect
Gogithub.com/go-openapi/swag/jsonutilsv0.25.5indirect
Gogithub.com/go-openapi/swag/loadingv0.25.5indirect
Gogithub.com/go-openapi/swag/manglingv0.25.5indirect
Gogithub.com/go-openapi/swag/netutilsv0.25.5indirect
Gogithub.com/go-openapi/swag/stringutilsv0.25.5indirect
Gogithub.com/go-openapi/swag/typeutilsv0.25.5indirect
Gogithub.com/go-openapi/swag/yamlutilsv0.25.5indirect
Gogithub.com/go-viper/mapstructure/v2v2.5.0indirect
Gogithub.com/google/gnostic-modelsv0.7.1indirect
Gogithub.com/google/go-querystringv1.2.0indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0indirect
Gogithub.com/hashicorp/go-cleanhttpv0.5.2indirect
Gogithub.com/hashicorp/go-retryablehttpv0.7.8indirect
Gogithub.com/hashicorp/go-versionv1.9.0indirect
Gogithub.com/hashicorp/golang-lruv1.0.2indirect
Gogithub.com/imfing/hextrav0.12.0indirect
Gogithub.com/inconshreveable/mousetrapv1.1.0indirect
Gogithub.com/json-iterator/gov1.1.12indirect
Gogithub.com/kballard/go-shellquotev0.0.0-20180428030007-95032a82bc51indirect
Gogithub.com/kelseyhightower/envconfigv1.4.0indirect
Gogithub.com/lunixbochs/vtcleanv1.0.0indirect
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1ddindirect
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31eeindirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/oklog/ulid/v2v2.1.1indirect
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2indirect
Gogithub.com/prometheus/client_golangv1.23.2indirect
Gogithub.com/prometheus/otlptranslatorv1.0.0indirect
Gogithub.com/prometheus/procfsv0.20.1indirect
Gogithub.com/puerkitobio/goqueryv1.12.0indirect
Gogithub.com/rickb777/datev1.22.0indirect
Gogithub.com/rickb777/pluralv1.4.10indirect
Gogithub.com/robfig/cron/v3v3.0.1indirect
Gogithub.com/spf13/pflagv1.0.10indirect
Gogithub.com/x448/float16v0.8.4indirect
Gogithub.com/xlzd/gotpv0.1.0indirect
Gogo.opentelemetry.io/auto/sdkv1.2.1indirect
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0indirect
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0indirect
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0indirect
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0indirect
Gogo.opentelemetry.io/proto/otlpv1.10.0indirect
Gogo.uber.org/atomicv1.11.0indirect
Gogo.uber.org/automaxprocsv1.6.0indirect
Gogo.uber.org/multierrv1.11.0indirect
Gogo.yaml.in/yaml/v2v2.4.4indirect
Gogo.yaml.in/yaml/v3v3.0.4indirect
Gogolang.org/x/cryptov0.53.0indirect
Gogolang.org/x/netv0.56.0indirect
Gogolang.org/x/sysv0.47.0indirect
Gogolang.org/x/timev0.15.0indirect
Gogomodules.xyz/jsonpatch/v2v2.5.0indirect
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260526163538-3dc84a4a5aaaindirect
Gogoogle.golang.org/grpcv1.81.1indirect
Gogopkg.in/evanphx/json-patch.v4v4.13.0indirect
Gogopkg.in/inf.v0v0.9.1indirect
Gogopkg.in/yaml.v3v3.0.1indirect
Gok8s.io/apiextensions-apiserverv0.36.2indirect
Gok8s.io/kube-openapiv0.0.0-20260330154417-16be699c7b31indirect
Gosigs.k8s.io/gateway-apiv1.5.1indirect
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730indirect
Gosigs.k8s.io/randfillv1.0.0indirect
Gosigs.k8s.io/structured-merge-diff/v6v6.3.2indirect
npm@axe-core/playwright^4.10.1indirect
npm@playwright/test^1.49.1indirect
npm@tailwindcss/postcss^4.1.18indirect
npmpostcss-cli^11.0.1indirect
npmprettier^3.8.0indirect
npmprettier-plugin-go-template^0.0.15indirect
npmtailwindcss^4.1.18indirect
Dependency advisories 3

This repository publishes no package the index resolves, so its own dependency graph was assessed — 156 packages, which also include development and test pins that never ship: 3 carry known advisories, of which 1 are direct. 7 could not be assessed — no resolved version, an unsupported ecosystem, or beyond the reported package list.

PackageVersionRelationSeverityAdvisoriesFixed in
google.golang.org/grpcv1.81.1indirectcritical11.82.1
github.com/tektoncd/pipelinev1.14.0directunknown2
golang.org/x/cryptov0.53.0indirectunknown1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [
        "tekton-pipelines",
        "tekton",
        "github",
        "pipeline",
        "kubernetes",
        "continuous-delivery",
        "pipelines-as-code",
        "gitlab",
        "ci",
        "bitbucket",
        "gitops"
      ],
      "is_fork": false,
      "size_kb": 78996,
      "has_wiki": true,
      "homepage": "https://pipelinesascode.com",
      "languages": {
        "Go": 3487952,
        "Shell": 88231,
        "Python": 31194,
        "Makefile": 9406,
        "Go Template": 11587
      },
      "pushed_at": "2026-07-21T10:21:44Z",
      "created_at": "2021-04-06T13:26:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T10:21:49Z",
      "description": "Pipelines-as-Code for Tekton",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://tekton.dev",
      "name": "Tekton",
      "type": "Organization",
      "login": "tektoncd",
      "company": null,
      "location": null,
      "followers": 1421,
      "avatar_url": "https://avatars.githubusercontent.com/u/47602533?v=4",
      "created_at": "2019-02-13T14:53:43Z",
      "is_verified": null,
      "public_repos": 24,
      "account_age_days": 2715
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.48.1",
          "kind": "patch",
          "published_at": "2026-07-17T13:48:26Z"
        },
        {
          "tag": "v0.42.3",
          "kind": "patch",
          "published_at": "2026-07-17T13:39:45Z"
        },
        {
          "tag": "v0.49.0",
          "kind": "minor",
          "published_at": "2026-07-06T12:59:38Z"
        },
        {
          "tag": "v0.42.2",
          "kind": "patch",
          "published_at": "2026-06-15T07:19:37Z"
        },
        {
          "tag": "v0.37.8",
          "kind": "patch",
          "published_at": "2026-06-12T13:43:39Z"
        },
        {
          "tag": "v0.39.7",
          "kind": "patch",
          "published_at": "2026-06-09T18:31:33Z"
        },
        {
          "tag": "v0.42.1",
          "kind": "patch",
          "published_at": "2026-06-08T16:18:26Z"
        },
        {
          "tag": "v0.39.6",
          "kind": "patch",
          "published_at": "2026-06-08T14:41:54Z"
        },
        {
          "tag": "v0.48.0",
          "kind": "minor",
          "published_at": "2026-06-04T16:28:32Z"
        },
        {
          "tag": "v0.47.0",
          "kind": "minor",
          "published_at": "2026-05-26T08:24:42Z"
        },
        {
          "tag": "v0.46.0",
          "kind": "minor",
          "published_at": "2026-05-06T11:27:46Z"
        },
        {
          "tag": "v0.45.0",
          "kind": "minor",
          "published_at": "2026-04-08T08:38:24Z"
        },
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2026-03-31T18:49:00Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2026-03-12T10:28:22Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2026-02-23T14:42:23Z"
        },
        {
          "tag": "v0.37.7",
          "kind": "patch",
          "published_at": "2026-02-23T14:00:10Z"
        },
        {
          "tag": "v0.39.5",
          "kind": "patch",
          "published_at": "2026-02-19T18:57:07Z"
        },
        {
          "tag": "v0.37.6",
          "kind": "patch",
          "published_at": "2026-02-19T14:43:04Z"
        },
        {
          "tag": "v0.37.5",
          "kind": "patch",
          "published_at": "2026-01-29T15:13:18Z"
        },
        {
          "tag": "v0.39.4",
          "kind": "patch",
          "published_at": "2026-01-29T15:14:58Z"
        },
        {
          "tag": "v0.41.1",
          "kind": "patch",
          "published_at": "2026-01-29T10:33:18Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2026-01-20T14:11:55Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2025-12-19T06:49:11Z"
        },
        {
          "tag": "v0.39.3",
          "kind": "patch",
          "published_at": "2025-12-15T17:36:46Z"
        },
        {
          "tag": "v0.37.4",
          "kind": "patch",
          "published_at": "2025-12-15T09:42:51Z"
        },
        {
          "tag": "v0.35.4",
          "kind": "patch",
          "published_at": "2025-12-04T04:41:54Z"
        },
        {
          "tag": "v0.39.2",
          "kind": "patch",
          "published_at": "2025-11-19T11:02:58Z"
        },
        {
          "tag": "v0.37.3",
          "kind": "patch",
          "published_at": "2025-11-18T08:39:26Z"
        },
        {
          "tag": "v0.39.1",
          "kind": "patch",
          "published_at": "2025-11-18T07:41:53Z"
        },
        {
          "tag": "v0.37.2",
          "kind": "patch",
          "published_at": "2025-11-10T04:40:32Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2025-11-04T17:28:24Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2025-10-01T09:30:13Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2025-09-26T06:21:33Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2025-08-12T11:40:15Z"
        },
        {
          "tag": "v0.35.3",
          "kind": "patch",
          "published_at": "2025-07-16T18:29:05Z"
        },
        {
          "tag": "v0.35.2",
          "kind": "patch",
          "published_at": "2025-07-04T16:53:16Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2025-06-26T15:30:13Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2025-06-04T13:07:41Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2025-05-26T15:19:51Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2025-05-06T13:43:40Z"
        },
        {
          "tag": "v0.33.2",
          "kind": "patch",
          "published_at": "2025-05-02T08:04:29Z"
        },
        {
          "tag": "v0.33.1",
          "kind": "patch",
          "published_at": "2025-04-16T10:34:37Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2025-02-14T14:28:54Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2025-01-21T10:35:04Z"
        },
        {
          "tag": "v0.28.2",
          "kind": "patch",
          "published_at": "2025-01-07T13:23:58Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2025-01-07T13:23:36Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2024-12-17T10:56:53Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2024-11-27T11:51:15Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2024-11-08T16:55:33Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2024-10-31T16:23:11Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2024-09-19T17:40:55Z"
        },
        {
          "tag": "v0.27.2",
          "kind": "patch",
          "published_at": "2024-07-05T11:31:26Z"
        },
        {
          "tag": "v0.27.1",
          "kind": "patch",
          "published_at": "2024-06-10T15:39:31Z"
        },
        {
          "tag": "v0.24.7",
          "kind": "patch",
          "published_at": "2024-05-30T09:57:00Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2024-05-06T15:20:57Z"
        },
        {
          "tag": "v0.24.6",
          "kind": "patch",
          "published_at": "2024-05-06T14:39:36Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2024-04-18T11:57:55Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2024-03-25T15:21:09Z"
        },
        {
          "tag": "v0.24.5",
          "kind": "patch",
          "published_at": "2024-03-22T14:37:32Z"
        },
        {
          "tag": "v0.24.4",
          "kind": "patch",
          "published_at": "2024-03-21T14:02:29Z"
        },
        {
          "tag": "v0.24.3",
          "kind": "patch",
          "published_at": "2024-03-19T16:23:42Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2024-03-12T13:01:33Z"
        },
        {
          "tag": "v0.24.1",
          "kind": "patch",
          "published_at": "2024-02-14T16:31:12Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2024-02-05T14:01:16Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2024-01-09T09:51:56Z"
        },
        {
          "tag": "v0.22.6",
          "kind": "patch",
          "published_at": "2024-01-02T12:13:30Z"
        },
        {
          "tag": "v0.22.5",
          "kind": "patch",
          "published_at": "2023-12-15T14:02:13Z"
        },
        {
          "tag": "v0.22.4",
          "kind": "patch",
          "published_at": "2023-11-23T10:10:32Z"
        },
        {
          "tag": "v0.22.3",
          "kind": "patch",
          "published_at": "2023-11-21T12:25:21Z"
        },
        {
          "tag": "v0.22.2",
          "kind": "patch",
          "published_at": "2023-11-16T08:22:54Z"
        },
        {
          "tag": "v0.22.1",
          "kind": "patch",
          "published_at": "2023-11-13T10:57:32Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2023-11-10T09:05:21Z"
        },
        {
          "tag": "v0.21.5",
          "kind": "patch",
          "published_at": "2023-10-31T14:38:00Z"
        },
        {
          "tag": "v0.21.4",
          "kind": "patch",
          "published_at": "2023-10-20T07:48:16Z"
        },
        {
          "tag": "v0.17.7",
          "kind": "patch",
          "published_at": "2023-10-20T07:28:36Z"
        },
        {
          "tag": "v0.19.6",
          "kind": "patch",
          "published_at": "2023-10-20T09:04:23Z"
        },
        {
          "tag": "v0.17.6",
          "kind": "patch",
          "published_at": "2023-10-18T15:19:51Z"
        },
        {
          "tag": "v0.19.5",
          "kind": "patch",
          "published_at": "2023-10-18T14:48:27Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2023-10-17T11:10:03Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2023-10-10T12:49:07Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2023-09-26T11:34:53Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2023-09-13T18:01:46Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2023-08-25T06:56:16Z"
        },
        {
          "tag": "v0.19.4",
          "kind": "patch",
          "published_at": "2023-08-04T08:37:21Z"
        },
        {
          "tag": "v0.19.3",
          "kind": "patch",
          "published_at": "2023-08-01T15:58:54Z"
        },
        {
          "tag": "v0.17.5",
          "kind": "patch",
          "published_at": "2023-08-01T14:00:28Z"
        },
        {
          "tag": "v0.17.4",
          "kind": "patch",
          "published_at": "2023-06-09T12:03:37Z"
        },
        {
          "tag": "v0.19.2",
          "kind": "patch",
          "published_at": "2023-06-08T14:05:48Z"
        },
        {
          "tag": "v0.19.1",
          "kind": "patch",
          "published_at": "2023-05-24T15:19:57Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2023-05-04T09:10:44Z"
        },
        {
          "tag": "v0.15.6",
          "kind": "patch",
          "published_at": "2023-04-19T09:46:58Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2023-04-18T13:34:40Z"
        },
        {
          "tag": "v0.17.3",
          "kind": "patch",
          "published_at": "2023-04-18T11:26:19Z"
        },
        {
          "tag": "v0.17.2",
          "kind": "patch",
          "published_at": "2023-03-30T12:31:01Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2023-03-08T15:15:55Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2023-03-02T14:50:12Z"
        },
        {
          "tag": "v0.15.5",
          "kind": "patch",
          "published_at": "2023-02-06T11:46:56Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2023-02-06T10:59:31Z"
        },
        {
          "tag": "v0.15.4",
          "kind": "patch",
          "published_at": "2023-02-06T11:01:40Z"
        },
        {
          "tag": "v0.15.3",
          "kind": "patch",
          "published_at": "2023-01-19T11:50:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
          "body": "Corrected the default container image path for the controller in the\nmulti-controller documentation to point to the correct GitHub Container\nRegistry repository.\n\nFixes #2559\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Update controller image path in multi-controller docs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-21T10:21:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4dfe8e76d8674cb78bc70bd5b84201f05799323",
          "body": "When updating a Bitbucket Cloud token via update-token, also\nprompt for the Atlassian account email and update\ngit_provider.user on the Repository CR. Without this, tokens\nrotated via the CLI leave a stale username that causes 401\nerrors on all provider API calls.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cli): set BB Cloud email in update-token",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-21T07:54:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "558561804964b529a161aea871788868687b0378",
          "body": "this deletes the gemini config from PaC repo\nbecause gemini code review is decommisioned and\nit is no longer needed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: delete gemini config from repo",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-20T18:43:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0feb33f9f5b2ead03cc2d510df497577b6ebee14",
          "body": "Replace testify/assert with gotest.tools/v3/assert in\ninfo_test.go and task_status_test.go to match the project's\nstandard assertion library and eliminate mixed usage.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "test: use gotest.tools/v3/assert consistently",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-20T12:09:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f1fe585601252cf88ded8a2487dde0cb25fdb3",
          "body": "Tekton Hub has been shut down and is no longer supported in\nOSP 1.24. Remove all TektonHub-specific code, configuration,\ntests, and documentation, leaving only Artifact Hub integration.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(hub): remove Tekton Hub support",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-20T12:09:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6e3f736a86b0e89103b84dfda95e5999075a0c72",
          "body": "Added logic to extract and display error messages from waiting container\nstates, which occur when secrets or other configuration issues prevent\npod creation. This allows users to see the actual error (e.g., \"secret\nnot found\") in the pipeline failure output instead of just a generic\nreason code. Als\n[…]\ns to include container creation and pod creation errors.\n\nFixes #2751\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12208\nCo-Authored-By: Gemini\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: capture container creation error messages in logs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-20T10:08:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad947f41d3d277edd7b761a030d5911dc3cc72c5",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.5.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356f\n[…]\n\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/setup-go in the github-actions group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:25:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d121ae3e51f0ffdcdcd3391a674b6877a7af0ec",
          "body": "Bumps the go-dependencies group with 1 update: [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty).\n\n\nUpdates `github.com/mattn/go-isatty` from 0.0.22 to 0.0.23\n- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)\n\n---\nupdated-dependencies:\n- dependency-name: github\n[…]\n dependency-version: 0.0.23\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump github.com/mattn/go-isatty in the go-dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:18:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e25db4412aa0a70b220da6dc1e2a268b386c7131",
          "body": "Enabled verbose JSON logging with connection timeouts and retries for\ngosmee clients to make end-to-end test failures easier to debug.\nIsolated Gitea and GitHub Enterprise webhook client logs into their\nown directories and files to prevent them from overwriting or\nappending to shared main logs. Upda\n[…]\non script to\ngather these new logs, capture internal Kubernetes gosmee deployment\ndetails when available, and redact the newly added webhook URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: Improve gosmee client debugging for end-to-end tests",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:11:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a054817abb339b0eef99e76aab00ed42bd571d89",
          "body": "Updated the AI code reviewer prompt to provide more detailed guidance on\nreview standards. Enhanced instructions to clarify what constitutes\nactionable findings versus nits, added explicit severity level\ndefinitions for consistent issue categorization, and improved guidance\non when and how to provid\n[…]\nuggestions. These changes aim to\nproduce more focused and useful pull request reviews by setting clearer\nexpectations for the reviewer's behavior.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: refine paco code review prompt",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:07:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f314275a165afc0641f3e6cef98bbecf0e51134",
          "body": "Extend Paco's structured review response with a difficulty rating, a\nshort explanation, and a security-sensitivity flag. Explain the rating\ncriteria in the model prompt so scores account for change size,\ncomplexity, risk, and blast radius while keeping summary-only runs\nconsistent with full reviews.\n[…]\nthe review instructions to suppress subjective formatting,\nnaming, and phrasing nits unless they affect correctness, security, or\nmaintainability.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: score review difficulty and other paco impro",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:07:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad2dcdb267f0d0b5ad99f3366bb4365d277c2fe0",
          "body": "Added an automated code review pipeline powered by AI to analyze pull\nrequest diffs against project-specific guidelines. This was done to help\ndevelopers catch bugs, style violations, and security flaws early by\nposting inline comments and a persistent overview summary directly onto\nGitHub pull requests.\n\nThis using opencode cli backend (but thats an implementation detail) and\nsupport custom review rules via a .tekton/ai/REVIEW.md file.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Introduce Paco AI code review",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T08:34:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29c47b6e5245b6f115934cc6e4a889e60909dab1",
          "body": "Remove the Status []RepositoryRunStatus field from the Repository\nCR to eliminate informer cache churn caused by updating the CR on\nevery PipelineRun completion. CLI commands now query PipelineRuns\ndirectly via label selectors instead of reading repo status.\n\n- Delete updateRepoRunStatus reconciler \n[…]\n ShowLastSHA, ShowStatus, ShowLastAge\n- Update deepcopy, test helpers, informer transform, golden files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
          "is_bot": false,
          "headline": "refactor: remove Repository CR pipelinerun_status field",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-16T07:18:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6a391687b88008a8b4cc264077508b7a1c8181c",
          "body": "Replace IsCollaborator (which returns true for read-only collaborators)\nwith CollaboratorPermission to verify the sender has write or admin\nor owner access before allowing pipeline runs. Also fix\nCreateForkPullRequest to grant access to SecondUserName instead of\nTargetRefName.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(gitea): check write/admin permission instead of collaborator only",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-16T06:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84829463a99d791164a3ef8f7f5dc1cd00fc6766",
          "body": "Adds TestOTelMetrics, a consolidated e2e test for the OC→OTel metrics\nmigration in Pipelines-as-Code (PR #2567). The test scrapes two pods:\n\nController (app.kubernetes.io/name=controller):\n- Asserts http_client_* metrics from knative k8s client OTel instrumentation\n- Asserts go_* runtime metrics\n- C\n[…]\ne metrics\n\nVerified locally with PAC controller and watcher deployed to kind via ko.\n\nRelates to tektoncd/pipelines-as-code#2567\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add e2e test for OpenCensus to OpenTelemetry metrics migration",
          "author_name": "Khurram Baig",
          "author_login": "khrm",
          "committed_at": "2026-07-16T04:12:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69c4496b1d39ca6d22eff42a499bd7626e40e949",
          "body": "Add missing unit tests for low-coverage packages identified via\ncodecov analysis: params/clients, cli, bootstrap, pipelinerunmetrics,\nwebhook, and llm/llm-context. Also exclude test-helper packages from\ncodecov accounting and add a codecov badge to README.\n\nCoverage improvements:\n- params/clients: 1\n[…]\n: 39.6% -> 81.3%\n- webhook: 47.9% -> 70.9%\n- llm: 46.8% -> 57.9%\n- llm/context: 38.8% -> 77.5%\n\nOverall project statement coverage: 65.6% -> 68.3%\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: raise unit test coverage across packages",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-15T13:47:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5438a1e06ea50062a79fe8fcd52f456a1b974a46",
          "body": "The warning about the old profiling.enable key is migration\nguidance that describes historical state rather than current\nbehavior. Since the old key no longer works, only the current\nruntime-profiling key needs to be documented.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "docs(profiling): remove deprecated key callout",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-15T09:04:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35ee9df55f472c448f203fb60b566fbc27efd06f",
          "body": "The Gitea cancel run test used a hardcoded sleep before sending the\ncancel comment. This caused test failures when the webhook relay took\nlonger than expected to deliver the event, sending the cancel command\nbefore the pipeline run existed. Replaced the sleep with a check that\nwaits for the pipeline run to be created first.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: Wait for pipelinerun to be created before cancellation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-15T07:32:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "85b606bb30f6b42d645cd79526dfd5ceba629f88",
          "body": "The apiextensions-apiserver indirect dependency is updated\nfrom v0.35.6 to v0.36.2 along with the corresponding\nk8s.io/apiserver transitive dependency. The vendored files\nreflect upstream changes including a new StorageMigrating\ncondition type and the removal of the deprecated\nprotomessage compatibility shim.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore: bump k8s.io/apiextensions-apiserver to v0.36.2",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-10T08:07:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c6483e2865399ae6794a5a3f57f2fac628bdd93",
          "body": "Bumps the go-dependencies group with 1 update: [k8s.io/client-go](https://github.com/kubernetes/client-go).\n\n\nUpdates `k8s.io/client-go` from 0.35.6 to 0.36.2\n- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/kubernetes/client-go/compare/v\n[…]\n dependency-version: 0.36.2\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump k8s.io/client-go in the go-dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T08:07:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e845ef225649de5ab631288562795a1c4037e83",
          "body": "rh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
          "is_bot": false,
          "headline": "refractor: split gitea_test.go into focused files",
          "author_name": "KMI1011",
          "author_login": "KMI1011",
          "committed_at": "2026-07-10T07:32:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85cad747dee15d9847c04cec0d79a4c4fab5789a",
          "body": null,
          "is_bot": false,
          "headline": "fix: bump knative.dev/pkg and semconv to fix otel schema panic",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fe2198bfa19188481c1a166b368df68055fc1e2",
          "body": "Dependabot generates automated commit messages that often violate line\nlength or body formatting rules. Added a check to bypass commit\nvalidation for dependabot pull requests, allowing these automated\nupdates to proceed without linting failures.",
          "is_bot": false,
          "headline": "ci: skip commit validation on dependabot PRs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c421e079e553bbf0b3fcdf7291fca29ee66e6b7",
          "body": null,
          "is_bot": false,
          "headline": "ci: ignore go-github and ghinstallation in dependabot",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b3981bc20b55759649f413d515452f7161b029b",
          "body": "Bumps the go-dependencies group with 15 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/bradleyfalzon/ghinstallation/v2](https://github.com/bradleyfalzon/ghinstallation) | `2.18.0` | `2.19.0` |\n| [github.com/google/cel-go](https://github.com/google/cel-go) | `0.28.1` | `0.29.2` |\n[…]\nx: pin ghinstallation to v2.18.0\n\nDowngraded ghinstallation from v2.19.0 to v2.18.0 and removed the unused\ngo-github v88 dependency that was pulled in transitively.\n\nfix: pin ghinstallation to v2.18.0",
          "is_bot": true,
          "headline": "ci: bump the go-dependencies group with 15 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "717f163e6fd3bfef22bd51108202c1049050bd7e",
          "body": "Added Go module tracking to the Dependabot configuration to keep Go\ndependencies updated. Since we can now group these updates together, we\ncan prevent an excessive number of pull requests.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Readd Go module updates in Dependabot",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T12:38:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "912f4e6b3b4147f4143f45e9cedbf2e767f562fd",
          "body": "- Update Go version from 1.26.4 to 1.26.5 in go.mod\n- Addresses crypto/tls Encrypted Client Hello privacy leak\n- CVE-2026-42505 / GO-2026-5856 fixed in go1.26.5\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): CVE-2026-42505 - update Go to 1.26.5",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-09T11:50:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a8413915cd80a6217b6eb3d50018b449082550a",
          "body": "The test waited on the PR head SHA status which is already green from\nthe pull_request run, then slept 5s; a delayed push webhook made\nGetStandardParams fail fatally on its first iteration with zero push\npipelineruns.\n\nWait for both pipelineruns to succeed after the merge and make\nGetStandardParams \n[…]\nhecking helper is patient\nenough to retry while things are still warming up, instead of quitting\nat the first empty result.\n\nAI-assisted-by: Cursor\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(e2e): wait for push pipelinerun in gitea params test",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-08T11:47:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e270e68e403cf5f937f48e6e5ea73ea663818888",
          "body": "The GitLab token auto-rotation feature revoked the old token via the\nself-rotate API before making the first Kubernetes API call that\ncould fail with a permission error. If the subsequent Secret update\nfailed, the old token was already revoked and the new token was\ndiscarded, irrecoverably destroyin\n[…]\n the\nrotation is aborted with a clear error while the old token is still\nvalid, so nothing is lost.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gitlab): verify write access before rotating token",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-08T08:23:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73cb521a48abeca491396811ac795e5a0039ece2",
          "body": "Document that provider code must use v.Logger instead of\nrun.Clients.Log, since the provider logger carries standard\ncontext variables (provider, repository, event-id). This\nprevents regressions of the pattern fixed in the recent\nprovider logging commits.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore: add provider logginf guidance to AGENTS.md",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-08T05:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b89b22edfa4ae5a6c296b11b8a39e6c01cd7caab",
          "body": "The token auto-rotation logging in the GitLab provider's\nsetClient was still using run.Clients.Log instead of the\nprovider's own logger. This logger lacks the standard context\nvariables (provider, repository, event-id) that v.Logger\ncarries.\n\nFollow-up-to: https://github.com/tektoncd/pipelines-as-code/pull/2827\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(provider): use provider logger in gitlab setClient",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-08T05:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "939d30a4365440484d4319046065af596601a37a",
          "body": "The run.CLients.Log logger is created early and does not have the\nstandard context variables. The provider logger is used primarily and\nwhile technically possible because pointers, provider.Logger == nil is\nan illegal state.\n\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(provider): always use log using Provider logger",
          "author_name": "Andrew Thorp",
          "author_login": "aThorp96",
          "committed_at": "2026-07-07T13:08:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e62d212d539ff389a82f4ca257aa9a7655cf042",
          "body": "Complete the refactor started in 39271f36a which removed the wait\nhelpers polling the deprecated Repository CR Status field. Three\nloose ends were left behind and are tied off here.\n\nFix zero-minimum wait semantics. The removed helpers compared with\n\">\" so MinNumberStatus: 0 meant \"wait for one\". Th\n[…]\nross 22\nE2E test files are deleted.\n\nValidated with go test ./test/pkg/wait and a compile of the e2e\ntagged test package.\n\nAssisted-by: Claude Code\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "refactor(e2e): finish Repository.Status removal in waits",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-07T11:16:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39271f36a191962287f27270b75ebc52084c3f84",
          "body": "The Repository CR's Status field is deprecated and will be removed.\nThis refactors E2E test wait helpers to use PipelineRun objects directly\ninstead of polling Repository.Status:\n\n- Remove UntilRepositoryUpdated and UntilRepositoryHasStatusReason\n- Remove FailOnRepoCondition from wait.Opts\n- Modify \n[…]\ninstead\n  of repo.Status fields\n- Migrate all ~40 call sites across 20 test files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(e2e): remove reliance on Repository.Status in wait functions",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-07T07:39:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1433ee8668857940524d58b6c8510d4d8552d7b8",
          "body": "Add Forgejo to the webhook setup used by `tkn pac create repo` and\n`tkn pac webhook add`. Create the repository webhook and store the\ntoken and webhook secret for runtime use.\n\nHandle repository URLs with `.git` suffixes, trailing slashes,\ninstance subpaths, and SSH forms without blocking manual set\n[…]\noken permission is needed and clarify when the CLI\ncreates the provider secret.\n\nFixes #2755.\n\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>\nSigned-off-by: Katie Mulliken <mulliken@redhat.com>",
          "is_bot": false,
          "headline": "feat(webhook): add Forgejo CLI setup",
          "author_name": "Katie Mulliken",
          "author_login": "SecKatie",
          "committed_at": "2026-07-06T12:02:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0badfa041319b55f201e956df9ecf152923581f",
          "body": "Pipelines-as-Code automatically rotated GitLab access tokens to\nprevent pipeline failures caused by expired credentials. Expiring\ntokens were replaced with new tokens and updated in the corresponding\nKubernetes Secret, reducing manual maintenance. Shared secrets from the\nglobal repository were exclu\n[…]\ns. This behavior is disabled\nby default but could be turned on via repository configuration.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-11153\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Implement automatic GitLab access rotation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-06T11:22:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bd2cc1be180b32ada848ab65d1090d32e6bf1a2",
          "body": "Removed the testrr integration, including the upload script, CI\nenvironment variables, and documentation. The testrr service is no\nlonger used to track test results from Tekton and GitHub Actions.\n\nIt was never really used and created a lot of resources waste, so we are\nremoving it to simplify our CI/CD pipeline and reduce unnecessary\ndependencies.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Remove testrr test reporting from the CI environment",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-06T09:04:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27ac5d7e2567f21b5ae281fa54db0fcc89dd3c80",
          "body": "The reconciler is a shared controller object. It can work on more than one\nPipelineRun at the same time. Some values it used while loading Git provider\ncredentials were stored on that shared object, even though they only belonged\nto the PipelineRun currently being processed.\n\nThat could let one Pipe\n[…]\non. Also copy Repository objects before merging global settings, so\nwe do not modify objects that came from the shared informer cache.\n\nFixes #2824\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(reconciler): avoid shared state",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-03T13:29:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63e8059d17c3fde3e60fd1dc07b48b260d9996a5",
          "body": "Updated the documentation and scaffolding templates to clarify task\nresolution behaviors. Explicitly distinguished annotation-based task\ninlining from native Tekton Hub resolver syntax because combining them\ncaused configuration errors. Replaced outdated git-clone catalog URLs\nwith the correct Artifact Hub links to ensure accurate references.\n\nFixes #2814\nAI-assisted-by: OpenAI ChatGPT\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Clarify task resolution in the pipeline documentation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-03T07:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccba1d5ca7a56c0eb66c102420bb553c8581f48b",
          "body": "this commit reverts a github link in docs from using\nmain branch to point to a specific commit to make\npermalink lint happy.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: use commit sha to prevent permalint lint error",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-03T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e30e597f4318d7438df004401802772ff56e6429",
          "body": "Label removal events on GitLab merge requests were incorrectly triggering\npipeline runs. The hasOnlyLabelsChanged check used an OR condition that\nmatched both additions and removals. Changed to compare current vs previous\nlabel count so only label additions are processed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gitlab): discard label removal events on merge requests",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-03T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a7f21344bdf3ab247c8759fdcbefff42f8a62fc",
          "body": "- Upgrade github.com/tektoncd/pipeline from v1.13.1 to v1.14.0\n- Fixes GHSA-cv4x-93xx-wgfj / CVE-2026-33022: controller panic via long\n  resolver name in TaskRun/PipelineRun (GenerateDeterministicNameFromSpec)\n- Fixes GO-2023-1901: Pipelines do not validate child UIDs\n- Co-upgrade transitive deps pu\n[…]\n,text} minor bumps\n- Ran: go mod tidy && go mod verify && go mod vendor\n\nResolves: SRVKP-11100\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): CVE-2026-33022 - upgrade tektoncd/pipeline v1.13.1 → v1.14.0",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-03T05:20:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03cd060cbf610d5343af4d10e8bbf0e3d66279e6",
          "body": "Added a Go formatting check to the linting process using gofumpt.\nIntegrated this verification step into the local Makefile lint target\nand the automated Tekton CI pipeline to ensure consistent code style\nacross the repository.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Enforce Go code formatting checks in lint pipeline",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-02T13:42:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8966a5331f743fe9e68d2262da1234b2391e4cb",
          "body": "Code was reformatted using fumpt to improve consistency with Go\nformatting standards. This includes adjusting line breaks in function\ncalls and adding parentheses for better readability where function\narguments span multiple lines. chore: reformat files with make fumpt",
          "is_bot": false,
          "headline": "chore: reformat code with fumpt",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-02T08:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dfcd60091c46844449e91a38bf38b76bea56c47",
          "body": "Switch Bitbucket Cloud setup away from app-password language and\nmake the CLI collect the Atlassian account email used for API token\nauthentication. Webhook creation now uses that email with the scoped\nAPI token instead of authenticating with the repository owner.\n\nKeep Repository CRD shape unchange\n[…]\nthe CLI auth flow, token rotation prompt, and generated git auth\nsecret behavior.\n\nFixes #2818\nJira https://redhat.atlassian.net/browse/SRVKP-12685\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix: bitbucket API tokens instead of app-passwords",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-01T15:55:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fdee04551602b8af9ef267e121863f045c256e5",
          "body": "Addresses SRVKP-12311 by moving unit coverage publishing to a\ndedicated GitHub Actions workflow. The workflow runs on pull requests,\npushes to main, and manual dispatch, then uploads coverage with the\nunit-tests flag through Codecov OIDC.\n\nRemove the older Tekton Codecov uploader steps that relied o\n[…]\no longer suggests Codecov coverage ownership.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12311\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: add codecov oidc upload",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-01T09:33:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9d51949f5027d41d9e8941ffa651a541acd8188f",
          "body": "Explain that disabling GitLab PipelineRun status comments does not\nhide validation errors from PipelineRuns in the `.tekton/` directory.\nThis keeps the note in normal prose instead of an info callout, so\nthe GitLab guide reads as a continuous troubleshooting section.\n\nSigned-off-by: Estee Cohen <estherco@post.bgu.ac.il>\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: clarify GitLab comment strategy behavior",
          "author_name": "Estee Cohen",
          "author_login": "EsteeCohen",
          "committed_at": "2026-07-01T09:16:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffc50929a53e9d07fda018ac73bd6f899a31310d",
          "body": null,
          "is_bot": false,
          "headline": "fix(llm): run default AI roles on completed PipelineRuns",
          "author_name": "BoseKarthikeyan",
          "author_login": "BoseKarthikeyan",
          "committed_at": "2026-06-30T09:21:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d2cde6492c70ac4f983f6fede548dd138c5d73b",
          "body": "Knative's config-observability ConfigMap only exposes a flat\ntracing-sampling-rate, so at fractional rates each service in the chain\nrolls independently — PaC can drop a trace while Tekton keeps it, leaving\nexecution spans whose parent_spanID points at nothing. Switching to the\nOTel SDK opens up OTE\n[…]\nonally not honored per Konflux-CI\nADR 0061. otlptracegrpc and otlptracehttp promoted from indirect to direct\ndependencies.\n\nAssisted-by: Claude Code\nSigned-off-by: Josiah England <jengland@redhat.com>",
          "is_bot": false,
          "headline": "fix(tracing): direct OTel SDK setup for chain-coherent sampling",
          "author_name": "Josiah England",
          "author_login": "ci-operator",
          "committed_at": "2026-06-30T05:31:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1a2f48ed544837c80ea38487d1ed728df82c819",
          "body": "Replace duplicate 404 and non-404 error subtests with a\ntable-driven test to satisfy the dupl linter.\n\nFixes https://github.com/tektoncd/pipelines-as-code/issues/2653\n\nrh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
          "is_bot": false,
          "headline": "fix: downgrade 404 API responses from error to debug log level",
          "author_name": "KMI1011",
          "author_login": "KMI1011",
          "committed_at": "2026-06-29T14:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74939ef42af88d708302559927406a59c7f16bbb",
          "body": "Reduce PR noise by grouping all GitHub Actions dependency updates into a\nsingle consolidated pull request, improving workflow efficiency.",
          "is_bot": false,
          "headline": "chore: Configure Dependabot to group GitHub Actions updates",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-29T08:16:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f045c6cf34367dbc09d0e0da9cdd72f9610b76d",
          "body": "Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fcca\n[…]\ns:\n- dependency-name: actions/cache\n  dependency-version: 6.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/cache from 5.0.5 to 6.1.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:41:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa462865bb55ec617868b0f23451bc03ebcd0452",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n  dependency-version: 6.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:41:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a781dbea31c5b894d6419b95df9fd2eb6f2cb1d",
          "body": "Bumps [ko-build/setup-ko](https://github.com/ko-build/setup-ko) from 0.9 to 0.10.\n- [Release notes](https://github.com/ko-build/setup-ko/releases)\n- [Commits](https://github.com/ko-build/setup-ko/compare/d006021bd0c28d1ce33a07e7943d48b079944c8d...61b4d1d396f5b2e7d6bb6fefdce3dc38d1a13445)\n\n---\nupdate\n[…]\ndependency-name: ko-build/setup-ko\n  dependency-version: '0.10'\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ko-build/setup-ko from 0.9 to 0.10",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:40:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82843027ab11abb03ce42f4603361cc3718e9ee9",
          "body": "Cache ListOrgTeams API responses per organization to avoid\nredundant API calls when checking policy for the same org\nacross multiple allowed teams evaluations.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "feat(forgejo): cache org teams in policy check",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-26T13:57:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "181a27faf760794cb3104995f0dcc88c12cb6be9",
          "body": "this allows e2e workflow run on any changes in hack/\ndirectory as there are all the script used across\nworkflow file.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore(ci): allow e2e workflow run hack/* changes",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-26T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8ac13de68283c7aade7524100f9ba0f980f6569",
          "body": "Use per-resource kubectl get with --- separators when collecting\npipelineruns, repositories, and configmaps in CI log artifacts so\neach resource is a distinct YAML document.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): separate collected resources with YAML document markers",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-26T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fb79c78fc4bb95b6aafeac654f2ab76cebcdf1e",
          "body": "Add table-driven unit tests for pkg/provider/gitea/parse_payload.go:\n\n- TestParsePayloadPullRequest covers the opened, synchronized, label_updated\n  and closed actions (event type, trigger target and label extraction).\n- TestParsePayloadPush covers the head_commit path and the before-SHA fallback.\n-\n[…]\noad helper builds the request and calls ParsePayload, and\nprPayload builds pull_request webhook bodies.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Kshitiz Jain <kshitizj@gmail.com>",
          "is_bot": false,
          "headline": "test(gitea): add unit tests for parse_payload",
          "author_name": "Kshitiz Jain",
          "author_login": "kshitizj03",
          "committed_at": "2026-06-25T09:21:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fff1dac7fad8183449d7521d3a6c0e797b06efe6",
          "body": "Tekton workspaces are shallow detached-HEAD clones; remote tracking\nrefs like origin/main are not available after git fetch -a --tags.\nUsing {{revision}} (the triggering commit SHA) matches the pattern\nalready used in .tekton/release-pipeline.yaml.",
          "is_bot": false,
          "headline": "fix: use revision instead of origin/main for nightly branch checkout",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-23T13:51:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f765bcb26a4da9fd5cd13137179450683953f56",
          "body": "actions/checkout v7 now refuses to fetch fork pull request code in\npull_request_target workflows by default to prevent pwn request\nattacks. Add allow-unsafe-pr-checkout: true to the e2e workflow\ncheckout step that needs to build and test fork PR code with\nrepository secrets.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): allow checkout of fork PR code in pull_request_target workflow",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-23T11:27:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6554d32b4a9b867c0d3ecc9b902e2b5b358ce38c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-23T08:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20a29a92b595e6e1c7794d1f9d0771b9554eb14f",
          "body": "Value.Emit() is deprecated in the updated OpenTelemetry SDK;\nreplace with Value.String() to resolve linter warning.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(tracing): use String instead of deprecated Emit",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-23T07:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d39d0d9b0924b8133e16d99d3e5997e1ef058b5",
          "body": "- Update github.com/tektoncd/pipeline from v1.11.1 to v1.13.1\n- Co-upgrades: cel-go v0.28.1, go-scm v1.15.22, otel v1.44.0,\n  zap v1.28.0, k8s.io/* v0.35.5, grpc v1.81.1\n\nCVE-2026-33022 (GHSA-cv4x-93xx-wgfj, CVSS 6.5 Medium):\nTekton Pipelines controller panic via long resolver name in\nGenerateDeterm\n[…]\nIs (pkg/apis, pkg/client) and does not run the\nTekton controller binary.\n\nResolves: SRVKP-9042\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(deps): bump tektoncd/pipeline to v1.13.1",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-23T07:10:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ad17d4501ebcc8021b929c13ae397fcff5c8554",
          "body": "Updated the Homebrew installation documentation to include instructions\nfor trusting the tap to support newer Homebrew versions. Added steps\nto handle macOS Gatekeeper blocking the binary on first run, and\ndefined corresponding caveats in the release configuration.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Update homebrew installation instructions for tap trust",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-22T11:19:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3dcf4ae3040e688935b84886bb4d6bbd9f6498a5",
          "body": "this commits adds a reason in log message that why the\nPipelineRun is cancelled so to make it clear to users.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "refactor: enhance log message for cancel-in-progress",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-19T15:22:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c38b0283fe109f5d9dcdfc9a215e07788e112a6c",
          "body": "Addresses Go stdlib vulnerabilities that require upgrading the compiler\ntoolchain from Go 1.25.11 to Go 1.26.4.\n\nCVEs fixed:\n- CVE-2026-27137 (GO-2026-4599): Incorrect email constraints in crypto/x509\n- CVE-2026-27138 (GO-2026-4600): Panic in name constraint checking in crypto/x509\n- CVE-2026-25679 \n[…]\n these fixes require Go 1.26.x.\nNo dependency changes: go.sum unchanged, go mod verify passes.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(security): upgrade Go from 1.25.11 to 1.26.4 to fix 23 stdlib CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-18T13:37:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c0fabcc29f8a87bf2cb7169d2914b8321bbe684",
          "body": "Replaced the local HTTP-based git-clone stepaction with the official\nTekton Hub resolver across Tekton workflows. Removed the redundant\nlocal stepaction definition file to keep configuration centralized.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Use git-clone artifacthub stepactions",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-17T11:37:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aeb85ab653e95a4ddac059a2909cc41468097d36",
          "body": "Preserves the error chain for errors.Is/errors.As callers.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: use %w instead of %s for error wrapping in DetectPacInstallation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-17T11:37:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc818de1b009f8c117952eb651a783143c56e605",
          "body": "Add notes to the configmap and docs clarifying that\ncustom-console-url-pr-details, custom-console-url-namespace,\nand custom-console-url-pr-tasklog must all be configured when\ncustom-console-url is set. Also document console URL precedence\norder and add the missing custom-console-url-namespace example.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(consoleui): document required custom console settings",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-17T05:22:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52fd4ae9ff914eb88fda2013ec33f611b1726f15",
          "body": "Upgrade golang.org/x/crypto from v0.50.0 to v0.52.0 to address the\nfollowing vulnerabilities in the SSH package:\n\n- CVE-2026-42508 (GO-2026-5021): auth bypass via unenforced @revoked status in ssh/knownhosts\n- CVE-2026-39833 (GO-2026-5005): key constraints not enforced in ssh/agent\n- CVE-2026-39832 \n[…]\n3.0\n- golang.org/x/text: v0.36.0 → v0.37.0\n\nAll fixed in v0.52.0 (minimum safe patch version).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade golang.org/x/crypto v0.50.0 → v0.52.0 to fix 13 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-17T03:54:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3180f7ca1db2856ddcc1f1e968c414d0cb89a812",
          "body": "this commit fixes the linting issues after a new\nvale release changes the rule I guess.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(ci): linting issue after new release",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-16T12:59:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6035f789cdf72090f5b6a58e3dece394323c3bf",
          "body": "Upgrade go directive in go.mod from go1.25.7 to go1.25.11 to address\nthe following Go standard library vulnerabilities:\n\n- CVE-2026-42507 (GO-2026-5039): arbitrary inputs in errors without escaping in net/textproto\n- CVE-2026-42504 (GO-2026-5038): quadratic complexity in mime.WordDecoder.DecodeHeade\n[…]\not escaped in html/template\n\nAll fixed in go1.25.11 (minimum safe patch in the go1.25.x line).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade Go stdlib to go1.25.11 to fix 16 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-16T11:04:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f06dcf55cf3d3f83af65ac8fc9733448b545a4f5",
          "body": "Upgrade golang.org/x/net from v0.53.0 to v0.55.0 to address the\nfollowing vulnerabilities in golang.org/x/net:\n\n- CVE-2026-39821 (GO-2026-5026): failure to reject ASCII-only Punycode-encoded labels\n- CVE-2026-42506 (GO-2026-5025): incorrect handling of namespaced elements in foreign content\n- CVE-20\n[…]\n/text: v0.36.0 → v0.37.0\n\nNote: A separate PR upgrades x/crypto to v0.52.0 to fix 13 SSH CVEs.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade golang.org/x/net v0.53.0 → v0.55.0 to fix 6 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-16T11:03:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbd582d0eef060094da1bbac907a1d6764b210df",
          "body": "… in the set client",
          "is_bot": false,
          "headline": "feat(bitbucketdatacenter): allow service accounts to not require user…",
          "author_name": "Ruben Rodrigues",
          "author_login": "Ru13en",
          "committed_at": "2026-06-09T18:56:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe709aecfe20b4da430a686463f655b4e1ebefac",
          "body": "gosmee v0.31.1 fixed an inverted TLS flag (InsecureSkipVerify was\nnegated), so the flag now works correctly. Restore it for e2e tests\nthat use self-signed minica certificates and unpin the version to\npick up the security fixes in v0.31.1+.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(ci): restore --insecure-skip-tls-verify and unpin gosmee version",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T15:08:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f9c939d7369a9d246ced54404e90642a2d963655",
          "body": "The e2e workflow now installs the minica CA certificate into the system\ntrust store, so gosmee no longer needs to skip TLS verification.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): remove --insecure-skip-tls-verify flag from gosmee client",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T12:01:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ce4774d3f94b07ecc723a920d8312412d730a091",
          "body": "we've seen some failure in E2E test which could\nbe surfaced due to recent gosmee release so using\nv0.31.0 version to see the affect.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: stick gosmee version to v0.31.0",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T11:22:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85f323a53088693acf3e403ff9b6219ce346cc9c",
          "body": "Update release notes format reference to use the new\nTekton Github org name as well as product name,\nreplacing openshift-pipelines and OpenShift references.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(release-notes): update org and branding refs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-09T08:56:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70faf9f9220253a15f9d71058faeb11097824a78",
          "body": "Gosmee starts before startpaac generates minica certs and before\nupdate-ca-certificates runs. Even after the CA is installed, the\nalready-running gosmee process doesn't pick it up since Go loads\nthe cert pool at startup. This only affects the downstream\nconnection to the PAC controller inside the ephemeral CI cluster,\nnot the upstream SSE connection or any git provider connections.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): skip TLS verification for gosmee client in e2e tests",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-08T12:23:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5bee3b79913be2d55892b4b1dc7306301701e88b",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 6.0.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-07T11:12:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "402d5c7eeece881cb082ec68e9e8b61709e39ace",
          "body": "Removed logic that blindly accepted the X-GitHub-Enterprise-Host header\nand now validate that it matches the repository URL in the webhook payload.\nAdded webhook signature verification before token generation to ensure\nthe payload hasn't been tampered with. This prevents an attacker from\nredirecting token requests to their own server by forging the Enterprise\nHost header.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix: prevent GitHub Enterprise header hijacking in app token requests",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-04T15:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee5d9b0a55afcd66b09ebce0d9d58d30c050cdb5",
          "body": "Use DeepCopy when reusing cached Pipeline and Task objects across\nPipelineRuns. Without this, inlineTasks mutates the cached\noriginal, contaminating subsequent runs that reference the same\nremote pipeline.\n\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(resolve): deep-copy cached resources before inlining",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-04T15:50:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "001782829e82b83ecb3da903f5a024ca0826b64c",
          "body": "Scope GitHub App installation tokens so they cannot access\nrepositories beyond the triggering one.  Normal webhooks now\nextract the repository ID from the payload and pass it to\nInstallationTokenOptions.  Incoming webhooks lack a payload\nrepo ID, so a new RepositoryNames field lets SetClient scope\nt\n[…]\npe providers and extend SetClient's\nfallback to reissue a scoped token when either field is set.\n\nCo-Authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(github): scope App token to triggering repo",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-04T15:50:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd262aa3b7ad12ea664f9d654351a8766f2c1306",
          "body": "this updates the message about deprecation of secret passing\nin URL query parameters so which would be removed in future\nrelease.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: update incoming webhook legacy params deprecation message",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-04T11:39:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c03760fd7181c2b5da1e4ce4356279bf322a7ae",
          "body": "Signed-off-by: Shubham Bhardwaj <shubbhar@redhat.com>",
          "is_bot": false,
          "headline": "fix(security): redact query string from incoming webhook log",
          "author_name": "Shubham Bhardwaj",
          "author_login": "infernus01",
          "committed_at": "2026-06-03T15:42:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "223e39c0ec6d784114d566364a7c6eb99964172a",
          "body": "The notify-slack script looked for e2e-test-output.log which was\nnever produced by gotestsum. Switch to parsing e2e-test-output.json\nusing jq so scheduled run failures are reported to Slack.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): parse JSON test output for Slack notifications",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-03T11:45:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "885427460c5323b1267bd10eccbcd59a29baa1bf",
          "body": "The pipelines-as-code-controller ServiceAccount had cluster-wide delete\npermission on secrets that was never used in the codebase. This change\nremoves the unused permission to follow the principle of least privilege.\n\nThe controller only requires 'get' permission on secrets for:\n- Incoming webhook v\n[…]\nate, delete) for managing the\nlifecycle of pac-gitauth-* secrets.\n\nVerification:\n- All unit tests pass (2816 tests)\n- Linting passes\n- Watcher permissions unchanged\n- No functional impact\n\nFixes #2743",
          "is_bot": false,
          "headline": "fix: remove unused secrets/delete permission from controller",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-03T06:58:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d0454b7d2cd8ddef53fc8c6b147851b053acff2",
          "body": "Bumps [mxschmitt/action-tmate](https://github.com/mxschmitt/action-tmate) from 3.23 to 3.24.\n- [Release notes](https://github.com/mxschmitt/action-tmate/releases)\n- [Changelog](https://github.com/mxschmitt/action-tmate/blob/master/RELEASE.md)\n- [Commits](https://github.com/mxschmitt/action-tmate/com\n[…]\ndency-name: mxschmitt/action-tmate\n  dependency-version: '3.24'\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump mxschmitt/action-tmate from 3.23 to 3.24",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T14:47:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67cfa525176645dee0e19297584436c0526f6183",
          "body": "Replace the obsolete profiling.enable ConfigMap key with\nruntime-profiling (enabled/disabled). Remove the K_METRICS_CONFIG\ncontroller section since the controller now uses ConfigMap-based\nobservability via the eventing adapter. Document that controller\nprofiling requires a pod restart as the adapter\n[…]\nconfig once\nat startup. Add CONFIG_OBSERVABILITY_NAME prerequisite for the\nwebhook.\n\nFixes #2633\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(profiling): update guide for OTel migration",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-29T12:34:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3811249c246b4084b1f2e337069c0ccf412ac516",
          "body": "Update knative/eventing to v0.49.0 which includes the pprof server\nfix (knative/eventing#9008). Also bumps k8s.io to v0.35.4,\nknative/pkg, and golang.org/x dependencies.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(deps): bump knative/eventing to v0.49.0",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-29T12:34:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bb2f82a9cfac342fe22a948cc7b7c035d9ec4a3",
          "body": "Add configurable TLS settings for the PAC controller via\ndeployment environment variables. This allows the Tekton Operator\nto propagate TLS configuration (min version, cipher suites, curve\npreferences) to the controller without code changes.\n\n- Add pkg/tlsconfig package for parsing TLS configuration\n[…]\n_CURVE_PREFERENCES env vars to the controller deployment\n  with secure defaults matching Tekton Results\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
          "is_bot": false,
          "headline": "feat: add TLS configuration support",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-28T12:49:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4dac4d6d836a59f2ec81cb3d5f0f132227b9c102",
          "body": "Deprecated the Tekton Hub catalog integration across documentation,\nconfiguration settings, and resource resolution. Added deprecation\nwarnings via logger messages, Kubernetes events on Repository CRs,\nand automated comments on pull requests when resources were resolved\nfrom Tekton Hub catalogs. Thi\n[…]\nnge prepared users for the complete\nremoval of Tekton Hub support in a future release, encouraging them\nto migrate to Artifact Hub or remote URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Add deprecation warnings for Tekton Hub integration",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-28T12:06:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69fa323d60c2436976059296b33993a03ecd5553",
          "body": "When a version tag (e.g. v0.47.0) is pushed, the container workflow's\ntag sanitization converts dots to dashes producing v0-47-0 images.\nThe release pipeline generates release.yaml referencing v0.47.0\n(with dots), causing a mismatch where manifests point to nonexistent\nimage tags.\n\nAdd a condition for refs/tags/v* that uses the tag name as-is, since\nDocker image tags support dots.\n\nCloses #2741",
          "is_bot": false,
          "headline": "fix(release): preserve dots in image tags for version tag pushes",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-27T08:37:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32820cbb4c98d6b66e40e5445c20e5f85459e678",
          "body": "Enable Gitea/Forgejo provider to resolve remote taskRef URLs using\nthe provider's authenticated API instead of returning \"not\nsupported\". Supports branch, tag, and commit SHA URL formats.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gitea): implement GetTaskURI for remote task resolution",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-27T08:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "529a725ac61ca5c4e0a0e35408e36c16fe238e33",
          "body": "When a merge request originates from a fork the bot cannot access,\npost an informative comment on the MR explaining the issue. Uses\nCreateComment with an update marker to prevent duplicate comments\non reconciler retries.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(gitlab): post MR comment on inaccessible fork",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-25T10:11:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c7b0e06e41e7d3834292bd66e13dee95f195c9d",
          "body": "The watcher observes PipelineRun status but does not own it.\nDisable generated status synchronization so informer cache\ntransforms cannot trigger UpdateStatus calls against the\nPipelineRun /status subresource.\n\nThis avoids forbidden errors on clusters where the watcher\nonly has metadata and spec-level PipelineRun permissions.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(reconciler): skip watcher status updates",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-20T11:46:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b9a6f1842eb647014055bb183f76fb724f0b3d6",
          "body": "The gomodguard_v2 linter was introduced in v2.12.0 but the CI\nimage was still on v2.10.1, causing lint failures with unknown\nlinter error.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "ci: update golangci-lint to v2.12.2",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-20T10:09:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9db1feca2d2b030a3f08ffac7f1710928f5d11f8",
          "body": "Updated gomodguard to gomodguard_v2 for the latest linter\nversion. Also disabled the inline check in govet to reduce\nfalse positives during code analysis.\n\nError was:\n\nlevel=warning msg=\"The linter 'gomodguard' is deprecated (since v2.12.0)\ndue to: new major version. Replaced by gomodguard_v2.\" leve\n[…]\nta) ^\ntest/pkg/configmap/configmap.go:22:11: inline: cannot inline: type\nparameter inference is not yet supported (govet) maps.Copy(newData,\ndata)\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: update golangci linter configuration",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-20T03:18:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "445941b2cc745ff67afc9fcc9549a3b66a011b74",
          "body": "Previously, CEL expressions in Pipelines-as-Code only had access to\nthe core CEL operators, which limited users to basic comparisons and\nlogical expressions. Functions like join(), replace(), substring(),\nand other string/list manipulation operations were unavailable,\nforcing users to work around th\n[…]\nparison, since the output is a single\ndynamic file path that varies per test run.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cel): enable string and list extension functions in CEL expressions",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-19T15:07:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f841d2d728d228f4008fa0cb336793e5a182cd74",
          "body": "When a pull request is merged in Bitbucket Data Center, the resulting\npush event contains a merge commit that reports no file changes. This\ncaused on-path-change and on-cel-expression filters to silently skip\nPipelineRuns because the changed files list was always empty.\n\nThe fix detects merge commit\n[…]\n for on-path-change annotation surviving a PR merge push\n- Add unit tests for getMergeCommitChanges and merge commit GetFiles path\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bitbucket-datacenter): detect changes on merged PR push",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-19T10:57:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 575,
      "latest_release_at": "2026-07-17T13:48:26Z",
      "latest_release_tag": "v0.48.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 51,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 5.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/openshift-pipelines/pipelines-as-code",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": false,
          "registry_url": "https://pkg.go.dev/github.com/openshift-pipelines/pipelines-as-code",
          "is_deprecated": false,
          "latest_version": "v0.49.0",
          "repository_url": "https://github.com/openshift-pipelines/pipelines-as-code",
          "versions_count": 113,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-06T12:02:19Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 15
        }
      ]
    },
    "popularity": {
      "forks": 135,
      "stars": 203,
      "watchers": 9,
      "fork_history": {
        "days": [
          {
            "date": "2021-04-06",
            "count": 1
          },
          {
            "date": "2021-04-22",
            "count": 1
          },
          {
            "date": "2021-05-20",
            "count": 1
          },
          {
            "date": "2021-07-01",
            "count": 1
          },
          {
            "date": "2021-08-12",
            "count": 1
          },
          {
            "date": "2021-08-16",
            "count": 1
          },
          {
            "date": "2021-08-29",
            "count": 1
          },
          {
            "date": "2021-09-14",
            "count": 1
          },
          {
            "date": "2021-10-14",
            "count": 1
          },
          {
            "date": "2021-11-11",
            "count": 1
          },
          {
            "date": "2021-11-15",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 1
          },
          {
            "date": "2021-11-19",
            "count": 1
          },
          {
            "date": "2021-11-24",
            "count": 1
          },
          {
            "date": "2021-11-29",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-01-21",
            "count": 1
          },
          {
            "date": "2022-01-26",
            "count": 1
          },
          {
            "date": "2022-02-07",
            "count": 1
          },
          {
            "date": "2022-02-15",
            "count": 1
          },
          {
            "date": "2022-03-11",
            "count": 1
          },
          {
            "date": "2022-03-24",
            "count": 1
          },
          {
            "date": "2022-03-25",
            "count": 1
          },
          {
            "date": "2022-04-04",
            "count": 2
          },
          {
            "date": "2022-04-07",
            "count": 1
          },
          {
            "date": "2022-04-18",
            "count": 1
          },
          {
            "date": "2022-06-08",
            "count": 1
          },
          {
            "date": "2022-06-09",
            "count": 2
          },
          {
            "date": "2022-07-07",
            "count": 1
          },
          {
            "date": "2022-07-16",
            "count": 1
          },
          {
            "date": "2022-08-17",
            "count": 1
          },
          {
            "date": "2022-08-30",
            "count": 1
          },
          {
            "date": "2022-10-05",
            "count": 1
          },
          {
            "date": "2022-10-16",
            "count": 1
          },
          {
            "date": "2022-11-01",
            "count": 1
          },
          {
            "date": "2022-11-18",
            "count": 1
          },
          {
            "date": "2023-01-06",
            "count": 1
          },
          {
            "date": "2023-01-11",
            "count": 1
          },
          {
            "date": "2023-01-13",
            "count": 1
          },
          {
            "date": "2023-01-19",
            "count": 1
          },
          {
            "date": "2023-02-14",
            "count": 1
          },
          {
            "date": "2023-03-09",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 1
          },
          {
            "date": "2023-03-26",
            "count": 2
          },
          {
            "date": "2023-03-29",
            "count": 2
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-04-26",
            "count": 1
          },
          {
            "date": "2023-05-03",
            "count": 1
          },
          {
            "date": "2023-05-17",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-12",
            "count": 1
          },
          {
            "date": "2023-09-04",
            "count": 1
          },
          {
            "date": "2023-10-15",
            "count": 1
          },
          {
            "date": "2023-10-25",
            "count": 1
          },
          {
            "date": "2023-11-06",
            "count": 1
          },
          {
            "date": "2023-11-16",
            "count": 1
          },
          {
            "date": "2023-12-07",
            "count": 1
          },
          {
            "date": "2023-12-13",
            "count": 1
          },
          {
            "date": "2024-02-04",
            "count": 1
          },
          {
            "date": "2024-03-14",
            "count": 1
          },
          {
            "date": "2024-03-22",
            "count": 2
          },
          {
            "date": "2024-04-08",
            "count": 1
          },
          {
            "date": "2024-06-04",
            "count": 1
          },
          {
            "date": "2024-06-05",
            "count": 1
          },
          {
            "date": "2024-06-20",
            "count": 1
          },
          {
            "date": "2024-06-28",
            "count": 1
          },
          {
            "date": "2024-07-02",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-10-15",
            "count": 1
          },
          {
            "date": "2024-11-26",
            "count": 1
          },
          {
            "date": "2024-11-28",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-03",
            "count": 1
          },
          {
            "date": "2024-12-27",
            "count": 1
          },
          {
            "date": "2025-01-03",
            "count": 1
          },
          {
            "date": "2025-01-18",
            "count": 1
          },
          {
            "date": "2025-01-22",
            "count": 1
          },
          {
            "date": "2025-01-30",
            "count": 2
          },
          {
            "date": "2025-02-06",
            "count": 1
          },
          {
            "date": "2025-02-11",
            "count": 1
          },
          {
            "date": "2025-02-23",
            "count": 1
          },
          {
            "date": "2025-02-28",
            "count": 1
          },
          {
            "date": "2025-03-14",
            "count": 1
          },
          {
            "date": "2025-03-20",
            "count": 1
          },
          {
            "date": "2025-04-15",
            "count": 1
          },
          {
            "date": "2025-05-08",
            "count": 1
          },
          {
            "date": "2025-05-28",
            "count": 1
          },
          {
            "date": "2025-06-05",
            "count": 1
          },
          {
            "date": "2025-06-13",
            "count": 1
          },
          {
            "date": "2025-06-20",
            "count": 1
          },
          {
            "date": "2025-06-30",
            "count": 1
          },
          {
            "date": "2025-07-20",
            "count": 1
          },
          {
            "date": "2025-08-04",
            "count": 1
          },
          {
            "date": "2025-08-10",
            "count": 1
          },
          {
            "date": "2025-09-30",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-11-21",
            "count": 1
          },
          {
            "date": "2025-12-17",
            "count": 1
          },
          {
            "date": "2026-01-17",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-02-19",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-03-18",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-16",
            "count": 1
          },
          {
            "date": "2026-04-20",
            "count": 1
          },
          {
            "date": "2026-05-13",
            "count": 2
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          },
          {
            "date": "2026-06-09",
            "count": 1
          },
          {
            "date": "2026-06-18",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 129,
        "total_forks": 135
      },
      "star_history": {
        "days": [
          {
            "date": "2021-05-27",
            "count": 2
          },
          {
            "date": "2021-06-07",
            "count": 1
          },
          {
            "date": "2021-06-25",
            "count": 1
          },
          {
            "date": "2021-06-29",
            "count": 1
          },
          {
            "date": "2021-07-03",
            "count": 1
          },
          {
            "date": "2021-07-04",
            "count": 1
          },
          {
            "date": "2021-07-05",
            "count": 1
          },
          {
            "date": "2021-07-06",
            "count": 2
          },
          {
            "date": "2021-09-01",
            "count": 1
          },
          {
            "date": "2021-09-08",
            "count": 1
          },
          {
            "date": "2021-09-19",
            "count": 1
          },
          {
            "date": "2021-09-21",
            "count": 1
          },
          {
            "date": "2021-10-13",
            "count": 1
          },
          {
            "date": "2021-10-26",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 2
          },
          {
            "date": "2021-11-23",
            "count": 1
          },
          {
            "date": "2021-11-24",
            "count": 1
          },
          {
            "date": "2021-12-09",
            "count": 1
          },
          {
            "date": "2021-12-10",
            "count": 2
          },
          {
            "date": "2021-12-15",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-01-08",
            "count": 1
          },
          {
            "date": "2022-01-11",
            "count": 1
          },
          {
            "date": "2022-02-08",
            "count": 1
          },
          {
            "date": "2022-03-01",
            "count": 1
          },
          {
            "date": "2022-03-04",
            "count": 1
          },
          {
            "date": "2022-03-08",
            "count": 1
          },
          {
            "date": "2022-03-16",
            "count": 1
          },
          {
            "date": "2022-03-17",
            "count": 1
          },
          {
            "date": "2022-04-01",
            "count": 1
          },
          {
            "date": "2022-04-08",
            "count": 1
          },
          {
            "date": "2022-04-11",
            "count": 1
          },
          {
            "date": "2022-04-12",
            "count": 1
          },
          {
            "date": "2022-04-19",
            "count": 1
          },
          {
            "date": "2022-04-27",
            "count": 1
          },
          {
            "date": "2022-04-29",
            "count": 1
          },
          {
            "date": "2022-05-13",
            "count": 1
          },
          {
            "date": "2022-05-14",
            "count": 1
          },
          {
            "date": "2022-05-17",
            "count": 1
          },
          {
            "date": "2022-05-25",
            "count": 1
          },
          {
            "date": "2022-06-10",
            "count": 1
          },
          {
            "date": "2022-06-14",
            "count": 1
          },
          {
            "date": "2022-06-22",
            "count": 1
          },
          {
            "date": "2022-06-25",
            "count": 1
          },
          {
            "date": "2022-07-14",
            "count": 1
          },
          {
            "date": "2022-07-21",
            "count": 1
          },
          {
            "date": "2022-08-05",
            "count": 1
          },
          {
            "date": "2022-08-07",
            "count": 1
          },
          {
            "date": "2022-08-23",
            "count": 1
          },
          {
            "date": "2022-10-19",
            "count": 1
          },
          {
            "date": "2022-11-05",
            "count": 1
          },
          {
            "date": "2022-12-13",
            "count": 1
          },
          {
            "date": "2022-12-14",
            "count": 1
          },
          {
            "date": "2022-12-29",
            "count": 1
          },
          {
            "date": "2023-01-17",
            "count": 1
          },
          {
            "date": "2023-01-27",
            "count": 2
          },
          {
            "date": "2023-02-03",
            "count": 1
          },
          {
            "date": "2023-02-06",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-02-16",
            "count": 1
          },
          {
            "date": "2023-03-01",
            "count": 1
          },
          {
            "date": "2023-03-15",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 2
          },
          {
            "date": "2023-03-28",
            "count": 1
          },
          {
            "date": "2023-04-08",
            "count": 1
          },
          {
            "date": "2023-04-11",
            "count": 1
          },
          {
            "date": "2023-04-12",
            "count": 1
          },
          {
            "date": "2023-04-15",
            "count": 1
          },
          {
            "date": "2023-04-21",
            "count": 1
          },
          {
            "date": "2023-04-24",
            "count": 1
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-04-30",
            "count": 1
          },
          {
            "date": "2023-05-02",
            "count": 1
          },
          {
            "date": "2023-05-25",
            "count": 1
          },
          {
            "date": "2023-05-31",
            "count": 1
          },
          {
            "date": "2023-06-01",
            "count": 1
          },
          {
            "date": "2023-06-08",
            "count": 1
          },
          {
            "date": "2023-06-20",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-04",
            "count": 1
          },
          {
            "date": "2023-07-08",
            "count": 1
          },
          {
            "date": "2023-07-13",
            "count": 1
          },
          {
            "date": "2023-07-24",
            "count": 1
          },
          {
            "date": "2023-08-28",
            "count": 1
          },
          {
            "date": "2023-09-04",
            "count": 1
          },
          {
            "date": "2023-09-08",
            "count": 1
          },
          {
            "date": "2023-09-20",
            "count": 1
          },
          {
            "date": "2023-09-25",
            "count": 2
          },
          {
            "date": "2023-10-03",
            "count": 1
          },
          {
            "date": "2023-10-30",
            "count": 1
          },
          {
            "date": "2023-11-10",
            "count": 1
          },
          {
            "date": "2023-12-08",
            "count": 1
          },
          {
            "date": "2023-12-19",
            "count": 1
          },
          {
            "date": "2023-12-21",
            "count": 1
          },
          {
            "date": "2023-12-28",
            "count": 1
          },
          {
            "date": "2024-01-02",
            "count": 1
          },
          {
            "date": "2024-01-19",
            "count": 1
          },
          {
            "date": "2024-02-07",
            "count": 2
          },
          {
            "date": "2024-02-20",
            "count": 1
          },
          {
            "date": "2024-02-26",
            "count": 1
          },
          {
            "date": "2024-02-28",
            "count": 1
          },
          {
            "date": "2024-03-11",
            "count": 1
          },
          {
            "date": "2024-03-27",
            "count": 1
          },
          {
            "date": "2024-04-02",
            "count": 1
          },
          {
            "date": "2024-04-09",
            "count": 2
          },
          {
            "date": "2024-04-25",
            "count": 1
          },
          {
            "date": "2024-05-06",
            "count": 1
          },
          {
            "date": "2024-05-08",
            "count": 1
          },
          {
            "date": "2024-06-05",
            "count": 1
          },
          {
            "date": "2024-06-18",
            "count": 1
          },
          {
            "date": "2024-06-19",
            "count": 1
          },
          {
            "date": "2024-06-20",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-07-21",
            "count": 1
          },
          {
            "date": "2024-08-02",
            "count": 1
          },
          {
            "date": "2024-08-08",
            "count": 1
          },
          {
            "date": "2024-08-13",
            "count": 1
          },
          {
            "date": "2024-09-27",
            "count": 1
          },
          {
            "date": "2024-10-16",
            "count": 1
          },
          {
            "date": "2024-10-20",
            "count": 1
          },
          {
            "date": "2024-10-27",
            "count": 1
          },
          {
            "date": "2024-10-28",
            "count": 1
          },
          {
            "date": "2024-11-10",
            "count": 1
          },
          {
            "date": "2024-11-15",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-25",
            "count": 1
          },
          {
            "date": "2025-01-09",
            "count": 2
          },
          {
            "date": "2025-02-07",
            "count": 1
          },
          {
            "date": "2025-02-12",
            "count": 4
          },
          {
            "date": "2025-02-13",
            "count": 2
          },
          {
            "date": "2025-02-24",
            "count": 1
          },
          {
            "date": "2025-02-26",
            "count": 1
          },
          {
            "date": "2025-03-19",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-04-23",
            "count": 1
          },
          {
            "date": "2025-05-21",
            "count": 2
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-05-30",
            "count": 1
          },
          {
            "date": "2025-06-07",
            "count": 1
          },
          {
            "date": "2025-06-11",
            "count": 4
          },
          {
            "date": "2025-07-01",
            "count": 2
          },
          {
            "date": "2025-07-06",
            "count": 1
          },
          {
            "date": "2025-08-30",
            "count": 1
          },
          {
            "date": "2025-10-10",
            "count": 1
          },
          {
            "date": "2025-10-11",
            "count": 1
          },
          {
            "date": "2025-10-22",
            "count": 1
          },
          {
            "date": "2025-11-07",
            "count": 1
          },
          {
            "date": "2025-11-19",
            "count": 1
          },
          {
            "date": "2025-11-26",
            "count": 1
          },
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-01-30",
            "count": 1
          },
          {
            "date": "2026-02-03",
            "count": 1
          },
          {
            "date": "2026-02-06",
            "count": 1
          },
          {
            "date": "2026-02-08",
            "count": 1
          },
          {
            "date": "2026-02-09",
            "count": 1
          },
          {
            "date": "2026-02-10",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-01",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 2
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-14",
            "count": 1
          },
          {
            "date": "2026-04-19",
            "count": 1
          },
          {
            "date": "2026-04-23",
            "count": 1
          },
          {
            "date": "2026-04-26",
            "count": 1
          },
          {
            "date": "2026-05-02",
            "count": 1
          },
          {
            "date": "2026-05-04",
            "count": 2
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-05-30",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-07",
            "count": 1
          },
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          },
          {
            "date": "2026-06-23",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 2
          },
          {
            "date": "2026-07-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 203,
        "total_stars": 203
      },
      "open_issues_and_prs": 80
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "samples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
        "vendor/github.com/emicklei/go-restful/v3/Makefile",
        "vendor/github.com/felixge/httpsnoop/Makefile",
        "vendor/github.com/hashicorp/go-retryablehttp/Makefile",
        "vendor/github.com/juju/ansiterm/Makefile",
        "vendor/github.com/ktrysmt/go-bitbucket/Makefile",
        "vendor/github.com/munnerz/goautoneg/Makefile",
        "vendor/github.com/pkg/errors/Makefile",
        "vendor/github.com/prometheus/procfs/Makefile",
        "vendor/github.com/spf13/cobra/Makefile",
        "vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
        "vendor/go.opentelemetry.io/otel/Makefile",
        "vendor/go.uber.org/atomic/Makefile",
        "vendor/go.uber.org/multierr/Makefile",
        "vendor/go.uber.org/zap/Makefile",
        "vendor/google.golang.org/grpc/Makefile",
        "vendor/sigs.k8s.io/json/Makefile"
      ],
      "api_schema_files": [
        "vendor/github.com/google/gnostic-models/extensions/extension.proto",
        "vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
        "vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
        "vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
        "vendor/k8s.io/api/admission/v1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
        "vendor/k8s.io/api/apidiscovery/v2/generated.proto",
        "vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
        "vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
        "vendor/k8s.io/api/apps/v1/generated.proto",
        "vendor/k8s.io/api/apps/v1beta1/generated.proto",
        "vendor/k8s.io/api/apps/v1beta2/generated.proto",
        "vendor/k8s.io/api/authentication/v1/generated.proto",
        "vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
        "vendor/k8s.io/api/authentication/v1beta1/generated.proto",
        "vendor/k8s.io/api/authorization/v1/generated.proto",
        "vendor/k8s.io/api/authorization/v1beta1/generated.proto",
        "vendor/k8s.io/api/autoscaling/v1/generated.proto",
        "vendor/k8s.io/api/autoscaling/v2/generated.proto",
        "vendor/k8s.io/api/batch/v1/generated.proto",
        "vendor/k8s.io/api/batch/v1beta1/generated.proto",
        "vendor/k8s.io/api/certificates/v1/generated.proto",
        "vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
        "vendor/k8s.io/api/certificates/v1beta1/generated.proto",
        "vendor/k8s.io/api/coordination/v1/generated.proto",
        "vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
        "vendor/k8s.io/api/coordination/v1beta1/generated.proto",
        "vendor/k8s.io/api/core/v1/generated.proto",
        "vendor/k8s.io/api/discovery/v1/generated.proto",
        "vendor/k8s.io/api/discovery/v1beta1/generated.proto",
        "vendor/k8s.io/api/events/v1/generated.proto",
        "vendor/k8s.io/api/events/v1beta1/generated.proto",
        "vendor/k8s.io/api/extensions/v1beta1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
        "vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
        "vendor/k8s.io/api/networking/v1/generated.proto",
        "vendor/k8s.io/api/networking/v1beta1/generated.proto",
        "vendor/k8s.io/api/node/v1/generated.proto",
        "vendor/k8s.io/api/node/v1alpha1/generated.proto",
        "vendor/k8s.io/api/node/v1beta1/generated.proto",
        "vendor/k8s.io/api/policy/v1/generated.proto",
        "vendor/k8s.io/api/policy/v1beta1/generated.proto",
        "vendor/k8s.io/api/rbac/v1/generated.proto",
        "vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
        "vendor/k8s.io/api/rbac/v1beta1/generated.proto",
        "vendor/k8s.io/api/resource/v1/generated.proto",
        "vendor/k8s.io/api/resource/v1alpha3/generated.proto",
        "vendor/k8s.io/api/resource/v1beta1/generated.proto",
        "vendor/k8s.io/api/resource/v1beta2/generated.proto",
        "vendor/k8s.io/api/scheduling/v1/generated.proto",
        "vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
        "vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
        "vendor/k8s.io/api/storage/v1/generated.proto",
        "vendor/k8s.io/api/storage/v1alpha1/generated.proto",
        "vendor/k8s.io/api/storage/v1beta1/generated.proto",
        "vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
        "vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "docs/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 92818,
      "source_files_sampled": 518,
      "oversized_source_files": 3,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
        "vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
        "vendor/go.opentelemetry.io/otel/AGENTS.md",
        "vendor/go.opentelemetry.io/otel/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 12245
    },
    "dependencies": {
      "manifests": [
        "docs/go.mod",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.81.1",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          },
          {
            "name": "github.com/tektoncd/pipeline",
            "direct": true,
            "version": "v1.14.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2023-1901",
              "GO-2026-4730"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": 700
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 2,
          "critical": 1
        },
        "advisory_count": 4,
        "affected_count": 3,
        "assessed_count": 156,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 7,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.0"
        },
        {
          "name": "github.com/AlecAivazis/survey/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.3.7"
        },
        {
          "name": "github.com/bradleyfalzon/ghinstallation/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.18.0"
        },
        {
          "name": "github.com/chzyer/readline",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.1"
        },
        {
          "name": "github.com/cloudevents/sdk-go/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.16.2"
        },
        {
          "name": "github.com/fvbommel/sortorder",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/gobwas/glob",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.3"
        },
        {
          "name": "github.com/google/cel-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.29.2"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-github/scrape",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260403152401-96a365122246"
        },
        {
          "name": "github.com/google/go-github/v84",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v84.0.0"
        },
        {
          "name": "github.com/google/go-github/v85",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v85.0.0"
        },
        {
          "name": "github.com/hako/durafmt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20210608085754-5c1018a4e16b"
        },
        {
          "name": "github.com/jenkins-x/go-scm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.15.31"
        },
        {
          "name": "github.com/jonboulle/clockwork",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.0"
        },
        {
          "name": "github.com/juju/ansiterm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/ktrysmt/go-bitbucket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.10.0"
        },
        {
          "name": "github.com/mattn/go-colorable",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.15"
        },
        {
          "name": "github.com/mattn/go-isatty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.23"
        },
        {
          "name": "github.com/mgutz/ansi",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20200706080929-d51e80ef957d"
        },
        {
          "name": "github.com/mitchellh/mapstructure",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/pkg/errors",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tektoncd/pipeline",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.0"
        },
        {
          "name": "gitlab.com/gitlab-org/api/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.46.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.28.0"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260312153236-7ab1446f8b90"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "gopkg.in/yaml.v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.4.0"
        },
        {
          "name": "gotest.tools/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.5.2"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260319190234-28399d86e0b5"
        },
        {
          "name": "knative.dev/eventing",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.2"
        },
        {
          "name": "knative.dev/pkg",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260622140654-39ebae2ee2dc"
        },
        {
          "name": "sigs.k8s.io/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/golang-jwt/jwt/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.5.2"
        },
        {
          "name": "github.com/prometheus/client_model",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.2"
        },
        {
          "name": "github.com/prometheus/common",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "google.golang.org/genproto/googleapis/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260526163538-3dc84a4a5aaa"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.12-0.20260120151049-f2248ac996af"
        },
        {
          "name": "k8s.io/klog/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.140.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
            "direct": true,
            "version": "v3.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecaivazis/survey/v2",
            "direct": true,
            "version": "v2.3.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bradleyfalzon/ghinstallation/v2",
            "direct": true,
            "version": "v2.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chzyer/readline",
            "direct": true,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/v2",
            "direct": true,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fvbommel/sortorder",
            "direct": true,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobwas/glob",
            "direct": true,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v4",
            "direct": true,
            "version": "v4.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/cel-go",
            "direct": true,
            "version": "v0.29.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/scrape",
            "direct": true,
            "version": "v0.0.0-20260403152401-96a365122246",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v84",
            "direct": true,
            "version": "v84.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v85",
            "direct": true,
            "version": "v85.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hako/durafmt",
            "direct": true,
            "version": "v0.0.0-20210608085754-5c1018a4e16b",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jenkins-x/go-scm",
            "direct": true,
            "version": "v1.15.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jonboulle/clockwork",
            "direct": true,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/juju/ansiterm",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ktrysmt/go-bitbucket",
            "direct": true,
            "version": "v0.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": true,
            "version": "v0.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": true,
            "version": "v0.0.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mgutz/ansi",
            "direct": true,
            "version": "v0.0.0-20200706080929-d51e80ef957d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": true,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": true,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tektoncd/pipeline",
            "direct": true,
            "version": "v1.14.0",
            "ecosystem": "go"
          },
          {
            "name": "gitlab.com/gitlab-org/api/client-go",
            "direct": true,
            "version": "v1.46.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": true,
            "version": "v1.28.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": true,
            "version": "v0.0.0-20260312153236-7ab1446f8b90",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": true,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": true,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.12-0.20260120151049-f2248ac996af",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": true,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gotest.tools/v3",
            "direct": true,
            "version": "v3.5.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": true,
            "version": "v2.140.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": true,
            "version": "v0.0.0-20260319190234-28399d86e0b5",
            "ecosystem": "go"
          },
          {
            "name": "knative.dev/eventing",
            "direct": true,
            "version": "v0.49.2",
            "ecosystem": "go"
          },
          {
            "name": "knative.dev/pkg",
            "direct": true,
            "version": "v0.0.0-20260622140654-39ebae2ee2dc",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/42wim/httpsig",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/andybalholm/cascadia",
            "direct": false,
            "version": "v1.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr/antlr4/runtime/go/antlr",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr4-go/antlr/v4",
            "direct": false,
            "version": "v4.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blang/semver/v4",
            "direct": false,
            "version": "v4.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blendle/zapdriver",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cert-manager/cert-manager",
            "direct": false,
            "version": "v1.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/observability/opentelemetry/v2",
            "direct": false,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/sql/v2",
            "direct": false,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-oidc/v3",
            "direct": false,
            "version": "v3.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davidmz/go-pageant",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/evanphx/json-patch/v5",
            "direct": false,
            "version": "v5.9.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-fed/httpsig",
            "direct": false,
            "version": "v1.1.1-0.20201223112313-55836744818e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v3",
            "direct": false,
            "version": "v3.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": false,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/zapr",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/errors",
            "direct": false,
            "version": "v0.22.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.22.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.21.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/strfmt",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/cmdutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/conv",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/fileutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonname",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/loading",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/mangling",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/netutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/stringutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/typeutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/yamlutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-cleanhttp",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-retryablehttp",
            "direct": false,
            "version": "v0.7.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-version",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/golang-lru",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/imfing/hextra",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kballard/go-shellquote",
            "direct": false,
            "version": "v0.0.0-20180428030007-95032a82bc51",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kelseyhightower/envconfig",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lunixbochs/vtclean",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": false,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/puerkitobio/goquery",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rickb777/date",
            "direct": false,
            "version": "v1.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rickb777/plural",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/robfig/cron/v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xlzd/gotp",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": false,
            "version": "v0.66.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/automaxprocs",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.4",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "gomodules.xyz/jsonpatch/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.81.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": false,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20260330154417-16be699c7b31",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/gateway-api",
            "direct": false,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.2",
            "ecosystem": "go"
          },
          {
            "name": "@axe-core/playwright",
            "direct": false,
            "version": "^4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "^1.49.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/postcss",
            "direct": false,
            "version": "^4.1.18",
            "ecosystem": "npm"
          },
          {
            "name": "postcss-cli",
            "direct": false,
            "version": "^11.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "^3.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "prettier-plugin-go-template",
            "direct": false,
            "version": "^0.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "^4.1.18",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 163,
        "direct_count": 54,
        "indirect_count": 109
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 2014,
        "open_issues": 70,
        "closed_ratio": 0.88,
        "closed_issues": 515,
        "closed_unmerged_prs": 252
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "chmouel",
          "commits": 2290,
          "avatar_url": "https://avatars.githubusercontent.com/u/98980?v=4"
        },
        {
          "type": "User",
          "login": "zakisk",
          "commits": 223,
          "avatar_url": "https://avatars.githubusercontent.com/u/49492007?v=4"
        },
        {
          "type": "User",
          "login": "savitaashture",
          "commits": 107,
          "avatar_url": "https://avatars.githubusercontent.com/u/9441662?v=4"
        },
        {
          "type": "User",
          "login": "theakshaypant",
          "commits": 84,
          "avatar_url": "https://avatars.githubusercontent.com/u/16561942?v=4"
        },
        {
          "type": "User",
          "login": "piyush-garg",
          "commits": 31,
          "avatar_url": "https://avatars.githubusercontent.com/u/19270240?v=4"
        },
        {
          "type": "User",
          "login": "aThorp96",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/28596783?v=4"
        },
        {
          "type": "User",
          "login": "sm43",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/55777192?v=4"
        },
        {
          "type": "User",
          "login": "PuneetPunamiya",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/32545638?v=4"
        },
        {
          "type": "User",
          "login": "vdemeester",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/6508?v=4"
        },
        {
          "type": "User",
          "login": "infernus01",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/89133323?v=4"
        }
      ],
      "contributors_sampled": 59,
      "top_contributor_share": 0.776
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "codecov.yaml",
        "container.yaml",
        "e2e.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml",
        ".golangci.yml",
        ".pylintrc"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 8,
            "reason": "Found 17/20 approved changesets -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 33 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 8,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
        "ran_at": "2026-07-22T02:12:12Z",
        "aggregate_score": 5.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T13:36:38Z",
      "oldest_open_prs": [
        {
          "number": 2655,
          "created_at": "2026-04-08T09:02:29Z",
          "last_comment_at": "2026-07-16T11:44:33Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2848,
          "created_at": "2026-07-10T19:24:17Z",
          "last_comment_at": "2026-07-21T07:29:37Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2854,
          "created_at": "2026-07-15T12:23:38Z",
          "last_comment_at": "2026-07-15T18:09:09Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2856,
          "created_at": "2026-07-16T08:41:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2859,
          "created_at": "2026-07-16T11:10:41Z",
          "last_comment_at": "2026-07-21T06:28:58Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2867,
          "created_at": "2026-07-21T11:07:16Z",
          "last_comment_at": "2026-07-21T11:07:40Z",
          "last_comment_author": "pipelines-as-code"
        },
        {
          "number": 2868,
          "created_at": "2026-07-21T11:09:17Z",
          "last_comment_at": "2026-07-21T11:47:47Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2869,
          "created_at": "2026-07-21T12:56:50Z",
          "last_comment_at": "2026-07-21T13:02:50Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2870,
          "created_at": "2026-07-21T13:02:08Z",
          "last_comment_at": "2026-07-21T13:14:09Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 2871,
          "created_at": "2026-07-21T13:30:25Z",
          "last_comment_at": "2026-07-21T13:33:08Z",
          "last_comment_author": "codecov"
        }
      ],
      "last_merged_pr_at": "2026-07-21T10:21:44Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 508,
          "created_at": "2022-04-01T13:59:38Z",
          "last_comment_at": "2026-02-26T11:40:23Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 724,
          "created_at": "2022-06-09T08:42:43Z",
          "last_comment_at": "2025-10-15T09:37:31Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 732,
          "created_at": "2022-06-20T06:56:49Z",
          "last_comment_at": "2026-02-26T11:40:05Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 780,
          "created_at": "2022-08-01T15:57:45Z",
          "last_comment_at": "2026-02-26T11:39:49Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 790,
          "created_at": "2022-08-09T12:42:02Z",
          "last_comment_at": "2026-02-26T11:40:07Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 828,
          "created_at": "2022-09-09T12:32:05Z",
          "last_comment_at": "2026-02-26T11:40:31Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 924,
          "created_at": "2022-10-17T13:23:32Z",
          "last_comment_at": "2026-02-26T11:40:19Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 933,
          "created_at": "2022-10-20T10:25:52Z",
          "last_comment_at": "2026-02-26T11:40:43Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 934,
          "created_at": "2022-10-20T10:29:41Z",
          "last_comment_at": "2026-02-26T11:40:18Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 998,
          "created_at": "2022-11-21T07:04:20Z",
          "last_comment_at": "2026-02-26T11:40:36Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1049,
          "created_at": "2022-12-05T12:02:37Z",
          "last_comment_at": "2026-02-26T15:23:46Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1070,
          "created_at": "2022-12-12T15:15:51Z",
          "last_comment_at": "2026-02-26T11:51:25Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1098,
          "created_at": "2023-01-05T11:28:07Z",
          "last_comment_at": "2026-02-26T11:40:08Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1112,
          "created_at": "2023-01-19T11:18:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1152,
          "created_at": "2023-02-14T11:04:32Z",
          "last_comment_at": "2026-02-26T11:51:20Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1227,
          "created_at": "2023-04-12T07:07:13Z",
          "last_comment_at": "2026-02-26T11:41:47Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1235,
          "created_at": "2023-04-13T14:52:59Z",
          "last_comment_at": "2026-02-26T13:50:34Z",
          "last_comment_author": "tekton-pac-bot"
        },
        {
          "number": 1237,
          "created_at": "2023-04-17T09:46:26Z",
          "last_comment_at": "2026-02-26T11:40:55Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1246,
          "created_at": "2023-04-22T12:57:18Z",
          "last_comment_at": "2026-02-26T11:42:27Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1291,
          "created_at": "2023-05-18T07:12:16Z",
          "last_comment_at": "2026-03-06T10:32:53Z",
          "last_comment_author": "mikem-of"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/tektoncd/pipelines-as-code",
    "host": "github.com",
    "name": "pipelines-as-code",
    "owner": "tektoncd"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 79,
      "inputs": {
        "security": 62,
        "vitality": 95,
        "community": 75,
        "governance": 65,
        "engineering": 96
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 95,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "commits_last_year": 575,
              "human_commit_share": 0.9,
              "days_since_last_push": 0,
              "active_weeks_last_year": 51
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "51/52 weeks with commits",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 51
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "575 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 575
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.48.1",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 5.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~5.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 5.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 75,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "forks": 135,
              "stars": 203,
              "watchers": 9,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "203 stars",
                "points": 37.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 203
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "135 forks",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 135
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "9 watchers",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 65,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 59,
              "top_contributor_share": 0.776
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 78% of commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 78
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "59 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 59
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "merged_prs": 2014,
              "open_issues": 70,
              "closed_issues": 515,
              "issue_closed_ratio": 0.88,
              "closed_unmerged_prs": 252
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "88% of issues closed",
                "points": 41.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 88
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2014/2266 decided PRs merged",
                "points": 34,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2014,
                      "decided": 2266
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 17/20 approved changesets -- score normalized to 8",
                "points": 12,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "followers": 1421,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "tektoncd",
              "public_repos": 24,
              "account_age_days": 2715
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,421 followers of tektoncd",
                "points": 22.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1421,
                      "login": "tektoncd"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "24 public repos, account ~7 yr old",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 24
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 96,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml, .golangci.yml, .pylintrc",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml, .pylintrc"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "tekton-pipelines",
                "tekton",
                "github",
                "pipeline",
                "kubernetes",
                "continuous-delivery",
                "pipelines-as-code",
                "gitlab",
                "ci",
                "bitbucket",
                "gitops"
              ],
              "has_wiki": true,
              "homepage": "https://pipelinesascode.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://pipelinesascode.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "11 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 17/20 approved changesets -- score normalized to 8",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 156 resolved dependencies against OSV; 7 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 156
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 7
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 85,
            "inputs": {
              "source": "osv",
              "advisories": 4,
              "affected_packages": 3,
              "assessed_packages": 156,
              "unassessed_packages": 7,
              "affected_by_severity": "critical 1, unknown 2",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: github.com/tektoncd/pipeline v1.14.0 (unknown)",
                "points": 26.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "github.com/tektoncd/pipeline v1.14.0 (unknown)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 700 days ago",
                "points": 37.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 700
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 156,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 17
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 96,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
                "vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
                "vendor/go.opentelemetry.io/otel/AGENTS.md",
                "vendor/go.opentelemetry.io/otel/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 12245
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 90 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
                "vendor/github.com/emicklei/go-restful/v3/Makefile",
                "vendor/github.com/felixge/httpsnoop/Makefile",
                "vendor/github.com/hashicorp/go-retryablehttp/Makefile",
                "vendor/github.com/juju/ansiterm/Makefile",
                "vendor/github.com/ktrysmt/go-bitbucket/Makefile",
                "vendor/github.com/munnerz/goautoneg/Makefile",
                "vendor/github.com/pkg/errors/Makefile",
                "vendor/github.com/prometheus/procfs/Makefile",
                "vendor/github.com/spf13/cobra/Makefile",
                "vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
                "vendor/go.opentelemetry.io/otel/Makefile",
                "vendor/go.uber.org/atomic/Makefile",
                "vendor/go.uber.org/multierr/Makefile",
                "vendor/go.uber.org/zap/Makefile",
                "vendor/google.golang.org/grpc/Makefile",
                "vendor/sigs.k8s.io/json/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.26,
              "toolchain_manifests": [
                "docs/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.1
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml, .golangci.yml, .pylintrc",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml, .pylintrc"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "26 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 26,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "10 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 10,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 92818,
              "source_files_sampled": 518,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/518 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 518,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "vendor/github.com/google/gnostic-models/extensions/extension.proto",
                "vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
                "vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
                "vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
                "vendor/k8s.io/api/admission/v1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
                "vendor/k8s.io/api/apidiscovery/v2/generated.proto",
                "vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
                "vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
                "vendor/k8s.io/api/apps/v1/generated.proto",
                "vendor/k8s.io/api/apps/v1beta1/generated.proto",
                "vendor/k8s.io/api/apps/v1beta2/generated.proto",
                "vendor/k8s.io/api/authentication/v1/generated.proto",
                "vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
                "vendor/k8s.io/api/authentication/v1beta1/generated.proto",
                "vendor/k8s.io/api/authorization/v1/generated.proto",
                "vendor/k8s.io/api/authorization/v1beta1/generated.proto",
                "vendor/k8s.io/api/autoscaling/v1/generated.proto",
                "vendor/k8s.io/api/autoscaling/v2/generated.proto",
                "vendor/k8s.io/api/batch/v1/generated.proto",
                "vendor/k8s.io/api/batch/v1beta1/generated.proto",
                "vendor/k8s.io/api/certificates/v1/generated.proto",
                "vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
                "vendor/k8s.io/api/certificates/v1beta1/generated.proto",
                "vendor/k8s.io/api/coordination/v1/generated.proto",
                "vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
                "vendor/k8s.io/api/coordination/v1beta1/generated.proto",
                "vendor/k8s.io/api/core/v1/generated.proto",
                "vendor/k8s.io/api/discovery/v1/generated.proto",
                "vendor/k8s.io/api/discovery/v1beta1/generated.proto",
                "vendor/k8s.io/api/events/v1/generated.proto",
                "vendor/k8s.io/api/events/v1beta1/generated.proto",
                "vendor/k8s.io/api/extensions/v1beta1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
                "vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
                "vendor/k8s.io/api/networking/v1/generated.proto",
                "vendor/k8s.io/api/networking/v1beta1/generated.proto",
                "vendor/k8s.io/api/node/v1/generated.proto",
                "vendor/k8s.io/api/node/v1alpha1/generated.proto",
                "vendor/k8s.io/api/node/v1beta1/generated.proto",
                "vendor/k8s.io/api/policy/v1/generated.proto",
                "vendor/k8s.io/api/policy/v1beta1/generated.proto",
                "vendor/k8s.io/api/rbac/v1/generated.proto",
                "vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
                "vendor/k8s.io/api/rbac/v1beta1/generated.proto",
                "vendor/k8s.io/api/resource/v1/generated.proto",
                "vendor/k8s.io/api/resource/v1alpha3/generated.proto",
                "vendor/k8s.io/api/resource/v1beta1/generated.proto",
                "vendor/k8s.io/api/resource/v1beta2/generated.proto",
                "vendor/k8s.io/api/scheduling/v1/generated.proto",
                "vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
                "vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
                "vendor/k8s.io/api/storage/v1/generated.proto",
                "vendor/k8s.io/api/storage/v1alpha1/generated.proto",
                "vendor/k8s.io/api/storage/v1beta1/generated.proto",
                "vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
                "vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T02:12:45.089451Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tektoncd/pipelines-as-code.svg",
  "full_name": "tektoncd/pipelines-as-code",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.26.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.