Public record
Software health reportschema 0.27.0 · metrics 1.13.0 · 2026-07-25 16:24 UTC

tsarna / vinculum

A low-code, mostly-declarative system for gluing together different systems and bridging multiple protocols

GoApache-2.0★ 3 stars⑂ 0 forkssince Aug 2025View on GitHub ↗

tsarna/vinculum holds a health index of 59 out of 100, placing it in the Moderate band. It scores highest on Vitality (85/100) and lowest on Community & Adoption (26/100). It was last updated today. A single contributor accounts for most of its recent work.

59
overall / 100
Moderate

Software health index

Metrics are grouped into weighted categories on one standardized 1–100 scale. Overall starts as their weighted mean; when public evidence triggers the High-Risk Jurisdiction Policy, the rating is adjusted and receives an At risk ceiling of 49. AI Readiness sits outside the overall score.

59
Excellent85-100Exemplary; meets essentially all checked criteria
Good70-84Healthy; minor gaps
Moderate50-69Acceptable with notable gaps; review recommended
At risk30-49Significant weaknesses; adoption warrants caution
Critical1-29Severe problems (abandoned, single-maintainer, no hygiene)
VitalityCommunity &AdoptionSustainability &GovernanceEngineeringQualitySecurityAI Readiness

Score profile

Each axis is a category. The shape matters more than the average — a healthy subject fills the whole shape, while a spike-and-crater profile means strength in one dimension is masking risk in another.

Ownership

Ty SarnaPersonal account
4 followers48 public repossince Feb 2011

This repository is owned by a personal account. A single-owner project carries more continuity risk than an organization-backed one.

Package ecosystems

RegistryPackageVersionDownloads / moVersionsLast publish
Gogithub.com/tsarna/vinculumv0.44.0-483 days ago

Metrics by category

Vitality

Is the project alive — is code being written and are releases shipping?

85Excellent · 22% of overall
How it's scored
36/36Push recency — last push 0 days ago
17.3/36Commit cadence — 25/52 weeks with commits
18/18Commit volume — 507 commits in the last year
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Inputs used
commits_last_year507
human_commit_share0.99
days_since_last_push0
active_weeks_last_year25
How it's scored
27/27Ships releases — 8 releases published
36/36Release recency — latest release 1 days ago
27/27Release cadence — a release every ~7.1 days
0/10OpenSSF Scorecard: Signed-Releases — Project has not signed or included provenance with any releases.
Inputs used
releases_count8
latest_release_tagv0.44.0
releases_from_tagsno
days_since_latest_release1
mean_days_between_releases7.1

Community & Adoption

Does the project have users, downloads, attention, and a welcoming setup for contributors?

26Critical · 18% of overall
How it's scored
4.9/60Stars — 3 stars
0/25Forks — 0 forks
0/15Watchers — 1 watchers
Inputs used
forks0
stars3
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
How it's scored
22.5/22.5README
22.5/22.5License — recognized license (Apache-2.0)
0/18CONTRIBUTING guide
0/13.5Code of conduct
0/7.2Issue template
0/6.3PR template
Inputs used
has_readmeyes
has_licenseyes
has_contributingno
has_issue_templateno
has_code_of_conductno
has_pull_request_templateno

Sustainability & Governance

Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?

50Moderate · 24% of overall
How it's scored
9/54Bus factor — 1 contributor(s) cover half of all commits
0/22.5Commit distribution — top contributor authored 100% of commits
1.4/13.5Contributor breadth — 1 contributors
0/10OpenSSF Scorecard: Contributors — project has 0 contributing companies or organizations -- score normalized to 0
Inputs used
bus_factor1
contributors_sampled1
top_contributor_share1
How it's scored
0/46.8Issue resolution — no issues or no data
32/38.3PR acceptance — 127/152 decided PRs merged
0/15OpenSSF Scorecard: Code-Review — Found 0/29 approved changesets -- score normalized to 0
Inputs used
merged_prs127
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs25
Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.
How it's scored
10/30Ownership backing — personal (user) account
0/20Verified domain — not applicable to user accounts
5/25Owner reach — 4 followers of tsarna
24.3/25Track record — 48 public repos, account ~15 yr old
Inputs used
followers4
owner_typeUser
is_verified
owner_logintsarna
public_repos48
account_age_days5,633
Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.
How it's scored
25/25Published & resolvable — 1 package(s) on go
35/35Publish recency — latest publish 3 days ago
20/20Version history — 48 published versions
20/20Not deprecated — active, not deprecated or yanked
Inputs used
packagesgithub.com/tsarna/vinculum
ecosystemsgo
any_deprecatedno
min_days_since_publish3

Engineering Quality

Are baseline engineering and documentation practices in place?

67Moderate · 20% of overall
How it's scored
24/24CI workflows — 5 workflow(s)
24/24Tests present
0/16Linter config
0/9.6Pre-commit hooks
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
Inputs used
has_ciyes
has_testsyes
has_editorconfigno
has_linter_configno
has_precommit_configno

Documentation

65Moderate
How it's scored
30/30README
25/25Documentation directory
0/15Documentation / homepage site
10/10Repository description
0/10Topics
0/10Wiki
Inputs used
topics
has_wikino
homepage
has_readmeyes
has_docs_diryes
has_descriptionyes

Security

Are visible security and supply-chain practices strong, without unresolved high-risk jurisdiction exposure?

63Moderate · 16% of overall
How it's scored
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — no data
2.5/2.5CI-Tests — 13 out of 13 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5License — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool is run on all commits
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
Inputs used
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.6
Excluded from scoring (no data or not applicable): branch_protection. Remaining weights renormalized.
How it's scored
26.6/35Direct dependencies free of known advisories — 1 affected: golang.org/x/crypto v0.54.0 (unknown)
0/25Indirect dependencies free of known advisories — transitive set not separable from development and test dependencies in this scope
40/40No advisories left outstanding — no advisory has been public longer than 90 days
Inputs used
sourceosv
advisories1
affected_packages1
assessed_packages169
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages1
Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 169 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.

AI Readiness

How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score.

85Excellent · 0% of overall
How it's scored
45/45Agent instructions — CLAUDE.md
0/15Machine-readable docs (llms.txt)
40/40Legible commit history — 96 of 99 human commits state their intent (structured subject or explanatory body)
Inputs used
has_llms_txtno
legible_history_share0.97
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes27,416
How it's scored
12.6/18One-command bootstrap — go.mod, testdata/plugin-smoke/go.mod (toolchain convention, no task runner)
22/22Automated tests
0/11Lint / format config
11/11Static type checking — Go (statically typed)
10/10Reproducible environment — Dockerfile, lockfile
10/10Demonstrated agent practice — 50 of the last 100 commits agent-authored or agent-credited
8/8Automated maintenance — 1 of the last 100 commits are automated dependency updates
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Inputs used
has_nixno
has_testsyes
lockfilesgo.sum
has_dockerfileyes
typed_languageyes
bootstrap_files
has_devcontainerno
has_linter_configno
typecheck_configs
agent_commit_share0.5
toolchain_manifestsgo.mod, testdata/plugin-smoke/go.mod
dependency_bot_commit_share0.01
How it's scored
45/45Type-checkable code — Go (statically typed)
54.8/55Manageable file sizes — 1/328 source files over 60KB
Inputs used
primary_languageGo
largest_source_bytes73,014
source_files_sampled328
oversized_source_files1
How it's scored
40/40API schema (OpenAPI/GraphQL/proto) — wireformats/protobuf/testdata/orders.proto
20/20MCP server
40/40Runnable examples — examples, sample
Inputs used
example_dirsexamples, sample
has_mcp_signalyes
api_schema_fileswireformats/protobuf/testdata/orders.proto

Key facts

3GitHub stars
1contributors
507commits, last 12 months
0days since last push
8releases
1bus factor
0open issues
Gopackage ecosystems

Data collection warnings

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

More detail

OpenSSF Scorecard 5.6 / 10
5.6aggregate

Independent, tool-agnostic security assessment from the open-source OpenSSF Scorecard. Each check rewards a security practice, not a specific vendor's tool. Checks Scorecard could not determine are marked n/a and excluded from the security score (never counted as zero).Scorecard v5.5.0 · 2026-07-25 16:24 UTC

10Binary-Artifactsno binaries found in the repo
n/aBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests13 out of 13 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool is run on all commits
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
Direct dependencies 72
RegistryPackageVersion constraintManifest
Gogithub.com/tsarna/bytes-cty-typev0.3.0go.mod
Gogo.uber.org/zapv1.28.0go.mod
Gogithub.com/alicebob/miniredis/v2v2.38.0go.mod
Gogithub.com/aws/aws-sdk-go-v2v1.43.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.31go.mod
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.30go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/snsv1.42.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/sqsv1.46.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.45.0go.mod
Gogithub.com/coder/websocketv1.8.15go.mod
Gogithub.com/fsnotify/fsnotifyv1.10.1go.mod
Gogithub.com/go-git/go-git/v5v5.19.1go.mod
Gogithub.com/go-sql-driver/mysqlv1.10.0go.mod
Gogithub.com/hashicorp/go-cty-funcsv0.1.0go.mod
Gogithub.com/hashicorp/hcl/v2v2.24.0go.mod
Gogithub.com/itchyny/gojqv0.12.19go.mod
Gogithub.com/jackc/pgx/v5v5.10.0go.mod
Gogithub.com/jmoiron/sqlxv1.4.0go.mod
Gogithub.com/lestrrat-go/jwx/v2v2.1.7go.mod
Gogithub.com/mattn/go-sqlite3v1.14.48go.mod
Gogithub.com/modelcontextprotocol/go-sdkv1.6.1go.mod
Gogithub.com/prometheus/client_golangv1.24.1go.mod
Gogithub.com/rabbitmq/amqp091-gov1.13.0go.mod
Gogithub.com/redis/go-redis/v9v9.20.0go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogithub.com/sashabaranov/go-openaiv1.41.2go.mod
Gogithub.com/sosodev/durationv1.4.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tsarna/barcode-cty-funcv0.2.0go.mod
Gogithub.com/tsarna/functyv0.12.0go.mod
Gogithub.com/tsarna/geo-cty-funcsv0.4.0go.mod
Gogithub.com/tsarna/go-structdiffv0.2.1go.mod
Gogithub.com/tsarna/go2cty2gov0.3.0go.mod
Gogithub.com/tsarna/hcl-jqfuncv0.1.4go.mod
Gogithub.com/tsarna/rand-cty-funcsv0.2.0go.mod
Gogithub.com/tsarna/rich-cty-typesv0.5.1go.mod
Gogithub.com/tsarna/sqid-cty-funcsv0.2.0go.mod
Gogithub.com/tsarna/time-cty-funcsv0.4.0go.mod
Gogithub.com/tsarna/vinculum-busv0.15.1go.mod
Gogithub.com/tsarna/vinculum-kafkav0.11.0go.mod
Gogithub.com/tsarna/vinculum-mqttv0.9.0go.mod
Gogithub.com/tsarna/vinculum-rabbitmqv0.2.0go.mod
Gogithub.com/tsarna/vinculum-redisv0.4.0go.mod
Gogithub.com/tsarna/vinculum-snsv0.3.0go.mod
Gogithub.com/tsarna/vinculum-sqsv0.4.0go.mod
Gogithub.com/tsarna/vinculum-vwsv0.13.0go.mod
Gogithub.com/tsarna/vinculum-wirev0.4.0go.mod
Gogithub.com/twmb/franz-gov1.21.5go.mod
Gogithub.com/twmb/franz-go/pkg/kfakev0.0.0-20260721222903-95f7d9a51d6ago.mod
Gogithub.com/twmb/franz-go/plugin/kotelv1.7.0go.mod
Gogithub.com/yosida95/uritemplate/v3v3.0.2go.mod
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0go.mod
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0go.mod
Gogo.opentelemetry.io/contrib/processors/baggagecopyv0.16.1go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogolang.org/x/cryptov0.54.0go.mod
Gogolang.org/x/netv0.57.0go.mod
Gogolang.org/x/sysv0.47.0go.mod
Gogolang.org/x/termv0.45.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogithub.com/heimdalr/dagv1.5.1go.mod
Gogithub.com/tsarna/url-cty-funcsv0.2.0go.mod
Gogithub.com/tsarna/vinculum-fsmv0.5.1go.mod
Gogithub.com/zclconf/go-ctyv1.19.0go.mod
All dependencies 169

Full resolved dependency set from the GitHub dependency graph: 72 direct and 97 indirect (transitive) packages. The transitive closure is complete when the repository commits a lockfile.

RegistryPackageVersionRelation
Gogithub.com/alicebob/miniredis/v2v2.38.0direct
Gogithub.com/aws/aws-sdk-go-v2v1.43.0direct
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.31direct
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.30direct
Gogithub.com/aws/aws-sdk-go-v2/service/snsv1.42.0direct
Gogithub.com/aws/aws-sdk-go-v2/service/sqsv1.46.0direct
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.45.0direct
Gogithub.com/coder/websocketv1.8.15direct
Gogithub.com/fsnotify/fsnotifyv1.10.1direct
Gogithub.com/go-git/go-git/v5v5.19.1direct
Gogithub.com/go-sql-driver/mysqlv1.10.0direct
Gogithub.com/hashicorp/go-cty-funcsv0.1.0direct
Gogithub.com/hashicorp/hcl/v2v2.24.0direct
Gogithub.com/heimdalr/dagv1.5.1direct
Gogithub.com/itchyny/gojqv0.12.19direct
Gogithub.com/jackc/pgx/v5v5.10.0direct
Gogithub.com/jmoiron/sqlxv1.4.0direct
Gogithub.com/lestrrat-go/jwx/v2v2.1.7direct
Gogithub.com/mattn/go-sqlite3v1.14.48direct
Gogithub.com/modelcontextprotocol/go-sdkv1.6.1direct
Gogithub.com/prometheus/client_golangv1.24.1direct
Gogithub.com/rabbitmq/amqp091-gov1.13.0direct
Gogithub.com/redis/go-redis/v9v9.20.0direct
Gogithub.com/robfig/cron/v3v3.0.1direct
Gogithub.com/sashabaranov/go-openaiv1.41.2direct
Gogithub.com/sosodev/durationv1.4.0direct
Gogithub.com/spf13/cobrav1.10.2direct
Gogithub.com/stretchr/testifyv1.11.1direct
Gogithub.com/tsarna/barcode-cty-funcv0.2.0direct
Gogithub.com/tsarna/bytes-cty-typev0.3.0direct
Gogithub.com/tsarna/functyv0.12.0direct
Gogithub.com/tsarna/geo-cty-funcsv0.4.0direct
Gogithub.com/tsarna/go-structdiffv0.2.1direct
Gogithub.com/tsarna/go2cty2gov0.3.0direct
Gogithub.com/tsarna/hcl-jqfuncv0.1.4direct
Gogithub.com/tsarna/rand-cty-funcsv0.2.0direct
Gogithub.com/tsarna/rich-cty-typesv0.5.1direct
Gogithub.com/tsarna/sqid-cty-funcsv0.2.0direct
Gogithub.com/tsarna/time-cty-funcsv0.4.0direct
Gogithub.com/tsarna/url-cty-funcsv0.2.0direct
Gogithub.com/tsarna/vinculum-busv0.15.1direct
Gogithub.com/tsarna/vinculum-fsmv0.5.1direct
Gogithub.com/tsarna/vinculum-kafkav0.11.0direct
Gogithub.com/tsarna/vinculum-mqttv0.9.0direct
Gogithub.com/tsarna/vinculum-rabbitmqv0.2.0direct
Gogithub.com/tsarna/vinculum-redisv0.4.0direct
Gogithub.com/tsarna/vinculum-snsv0.3.0direct
Gogithub.com/tsarna/vinculum-sqsv0.4.0direct
Gogithub.com/tsarna/vinculum-vwsv0.13.0direct
Gogithub.com/tsarna/vinculum-wirev0.4.0direct
Gogithub.com/twmb/franz-gov1.21.5direct
Gogithub.com/twmb/franz-go/pkg/kfakev0.0.0-20260721222903-95f7d9a51d6adirect
Gogithub.com/twmb/franz-go/plugin/kotelv1.7.0direct
Gogithub.com/yosida95/uritemplate/v3v3.0.2direct
Gogithub.com/zclconf/go-ctyv1.19.0direct
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0direct
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0direct
Gogo.opentelemetry.io/contrib/processors/baggagecopyv0.16.1direct
Gogo.opentelemetry.io/otelv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0direct
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0direct
Gogo.opentelemetry.io/otel/metricv1.44.0direct
Gogo.opentelemetry.io/otel/sdkv1.44.0direct
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0direct
Gogo.opentelemetry.io/otel/tracev1.44.0direct
Gogo.uber.org/zapv1.28.0direct
Gogolang.org/x/cryptov0.54.0direct
Gogolang.org/x/netv0.57.0direct
Gogolang.org/x/sysv0.47.0direct
Gogolang.org/x/termv0.45.0direct
Gogoogle.golang.org/protobufv1.36.11direct
Godario.cat/mergov1.0.0indirect
Gofilippo.io/edwards25519v1.2.0indirect
Gogithub.com/agext/levenshteinv1.2.1indirect
Gogithub.com/amir-yaghoubi/mqttpatternv0.0.0-20250829083210-f7d8d46a786eindirect
Gogithub.com/apparentlymart/go-cidrv1.1.0indirect
Gogithub.com/apparentlymart/go-textseg/v15v15.0.0indirect
Gogithub.com/apparentlymart/go-textseg/v17v17.0.1indirect
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.31indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.31indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.31indirect
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.32indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.13indirect
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.31indirect
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.5.0indirect
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.33.0indirect
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.38.0indirect
Gogithub.com/aws/smithy-gov1.27.3indirect
Gogithub.com/beorn7/perksv1.0.1indirect
Gogithub.com/bmatcuk/doublestarv1.3.4indirect
Gogithub.com/boombuler/barcodev1.1.0indirect
Gogithub.com/cenkalti/backoff/v5v5.0.3indirect
Gogithub.com/cespare/xxhash/v2v2.3.0indirect
Gogithub.com/chzyer/readlinev1.5.1indirect
Gogithub.com/cloudflare/circlv1.6.3indirect
Gogithub.com/cyphar/filepath-securejoinv0.6.1indirect
Gogithub.com/davecgh/go-spewv1.1.1indirect
Gogithub.com/decred/dcrd/dcrec/secp256k1/v4v4.4.1indirect
Gogithub.com/eclipse/paho.golangv0.23.0indirect
Gogithub.com/emirpasic/godsv1.18.1indirect
Gogithub.com/felixge/httpsnoopv1.0.4indirect
Gogithub.com/go-git/gcfgv1.5.1-0.20230307220236-3a3c6141e376indirect
Gogithub.com/go-git/go-billy/v5v5.9.0indirect
Gogithub.com/go-logr/logrv1.4.3indirect
Gogithub.com/go-logr/stdrv1.2.2indirect
Gogithub.com/goccy/go-jsonv0.10.6indirect
Gogithub.com/golang/geov0.0.0-20260713102120-857a528af641indirect
Gogithub.com/golang/groupcachev0.0.0-20241129210726-2c02b8208cf8indirect
Gogithub.com/google/go-cmpv0.7.0indirect
Gogithub.com/google/jsonschema-gov0.4.3indirect
Gogithub.com/google/uuidv1.6.0indirect
Gogithub.com/gorilla/websocketv1.5.3indirect
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0indirect
Gogithub.com/inconshreveable/mousetrapv1.1.0indirect
Gogithub.com/itchyny/timefmt-gov0.1.8indirect
Gogithub.com/jackc/pgpassfilev1.0.0indirect
Gogithub.com/jackc/pgservicefilev0.0.0-20240606120523-5a60cdf6a761indirect
Gogithub.com/jackc/puddle/v2v2.2.2indirect
Gogithub.com/jbenet/go-contextv0.0.0-20150711004518-d14ea06fba99indirect
Gogithub.com/kevinburke/ssh_configv1.2.0indirect
Gogithub.com/kixorz/suncalcv1.0.0indirect
Gogithub.com/klauspost/compressv1.19.1indirect
Gogithub.com/klauspost/cpuid/v2v2.3.0indirect
Gogithub.com/lestrrat-go/blackmagicv1.0.4indirect
Gogithub.com/lestrrat-go/httpccv1.0.1indirect
Gogithub.com/lestrrat-go/httprcv1.0.6indirect
Gogithub.com/lestrrat-go/iterv1.0.2indirect
Gogithub.com/lestrrat-go/optionv1.0.1indirect
Gogithub.com/microsoft/go-winiov0.6.2indirect
Gogithub.com/mitchellh/go-homedirv1.1.0indirect
Gogithub.com/mitchellh/go-wordwrapv1.0.1indirect
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822indirect
Gogithub.com/natemcintosh/geographiclib-gov0.1.0indirect
Gogithub.com/nathan-osman/go-sunrisev1.1.0indirect
Gogithub.com/pierrec/lz4/v4v4.1.26indirect
Gogithub.com/pjbgf/sha1cdv0.6.0indirect
Gogithub.com/pmezard/go-difflibv1.0.0indirect
Gogithub.com/prometheus/client_modelv0.6.2indirect
Gogithub.com/prometheus/commonv0.70.1indirect
Gogithub.com/prometheus/otlptranslatorv1.0.0indirect
Gogithub.com/prometheus/procfsv0.21.1indirect
Gogithub.com/protonmail/go-cryptov1.1.6indirect
Gogithub.com/segmentio/asmv1.2.1indirect
Gogithub.com/segmentio/encodingv0.5.4indirect
Gogithub.com/sergi/go-diffv1.3.2-0.20230802210424-5b0b94c5c0d3indirect
Gogithub.com/skeema/knownhostsv1.3.1indirect
Gogithub.com/spf13/pflagv1.0.10indirect
Gogithub.com/sqids/sqids-gov0.4.1indirect
Gogithub.com/twmb/franz-go/pkg/kmsgv1.13.1indirect
Gogithub.com/xanzy/ssh-agentv0.3.3indirect
Gogithub.com/yuin/gopher-luav1.1.1indirect
Gogo.opentelemetry.io/auto/sdkv1.2.1indirect
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0indirect
Gogo.opentelemetry.io/otel/logv0.20.0indirect
Gogo.opentelemetry.io/otel/sdk/logv0.20.0indirect
Gogo.opentelemetry.io/proto/otlpv1.10.0indirect
Gogo.uber.org/atomicv1.11.0indirect
Gogo.uber.org/multierrv1.10.0indirect
Gogolang.org/x/modv0.37.0indirect
Gogolang.org/x/oauth2v0.36.0indirect
Gogolang.org/x/syncv0.22.0indirect
Gogolang.org/x/textv0.40.0indirect
Gogolang.org/x/toolsv0.47.0indirect
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaaindirect
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260526163538-3dc84a4a5aaaindirect
Gogoogle.golang.org/grpcv1.82.1indirect
Gogopkg.in/warnings.v0v0.1.2indirect
Gogopkg.in/yaml.v3v3.0.1indirect
Dependency advisories 1

This repository publishes no package the index resolves, so its own dependency graph was assessed — 169 packages, which also include development and test pins that never ship: 1 carry known advisories, of which 1 are direct.

PackageVersionRelationSeverityAdvisoriesFixed in
golang.org/x/cryptov0.54.0directunknown1

An advisory means the version recorded in the dependency graph falls inside an advisory’s affected range. Reachability is not analysed, and the graph includes development and test pins — a finding may concern tooling rather than shipped software.

Raw JSON report machine-readable
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2701,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 2078879,
        "VCL": 4396,
        "Shell": 5134,
        "Python": 2973,
        "Dockerfile": 3294
      },
      "pushed_at": "2026-07-25T15:18:53Z",
      "created_at": "2025-08-28T16:32:56Z",
      "owner_type": "User",
      "updated_at": "2026-07-25T15:19:19Z",
      "description": "A low-code, mostly-declarative system for gluing together different systems and bridging multiple protocols",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Ty Sarna",
      "type": "User",
      "login": "tsarna",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/630146?v=4",
      "created_at": "2011-02-21T15:36:43Z",
      "is_verified": null,
      "public_repos": 48,
      "account_age_days": 5633
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2026-07-24T15:50:05Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2026-07-19T02:17:12Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2026-06-27T21:33:19Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2026-06-20T02:07:07Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2026-06-16T20:54:10Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2026-06-12T21:41:04Z"
        },
        {
          "tag": "v0.38.1",
          "kind": "patch",
          "published_at": "2026-06-12T21:35:51Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2026-06-04T15:33:05Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "cf898f4c5a43def1f49f7dbbcf217052e74ee30c",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/lestrrat-go/jwx/v4 to v4.2.0 (#153)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-25T15:18:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c52fea5e3bc958397ce5c328c8a907ea7ed87d8c",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/prometheus/client_golang to v1.24.1 (#152)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-25T15:18:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "645f3b7a279d13735861585940c45211e5fc1bc4",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/lestrrat-go/jwx/v2 to v4 (#128)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-24T17:57:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b317b0d9cf4c6ba8bf8c64a5fe1e0fc4b3c20b6",
          "body": "Run the functy `test` blocks embedded in a configuration's .cty files\nagainst a booted runtime, so they can reference bus/client/server, send()\nmessages, and assert on the resulting state.\n\n- sys.testing ambient bool (Config.Testing / WithTesting), so a config can\n  gate real external I/O off under \n[…]\ntest file passed by path is not parsed as VCL.\n- doc/testing.md and config integration tests + fixtures.\n\nBumps functy to v0.12.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add `vinculum test` command",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-24T17:31:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee2e723a6428936fe498ff0d2f841cbd07b93209",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/tsarna/vinculum to v0.44.0 (#151)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-24T15:03:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba0a4c7a3cbc52318f52b358104901f15c940cd2",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/rabbitmq/amqp091-go to v1.13.0 (#150)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-24T15:03:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "058fac734e6f0843c38f6ed66fe7eac41f3e58e1",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/sqs to v1.46.0 (#149)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-24T15:02:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8412f84c9c4f5b907af9ada7f49619b750a7ff31",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/sns to v1.42.0 (#148)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-23T20:31:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74f214adc8d7e7420d72d0d54f65fef549f0dba2",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/config to v1.32.31 (#147)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-23T02:57:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40f3f6bb3e63471520a25fe4d55288002f489d60",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update github.com/twmb/franz-go/pkg/kfake digest to 95f7d9a (#146)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-23T02:57:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "717c1d4aedade8ddb7b0f2f40a406b6d0824f8c7",
          "body": "Format config and functy source by extension: .vcl/.vinit as HCL (via\nhclwrite, 2-space like `terraform fmt`) and .cty as functy source (via a\nparser configured with Vinculum's registered named types). A file that\ndoes not parse is reported and left byte-for-byte unchanged — formatting\nnever drops o\n[…]\nit so read-only tooling can\nload plugins without cloning git blocks). Adds a printDiags helper for\nsource-context error rendering.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add `vinculum fmt` command",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-23T02:39:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "527c514537b589ed677f5022f614b2872aa1875b",
          "body": "Add a CHANGELOG [Unreleased] entry and a README \"Or run the binary\ndirectly\" section covering the new release archives and Homebrew cask\n(brew install tsarna/tap/vinculum), noting the container remains the\nrecommended deployment and that the static binaries lack plugin/SQLite\nsupport.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: document prebuilt binaries and Homebrew install",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-23T02:19:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fd0b5d2f558012fc90fd9c74ae8fec98eb87efbb",
          "body": "The smoke test's `go mod tidy` verified the just-pushed vinculum\npseudo-version against sum.golang.org, which intermittently 500s (and can\nlag) on a fresh commit — failing the release gate for no real reason. Set\nGOPRIVATE=github.com/tsarna/vinculum in the build container so it fetches\nour module directly and skips the sumdb, matching the Dockerfile's\nexisting rationale.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CI: harden plugin-smoke against sumdb flakiness",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-23T01:49:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4254714ce058878ac226bb62d7b5b7a5a3af4137",
          "body": "Cut cross-compiled binary archives (linux/darwin, amd64/arm64) with\nchecksums on every vX.Y.Z tag, and publish a Homebrew cask to\ntsarna/homebrew-tap (brew install tsarna/tap/vinculum), mirroring functy.\n\nBinaries are CGO_ENABLED=0 static builds (like the minimal Docker image):\nno plugin loading and\n[…]\nsourced from the matching CHANGELOG.md section. Requires\na HOMEBREW_TAP_GITHUB_TOKEN repo secret (as functy has) for the tap push.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add GoReleaser binary + Homebrew releases",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-22T20:00:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02292989fcc32f5e38a033e3c32a47c69a3f03c1",
          "body": "Avoid sharing the base name \"build\" with ci.yml's required status check.\nCosmetic only; matrix contexts were already distinct.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CI: rename Docker matrix job to docker-build",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-22T19:43:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8b7d93cbdb73b12dd9e89a1f0fe5e74274af0a5e",
          "body": "The Docker workflow built all three images (alpine, minimal, build) for\nlinux/amd64,linux/arm64 sequentially in one job, with arm64 under QEMU\nemulation — ~50 minutes per run. Restructure into the standard\nbuild-by-digest → merge-manifest pattern: 6 legs (3 images × 2 arches)\nbuild concurrently on n\n[…]\ntagged\nmulti-arch manifest. Also switch cache-to to mode=max for better layer\nreuse. No Dockerfile, test, or tag/platform changes.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CI: build Docker images on native arm64 runners",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-22T19:32:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "caf5aa595dcfe866cfabfde602fd6677a63a4e93",
          "body": "Fix the stated license (MIT -> Apache 2.0), add a Getting Started section\n(container deployment, weather-mcp example, git-sourced config), and round\nout Related Projects with functy, vinculum-wire, and the missing cty helper\nlibraries. Cut the 0.44.0 changelog entry.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Prepare 0.44.0 release: README polish and changelog",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-22T15:16:31Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2b9f89033100076ccb3203fcbcf6e04070a4897d",
          "body": "Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.81.1 to 1.82.1.\n- [Release notes](https://github.com/grpc/grpc-go/releases)\n- [Commits](https://github.com/grpc/grpc-go/compare/v1.81.1...v1.82.1)\n\n---\nupdated-dependencies:\n- dependency-name: google.golang.org/grpc\n  dependency-version: 1.82.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#145)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T12:00:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4eb8b7767c522164c718bfb1cf10b5586a53d77e",
          "body": "Implement a schema-driven \"protobuf\" wire_format that decodes Protocol\nBuffers binary into VCL values and encodes them back, driven by a compiled\nFileDescriptorSet. It is the first block-based wire format in the tree\n(RegisterWireFormatType previously had no callers).\n\nNew package wireformats/protob\n[…]\no with a real protoc and\ndrives the full config pipeline over wire::serialize / wire::deserialize;\nit skips when protoc is absent.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add protobuf wire format",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-22T02:53:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0b6d0cc1e76c1855bf0713b6382a35267b8afe49",
          "body": "CtyWireFormat carried a rawBytesFromCty helper so that a bytes value sent\nback out reached the wire format as raw []byte rather than being\nflattened into its object attributes by CtyToAny. That was a workaround\nfor go2cty2go having no way to let a capsule control its own native\nform.\n\ngo2cty2go v0.3\n[…]\nayer cannot depend on bytes-cty-type to do otherwise, so that\npromotion stays here.\n\nBumps go2cty2go and bytes-cty-type to v0.3.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Convert bytes payloads via the go2cty2go interfaces",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-21T18:26:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8e138c1aa00e576f83291896ad8d84014f73ac7d",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/prometheus/client_golang to v1.24.0 (#143)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-21T18:07:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abd12225f47b71721656d1155420dc4153602727",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update actions/setup-python action to v7 (#144)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-21T18:04:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6290860ec31033ec37c0e6cb81d6d2f50420c09e",
          "body": "Every messaging receiver (rabbitmq, mqtt, kafka, sqs, redis pub/sub,\nredis stream) used to swallow a deserialize failure: log a warning,\nsubstitute the raw bytes for the payload, and deliver the message\nanyway — even when the config explicitly said wire_format = \"json\".\nThere was no way to say \"mess\n[…]\nregardless of its values.\n\nDocs and CHANGELOG updated; CHANGELOG stays under [Unreleased] pending\nfurther work before the release.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strict wire-format decoding with on_decode_error hook",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-20T21:15:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0d06c0f223437742d8925f713ce438fb25a5ee3c",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update actions/setup-go action to v7 (#140)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T20:31:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a42992a21542c6a97cb3de700aaedc21a3e1b396",
          "body": "The user-facing plugin doc named two Register* functions followed by\n\"etc.\" and never listed the rest, so the only complete list lived in the\nvinculum-plugin-example README -- a different repository.\n\nAdd an \"Extension points\" section under \"Writing a Plugin\" with all 13,\nand point the summary bulle\n[…]\nmitations rather than restating what\nplugins cannot do.\n\nNo CHANGELOG entry: this documents existing API, and changes no behavior.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "doc/plugins.md: document the Register* extension points",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T16:02:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ac28a18e09080392869e47e65563e6b04a0e2b3",
          "body": "The list named 9 of the 13 Register* contribution points, missing the\nthree functy hooks added in 0.43.0 (RegisterFunctyType,\nRegisterFunctyOpenType, RegisterFunctyExterns) and\nRegisterConditionalTriggerType, which has existed since v0.21.0.\n\nconfig/functy.go says outright that the functy type-regis\n[…]\n rather than a contribution\npoint, and cross-reference the vinculum-plugin-example README, which\ncarries the same list as a table.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CLAUDE.md: complete the list of what plugins can register",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T15:57:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "032563549743c00d1ce51d33374a812ba8b52e51",
          "body": "Bump the plugin-smoke fixture's default vinculum require to v0.43.0. The\nrelease gate rewrites it to the exact ref being built, so this only\naffects local runs of the gate.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Prepare for 0.43.0",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T02:04:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e40900bfed16230f543bafc66473ff186e2f2023",
          "body": "The table predated several doc pages. Add functy.md, procedure.md,\ndeprecations.md, editor.md, fsm.md, trigger.md, metric.md,\nserver-metrics.md, server-auth.md, and a row covering the per-client\nreferences.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CLAUDE.md: refresh the doc/ table",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T01:48:19Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "615116f158750ee85ce0e1d17dc5d7fcd72ed34d",
          "body": "… links\n\n- Drop the dangling \"(new, see below)\" on the geopoint type; there was no\n  such entry below it.\n- The functy entry stated flatly that top-level var/const bindings fold\n  into Vinculum's own pools. Since namespace scoping landed that holds\n  only for unnamespaced files: a namespaced file sc\n[…]\nnresolved\n  reference. Repoint it at v0.42.0 and regenerate the missing definitions;\n  all referenced tags were verified to exist.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "CHANGELOG: correct Unreleased entries and restore the version compare…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T01:48:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dc3153706912a58c99adf714bc4458deca7c7c17",
          "body": "…laim\n\nReorganize: the file had 22 ### sections under a single catch-all\n\"## Utility Functions\" whose description (\"available in any expression\ncontext\") applied to essentially all of them. Group them under themed ##\nheadings and add a table of contents. Control Flow and Reflection now\nlead instead \n[…]\no\n  separately parsed timestamps for the same instant are equal. Both\n  behaviors verified against the pinned dependency versions.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: reorganize functions.md, and fix stale names and a comparison c…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T01:47:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d13b48731880ed2e1095530ad611a9712a0dd48",
          "body": "Three anchors still pointed at the pre-namespacing heading slugs and no\nlonger resolved:\n\n  functions.md#mcp_image-data--mime_type -> #mcpimagedata--mime_type\n  client-http.md#http_must               -> #status-assertions-httpmust\n\nserver-auth.md described auth action results as an \"http_response /\n\n[…]\n but http_redirect was a function, now http::redirect, so\nthe pairing no longer named anything. Reworded to name the constructors.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: fix stale cross-references left by the function namespacing",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-19T01:47:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9f1d4ad779ffdf0d06e32aae2caf4ea76aead10c",
          "body": "Every function in the example was hand-prefixed voipms_*, which is exactly\nwhat a functy namespace provides. Declare `namespace voipms` in all four\n.cty files and drop the manual prefix:\n\n- Siblings now call each other by bare name (get_balance(ctx, true) inside\n  scrape_balance_metrics), which is t\n[…]\n_* names leak into the global map. (Note `vinculum\ncheck` alone does not catch this class of error — trigger action expressions\nare evaluated lazily, so a bad function name there still reports valid.)",
          "is_bot": false,
          "headline": "examples/voipms: use a `voipms` namespace for the .cty functions",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-18T19:20:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b74b1a28d1f70470151912564a0260489f3b8dd2",
          "body": "Add sys.functy.version to the sys ambient, reporting the version of the\nbundled functy (.cty) language. A library can't inject its own version via\n-ldflags the way the functy CLI's main package does, so read it from\nruntime/debug build info instead: new version.ModuleVersion(path) looks the\ndependen\n[…]\nbuild_time),\nnever per-dependency.\n\nAlso documents the previously-undocumented build-identity group in the\nsys.* reference (version, commit, build_time, modified) alongside the new\nsys.functy.version.",
          "is_bot": false,
          "headline": "Expose bundled functy version as sys.functy.version",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-18T18:48:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f02a43f9441c24d891e24edbc39f97c527983313",
          "body": "…tary\n\nProcedures are deprecated in favor of functy, so the public docs no longer\npresent them as a feature to reach for:\n\n- README.md / overview.md: the \"Transformations and Procedures\" feature bullet\n  becomes \"Transformations and Scripting\", pointing at functy; the DNS-updater\n  example descripti\n[…]\ndeprecation-flagged. wire_format is\ndescribed accurately as a plugin extension point (no built-in types are\nregistered in-tree; the built-in formats are selected via a client's\nwire_format attribute).",
          "is_bot": false,
          "headline": "docs: repoint procedure references to functy; reframe jq as complemen…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-18T18:48:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1f4f31a6606c3741cc6e28d24fd8efa94b7d9c7c",
          "body": "Adopt functy v0.11.0's per-namespace const/value plumbing. A namespaced\n.cty file's top-level const now belongs to that namespace instead of\nbeing folded flat into the shared const surface, so two namespaces may\neach declare `const greeting` without colliding.\n\nPolicy (mirrors the functy CLI and sym\n[…]\n new Namespaces section in doc/functy.md. Tests cover namespaced\nscoping/no-collision/own+global and the namespaced-var rejection.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Namespace-scope functy consts; reject namespaced functy vars",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-18T18:48:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "93e4dd7fd57d906ed645ccc2d22f540d285d5ed0",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update github.com/twmb/franz-go/pkg/kfake digest to dd56926 (#139)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-18T02:57:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c0b3054a8974b6912446143ec1fb0d352103606",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/sqs to v1.45.1 (#137)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-18T02:45:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "463040c51a669dc8a2d8a21e18fe45a108500461",
          "body": "…ion surface\n\nBump functy to v0.10.0 and the cty sibling packages to their new releases, and build on\nwhat they add. help() and doc() are wired in (new reflect plugin). Every package that\nprovides functions cty cannot fully describe now registers //functy:extern declarations\nalongside it, and the ge\n[…]\n flat (Terraform/OpenTofu stdlib\ncompatibility), as do diff, patch, kill, help, and doc. A guard test keeps the metadata\ncomplete.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Adopt functy externs and reflection; complete and namespace the funct…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-16T02:05:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0fed8c947359c7c9ffbc6e96e2eb03881baedfbb",
          "body": "Vinculum had no reflection at all: no way, from VCL or the REPL, to ask what a\nfunction is or what its arguments mean. help(\"f\") now returns a function's\nsignature, description, and per-parameter docs; help() with no argument lists\nevery callable name; doc(\"f\") returns just the description.\n\nhelp() \n[…]\nno .cty sources: the Result carries the host externs, and help() needs them\nwhether or not the user wrote any functy of their own.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add help() and doc(), and register rich-cty-types' extern declarations",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-16T02:02:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "924b85dafb3e87281f23846460c4d319c58d1c9e",
          "body": "Update the block-types list to the current set: add condition, editor, fsm,\nmetric, procedure, trigger, var, and wire_format; drop the standalone cron and\nsignals entries and note they are trigger types (trigger \"cron\"/\"signals\"), and\nthat function/jq/editor/procedure are function-definition blocks extracted early\nin Build().\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refresh the VCL block-type reference in CLAUDE.md",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-16T02:02:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b23f3b596eae157ea41d8e8cde6c29b862746613",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/sns to v1.41.1 (#136)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-15T15:53:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7ba3efe6eaf134360d131d23d20f96af7cb8c74",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/config to v1.32.30 (#135)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-14T22:23:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fa8cbb21defe4d686b884ef7c294353ea08470b",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/mattn/go-sqlite3 to v1.14.48 (#134)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-14T17:52:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "044ce8f850b322ff00d84865580e818a0e6ecc0f",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module golang.org/x/net to v0.57.0 (#131)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-12T16:52:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed8a43adab78e5a47c050bd45269ba8ba776cf4b",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/tsarna/functy to v0.9.0 (#126)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-11T17:35:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "971c77c26cc79ad63b8b80423e8aaf9b958677b5",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module golang.org/x/crypto to v0.54.0 (#130)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-11T17:29:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "695a960dc596db2b5252b72119e8015d51bd3cf6",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/config to v1.32.29 (#129)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-11T17:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab959554df8d594ac396d01cef5eab11d7ecd455",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module golang.org/x/term to v0.45.0 (#133)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-11T17:12:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49b85bd950143946d25439c552a293d14202e34e",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/zclconf/go-cty to v1.19.0 (#127)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T21:33:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae68e8f76aa6b6da54c4f1bd26ca4c998c15aff1",
          "body": "Refactor the interactive REPL (serve -i) to consume the generic engine now\nshipped in github.com/tsarna/functy/repl (v0.7.0) rather than carrying its own\ncopy. The generic loop, result history, session bindings, meta-command\ndispatch, multi-line accumulation, value formatting, and tab-completion all\n[…]\n expressions still evaluate as HCL against the running\nconfiguration, with identical output, history, completion, and log control.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Build the REPL on functy's repl engine",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T21:18:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c2a6548f53953f2b10bf6ac68fb78f86fd19426f",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/lestrrat-go/jwx/v2 to v4 (#115)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T21:10:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b6455f4932e489c3389c6c16f56e271972009f6",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/sqs to v1.45.0 (#122)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T21:07:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48179d82e447b51342fa33674ec0afc004856432",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/service/sns to v1.41.0 (#120)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T20:57:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0db90f20326840a96e85ce47f75b62f3e3210236",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/twmb/franz-go to v1.21.5 (#125)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T20:56:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "109a641cc26390eb38697888a0a2aa628cf27f87",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/aws/aws-sdk-go-v2/config to v1.32.28 (#117)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T20:30:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e686e4da705348bee57cbd04fba8c05df8697b68",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update github.com/twmb/franz-go/pkg/kfake digest to 0aa5aa6 (#119)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-07T20:21:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f78854a60e3fee8afad978a4c713072e10fb2c5",
          "body": "functy 0.5.0 allows multi-line function signatures and captures a leading\n//-comment block directly above a declaration as its documentation (with\nper-parameter trailing docs in the multi-line layout).\n\n- go.mod/go.sum: functy v0.4.0 -> v0.5.0\n- dns-zone-updater.cty: doc comment now sits immediately\n[…]\nnd func.\n\ngo build ./... and go test ./... pass; vinculum check on both example groups\nreports valid with no deprecation warnings.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump functy to 0.5.0; adopt its doc-comment conventions in examples",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-04T00:04:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "38402fa577660c38ac53154f0d0a1004cd827f17",
          "body": "…ubdirs\n\nThe procedure block is deprecated in favor of functy (.cty) files, so convert\nevery example that used one:\n\n- dns-zone-updater: update_dns() moved to a .cty function; example is now its\n  own directory (dns-zone-updater/) so the .vcl and .cty share a namespace.\n- voipms: the three scrape pr\n[…]\nupdate the example READMEs\n(paths, functy links, .cty file list). All examples pass `vinculum check` with\nno deprecation warnings.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Port procedure-block examples to functy; move dns/mcp examples into s…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-03T20:13:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d974699b75acc8a47781f837c2011ce3f70b8624",
          "body": "A configuration directory may now contain functy source files (.cty) alongside\nits .vcl files. functy is a small expression/statement language with real syntax\nfor functions, typed locals, reassignment, branching, loops, try/catch, and\nstructured errors — a more expressive alternative to `function`,\n[…]\n\n\nDocs: new doc/functy.md and doc/deprecations.md; updates to config.md,\noverview.md, procedure.md, functions.md; CHANGELOG entry.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Integrate the functy (.cty) language",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-07-03T19:08:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5ff8c67dec8cfbb279807139fc58407df1158fdc",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/tsarna/vinculum to v0.42.0 (#116)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-29T02:49:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60f2e52a43d12968427b055ad928d0db78789216",
          "body": null,
          "is_bot": false,
          "headline": "Prepare for 0.42.0",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T20:12:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c52b47e9eed9cdcd916d4e09e95c43d92bac85fd",
          "body": "Extend the secure-by-default baggage trust filter to client \"redis_stream\"\nconsumers. Reuses the NewBaggageFilterSubscriber wrapper added for the other\ntransports.\n\n- Add an optional baggage {} block to redis_stream consumer blocks (per\n  consumer), validated like the other surfaces, and wrap each c\n[…]\na)\nasserts the action's ctx.baggage for the strip/allow/passthrough cases. Docs\nupdated in doc/client-redis.md and doc/baggage.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strip untrusted inbound baggage on Redis stream consumers by default",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T17:15:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "581a6b8a55ca8980e541f6173449bfc4ce110d85",
          "body": "Extend the secure-by-default baggage trust filter to client \"sqs_receiver\".\nReuses the NewBaggageFilterSubscriber wrapper added for the other transports.\n\n- Add an optional baggage {} block to client \"sqs_receiver\" (per client),\n  validated like the other surfaces, and wrap the resolved subscriber w\n[…]\ns cover end-to-end parsing of the baggage block and the allow+deny\nconflict. Docs updated in doc/client-sqs.md and doc/baggage.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strip untrusted inbound baggage on SQS receivers by default",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T14:08:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1fd28a5d5ae7e5f011904cb7d43b452fb733cc33",
          "body": "Extend the secure-by-default baggage trust filter to MQTT consumers. Reuses\nthe NewBaggageFilterSubscriber wrapper added for Kafka/RabbitMQ.\n\n- Add an optional baggage {} block to client \"mqtt\" receiver blocks\n  (per-receiver), validated like the other surfaces, and wrap each receiver's\n  subscriber\n[…]\nd-to-end parsing of the receiver baggage block and the\nallow+deny conflict. Docs updated in doc/client-mqtt.md and doc/baggage.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strip untrusted inbound baggage on MQTT receivers by default",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T14:01:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "18a020b3b317971cd6c7088ac00cdad9a5b89736",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/twmb/franz-go/plugin/kotel to v1.7.0 (#113)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T13:59:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b239674569d85bed26e7a82f146b05683147db54",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/twmb/franz-go to v1.21.4 (#112)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T13:58:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0a2cb04d842913452e6074f09a6485c09358806",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/lestrrat-go/jwx/v2 to v4 (#110)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-27T13:31:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6590654a2187628d02e7598266025a12556c7202",
          "body": "Same moved-tag checksum problem as vinculum-bus: the v0.2.0 tag was moved\nafter publication, so its content no longer matched the Go checksum\ndatabase and CI failed `go build` with a checksum mismatch SECURITY\nERROR. v0.2.0 is poisoned in the sumdb; v0.2.1 is a clean re-release with\nthe same API.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump vinculum-wire to v0.2.1",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-26T22:38:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5369e809d94f47932b8f94e1627e2ab7f7aa3db2",
          "body": "The v0.15.0 tag was moved after publication, so its content no longer\nmatched the hash recorded in the Go checksum database. CI fell back to a\ndirect GitHub fetch of the moved tag and failed `go build` with a\nchecksum mismatch SECURITY ERROR. v0.15.0 is permanently poisoned in the\nsumdb; v0.15.1 is a clean re-release with the same API.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bump vinculum-bus to v0.15.1",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-26T22:15:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dcd3bb8a7cb7d0b80baab6f8ed1c32f619dd3bb5",
          "body": "Self-contained integration test using franz-go's in-process kfake broker\n(no external infrastructure). Produces a Kafka record carrying a baggage\nheader and consumes it through a real vinculum kafka receiver, asserting\nthe action's ctx.baggage:\n\n- no baggage block         -> stripped (secure default\n[…]\nst-only dependency on github.com/twmb/franz-go/pkg/kfake (compiled\ninto test binaries only) and bumps franz-go v1.21.2 -> v1.21.3.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add kfake round-trip test for Kafka inbound baggage filtering",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-26T03:13:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "905914c277c3a691306168873a937c7b6eaa5a4d",
          "body": "Extend the secure-by-default baggage trust filter to RabbitMQ consumers,\nwhich (like Kafka) deliver inbound baggage into subscription actions today,\nunfiltered. Reuses the NewBaggageFilterSubscriber wrapper added for Kafka.\n\n- Add an optional baggage {} block to client \"rabbitmq\" receiver blocks\n  (\n[…]\n-end parsing of the receiver baggage block and the\nallow+deny conflict. Docs updated in doc/client-rabbitmq.md and doc/baggage.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strip untrusted inbound baggage on RabbitMQ receivers by default",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-26T00:05:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ef60e29592021ec20ff8cb6d653589e394f49030",
          "body": "Extend the secure-by-default baggage trust policy (already on server \"http\"\nand server \"mcp\") to Kafka consumers, which deliver inbound baggage into\nsubscription actions today, unfiltered.\n\n- Add a reusable NewBaggageFilterSubscriber wrapper (config) that applies a\n  BaggageFilterConfig to each even\n[…]\nblock (including the allow+deny\nconflict) through the real config builder. Docs updated in doc/client-kafka.md\nand doc/baggage.md.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Strip untrusted inbound baggage on Kafka receivers by default",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-25T23:35:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8d92eafe05ba396f84ceecc595b6c040f5137138",
          "body": "… projection)\n\nExpose request-scoped W3C baggage to VCL and let config trust, mutate,\nand project it:\n\n- ctx.baggage capsule: read with get(), write with set()/delete()/clear(),\n  plus length()/tostring(). Writes go through the handler's shared context\n  pointer, so later send()/http_*()/publish cal\n[…]\nking\ndelete(ctx.baggage, ...)).\n\nDocs in doc/baggage.md, cross-linked from server-http, server-mcp,\nclient-otlp, and the overview.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add OpenTelemetry Baggage support (ctx.baggage, trust filtering, span…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-25T22:19:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5c97530fe20395381195f6c7fef80bebdbd58355",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update actions/cache action to v6 (#111)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-24T15:18:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3398253331659858ba20eaa1665c1b0c7035c476",
          "body": "The weather MCP example now includes an env-toggled client \"otlp\" that\nthe HTTP and mounted MCP servers auto-wire to for OpenTelemetry traces\nand metrics. It is disabled by default (try(env.OTEL_EXPORTER_OTLP_ENDPOINT,\n\"\") == \"\"), keeping the example zero-config, and exports both signals when\nOTEL_E\n[…]\ntion). Documented `disabled`\non client \"otlp\" in doc/client-otlp.md, updated examples/README.md, and\nextended the CHANGELOG entry.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add optional OTLP telemetry to weather MCP example",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-24T15:14:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "610c97685294c5a8d6b396493618b6b6640e4a1d",
          "body": "Resource URI placeholders were flattened onto ctx directly (ctx.table,\nctx.id), while tool and prompt arguments have always been nested under\nctx.args. Pack resource template variables into ctx.args.<name> too, so\nall three handler kinds are consistent. ctx.args is now always present\n(empty object f\n[…]\nted\nthe docs, the weather-mcp example, the test fixture, and the test\nassertion, and noted the break in CHANGELOG.md [Unreleased].\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Expose MCP resource template vars under ctx.args",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-24T03:52:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90807b0310b60e3bceed55fe2bf24088014be63d",
          "body": "A worked `server \"mcp\"` (examples/weather-mcp.vcl) wrapping the free,\nno-API-key Open-Meteo service. Exposes live weather to an MCP client as\ntwo tools (current_weather, forecast), a templated resource\n(weather://current/{place}), and a trip_packing prompt — no env vars or\ncredentials required.\n\nThe\n[…]\nll arguments), and mcp_error()\nvs. a plain resource string.\n\nIndexed in examples/README.md and noted in CHANGELOG.md [Unreleased].\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add weather MCP server example",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-23T21:51:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "51f3234abc3244b646f516836133316c5fd29dab",
          "body": "…light example\n\nHCL cannot conditionally include a sub-block, so add an optional\ndisabled = <expr> attribute (evaluated against env.*) to the auth and\nreal_ip blocks, mirroring the existing toggle on server/files/handle.\nWhen disabled the block is parsed but inert: ValidateAuthConfig and\nBuildAuthen\n[…]\nFFIC_-prefixed env var\nboth supplies a value and toggles its feature (unset => disabled), and\nrename HTML_DIR to TRAFFIC_HTML_DIR.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add disabled attribute to auth and real_ip blocks; env-drive traffic-…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-22T21:40:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3440b9bcae78018a438df6e8b9ffbc5abd900070",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/mattn/go-sqlite3 to v1.14.47 (#107)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-22T20:11:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "992898a80634f20e6d936c1bc2ed12460c5b3c0b",
          "body": "The provider attribute reported in telemetry was hardcoded to \"openai\". Add an\noptional `provider` block attribute (default \"openai\") so OpenAI-compatible\nendpoints can report their real upstream — e.g. \"groq\", \"mistral_ai\", \"x_ai\",\n\"deepseek\" — as gen_ai.provider.name on both the span and the metrics.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make gen_ai.provider.name configurable on client \"openai\"",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-21T14:16:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "df24afb8181f4da74b4b8163770ea8f85ffe211a",
          "body": "The OpenAI client already had HTTP-level tracing (its transport was wrapped\nwith otelhttp), but the resulting span was a generic HTTP POST — no GenAI\nattributes, and no metrics at all.\n\nEach call() now creates a `gen_ai.inference` client span named `chat {model}`,\nwith the otelhttp HTTP span nesting\n[…]\nd, no-op when none. The dependency graph already extracts\nmetrics=/tracing= references, so backend ordering needs no extra wiring.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add OpenTelemetry GenAI metrics and spans to client \"openai\"",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-21T14:07:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ba0bbc44edc5df7def5da63513cff4351fede49",
          "body": "The MCP server predates the observability work, so it only had HTTP-level\notelhttp instrumentation. Add MCP-protocol-level telemetry via a single SDK\nreceiving middleware, so coverage is identical in standalone and HTTP-mounted\nmodes.\n\nEach inbound request/notification now produces an `mcp.server` s\n[…]\nrules as server \"http\"), with noop fallback. Session-duration\nmetrics are deferred — go-sdk v1.6.1 has no session-disconnect hook.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add OpenTelemetry tracing and metrics to server \"mcp\"",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-21T00:27:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7f8ae2facf558f5b2f0e256798ea25dfefc73d88",
          "body": "Recover the real client IP when running behind a reverse proxy or load\nbalancer, porting nginx's real_ip module. A real_ip sub-block takes:\n\n  - trusted_proxies (CIDRs or bare IPs)  -> set_real_ip_from\n  - header (default X-Forwarded-For)      -> real_ip_header\n  - recursive (default false)         \n[…]\n remote_addr to the request log fields, plus docs (including a\nTraefik redirectScheme note for HTTP->HTTPS) and changelog entries.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add real_ip block and remote_addr request log to server \"http\"",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-21T00:27:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f265a92237216e4c9a8a519e87aca3b57d73c9d5",
          "body": "Scope a handle or files block to a specific Host by prefixing its\nroute/urlpath label with a host, using Go 1.22's [METHOD ][HOST]/[PATH]\nServeMux pattern grammar. One listener can now serve multiple hosts plus\na host-less catch-all from a single server block. Host matching is exact\n(more-specific p\n[…]\nrn/safeMuxHandle helpers, unit and integration tests\n(host routing, files host-scoping, error cases), and doc + changelog\nupdates.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add virtual host support to server \"http\"",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-21T00:27:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "63ef4b4c1bd23bf95c18e2987307807c1e35c8e4",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/tsarna/vinculum to v0.41.0 (#109)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-20T15:35:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a90d5342a2a816b4ab0ed7e21cf30f4ddfd40f3",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/lestrrat-go/jwx/v2 to v4 (#105)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-20T15:34:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00764930a81aa8088075158d45e0c4a95a540ebd",
          "body": null,
          "is_bot": false,
          "headline": "Prepare for 0.41.0",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-20T00:57:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d49cceadf86e7f0eca7a99591f6ed0bdd3b3f944",
          "body": "Refresh the repository-layout map and the server/client registration\nguidance to match the current package structure (servers/, clients/,\ntriggers/, conditions/, registry-based RegisterServerType/\nRegisterClientType dispatch, rich-object capsule sources). Add a\ndoc/condition.md row to the documentation table, now covering the\ntimer/threshold/counter/flipflop subtypes.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update CLAUDE.md repository docs",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-19T23:38:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5daf02a9196d0cdffc64aad47f962f7402b3d37b",
          "body": "Implement a fourth condition subtype exposing the standard digital-logic\nbistables — T, SR, gated SR, D, D-latch, JK — through a uniform set of\n\"wire\" attributes, where the combination of declared wires names the\nvariant.\n\n- Event wires set_on/reset_on/toggle_on fire on a configurable edge\n  (rising\n[…]\nrs. Also documents the subtype in doc/condition.md, adds\na CHANGELOG entry, and refreshes the stale unknown-subtype error message.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add condition \"flipflop\" subtype",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-19T23:38:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "292504247e0cff7a9f1a1e0b9fef1a35c2947b80",
          "body": "Tab completion previously stopped at the dot. Now `env.`, `bus.`, `sys.`,\n`ctx.`, etc. complete the next segment against the attributes of whatever the\nleading path resolves to, at any depth through nested objects and maps.\n\nThe globals are already cty.Object values in the eval context, so their\nsec\n[…]\n attributes (_capsule, _ctx) and keys that aren't\nvalid identifiers. Capsule values (e.g. a specific bus) correctly offer nothing.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "REPL: complete nested attributes after a dot",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-19T23:38:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "51b133da53028cab9dc3f1407adba1493d53dd34",
          "body": "Add an interactive read-eval-print loop reached via `vinculum serve -i` /\n`--interactive`. After normal startup, instead of blocking on a signal, the\nserver presents a prompt that evaluates VCL expressions against the live,\nrunning configuration — the same eval context handler actions use, so `bus.*\n[…]\nextracted into a shared helper used by both the signal and\nREPL-exit paths. Adds github.com/chzyer/readline and golang.org/x/term.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add interactive REPL (serve -i)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-19T23:38:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1dc9af4bb3c50694024ddc78adea43a700ff1a4e",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update actions/checkout action to v7 (#108)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-19T17:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44513b2235de2370c6bd4599dd3ba6d1510286fe",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module golang.org/x/net to v0.56.0 (#103)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-19T17:17:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c098cd1a6b63ab210270da9d1f087cd6d04d797",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module golang.org/x/sys to v0.46.0 (#104)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-17T14:45:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94a2d3d628ecc49f4038c8d7cfeab1a323faa49b",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/rabbitmq/amqp091-go to v1.12.0 (#106)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-17T14:43:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e3e8c2d29d9c03083d8a042498ab79e61fd4a0d",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module github.com/coder/websocket to v1.8.15 (#102)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-17T14:41:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0854fcda2fb6130966a5d00cc5e390697b9fc6a7",
          "body": "Co-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module golang.org/x/crypto to v0.53.0 (#101)",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-17T14:40:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e50286f75422035ae853c39964e04c0423ae746c",
          "body": "…0 (#100)\n\nCo-authored-by: Renovate Bot <renovate@sarna.org>",
          "is_bot": false,
          "headline": "Update module go.opentelemetry.io/otel/exporters/prometheus to v0.66.…",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-17T14:40:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "602fa7fd395d52c1f7ee892737b5a23a03724f5d",
          "body": "- CHANGELOG: stamp [0.40.0] - 2026-06-13 (Postgres + MySQL SQL clients\n  completing the SQL dialect set; the ::-cast placeholder fix).\n- README: add \"SQL Databases\" key feature (Postgres/MySQL/SQLite via\n  get()/call()).\n- testdata/plugin-smoke/go.mod: point the local-run default at v0.40.0.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Release prep for 0.40.0: changelog, README feature, plugin-smoke pin",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-13T19:47:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5d4e3c134ac4dd7c8afd9ae16d578a9d5759f9e9",
          "body": "Third and final SQL dialect alongside SQLite and Postgres, sharing the\ndialect-agnostic engine, query sub-blocks, parameter syntax, result object,\nand get()/call() surface.\n\n- clients/sql/mysql: go-sql-driver/mysql (pure Go, no cgo — works in the\n  minimal image too). DSN built via the driver's own \n[…]\nt; a gated\n  (//go:build integration) live-DB suite.\n- Docs/overview/changelog updated; the \"MySQL forthcoming\" notes are removed.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add client \"mysql\" SQL dialect — completes the SQL feature",
          "author_name": "Ty Sarna",
          "author_login": "tsarna",
          "committed_at": "2026-06-13T18:28:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 8,
      "commits_last_year": 507,
      "latest_release_at": "2026-07-24T15:50:05Z",
      "latest_release_tag": "v0.44.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 25,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 7.1
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/tsarna/vinculum",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/tsarna/vinculum",
          "is_deprecated": false,
          "latest_version": "v0.44.0",
          "repository_url": "https://github.com/tsarna/vinculum",
          "versions_count": 48,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-22T15:16:31Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 3,
      "watchers": 1,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples",
        "sample"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [
        "wireformats/protobuf/testdata/orders.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "testdata/plugin-smoke/go.mod"
      ],
      "largest_source_bytes": 73014,
      "source_files_sampled": 328,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 27416
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/crypto",
            "direct": true,
            "version": "v0.54.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 17
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 169,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/tsarna/bytes-cty-type",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.0"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.28.0"
        },
        {
          "name": "github.com/alicebob/miniredis/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.38.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.31"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/credentials",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.30"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sns",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sqs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.46.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.45.0"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.15"
        },
        {
          "name": "github.com/fsnotify/fsnotify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.1"
        },
        {
          "name": "github.com/go-git/go-git/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.19.1"
        },
        {
          "name": "github.com/go-sql-driver/mysql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.0"
        },
        {
          "name": "github.com/hashicorp/go-cty-funcs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.0"
        },
        {
          "name": "github.com/hashicorp/hcl/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.24.0"
        },
        {
          "name": "github.com/itchyny/gojq",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.12.19"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.10.0"
        },
        {
          "name": "github.com/jmoiron/sqlx",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/lestrrat-go/jwx/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.1.7"
        },
        {
          "name": "github.com/mattn/go-sqlite3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.48"
        },
        {
          "name": "github.com/modelcontextprotocol/go-sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.1"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.24.1"
        },
        {
          "name": "github.com/rabbitmq/amqp091-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.13.0"
        },
        {
          "name": "github.com/redis/go-redis/v9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.20.0"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "github.com/sashabaranov/go-openai",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.41.2"
        },
        {
          "name": "github.com/sosodev/duration",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tsarna/barcode-cty-func",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/tsarna/functy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.12.0"
        },
        {
          "name": "github.com/tsarna/geo-cty-funcs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/tsarna/go-structdiff",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.1"
        },
        {
          "name": "github.com/tsarna/go2cty2go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.0"
        },
        {
          "name": "github.com/tsarna/hcl-jqfunc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.4"
        },
        {
          "name": "github.com/tsarna/rand-cty-funcs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/tsarna/rich-cty-types",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.1"
        },
        {
          "name": "github.com/tsarna/sqid-cty-funcs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/tsarna/time-cty-funcs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/tsarna/vinculum-bus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.15.1"
        },
        {
          "name": "github.com/tsarna/vinculum-kafka",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.11.0"
        },
        {
          "name": "github.com/tsarna/vinculum-mqtt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.0"
        },
        {
          "name": "github.com/tsarna/vinculum-rabbitmq",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/tsarna/vinculum-redis",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/tsarna/vinculum-sns",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.3.0"
        },
        {
          "name": "github.com/tsarna/vinculum-sqs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/tsarna/vinculum-vws",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.0"
        },
        {
          "name": "github.com/tsarna/vinculum-wire",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/twmb/franz-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.21.5"
        },
        {
          "name": "github.com/twmb/franz-go/pkg/kfake",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260721222903-95f7d9a51d6a"
        },
        {
          "name": "github.com/twmb/franz-go/plugin/kotel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.0"
        },
        {
          "name": "github.com/yosida95/uritemplate/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.2"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/processors/baggagecopy",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.16.1"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/prometheus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.66.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.54.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.57.0"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.47.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "github.com/heimdalr/dag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.1"
        },
        {
          "name": "github.com/tsarna/url-cty-funcs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.0"
        },
        {
          "name": "github.com/tsarna/vinculum-fsm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.1"
        },
        {
          "name": "github.com/zclconf/go-cty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/alicebob/miniredis/v2",
            "direct": true,
            "version": "v2.38.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": true,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": true,
            "version": "v1.32.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": true,
            "version": "v1.19.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sns",
            "direct": true,
            "version": "v1.42.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sqs",
            "direct": true,
            "version": "v1.46.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": true,
            "version": "v1.45.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coder/websocket",
            "direct": true,
            "version": "v1.8.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": true,
            "version": "v1.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/go-git/v5",
            "direct": true,
            "version": "v5.19.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-sql-driver/mysql",
            "direct": true,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-cty-funcs",
            "direct": true,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/hcl/v2",
            "direct": true,
            "version": "v2.24.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/heimdalr/dag",
            "direct": true,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/itchyny/gojq",
            "direct": true,
            "version": "v0.12.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgx/v5",
            "direct": true,
            "version": "v5.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jmoiron/sqlx",
            "direct": true,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/jwx/v2",
            "direct": true,
            "version": "v2.1.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-sqlite3",
            "direct": true,
            "version": "v1.14.48",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modelcontextprotocol/go-sdk",
            "direct": true,
            "version": "v1.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": true,
            "version": "v1.24.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rabbitmq/amqp091-go",
            "direct": true,
            "version": "v1.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/v9",
            "direct": true,
            "version": "v9.20.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/robfig/cron/v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sashabaranov/go-openai",
            "direct": true,
            "version": "v1.41.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sosodev/duration",
            "direct": true,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/barcode-cty-func",
            "direct": true,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/bytes-cty-type",
            "direct": true,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/functy",
            "direct": true,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/geo-cty-funcs",
            "direct": true,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/go-structdiff",
            "direct": true,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/go2cty2go",
            "direct": true,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/hcl-jqfunc",
            "direct": true,
            "version": "v0.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/rand-cty-funcs",
            "direct": true,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/rich-cty-types",
            "direct": true,
            "version": "v0.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/sqid-cty-funcs",
            "direct": true,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/time-cty-funcs",
            "direct": true,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/url-cty-funcs",
            "direct": true,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-bus",
            "direct": true,
            "version": "v0.15.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-fsm",
            "direct": true,
            "version": "v0.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-kafka",
            "direct": true,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-mqtt",
            "direct": true,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-rabbitmq",
            "direct": true,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-redis",
            "direct": true,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-sns",
            "direct": true,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-sqs",
            "direct": true,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-vws",
            "direct": true,
            "version": "v0.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tsarna/vinculum-wire",
            "direct": true,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/twmb/franz-go",
            "direct": true,
            "version": "v1.21.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/twmb/franz-go/pkg/kfake",
            "direct": true,
            "version": "v0.0.0-20260721222903-95f7d9a51d6a",
            "ecosystem": "go"
          },
          {
            "name": "github.com/twmb/franz-go/plugin/kotel",
            "direct": true,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yosida95/uritemplate/v3",
            "direct": true,
            "version": "v3.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zclconf/go-cty",
            "direct": true,
            "version": "v1.19.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/processors/baggagecopy",
            "direct": true,
            "version": "v0.16.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": true,
            "version": "v0.66.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": true,
            "version": "v1.28.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": true,
            "version": "v0.54.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": true,
            "version": "v0.57.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "dario.cat/mergo",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "filippo.io/edwards25519",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/agext/levenshtein",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/amir-yaghoubi/mqttpattern",
            "direct": false,
            "version": "v0.0.0-20250829083210-f7d8d46a786e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/apparentlymart/go-cidr",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/apparentlymart/go-textseg/v15",
            "direct": false,
            "version": "v15.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/apparentlymart/go-textseg/v17",
            "direct": false,
            "version": "v17.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.32",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.33.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.38.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": false,
            "version": "v1.27.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bmatcuk/doublestar",
            "direct": false,
            "version": "v1.3.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/boombuler/barcode",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chzyer/readline",
            "direct": false,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.6.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cyphar/filepath-securejoin",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
            "direct": false,
            "version": "v4.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/eclipse/paho.golang",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emirpasic/gods",
            "direct": false,
            "version": "v1.18.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/gcfg",
            "direct": false,
            "version": "v1.5.1-0.20230307220236-3a3c6141e376",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/go-billy/v5",
            "direct": false,
            "version": "v5.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/goccy/go-json",
            "direct": false,
            "version": "v0.10.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/geo",
            "direct": false,
            "version": "v0.0.0-20260713102120-857a528af641",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/groupcache",
            "direct": false,
            "version": "v0.0.0-20241129210726-2c02b8208cf8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/jsonschema-go",
            "direct": false,
            "version": "v0.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/websocket",
            "direct": false,
            "version": "v1.5.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/itchyny/timefmt-go",
            "direct": false,
            "version": "v0.1.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgpassfile",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgservicefile",
            "direct": false,
            "version": "v0.0.0-20240606120523-5a60cdf6a761",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/puddle/v2",
            "direct": false,
            "version": "v2.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jbenet/go-context",
            "direct": false,
            "version": "v0.0.0-20150711004518-d14ea06fba99",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kevinburke/ssh_config",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kixorz/suncalc",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.19.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/cpuid/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/blackmagic",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/httpcc",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/httprc",
            "direct": false,
            "version": "v1.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/iter",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lestrrat-go/option",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/go-homedir",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/go-wordwrap",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/natemcintosh/geographiclib-go",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nathan-osman/go-sunrise",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pierrec/lz4/v4",
            "direct": false,
            "version": "v4.1.26",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pjbgf/sha1cd",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.70.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.21.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/protonmail/go-crypto",
            "direct": false,
            "version": "v1.1.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/segmentio/asm",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/segmentio/encoding",
            "direct": false,
            "version": "v0.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sergi/go-diff",
            "direct": false,
            "version": "v1.3.2-0.20230802210424-5b0b94c5c0d3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/skeema/knownhosts",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sqids/sqids-go",
            "direct": false,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/twmb/franz-go/pkg/kmsg",
            "direct": false,
            "version": "v1.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xanzy/ssh-agent",
            "direct": false,
            "version": "v0.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yuin/gopher-lua",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/log",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/log",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.82.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/warnings.v0",
            "direct": false,
            "version": "v0.1.2",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 169,
        "direct_count": 72,
        "indirect_count": 97
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 127,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 25
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "tsarna",
          "commits": 508,
          "avatar_url": "https://avatars.githubusercontent.com/u/630146?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "docker.yml",
        "ghcr-cleanup.yml",
        "release-index.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "cf898f4c5a43def1f49f7dbbcf217052e74ee30c",
        "ran_at": "2026-07-25T16:24:45Z",
        "aggregate_score": 5.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T15:24:10Z",
      "oldest_open_prs": [
        {
          "number": 93,
          "created_at": "2026-06-11T21:11:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-25T15:18:50Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/tsarna/vinculum",
    "host": "github.com",
    "name": "vinculum",
    "owner": "tsarna"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 63,
        "vitality": 85,
        "community": 26,
        "governance": 50,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 85,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 507,
              "human_commit_share": 0.99,
              "days_since_last_push": 0,
              "active_weeks_last_year": 25
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "25/52 weeks with commits",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 25
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "507 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 507
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 8,
              "latest_release_tag": "v0.44.0",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 7.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "8 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~7.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 7.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 26,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 5,
            "inputs": {
              "forks": 0,
              "stars": 3,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "3 stars",
                "points": 4.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 50,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "merged_prs": 127,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 25
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "127/152 decided PRs merged",
                "points": 32,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 127,
                      "decided": 152
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "followers": 4,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "tsarna",
              "public_repos": 48,
              "account_age_days": 5633
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of tsarna",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "tsarna"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "48 public repos, account ~15 yr old",
                "points": 24.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 48
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/tsarna/vinculum"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "48 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 48
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "5 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 63,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "13 out of 13 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 169 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 169
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 89,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 169,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: golang.org/x/crypto v0.54.0 (unknown)",
                "points": 26.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "golang.org/x/crypto v0.54.0 (unknown)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 169,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 85,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.97,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 27416
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "96 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 96,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.5,
              "toolchain_manifests": [
                "go.mod",
                "testdata/plugin-smoke/go.mod"
              ],
              "dependency_bot_commit_share": 0.01
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "go.mod, testdata/plugin-smoke/go.mod (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "go.mod, testdata/plugin-smoke/go.mod"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "50 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 50,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "1 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 73014,
              "source_files_sampled": 328,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/328 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 328,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "excellent",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "example_dirs": [
                "examples",
                "sample"
              ],
              "has_mcp_signal": true,
              "api_schema_files": [
                "wireformats/protobuf/testdata/orders.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "wireformats/protobuf/testdata/orders.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "wireformats/protobuf/testdata/orders.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples, sample",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples, sample"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T16:24:55.174170Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tsarna/vinculum.svg",
  "full_name": "tsarna/vinculum",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

Scores are signals, not warranties. They reflect publicly visible practices on GitHub — not a code audit, and not a security guarantee.

Missing data is excluded and weights renormalized, never scored as zero. Methodology is versioned and open: metrics v1.13.0, schema v0.27.0 — full methodology · metrics wiki.

How one result sits in the wider record: aggregate statisticsGo.