Raw JSON report machine-readable
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 77,
"has_wiki": true,
"homepage": null,
"languages": {
"Go": 21783
},
"pushed_at": "2026-07-20T13:04:31Z",
"created_at": "2024-02-27T18:55:45Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T13:07:56Z",
"description": "Reusable mage tasks",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "http://tt.se",
"name": "TT Nyhetsbyrån",
"type": "Organization",
"login": "ttab",
"company": null,
"location": "Sweden",
"followers": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/3897597?v=4",
"created_at": "2013-03-18T10:04:47Z",
"is_verified": null,
"public_repos": 107,
"account_age_days": 4880
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.9.3",
"kind": "patch",
"published_at": "2026-07-20T13:04:26Z"
},
{
"tag": "v0.9.2",
"kind": "patch",
"published_at": "2026-07-20T12:50:42Z"
},
{
"tag": "v0.9.1",
"kind": "patch",
"published_at": "2026-03-24T07:04:46Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-03-02T08:43:48Z"
},
{
"tag": "v0.8.4",
"kind": "patch",
"published_at": "2025-11-11T09:02:16Z"
},
{
"tag": "v0.8.3",
"kind": "patch",
"published_at": "2025-08-12T11:25:49Z"
},
{
"tag": "v0.8.2",
"kind": "patch",
"published_at": "2025-07-22T07:54:10Z"
},
{
"tag": "v0.8.1",
"kind": "patch",
"published_at": "2025-07-21T07:46:11Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2025-05-10T06:38:15Z"
},
{
"tag": "v0.7.5",
"kind": "patch",
"published_at": "2025-01-10T15:28:48Z"
},
{
"tag": "v0.7.4",
"kind": "patch",
"published_at": "2025-01-10T13:36:59Z"
},
{
"tag": "v0.7.3",
"kind": "patch",
"published_at": "2025-01-10T13:00:52Z"
},
{
"tag": "v0.7.2",
"kind": "patch",
"published_at": "2025-01-09T08:57:17Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2024-11-18T15:30:31Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2024-10-09T11:22:31Z"
},
{
"tag": "v0.6.2",
"kind": "patch",
"published_at": "2024-06-14T06:16:40Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2024-05-06T11:06:54Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2024-05-02T07:31:41Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2024-04-04T15:03:41Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2024-03-15T15:19:30Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2024-03-05T12:23:12Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2024-03-05T12:16:39Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2024-03-05T09:34:22Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2024-02-28T14:01:25Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2024-02-28T13:03:49Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2024-02-27T18:58:19Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2024-02-27T18:54:57Z"
}
],
"recent_commits": [
{
"oid": "1b2be609bd495f07d8507b0b762aee8ffaf6e3ee",
"body": "Bump to go 1.25.0 and update pgx, mage, minio-go and their transitive\ndependencies.",
"is_bot": false,
"headline": "update dependencies",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2026-07-20T13:04:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "26cfe843976ffd1a1856eb2aac87049e794d9899",
"body": "Bump checkout/setup-go to v7 and, importantly, golangci-lint-action to\nv9 with golangci-lint v2.12 so CI can read the v2-format .golangci.yml.",
"is_bot": false,
"headline": "update github workflows",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2026-07-20T12:56:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ccdbde0e1289368f0ed357d9a7633be49324f236",
"body": "Add a .golangci.yml matching the elephantine/tt-live setup and resolve\nall resulting findings: rename twirp.TwirpTools to twirp.Tools, wrap\nerrors from internal helpers, modernize interface{} to any, and fix\nwhitespace/nlreturn issues.",
"is_bot": false,
"headline": "add golangci-lint config and fix lint errors",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2026-07-20T12:50:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "57a28f7edc2a53f2cc530768069bb817227f4081",
"body": "Accepts a JSON-encoded array of table names and delegates to\nGrantReporting. This allows projects to embed their reporting\ntable list as a JSON file and pass it directly.",
"is_bot": false,
"headline": "add GrantReportingFromJSON helper",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2026-03-24T07:04:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0bc7baba6a2fe3d3c373ed65c9db2963efd809e0",
"body": null,
"is_bot": false,
"headline": "add tagging instructions to twirp:release",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2026-03-02T08:43:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85c39cbc9df0b0511a86457c8d829970626e082b",
"body": null,
"is_bot": false,
"headline": "reworked generate and release targets for twirp",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2026-03-02T08:39:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "36fd5efaaee15d9f12bf2a5a2c5dd08bdd889f3a",
"body": "Workaround for meta-command handling in sqlc",
"is_bot": false,
"headline": "Merge pull request #14 from ttab/feature/restrict-workaround",
"author_name": "Fredrik Appelberg",
"author_login": "fred-o",
"committed_at": "2025-11-11T09:02:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6cedaf29afb8a30db419ef7c0bcd39f35ec5b11f",
"body": null,
"is_bot": false,
"headline": "a better workaround",
"author_name": "Fredrik Appelberg",
"author_login": "fred-o",
"committed_at": "2025-11-06T14:36:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "144902d22967a2e54685e64228a330befb539d6c",
"body": null,
"is_bot": false,
"headline": "workaround for https://github.com/sqlc-dev/sqlc/issues/4065",
"author_name": "Fredrik Appelberg",
"author_login": "fred-o",
"committed_at": "2025-11-04T13:29:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e73a135d3d729bf8bf81b51ff10d98e988b63374",
"body": null,
"is_bot": false,
"headline": "add db dropping support",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-08-12T11:25:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "40e622e61cd4313d49c727ef1c152c007cf944a5",
"body": null,
"is_bot": false,
"headline": "add a re-usable GrantReporting target",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-07-22T07:54:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9d6c442f3d89b51512bb10b99f13543e31f9a24",
"body": null,
"is_bot": false,
"headline": "update dependencies",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-07-21T07:46:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6dae727f377b38f2b576b14c459366129fb686c",
"body": null,
"is_bot": false,
"headline": "move to pg17",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-05-10T06:38:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65c1d8a4c7d9a29eb4d877b9577b66cdf9ed5843",
"body": null,
"is_bot": false,
"headline": "tweak the protopath to generate code in the correct location",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-01-10T15:28:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dabfe08d281e9606e7edbfcf5143f0d55f32cb75",
"body": null,
"is_bot": false,
"headline": "update dependencies",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-01-10T13:36:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "72478ab2553771a41c4e5aefa10b2649f54e0d88",
"body": null,
"is_bot": false,
"headline": "update protoc args so that we can handle fully qualified go packages",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-01-10T13:00:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "67e73129dd8578132d8534c7f688b1540d34969a",
"body": null,
"is_bot": false,
"headline": "automatically include elephant-api for twirp generation",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2025-01-09T08:57:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5237a96fdaddf6143853c4964381cd5fb1c6cdc0",
"body": "…test method name against it",
"is_bot": false,
"headline": "fix regex expression for twirp service and method name, and actually …",
"author_name": "Danijel Vukoje",
"author_login": "danijelvukoje",
"committed_at": "2024-11-18T15:30:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "38842e5ff553816be4164a6864b36274954a563f",
"body": null,
"is_bot": false,
"headline": "upgrade dependencies",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-10-09T11:22:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dcc46f8355587d94e03021f2e2abb9b5b5256c2a",
"body": null,
"is_bot": false,
"headline": "automatically detect and generate services",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-10-09T10:59:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "69c8591f8096be367af3607d30a12667b828ff2a",
"body": null,
"is_bot": false,
"headline": "connection string helper",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-06-14T06:16:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9870be0cdb13f526b7655f06bc3917713a02ebb3",
"body": null,
"is_bot": false,
"headline": "export connection string helper",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-05-06T11:06:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac611f076391faa904d4e307a794b2529ee30288",
"body": "* Bump github.com/minio/minio-go/v7 from 7.0.68 to 7.0.70\r\n\r\nBumps [github.com/minio/minio-go/v7](https://github.com/minio/minio-go) from 7.0.68 to 7.0.70.\r\n- [Release notes](https://github.com/minio/minio-go/releases)\r\n- [Commits](https://github.com/minio/minio-go/compare/v7.0.68...v7.0.70)\r\n\r\n---\r\n[…]\ned-off-by: dependabot[bot] <support@github.com>\r\n\r\n---------\r\n\r\nSigned-off-by: dependabot[bot] <support@github.com>\r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "Chore/dep update 2024 05 02 (#7)",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-05-02T07:31:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "93d9022f77886bfcf988970df5ec6687a7036f08",
"body": null,
"is_bot": false,
"headline": "respect operating system conventions for user application data dir (#6)",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-05-02T07:22:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2fe6994501299113744ccd967da8d69e7fade955",
"body": null,
"is_bot": false,
"headline": "set include path to allow referencing other protobuf files",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-04-04T15:03:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "34d6af9d3d1cbb2e6f57785360730a34e22c5a71",
"body": null,
"is_bot": false,
"headline": "correct api stage url",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-03-15T15:19:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5c0db6e52d992b2cb2a4ab8185a572384456a41",
"body": null,
"is_bot": false,
"headline": "add workflows and dependabot config",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-03-06T15:09:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad26fceb633cc3d2c847d5e5a87b6b391c5b9182",
"body": null,
"is_bot": false,
"headline": "don't include ownership information in the database dump",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-03-05T12:23:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ab53cb6aa8e3ec92d5af11fed5f78c1a7680b4d0",
"body": null,
"is_bot": false,
"headline": "add minio targets, improve docs",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-03-05T12:16:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e12185f61bf40545c570cf0f14e62ae768ba7642",
"body": null,
"is_bot": false,
"headline": "typo in readme",
"author_name": "Danijel Vukoje",
"author_login": "danijelvukoje",
"committed_at": "2024-03-05T10:36:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d63cd6e949029af6dd5a618f2c114659b9233b3",
"body": null,
"is_bot": false,
"headline": "link to mage in readme",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-03-05T09:54:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "112eaa52298130685961a12d80ab2c93fb6fc88d",
"body": null,
"is_bot": false,
"headline": "let sql:db default to current directory name",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-03-05T09:34:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85209a28a47740f65eed01134b73856ee105dcfa",
"body": null,
"is_bot": false,
"headline": "small reorg",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-28T14:01:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "35b33007fe91cbbbee58c87c3f2acf72b9315da3",
"body": null,
"is_bot": false,
"headline": "set api version and manipulate servers in openapi spec",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-28T14:01:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dbfb0f7b3b95a169f80d97cc518900fe39e65ebf",
"body": null,
"is_bot": false,
"headline": "whitespace cleanup",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-28T13:06:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e82b089e8708180bd6a2858650227a1868395fdd",
"body": null,
"is_bot": false,
"headline": "add sql and twirp tasks",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-28T13:03:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "75ff4f91e705237fb90c5582ae868a5d38758c4e",
"body": null,
"is_bot": false,
"headline": "improve docs",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-27T19:08:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0620d1a7ec29e865af771582b3436ca147786dac",
"body": null,
"is_bot": false,
"headline": "add license and readme",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-27T18:58:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "11072ed76a0180029bf0afd97c8e0c048413e734",
"body": null,
"is_bot": false,
"headline": "initial commit",
"author_name": "Hugo Wetterberg",
"author_login": "hugowetterberg",
"committed_at": "2024-02-27T18:54:57Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 27,
"commits_last_year": 10,
"latest_release_at": "2026-07-20T13:04:26Z",
"latest_release_tag": "v0.9.3",
"releases_from_tags": true,
"days_since_last_push": 8,
"active_weeks_last_year": 6,
"days_since_latest_release": 8,
"mean_days_between_releases": 61.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/ttab/mage",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/ttab/mage",
"is_deprecated": false,
"latest_version": "v0.9.3",
"repository_url": "https://github.com/ttab/mage",
"versions_count": 27,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-20T13:04:26Z",
"latest_version_yanked": null,
"days_since_latest_publish": 8
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 4,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 3
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 9015,
"source_files_sampled": 8,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.54.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 21
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 24,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/jackc/pgx/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.10.0"
},
{
"name": "github.com/magefile/mage",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.17.2"
},
{
"name": "github.com/minio/minio-go/v7",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v7.2.1"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/jackc/pgx/v5",
"direct": true,
"version": "v5.10.0",
"ecosystem": "go"
},
{
"name": "github.com/magefile/mage",
"direct": true,
"version": "v1.17.2",
"ecosystem": "go"
},
{
"name": "github.com/minio/minio-go/v7",
"direct": true,
"version": "v7.2.1",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgpassfile",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgservicefile",
"direct": false,
"version": "v0.0.0-20240606120523-5a60cdf6a761",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/compress",
"direct": false,
"version": "v1.19.1",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/cpuid/v2",
"direct": false,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/crc32",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/kr/text",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/minio/crc64nvme",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/minio/md5-simd",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/philhofer/fwd",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/rs/xid",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/tinylib/msgp",
"direct": false,
"version": "v1.6.4",
"ecosystem": "go"
},
{
"name": "github.com/zeebo/xxh3",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.54.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": false,
"version": "v0.57.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.47.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.40.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/ini.v1",
"direct": false,
"version": "v1.67.3",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 24,
"direct_count": 3,
"indirect_count": 21
}
},
"maintainership": {
"issues": {
"open_prs": 3,
"merged_prs": 3,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 8
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "hugowetterberg",
"commits": 34,
"avatar_url": "https://avatars.githubusercontent.com/u/30441?v=4"
},
{
"type": "User",
"login": "fred-o",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/102433?v=4"
},
{
"type": "User",
"login": "danijelvukoje",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/26868671?v=4"
}
],
"contributors_sampled": 3,
"top_contributor_share": 0.872
},
"quality_signals": {
"has_ci": true,
"has_tests": false,
"ci_workflows": [
"lint.yaml",
"test.yaml"
],
"has_docs_dir": false,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 3,
"reason": "1 out of 3 merged PRs checked by a CI test -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 2/28 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 2,
"reason": "3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "1b2be609bd495f07d8507b0b762aee8ffaf6e3ee",
"ran_at": "2026-07-29T06:33:52Z",
"aggregate_score": 5.3,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-20T13:05:14Z",
"oldest_open_prs": [
{
"number": 8,
"created_at": "2024-05-13T08:00:03Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 9,
"created_at": "2024-05-27T08:05:34Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 13,
"created_at": "2024-07-22T08:01:36Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2025-11-11T09:02:16Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/ttab/mage",
"host": "github.com",
"name": "mage",
"owner": "ttab"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"security": 62,
"vitality": 58,
"community": 25,
"governance": 46,
"engineering": 48
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "moderate",
"name": "Vitality",
"value": 58,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "at_risk",
"name": "Development activity",
"note": null,
"notes": [],
"value": 44,
"inputs": {
"commits_last_year": 10,
"human_commit_share": 1,
"days_since_last_push": 8,
"active_weeks_last_year": 6
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 8 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "6/52 weeks with commits",
"points": 4.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 6
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "10 commits in the last year",
"points": 9.4,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 10
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2",
"points": 2,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "good",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"releases_count": 27,
"latest_release_tag": "v0.9.3",
"releases_from_tags": true,
"days_since_latest_release": 8,
"mean_days_between_releases": 61.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "27 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 27
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 8 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~61.8 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 61.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 8,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 8 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 8
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 25,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 3,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 4,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "4 watchers",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 4
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 46,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 19,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 3,
"top_contributor_share": 0.872
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 87% of commits",
"points": 2.9,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 87
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "3 contributors",
"points": 4.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 3
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 20,
"inputs": {
"merged_prs": 3,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 8
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "3/11 decided PRs merged",
"points": 10.4,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 3,
"decided": 11
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 2/28 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"followers": 6,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "ttab",
"public_repos": 107,
"account_age_days": 4880
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "6 followers of ttab",
"points": 6.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 6,
"login": "ttab"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "107 public repos, account ~13 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 107
}
},
{
"code": "account_age_years",
"params": {
"years": 13
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/ttab/mage"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 8
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 8 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 8
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "27 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 27
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "at_risk",
"name": "Engineering Quality",
"value": 48,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "at_risk",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 46,
"inputs": {
"has_ci": true,
"has_tests": false,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "1 out of 3 merged PRs checked by a CI test -- score normalized to 3",
"points": 6,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 62,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 53,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 5.3
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "1 out of 3 merged PRs checked by a CI test -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 2/28 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 24 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 24
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 24,
"unassessed_packages": 0,
"affected_by_severity": "unknown 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 24,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 45,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 10,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.179,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "7 of 39 human commits state their intent (structured subject or explanatory body)",
"points": 9.6,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 7,
"sampled": 39
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_nix": false,
"has_tests": false,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 39",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 39
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "dependency automation configured, none observed in the sampled commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "dependency_bot_config_only",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 9015,
"source_files_sampled": 8,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/8 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 8,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [],
"report_type": "repository",
"generated_at": "2026-07-29T06:33:59.248258Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/ttab/mage.svg",
"full_name": "ttab/mage",
"license_state": "standard",
"license_spdx": "MIT"
}