Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 45869,
"has_wiki": true,
"homepage": null,
"languages": {
"C": 249384,
"Go": 14742410,
"CSS": 26022,
"Lua": 6882,
"Nix": 9998,
"HTML": 38464,
"Rust": 16854,
"Shell": 89594,
"Swift": 56179,
"Makefile": 10304,
"Dockerfile": 8363,
"JavaScript": 3381,
"PowerShell": 19244,
"TypeScript": 163473,
"Go Template": 489
},
"pushed_at": "2026-07-20T14:45:57Z",
"created_at": "2026-06-10T08:43:11Z",
"owner_type": "Organization",
"updated_at": "2026-07-20T13:58:40Z",
"description": "Customised Tailscale for MESH",
"is_archived": false,
"is_disabled": false,
"license_spdx": "BSD-3-Clause",
"default_branch": "main",
"license_spdx_raw": "BSD-3-Clause",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://barghest.asia",
"name": "BARGHEST",
"type": "Organization",
"login": "BARGHEST-ngo",
"company": null,
"location": null,
"followers": 31,
"avatar_url": "https://avatars.githubusercontent.com/u/204176000?v=4",
"created_at": "2025-03-20T10:25:46Z",
"is_verified": null,
"public_repos": 10,
"account_age_days": 496
},
"license": {
"state": "standard",
"spdx_id": "BSD-3-Clause",
"raw_spdx": "BSD-3-Clause",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.95.0-pre",
"kind": "prerelease",
"published_at": "2026-01-14T22:19:17Z"
},
{
"tag": "v1.94.2",
"kind": "patch",
"published_at": "2026-02-13T19:41:21Z"
},
{
"tag": "v1.94.1",
"kind": "patch",
"published_at": "2026-01-22T18:44:55Z"
},
{
"tag": "v1.94.0",
"kind": "minor",
"published_at": "2026-01-14T20:55:28Z"
},
{
"tag": "v1.93.0-pre",
"kind": "prerelease",
"published_at": "2025-11-26T20:49:52Z"
},
{
"tag": "v1.92.5",
"kind": "patch",
"published_at": "2026-01-06T18:15:04Z"
},
{
"tag": "v1.92.4",
"kind": "patch",
"published_at": "2025-12-18T10:30:54Z"
},
{
"tag": "v1.92.3",
"kind": "patch",
"published_at": "2025-12-16T20:11:52Z"
},
{
"tag": "v1.92.2",
"kind": "patch",
"published_at": "2025-12-10T18:24:06Z"
},
{
"tag": "v1.92.1",
"kind": "patch",
"published_at": "2025-12-05T15:51:26Z"
},
{
"tag": "v1.92.0",
"kind": "minor",
"published_at": "2025-11-26T20:35:58Z"
},
{
"tag": "v1.91.0-pre",
"kind": "prerelease",
"published_at": "2025-10-20T16:11:05Z"
},
{
"tag": "v1.90.9",
"kind": "patch",
"published_at": "2025-11-25T16:12:16Z"
},
{
"tag": "v1.90.8",
"kind": "patch",
"published_at": "2025-11-18T18:31:30Z"
},
{
"tag": "v1.90.7",
"kind": "patch",
"published_at": "2025-11-18T17:32:04Z"
},
{
"tag": "v1.90.6",
"kind": "patch",
"published_at": "2025-10-31T21:18:03Z"
},
{
"tag": "v1.90.5",
"kind": "patch",
"published_at": "2025-10-30T17:38:25Z"
},
{
"tag": "v1.90.4",
"kind": "patch",
"published_at": "2025-10-28T18:29:24Z"
},
{
"tag": "v1.90.3",
"kind": "patch",
"published_at": "2025-10-27T16:15:14Z"
},
{
"tag": "v1.90.2",
"kind": "patch",
"published_at": "2025-10-24T16:49:00Z"
},
{
"tag": "v1.90.1",
"kind": "patch",
"published_at": "2025-10-23T16:06:03Z"
},
{
"tag": "v1.90.0",
"kind": "minor",
"published_at": "2025-10-20T16:01:07Z"
},
{
"tag": "v1.89.0-pre",
"kind": "prerelease",
"published_at": "2025-09-11T18:19:17Z"
},
{
"tag": "v1.88.4",
"kind": "patch",
"published_at": "2025-10-14T17:45:00Z"
},
{
"tag": "v1.88.3",
"kind": "patch",
"published_at": "2025-09-25T13:04:46Z"
},
{
"tag": "v1.88.2",
"kind": "patch",
"published_at": "2025-09-17T17:13:08Z"
},
{
"tag": "v1.88.1",
"kind": "patch",
"published_at": "2025-09-11T19:13:06Z"
},
{
"tag": "v1.88.0",
"kind": "minor",
"published_at": "2025-09-11T17:33:53Z"
},
{
"tag": "v1.87.0-pre",
"kind": "prerelease",
"published_at": "2025-07-24T18:25:57Z"
},
{
"tag": "v1.86.5",
"kind": "patch",
"published_at": "2025-08-22T16:30:19Z"
},
{
"tag": "v1.86.4",
"kind": "patch",
"published_at": "2025-08-07T16:46:29Z"
},
{
"tag": "v1.86.3",
"kind": "patch",
"published_at": "2025-08-07T15:18:21Z"
},
{
"tag": "v1.86.2",
"kind": "patch",
"published_at": "2025-07-29T16:56:20Z"
},
{
"tag": "v1.86.1",
"kind": "patch",
"published_at": "2025-07-25T17:54:40Z"
},
{
"tag": "v1.86.0",
"kind": "minor",
"published_at": "2025-07-24T18:11:13Z"
},
{
"tag": "v1.85.0-pre",
"kind": "prerelease",
"published_at": "2025-05-21T19:27:32Z"
},
{
"tag": "v1.84.3",
"kind": "patch",
"published_at": "2025-06-26T16:26:38Z"
},
{
"tag": "v1.84.2",
"kind": "patch",
"published_at": "2025-06-09T21:39:17Z"
},
{
"tag": "v1.84.1",
"kind": "patch",
"published_at": "2025-05-29T17:40:49Z"
},
{
"tag": "v1.84.0",
"kind": "minor",
"published_at": "2025-05-21T19:10:03Z"
},
{
"tag": "v1.83.0-pre",
"kind": "prerelease",
"published_at": "2025-03-26T13:29:38Z"
},
{
"tag": "v1.82.5",
"kind": "patch",
"published_at": "2025-04-17T19:01:26Z"
},
{
"tag": "v1.82.4",
"kind": "patch",
"published_at": "2025-04-11T17:52:10Z"
},
{
"tag": "v1.82.3",
"kind": "patch",
"published_at": "2025-04-11T16:32:59Z"
},
{
"tag": "v1.82.2",
"kind": "patch",
"published_at": "2025-04-10T19:53:40Z"
},
{
"tag": "v1.82.0",
"kind": "minor",
"published_at": "2025-03-26T19:50:33Z"
},
{
"tag": "v1.81.0-pre",
"kind": "prerelease",
"published_at": "2025-01-30T21:04:29Z"
},
{
"tag": "v1.80.3",
"kind": "patch",
"published_at": "2025-03-03T20:05:20Z"
},
{
"tag": "v1.80.2",
"kind": "patch",
"published_at": "2025-02-12T18:31:52Z"
},
{
"tag": "v1.80.1",
"kind": "patch",
"published_at": "2025-02-06T18:38:55Z"
},
{
"tag": "v1.80.0",
"kind": "minor",
"published_at": "2025-01-30T20:52:55Z"
},
{
"tag": "v1.79.0-pre",
"kind": "prerelease",
"published_at": "2024-12-06T17:25:12Z"
},
{
"tag": "v1.78.3",
"kind": "patch",
"published_at": "2024-12-11T20:26:51Z"
},
{
"tag": "v1.78.2",
"kind": "patch",
"published_at": "2024-12-11T18:06:06Z"
},
{
"tag": "v1.78.1",
"kind": "patch",
"published_at": "2024-12-05T23:51:23Z"
},
{
"tag": "v1.78.0",
"kind": "minor",
"published_at": "2024-12-05T19:16:48Z"
},
{
"tag": "v1.77.0-pre",
"kind": "prerelease",
"published_at": "2024-10-10T18:34:14Z"
},
{
"tag": "v1.76.6",
"kind": "patch",
"published_at": "2024-11-04T20:07:36Z"
},
{
"tag": "v1.76.3",
"kind": "patch",
"published_at": "2024-10-21T15:10:38Z"
},
{
"tag": "v1.76.1",
"kind": "patch",
"published_at": "2024-10-15T18:20:59Z"
},
{
"tag": "v1.76.0",
"kind": "minor",
"published_at": "2024-10-10T18:11:51Z"
},
{
"tag": "v1.75.0-pre",
"kind": "prerelease",
"published_at": "2024-09-12T20:19:46Z"
},
{
"tag": "v1.74.1",
"kind": "patch",
"published_at": "2024-09-18T18:54:26Z"
},
{
"tag": "v1.74.0",
"kind": "minor",
"published_at": "2024-09-12T19:58:22Z"
},
{
"tag": "v1.73.0-pre",
"kind": "prerelease",
"published_at": "2024-08-19T17:17:29Z"
},
{
"tag": "v1.72.1",
"kind": "patch",
"published_at": "2024-08-22T16:21:32Z"
},
{
"tag": "v1.72.0",
"kind": "minor",
"published_at": "2024-08-19T17:07:21Z"
},
{
"tag": "v1.71.0-pre",
"kind": "prerelease",
"published_at": "2024-07-17T17:27:05Z"
},
{
"tag": "v1.70.0",
"kind": "minor",
"published_at": "2024-07-17T17:11:59Z"
},
{
"tag": "v1.69.0-pre",
"kind": "prerelease",
"published_at": "2024-06-12T17:16:33Z"
},
{
"tag": "v1.68.2",
"kind": "patch",
"published_at": "2024-07-02T18:23:20Z"
},
{
"tag": "v1.68.1",
"kind": "patch",
"published_at": "2024-06-14T11:47:24Z"
},
{
"tag": "v1.68.0",
"kind": "minor",
"published_at": "2024-06-12T17:03:59Z"
},
{
"tag": "v1.67.0-pre",
"kind": "prerelease",
"published_at": "2024-05-08T21:00:17Z"
},
{
"tag": "v1.66.4",
"kind": "patch",
"published_at": "2024-05-21T00:28:00Z"
},
{
"tag": "v1.66.3",
"kind": "patch",
"published_at": "2024-05-14T21:16:13Z"
},
{
"tag": "v1.66.2",
"kind": "patch",
"published_at": "2024-05-14T20:44:56Z"
},
{
"tag": "v1.66.1",
"kind": "patch",
"published_at": "2024-05-09T20:21:31Z"
},
{
"tag": "v1.66.0",
"kind": "minor",
"published_at": "2024-05-08T20:52:24Z"
},
{
"tag": "v1.65.0-pre",
"kind": "prerelease",
"published_at": "2024-04-11T18:00:11Z"
},
{
"tag": "v1.64.2",
"kind": "patch",
"published_at": "2024-04-17T13:08:36Z"
},
{
"tag": "v1.64.1",
"kind": "patch",
"published_at": "2024-04-15T17:10:28Z"
},
{
"tag": "v1.64.0",
"kind": "minor",
"published_at": "2024-04-11T17:29:54Z"
},
{
"tag": "v1.63.0-pre",
"kind": "prerelease",
"published_at": "2024-03-13T14:51:52Z"
},
{
"tag": "v1.62.1",
"kind": "patch",
"published_at": "2024-03-26T19:40:57Z"
},
{
"tag": "v1.62.0",
"kind": "minor",
"published_at": "2024-03-13T14:35:30Z"
},
{
"tag": "v1.61.0-pre",
"kind": "prerelease",
"published_at": "2024-02-15T23:24:49Z"
},
{
"tag": "v1.60.1",
"kind": "patch",
"published_at": "2024-02-29T03:37:44Z"
},
{
"tag": "v1.60.0",
"kind": "minor",
"published_at": "2024-02-15T20:08:20Z"
},
{
"tag": "v1.58.2",
"kind": "patch",
"published_at": "2024-01-23T21:54:48Z"
},
{
"tag": "v1.58.1",
"kind": "patch",
"published_at": "2024-01-23T18:18:58Z"
},
{
"tag": "v1.58.0",
"kind": "minor",
"published_at": "2024-01-18T20:04:42Z"
},
{
"tag": "v1.56.1",
"kind": "patch",
"published_at": "2023-12-15T19:21:33Z"
},
{
"tag": "v1.56.0",
"kind": "minor",
"published_at": "2023-12-13T19:58:42Z"
},
{
"tag": "v1.44.3",
"kind": "patch",
"published_at": "2024-01-05T22:33:30Z"
}
],
"recent_commits": [
{
"oid": "96abef288847c5b4ce4869c8c18a828c31f37bb9",
"body": "Bug/leak local rfc1918 addresses",
"is_bot": false,
"headline": "Merge pull request #7 from BARGHEST-ngo/bug/leak-local-rfc1918-addresses",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-07-20T13:57:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "329986aad14565d459b1d928a5686c21d825b3cb",
"body": null,
"is_bot": false,
"headline": "add TestLANAddr",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-07-20T13:06:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6293878c903ea36e555884739a38d9b64d03a539",
"body": null,
"is_bot": false,
"headline": "filter private LAN addresses",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-07-20T12:52:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9571649c558c05ebc8d87f13502cad30bb495cd1",
"body": "fix: change stun software attr from tailnode",
"is_bot": false,
"headline": "Merge pull request #6 from BARGHEST-ngo/fix/change-stun-software-attr",
"author_name": "shockham",
"author_login": "shockham",
"committed_at": "2026-07-20T11:57:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "027afddec4cd650943e7c460a2404528c5a042c8",
"body": null,
"is_bot": false,
"headline": "fix: change stun software attr from tailnode",
"author_name": "shockham",
"author_login": "shockham",
"committed_at": "2026-07-20T10:54:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c3d80563fd00eef201d5c84c1b8a91c4f732e4ac",
"body": "…njection\n\nsanitize peer OS name",
"is_bot": false,
"headline": "Merge pull request #5 from BARGHEST-ngo/bug/sanitize-ansi-character-i…",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-07-20T09:48:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad8f19af11af9f34fa3cf41f2bf4a5ab28927eb5",
"body": null,
"is_bot": false,
"headline": "sanitize peer OS name",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-07-20T09:08:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0eb7a7af7a6e1c22cb0460ec7e003be10e3ab3bf",
"body": "fix: ANSI escape fix",
"is_bot": false,
"headline": "Merge pull request #4 from BARGHEST-ngo/fix/meshstatus-ansi-injection",
"author_name": "Ovi",
"author_login": "0x0v1",
"committed_at": "2026-06-18T15:45:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "191a42dfe19ecea1cdf40e158ff2b7ba4d6eed55",
"body": null,
"is_bot": false,
"headline": "fix: ANSI escape fix",
"author_name": "Ovi",
"author_login": "0x0v1",
"committed_at": "2026-06-18T14:55:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "22b649ecf789275ac60a7946d00020cfac84af0a",
"body": "fix: re-advertise endpoints on node-key change",
"is_bot": false,
"headline": "Merge pull request #3 from BARGHEST-ngo/fix/republish-on-rekey",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-06-16T10:13:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "da220baaaaf9cde2092134ab3720d4b7f1b8bf93",
"body": null,
"is_bot": false,
"headline": "Merge pull request #2 from BARGHEST-ngo/disable-scheduled-actions",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-06-12T09:51:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b682d09ddc7f52de9487864eef29332ad0907021",
"body": null,
"is_bot": false,
"headline": "fix: re-advertise endpoints on node-key change",
"author_name": "Ovi",
"author_login": "0x0v1",
"committed_at": "2026-06-11T16:01:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ceef8ba58972cd55e383bda874dd6c04107d059",
"body": null,
"is_bot": false,
"headline": "disable various scheduled actions",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-06-11T14:07:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ab574d4c0252ee0f2bebbc3d9828bcbc3b415155",
"body": "Disable scheduled runs in natlab-test.yml",
"is_bot": false,
"headline": "Merge pull request #1 from BARGHEST-ngo/disable-cron-jobs",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-06-11T10:09:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de9680fe5020b5319a4a65f8a8f565cceb5bdfc9",
"body": "Comment out the schedule trigger in the GitHub Actions workflow.",
"is_bot": false,
"headline": "Disable scheduled runs in natlab-test.yml",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-06-11T09:43:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "edfc235e37f0fbe79bfe6a43072625d49d8b3c4e",
"body": "Merge upstream",
"is_bot": false,
"headline": "Merge pull request #3 from BARGHEST-ngo/merge-upstream",
"author_name": "DWoodhouse22",
"author_login": "DWoodhouse22",
"committed_at": "2026-06-02T11:37:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a1a70a811461003aee6b562e9d7eeb6f7d6cfcd",
"body": null,
"is_bot": false,
"headline": "remove defunct test helper",
"author_name": "devtimber",
"author_login": "devtimber",
"committed_at": "2026-05-13T15:23:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dc9f5c50f47d608146b1efff02c48552381a334a",
"body": null,
"is_bot": false,
"headline": "merge mesh branch & resolve post-merge build errors after upstream sync",
"author_name": "devtimber",
"author_login": "devtimber",
"committed_at": "2026-05-13T12:26:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f47539e79614898317636cc1c0f55b77d3bdebc0",
"body": null,
"is_bot": false,
"headline": "resolve merge conflicts",
"author_name": "devtimber",
"author_login": "devtimber",
"committed_at": "2026-05-13T09:49:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6467f0d0673652e8d3cca1384b8571fad0c0c29f",
"body": "This fixes a log message where ipn/ipnlocal.shouldUseOneCGNATRoute\nwould claim that an android machines was actually macOS.\n\nUpdates #cleanup\nUpdates #19652\n\nSigned-off-by: Simon Law <sfllaw@tailscale.com>",
"is_bot": false,
"headline": "ipn/ipnlocal: fix minor typo in shouldUseOneCGNATRoute (#19719)",
"author_name": "Simon Law",
"author_login": "sfllaw",
"committed_at": "2026-05-13T04:55:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b729795c30f3f408b3caa983713eec1136d74ff",
"body": "Replace the process-global Server.mu lookup in the packet send hot path\nwith a global hashtriemap mirror of local clientSet entries. The\nauthoritative clients map remains guarded by Server.mu; clientsAtomic is\nonly a lock-free fast path for active local clients.\n\nMisses, stale inactive client sets, \n[…]\ndates #3560 (very indirectly, historically)\nUpdates #19713 (as an alternative to that PR)\n\nChange-Id: Ifb72e5c9854ad00e938cd24c6ab9c27312f297e8\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "derp/derpserver: use hashtriemap for peer lookup",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-12T23:08:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72578de0330c3a3150240b4f087033111e1f4b2e",
"body": "…services\n\nAdds two new cap resolution methods alongside the existing PeerCaps:\n\nPeerCapsForService(src netip.Addr, svcName tailcfg.ServiceName) resolves\nthe service name to its VIP addresses via the node's service IP mappings\nand returns caps scoped to that service. Exposed on /v0/whois via the\nsvc\n[…]\nhe existing PeerCaps/WhoIs path is\nunchanged: without a service parameter, WhoIs returns only host-level\ncaps.\n\nUpdates tailscale/corp#41632\n\nSigned-off-by: Adriano Sela Aviles <adriano@tailscale.com>",
"is_bot": false,
"headline": "ipn/{ipnlocal,localapi},client/local: add per-dst cap resolution for …",
"author_name": "Adriano Sela Aviles",
"author_login": "adrianosela",
"committed_at": "2026-05-12T22:50:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad8ead9c94a0dd66396528b23728b24e366d0942",
"body": "Fixes #12778\n\nChange-Id: If9f8b299cef0cb68f93b344845b5c6a5b7554d2c\nSigned-off-by: DeedleFake <deedlefake@users.noreply.github.com>",
"is_bot": false,
"headline": "cmd/tailscale/cli: add RunWithContext",
"author_name": "DeedleFake",
"author_login": "DeedleFake",
"committed_at": "2026-05-12T19:27:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f48567bf1933273b023c2f60e04babbecb68ae5",
"body": "…onnectivity (#19699)\n\nAdd new clientmetric counters for establishing contact with peers while using\ncached network map data. To do this, instrument the magicsock.Conn with a bit\nto indicate whether its peer data came from a cached netmap. If so, there are\ntwo conditions we will count as establishin\n[…]\n caching tests.\n\nUpdates https://github.com/tailscale/projects/issues/13\nUpdates #12639\n\nChange-Id: Ie8cf3244ac8af4f5bcfe4d0d944078da2ba08990\nSigned-off-by: M. J. Fromberger <fromberger@tailscale.com>",
"is_bot": false,
"headline": "ipn/ipnlocal,wgengine/magicsock: add basic counters for cached peer c…",
"author_name": "M. J. Fromberger",
"author_login": "creachadair",
"committed_at": "2026-05-12T19:01:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "120bfcf1cc3bdfcc7b5d78b12e725d161bb7f05f",
"body": "…d cache type name\n\nTwo changes that share the same intent of reducing per-T duplication\nin code that doesn't actually depend on T:\n\n1. Hoist the non-generic portion of newSubscriberFunc[T] into a\n newSubscriberFuncCore() helper. The hoisted work is the time\n timer setup, the subscriberFuncCore \n[…]\n7.6%) because the dispatch hot\npath no longer allocates a string on every event.\n\nUpdates #12614\n\nChange-Id: Ib3a3d6796785e16506330ec034e1144580d467a3\nSigned-off-by: James Tucker <james@tailscale.com>",
"is_bot": false,
"headline": "util/eventbus: extract non-generic SubscriberFunc constructor body an…",
"author_name": "James Tucker",
"author_login": "raggi",
"committed_at": "2026-05-12T18:16:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5e37e12167e6c63c6522e387f0a2dfcbfaffc7e3",
"body": "Use internal go modules",
"is_bot": false,
"headline": "Merge pull request #2 from BARGHEST-ngo/feature/no-mesh-patch",
"author_name": "Ovi",
"author_login": "0x0v1",
"committed_at": "2026-05-12T15:13:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "758ebe98394d92f02831498eb58456030a7dc2ab",
"body": "macOS limits Unix socket paths to 104 bytes. The Go test TempDir\npath (e.g. /var/folders/.../TestDirectConnection...679197086/001/)\neasily exceeds that, causing \"bind: invalid argument\". Create a\nshort /tmp/vmtest* directory for all socket files (vnet, QMP,\ndgram) so the paths stay well under the limit on every platform.\n\nUpdates #13038\n\nChange-Id: I721d24561d1766aaa964692bc77f40a131aa9455\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: use short paths for Unix sockets",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-12T04:54:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4c5613156dd382235929e5fb6de8f8088095614",
"body": "startCloudQEMU hardcoded -machine q35,accel=kvm and -cpu host,\nwhich fails on any host without KVM (notably macOS). Replace\nwith a qemuAccelArgs helper that probes /dev/kvm and falls back\nto QEMU's TCG software emulation, matching the pattern already\nused by tstest/integration/nat. Also wire the helper into\nstartGokrazyQEMU so gokrazy VMs pick up KVM when available.\n\nUpdates #13038\n\nChange-Id: I7745518db823279b1880957bb14ca2ffdaab4c50\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: don't require KVM; use TCG on macOS",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-12T02:18:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e062b46984a2a8e02881617a7105593da70924a5",
"body": "The natlab vmtest suite (tstest/natlab/vmtest) and the integration nat\ntests are gated behind --run-vm-tests because they need KVM and are\nslow. Until now nothing in CI exercised them apart from a single\ncanary TestEasyEasy run on every PR.\n\nAdd .github/workflows/natlab-test.yml that runs the full o\n[…]\nt only fires after 10s, so a truly stuck agent connection still\nsurfaces.\n\nUpdates #13038\n\nChange-Id: I4582098d8865200fd5a73a9b696942319ccf3bf0\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab, .github/workflows: add opt-in natlab CI workflow",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-12T00:14:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4eec4423b42a22e5331e99240baa75fd3d6b6f3b",
"body": "…ic core\n\nMirrors the same refactor previously applied to SubscriberFunc:\n\n - Publisher[T]: a thin user-facing facade. Holds a pointer to a\n non-generic publisherCore and exposes Publish/Close/ShouldPublish.\n - publisherCore: a non-generic struct that owns the *Client back-\n pointer, stop fl\n[…]\n within noise\n(2018 -> 2038 ns/op at -benchtime=2s) and all eventbus tests pass.\n\nUpdates #12614\n\nChange-Id: I61979c2bf95d2a711c2321e6e0b4b7d15980e9f5\nSigned-off-by: James Tucker <james@tailscale.com>",
"is_bot": false,
"headline": "util/eventbus: move Publisher publisher-interface impl to a non-gener…",
"author_name": "James Tucker",
"author_login": "raggi",
"committed_at": "2026-05-11T21:39:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d72cde1a6ba0c9559fa20d72f1d362427a11b71f",
"body": "…-generic core\n\nSplits SubscriberFunc[T] into:\n\n - SubscriberFunc[T]: a thin user-facing facade that holds only a\n pointer to a non-generic core. It exposes Close() to user code,\n which forwards to the core.\n - subscriberFuncCore: a non-generic struct that owns all the\n subscriber state (\n[…]\ns within noise\n(1955 -> 1941 ns/op on the test box) and all eventbus tests pass.\n\nUpdates #12614\n\nChange-Id: I646b3b05fd8d95f9afead59bfd0f69cd18b7a709\nSigned-off-by: James Tucker <james@tailscale.com>",
"is_bot": false,
"headline": "util/eventbus: move SubscriberFunc subscriber-interface impl to a non…",
"author_name": "James Tucker",
"author_login": "raggi",
"committed_at": "2026-05-11T19:14:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ead5ce65a3d7a50e8ce07cce3c746aadbeaa9a55",
"body": "There is a 30-second timeout set on client TLS connections but the handshake was\ncalled on the wrong connection and so the timeout was never used in practice.\n\nSigned-off-by: Francois Marier <francois@fmarier.org>",
"is_bot": false,
"headline": "cmd/pgproxy: fix client TLS handshake timeout",
"author_name": "Francois Marier",
"author_login": "fmarier",
"committed_at": "2026-05-11T18:12:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f45a6a9d8e180373414d42246914a2fb0af0a0c",
"body": "Make it possible to remove the least recently used expired address\nassignment from addrAssignments.\nBefore checking out a new address from the IP pools, return a handful of\nexpired addresses.\n\nUpdates tailscale/corp#39975\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
"is_bot": false,
"headline": "feature/conn25: return expired assignments to address pools",
"author_name": "Fran Bull",
"author_login": "franbull",
"committed_at": "2026-05-08T21:33:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "82346f388249b7f45355efdb13984d7ca3b5b74b",
"body": "Updates tailscale/corp#39975\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
"is_bot": false,
"headline": "feature/conn25: move addrAssignments to their own file",
"author_name": "Fran Bull",
"author_login": "franbull",
"committed_at": "2026-05-08T21:33:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "469d356ed899c0a097e6bcb7907fea819dcf3cba",
"body": "…9660)\n\nWhen a peer is not able to connect to control after a restart and is\nusing a cached netmap, that nodes should be able to connect to another\npeer in its tailnet (given that the home DERP of that peer has not\nchanged in the meantime).\n\nAdd test that starts two peers and connects them to a tail\n[…]\nrt it. Verify that the connection between the two ends up direct.\n\nAdds facilities for expecting a certain path type between nodes.\n\nUpdates: #19597\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: add test for direct conn with cached netmap (#1…",
"author_name": "Claus Lensbøl",
"author_login": "cmol",
"committed_at": "2026-05-08T20:57:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee2378b141f6c0365738e64d0057778fd7244d1a",
"body": "If a DNS query for a domain that should be routed through a connector\nresults in CNAME records in the response, collapse the CNAME chain to an\nA/AAAA record for the domain -> magic IP.\n\nFixes tailscale/corp#39978\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
"is_bot": false,
"headline": "feature/conn25: follow CNAMEs when rewriting DNS response",
"author_name": "Fran Bull",
"author_login": "franbull",
"committed_at": "2026-05-08T15:12:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24eb15744857437e41ea2eec7394ae9da8f72e3e",
"body": "Updates tailscale/corp#41490\n\nChange-Id: I35b67bdbcd71468fea03b033b17aeefe1319dc45\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "go.toolchain.rev: bump to Go 1.26.3",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-07T22:33:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d6ffc0d9865f9a8bbc3902c6c8f8d73731b96387",
"body": "The `CreateStateForTest` helper reduces boilerplate in cases where the test\nonly cares about the trusted keys and not the disablement values (and makes\nit more obvious where the disablement values are meaningful).\n\nThe `setupChonkStorage` helper reduces the boilerplate when creating on-disk\nTKA stor\n[…]\nduces the boilerplate when setting up a\n`LocalBackend` instance in the IPN tests.\n\nUpdates #cleanup\n\nChange-Id: Iacfba1be5f7fab208eec11e4369d63c7d7519da5\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
"is_bot": false,
"headline": "tka,ipn: reduce boilerplate in Tailnet Lock tests",
"author_name": "Alex Chan",
"author_login": "alexwlchan",
"committed_at": "2026-05-07T20:49:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "495d3acc7b7337131b94aaa28bdbd68d34e7f599",
"body": "Re-exec the test binary as a thin wrapper that holds a pipe inherited\nfrom the test. When the test goes away (any reason, including SIGKILL,\npanic, or OOM), the kernel closes the pipe write end; the wrapper sees\nEOF and SIGKILLs itself, taking QEMU and its children with it.\n\nUpdates #13038\n\nChange-Id: Ib2151098193551396c1d7bb51b07da3bd6b2cfb4\n\nSigned-off-by: Fernando Serboncini <fserb@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: kill QEMU when test process dies (#19676)",
"author_name": "Fernando Serboncini",
"author_login": "fserb",
"committed_at": "2026-05-07T20:14:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76248a68b2668081640fe7c043dc1c58e21495f9",
"body": "Running all vmtests in tstest/natlab/vmtest locally was breaking later\ntasks in the queue. The goroutine dump on timeout had goroutines hanging\naround for 9 minutes, meaning that something was not getting cleaned up.\n\n goroutine 262 [select, 9 minutes]:\n gvisor.dev/gvisor/pkg/tcpip/adapters/gonet.\n[…]\n) to gonet TCP connections when the test ends\n(inspired by ServeUnixConn()), and wait for them to shut down before\nexiting the test.\n\nUpdates #13038\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vnet: close gonet sockets when test is done (#19677)",
"author_name": "Claus Lensbøl",
"author_login": "cmol",
"committed_at": "2026-05-07T18:57:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "223cf5cb2486c40a8b18be6b59df7045655e573d",
"body": null,
"is_bot": false,
"headline": "Replace androidqf and wireguard",
"author_name": "devtimber",
"author_login": "devtimber",
"committed_at": "2026-05-07T11:56:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "33b9579c21d5c5841a38b3e18159ac8ff44943be",
"body": "…e (#19662)\n\nFixes: #14927\n\nSigned-off-by: Hazel T <hazel@tailscale.com>",
"is_bot": false,
"headline": "scripts/installer.sh: add openSUSE Slowroll as a Tumbleweed derivativ…",
"author_name": "Hazel T",
"author_login": "KannaDev",
"committed_at": "2026-05-07T11:43:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76712b32d9179843f301e431ebae634da2cd1c0d",
"body": "Updates #cleanup\n\nSigned-off-by: Erisa A <erisa@tailscale.com>",
"is_bot": false,
"headline": ".github: install ca-certificates on Kali to fix installer tests (#19673)",
"author_name": "Erisa A",
"author_login": "Erisa",
"committed_at": "2026-05-07T11:20:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0def0f19bdf150192efe22bca92b6b2649d1eb83",
"body": "…helper\n\nThe (*SubscriberFunc[T]).dispatch method body — a ~40-line select\nloop with slow-subscriber timer, snapshot handling, ctx-cancel\ndraining, and a CI stack-dump branch — was previously fully\nduplicated by the Go compiler for every distinct GC shape of T.\nNone of that body actually depends on \n[…]\nlocs/op, 144 B/op as the prior eventbus implementation. All\neventbus tests pass.\n\nUpdates #12614\n\nChange-Id: I85f933f50f58cd25bbfe5cc46bdda7aab22f0bf7\nSigned-off-by: James Tucker <james@tailscale.com>",
"is_bot": false,
"headline": "util/eventbus: extract SubscriberFunc.dispatch loop to a non-generic …",
"author_name": "James Tucker",
"author_login": "raggi",
"committed_at": "2026-05-07T01:56:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "87a74c3aa2ea1cebdc6db64e6e390849da457313",
"body": "The tailscale.com/wif package brings in the AWS SDK\n(github.com/aws/aws-sdk-go-v2/{config,sts,...} and github.com/aws/smithy-go)\nto support fetching ID tokens from AWS IMDS for workload identity\nfederation. Until now, tsnet pulled this in unconditionally via\nfeature/condregister/identityfederation, \n[…]\n, so it shouldn't be\nsubject to the ts_omit_identityfederation build tag.\n\nUpdates #12614\n\nChange-Id: I70599f2bdd4d3666b26a859d5b76caa5d6b94507\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tsnet: make workload identity federation opt-in",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-07T01:43:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "daddb14b8f293ded2489f54bf8b2f335bf0020a0",
"body": "When HTTPS is explicitly disabled (HTTPSPort == NoPort), the JS WebSocket\ndialer should use ws:// instead of wss://. This matches the behavior of\nthe non-JS client and fixes connections to development control servers\ne.g. http://localhost:31544.\n\nUpdates tailscale/corp#40944\n\nSigned-off-by: Adriano Sela Aviles <adriano@tailscale.com>",
"is_bot": false,
"headline": "control/controlhttp: use ws:// when HTTPSPort is NoPort in JS dialer",
"author_name": "Adriano Sela Aviles",
"author_login": "adrianosela",
"committed_at": "2026-05-06T22:58:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d06cc56987d85662bdf2f8ed61fbabb71da93347",
"body": "Per recent chat with @raggi about all this, I went and looked at this\ntest again.\n\nUpdates #cleanup\n\nChange-Id: Icb7d87b1ed2cebf481ee4e358a3aa603e63fb8a4\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "wgengine/magicsock: add more docs, checks to Test32bitAlignment",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-06T22:29:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "15bb10dbce3a8ee7ddd4350df179ff73ccfbe52e",
"body": "Commit 69c79cb9f (Sep 2025) moved awsstore and kubestore registration\nbehind condregister build tags so tsnet wouldn't pull in the AWS SDK\nand Kubernetes client by default. The accompanying TestDeps BadDeps\nentry was missed, so PR #19667 (which re-added those imports) wasn't\ncaught by the test.\n\nAdd\n[…]\no packages to BadDeps so future regressions fail the test.\n\nUpdates #19667\nUpdates #12614\n\nChange-Id: I903b7c976e5e122cc0c0b956dc73740f5d474fac\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tsnet: ban awsstore and kubestore as deps in TestDeps",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-06T21:57:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b74eeda0556f1a7167e10224e3effb1fd4320a17",
"body": "Include the unit (s) when printing the time taken to test each package.\n\nUpdates #cleanup\n\nSigned-off-by: Tom Proctor <tomhjp@users.noreply.github.com>",
"is_bot": false,
"headline": "cmd/testwrapper: print unit for package duration (#19663)",
"author_name": "Tom Proctor",
"author_login": "tomhjp",
"committed_at": "2026-05-06T21:31:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c721189cef88d7726b188f7d61d52cf0e8cdfc52",
"body": "Android rebuilds its VpnService interface when the VPN route\nconfiguration changes, which tears down long lived TCP connections\nthrough the tunnel. Use the same automatic OneCGNATRoute behavior as\nmacOS on Android, and prefer the single CGNAT route when no other\ninterface is using the CGNAT, falling back to fine grained peer routes\notherwise.\n\nUpdates tailscale/tailscale#19591\n\nSigned-off-by: kari <kari@tailscale.com>",
"is_bot": false,
"headline": "ipn/ipnlocal: prefer one CGNAT route on Android (#19652)",
"author_name": "kari-ts",
"author_login": "kari-ts",
"committed_at": "2026-05-06T02:11:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f844c8bc32f237bf21f83ce89923cafc6c830a00",
"body": "The test goroutine read lockCnt immediately after Lock returned, racing\nwith Close: close(lk.closing) wakes lockSlow's select, whose deferred\nAdd(-2) on lockCnt can run before Close's CAS clears the LSB. When that\nhappens, lockCnt is briefly 1 (3 - 2) instead of 0 (1 + 2 - 2 - 1),\nproducing \"lockCnt\n[…]\ne Lock goroutine has finished, so both updates\nhave settled before we read.\n\nFixes #19647\n\nChange-Id: Ia67036ff73a1beb528cbd621460db9048f3066ad\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "util/winutil/gp: deflake TestGroupPolicyReadLockClose",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-05T21:02:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "872d79089ead823cf2e930b007d6aad312e05cd2",
"body": "Signed-off-by: Jonathan Nobels <jonathan@tailscale.com>",
"is_bot": false,
"headline": "VERSION.txt: this is v1.99.0 (#19645)",
"author_name": "Jonathan Nobels",
"author_login": "barnstar",
"committed_at": "2026-05-05T19:07:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa21b0c0082040892064a4d4af0aabdc78dde653",
"body": "…9627)\n\nWhen an exit node was set before launching systray, the recommended row\nin exit nodes rendered as not selected even when the active exit node\nwas at the same location.\n\nThis looks to be two different things:\n\n- suggestExitNode takes its own suggestion into account, and not the\n users active\n[…]\nnd mutated via .Check(), which for newly\n created elements may be cached (such as when launching systray, with\n an already active node).\n\nFixes #19626\n\nSigned-off-by: Evan Lowry <evan@tailscale.com>",
"is_bot": false,
"headline": "client/systray: fix recommended exit node not showing as selected (#1…",
"author_name": "Evan Lowry",
"author_login": "Lykathia",
"committed_at": "2026-05-05T13:49:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eac531da8e22a87e18ca1f04e16e93bce1e50c04",
"body": "This was originally hidden during the beta period in both `up` and `set`,\nthen when device posture went GA we unhid the flag in `set` but not in\n`up`.\n\nThis is confusing for users, because an error message can direct them to\nrun `tailscale up` with this flag if they've set it previously, but the\nhelp text won't tell them what it does.\n\nUpdates #5902\nUpdates #17972\n\nChange-Id: I9a31946f4b3bb411feed0f5a6449d7ff9a5ba9d3\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
"is_bot": false,
"headline": "cmd/tailscale/cli: unhide `--report posture` flag in `up`",
"author_name": "Alex Chan",
"author_login": "alexwlchan",
"committed_at": "2026-05-05T09:12:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "883d4fd2cddf80cf860a10bd8e8b5e45cf00599e",
"body": "… instead\n\nFixes #19633\nFixes #13760\n\nChange-Id: I0fa9423523a3a0fb1dfcde57de0f26e51723ff97\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "wgengine/netstack, net/ping: stop using pro-bing and use our net/ping…",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-04T21:05:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "81569e891fdcd71aabc0fb0ccd2238f6f805abea",
"body": "The purpose of this package is to test the iOS dependency closure, but\nit had drifted from the actual import list of the ipn-go-bridge package\nin the corp repo (the Go side of the iOS / macOS app).\n\nUpdate the imports to match ipn-go-bridge's GOOS=ios import list,\nadding many missing packages includ\n[…]\ner-ping, so the iOS app already ships them.\nBut we should fix that later.\n\nUpdates #19633\n\nChange-Id: Ic50779fdb195685a2e8ccd7c513eee91b0feeaf8\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/iosdeps: update import list to mirror ipn-go-bridge",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-04T21:05:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9bb7ca6116a90da553454614e497a8cb84faa8c0",
"body": "Add a new vet checker that rejects variables, parameters, named\nreturn values, receivers, range/type-switch bindings, type\nparameters, struct fields, and constants named \"l\" (lowercase ell)\nor \"I\" (uppercase i). Both are hard to distinguish from the digit\n\"1\" and from each other in too many fonts.\n\n\n[…]\nstdata/ directories, which\nthe go tool ignores; they are not real packages.\n\nFixes #19631\n\nChange-Id: I71ad2fa990705f7a070406ebcdb8cefa7487d849\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "cmd/vet/lowerell, drive/driveimpl: forbid variables named \"l\" or \"I\"",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-04T21:03:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0cf899610c2ac62780826d8e3ba908ddcc3f2115",
"body": "Added in 2022, this appears to be unused now.\n\nUpdates #cleanup\n\nSigned-off-by: Andrew Lytvynov <awly@tailscale.com>",
"is_bot": false,
"headline": "util/linuxfw/linuxfwtest: remove unused package (#19520)",
"author_name": "Andrew Lytvynov",
"author_login": "awly",
"committed_at": "2026-05-04T19:33:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ca2317439dcc543cce62d55fa7ebd794f5ebe34f",
"body": "Signed-off-by: License Updater <noreply+license-updater@tailscale.com>",
"is_bot": false,
"headline": "licenses: update license notices",
"author_name": "License Updater",
"author_login": null,
"committed_at": "2026-05-04T17:34:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce76f44df2592dbd9c97b27ef0c04d079be907d0",
"body": "Which can be unfair around varying packet sizes.\n\nUpdates tailscale/corp#40962\n\nSigned-off-by: Jordan Whited <jordan@tailscale.com>",
"is_bot": false,
"headline": "derp/derpserver: remove global rate limiter",
"author_name": "Jordan Whited",
"author_login": "jwhited",
"committed_at": "2026-05-04T16:41:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29122506be064dbecfcb376d45a00106f762db26",
"body": "Move HOOK_VERSION into the githook package and export it as\ngithook.HookVersion, so tailscale/corp can reference it via\nthe shared-code bump instead of having to bump HOOK_VERSION\nby hand.\n\nNew launcher.sh composes the wanted version from 2 sources:\nthe shared HOOK_VERSION and an optional repo local\n[…]\nisc/git_hook/HOOK_VERSION, for repo-specific config bumps.\n\nUpdates tailscale/corp#40381\n\nChange-Id: I7cf16889ba53cb564cc2df7dfd7588748f542c55\n\nSigned-off-by: Fernando Serboncini <fserb@tailscale.com>",
"is_bot": false,
"headline": "misc/git_hook: propagate shared HOOK_VERSION (#19476)",
"author_name": "Fernando Serboncini",
"author_login": "fserb",
"committed_at": "2026-05-04T16:38:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "290a6cc03cb9ba59b4847a778c4bf9f382c52e21",
"body": "…9202)\n\nInstalled SplitDNS routes are always treated as wildcard domains,\nso the domains that we pass to the local resolver should be normalized\nand have any leading *. wildcard prefix removed.\n\nWhen looking at DNS responses to see if the domain matches, we need to\nconsider both exact matches and wi\n[…]\n response should be rewritten, it is ignored\nif any of the matching apps for the domain are in the self-hosted apps set.\n\nFixes tailscale/corp#39272\n\nSigned-off-by: George Jones <george@tailscale.com>",
"is_bot": false,
"headline": "appc, feature/conn25: handle exact and wildcard domains correctly (#1…",
"author_name": "George Jones",
"author_login": "george-tailscale",
"committed_at": "2026-05-01T21:33:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bdf3419e7d5c851b9fe4c974d93ffb6f0da4820d",
"body": "If another part of the client code registers a custom scheme with the\nforwarder, the forwarder will check resolver addresses to see if they\nmatch the scheme. If they do, the corresponding custom scheme handler\nwill be called to find the actual address for the resolver at this\nmoment. If the handler \n[…]\nwork that would like to make sure it sends DNS requests to the\ncurrent connector peer in a high availability configuration.\n\nUpdates tailscale/corp#39858\n\nSigned-off-by: Fran Bull <fran@tailscale.com>",
"is_bot": false,
"headline": "net/dns: add custom scheme resolvers",
"author_name": "Fran Bull",
"author_login": "franbull",
"committed_at": "2026-05-01T21:01:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78126c5d9f8876fb4e98be4a786a01c9ed9ab983",
"body": "Add a node capability to help determine if the desktop clients should\nshow services list/menu/section\n\nUpdates: https://github.com/tailscale/corp/issues/40900\n\nChange-Id: Ie34b3362f921d710173b2a0dd190354352bb26f0\n\nSigned-off-by: Rollie Ma <rollie@tailscale.com>",
"is_bot": false,
"headline": "tailcfg: add node capability for services in desktop clients (#19605)",
"author_name": "Rollie Ma",
"author_login": "waltzofpearls",
"committed_at": "2026-05-01T19:07:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee10f9881c86e5f230c2af34ed0bfaa009697b03",
"body": "also fixes memory leak with authKeyReissuing map on ProxyGroup\nreconciler authkey reissue.\n\nUpdates #19311\n\nSigned-off-by: chaosinthecrd <tom@tmlabs.co.uk>",
"is_bot": false,
"headline": "cmd/k8s-operator: add authkey reissuing to recorder reconciler (#19556)",
"author_name": "Tom Meadows",
"author_login": "ChaosInTheCRD",
"committed_at": "2026-05-01T17:26:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ced30b0b6b6aa085cfbba5f5a9bbc0a52d480b3",
"body": "Values get written into TKA state; secrets don't.\n\nUpdates #cleanup\n\nChange-Id: Ief9831dcb1102f584a33b2e71b611b38ca463724\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
"is_bot": false,
"headline": "tka: clarify that this limit is on disablement *values* not *secrets*",
"author_name": "Alex Chan",
"author_login": "alexwlchan",
"committed_at": "2026-05-01T17:25:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f15a4f441621e537340234d63271d3cf4dffe4b5",
"body": "There are only a couple endpoints that check peer capabilities. Keeping\npermission checks with the code that assumes they were performed, rather\nthan with the routing layer, feels easier to reason about.\n\nCheck that the caller is actually a peer and pass their capabilities via\na context value for ha\n[…]\nlers that want to check them.\n\nAlong with this, simplify the helper handler wrappers that are not\nneeded for most of the endpoints.\n\nUpdates #40851\n\nSigned-off-by: Andrew Lytvynov <awly@tailscale.com>",
"is_bot": false,
"headline": "client/web: move API permission checks into handlers (#19576)",
"author_name": "Andrew Lytvynov",
"author_login": "awly",
"committed_at": "2026-05-01T16:01:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bbcb8650d418f699034cfc57216d2ad8ec7d3556",
"body": "Stop opening an IPN bus subscription with NotifyInitialNetMap purely to\nread the current netmap once. Use the LocalAPI debug current-netmap\naction (added in 159cf8707) instead, which returns the current netmap\nsynchronously without subscribing to the bus.\n\nUpdates #12542\n\nChange-Id: I8aa2096d65aaea4dfe62634f03ce06b5470e0e51\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "cmd/tailscale/cli: fetch netmap via current-netmap debug action",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-01T14:53:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c3ed5ab32f29159301edd812d5948eef8602499",
"body": "Move tailscaled's in-tree reactive users from of IPN bus Notify.NetMap\nupdates to the narrower Notify.SelfChange signal introduced earlier in\nthis series. Consumers that need additional state (peers, DNS config,\netc.) fetch it on demand via the LocalAPI.\n\nIt is a step toward the larger goal of not f\n[…]\nto the\nupcoming new Notify APIs, we'll remove ipn.Notify.NetMap entirely)\n\nUpdates #12542\n\nChange-Id: I51ea9d86bdca1909d6ac0e7d5bd3934a3a4e8516\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "all: migrate code off Notify.NetMap to Notify.SelfChange",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-01T13:51:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff9c3f0e003ebf7f351dcae7c14a6b770b6c9544",
"body": "For testing the loading of netmap cache from disk, the cache needs to\nexist. The simple solution is to start two nodes and connect them to\ncontrol, with the netmap caching capability set. Then cut the connection\nto control, restart the nodes, and ping between them.\n\nThis tests that we can start from\n[…]\nstablish a connection between the nodes.\n\nFor now this is not testing how the nodes are able to talk to each other\n(DERP vs direct).\n\nUpdates #19597\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: add test loading netmap cache from disk (#19598)",
"author_name": "Claus Lensbøl",
"author_login": "cmol",
"committed_at": "2026-05-01T13:46:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "89a78dc9b733671bfc62d14377c6a7a4b7e1837d",
"body": "Add a narrow LocalAPI accessor and matching client/LocalBackend method\nto look up a single peer's current full [tailcfg.Node] by NodeID, in\nO(1) time on the daemon side, without fetching the entire netmap.\n\nUseful for callers that need the latest state of a single peer (e.g.\nin response to a peer-mutation event on the IPN bus) without paying\nfor a full netmap fetch.\n\nUpdates #12542\n\nChange-Id: I1cb2d350e6ad846a5dabc1f5368dfc8121387f7c\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "client/local, ipn/localapi, ipn/ipnlocal: add PeerByID",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-05-01T13:20:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cac94f51cc71d15fdca91582487d7216d93aa172",
"body": "Compacting on startup means nodes may compact at a different cadence\nbased on whether they're long-running or restarting frequently.\n\nWe already compact after every sync, which only occurs when the TKA\nstate has changed. Waiting for TKA changes to trigger compaction on\nnodes means compaction will occur more consistently across a tailnet.\n\nUpdates tailscale/corp#33537\n\nChange-Id: Ia0aa6d9e5e362e9ab08450fde69772841790d5b5\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
"is_bot": false,
"headline": "ipn/ipnlocal: don't compact TKA state on startup",
"author_name": "Alex Chan",
"author_login": "alexwlchan",
"committed_at": "2026-05-01T12:27:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6c5d237429f3f7e865d757e5f5075a8c919bbbd",
"body": "Add a new bus signal that lets reactive consumers (containerboot, kube\nagents, sniproxy, tsconsensus, etc.) react to self-node updates without\nhaving to subscribe to the full netmap. Today those consumers either\nwatch Notify.NetMap (which on large tailnets is expensive to encode and\nship per watcher\n[…]\nthe legacy NetMap emission to platforms whose host GUIs still\nrequire it.\n\nUpdates #12542\n\nChange-Id: I4441650b0e085d663eb6bf26a03748b7d961ca49\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "ipn, ipn/ipnlocal: add Notify.SelfChange",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-30T21:47:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9f343fdc0cf1455f5550cb0d6c6a344848049306",
"body": "Add two narrow LocalAPI accessors so callers don't have to subscribe to\nthe IPN bus and pull a full *netmap.NetworkMap just to read DNS-shaped\nfields:\n\n - GET /localapi/v0/cert-domains returns DNS.CertDomains.\n - GET /localapi/v0/dns-config returns the full tailcfg.DNSConfig.\n\nMigrate in-tree call\n[…]\nraveling on the IPN bus, so the bus payload can shrink in a\nlater change.\n\nUpdates #12542\n\nChange-Id: Ie10204e141d085fbac183b4cfe497226b670ad6c\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "client/local, ipn/localapi, all: add CertDomains and DNSConfig accessors",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-30T20:50:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "822299642b71ae381d2be1d46234fc48acf8ec5c",
"body": "We have two sources of truth for configuration state: the node view\n(from the netmap/policy) and prefs (the --advertise-connector option).\nThese come with two independent update paths: onSelfChange for node view\nchanges and profileStateChange for pref changes.\n\nCentralize config on Conn25 so that on\n[…]\nonfig. See getIPSets() in this commit.\n\n - As of this commit, the connector doesn't need config-derived state at\n all.\n\nFixes tailscale/corp#40872\n\nSigned-off-by: Michael Ben-Ami <mzb@tailscale.com>",
"is_bot": false,
"headline": "feature/conn25: centralize config on Conn25 with atomic access",
"author_name": "Michael Ben-Ami",
"author_login": "mzbenami",
"committed_at": "2026-04-30T20:29:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "159cf8707a0293e58c6e23360240b9b62f72294f",
"body": "…MapWithPeers\n\nAdd two narrower accessors alongside the existing\n[LocalBackend.NetMap], with docs that distinguish their semantics:\n\n - NetMapNoPeers: cheap (returns the cached *netmap.NetworkMap with\n a possibly-stale Peers slice). For callers that only read non-Peers\n fields like SelfNode, \n[…]\nreaking up a larger change for\nreview; on its own it is a no-op refactor.\n\nUpdates #12542\n\nChange-Id: Idbb30707414f8da3149c44ca0273262708375b02\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "ipn/ipnlocal, all: split LocalBackend.NetMap into NetMapNoPeers / Net…",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-30T18:14:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92179b1fc7ec203eaa9cb5f584f34ca36f25168c",
"body": "Move the template, request handler, and HTTP/HTTPS server wiring out\nof package main and into a new cmd/hello/helloserver package so the\nserver can be embedded in other binaries. The main package now only\nconstructs a helloserver.Server with the production addresses and\ncalls Run.\n\nWhile here, drop \n[…]\nllbacks they enabled; the binary is\nonly run in production.\n\nUpdates tailscale/corp#32398\n\nChange-Id: Id1d38b981733334cafc596021130f36e1c1eed67\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "cmd/hello: split server into helloserver package",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-30T15:40:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "644c3224e923b4f2e10035672bdb2fe2b16a6830",
"body": "This commit modifies the usage of the `egressservices.Configs` type\nwithin containerboot and the k8s operator.\n\nOriginally it was being thrown around as a pointer which is not required\nas maps are already pointers under the hood.\n\nSigned-off-by: David Bond <davidsbond93@gmail.com>",
"is_bot": false,
"headline": "cmd/{containerboot,k8s-operator}: don't return pointers to maps (#19593)",
"author_name": "David Bond",
"author_login": "davidsbond",
"committed_at": "2026-04-30T15:11:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "815bb291c9cecacfaca5f884bd4a1702f1c0edf2",
"body": "If a user passes --advertise-tags=foo,bar (with no colons in any\nsegment), automatically prepend \"tag:\" client-side so it goes on the\nwire as \"tag:foo,tag:bar\". Segments that already contain a colon are\nleft untouched and must be fully-qualified (\"tag:foo\"), which keeps\nthe door open for future colo\n[…]\nuto-qualifying tag names in advertise-tags and I hope I won't regret\nit :)\"\n\nUpdates #861\n\nChange-Id: I06935b0d3ae909894c95c9c2e185b7d6a219ff32\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "cmd/tailscale/cli: allow tag without \"tag:\" prefix in 'tailscale up'",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-30T14:13:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f343b496c3efef16b1d0dd4183a3d7624daba944",
"body": "…mand peers\n\nReplace the UAPI text protocol-based wireguard configuration with\nwireguard-go's new direct callback API (SetPeerLookupFunc,\nSetPeerByIPPacketFunc, RemoveMatchingPeers, SetPrivateKey).\n\nInstead of computing a trimmed wireguard config ahead of time upon\ncontrol plane updates and pushing \n[…]\nPs to node public keys\nusing the existing nodeByAddr index.\n\nUpdates tailscale/corp#12345\n\nChange-Id: I4cba80979ac49a1231d00a01fdba5f0c2af95dd8\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "wgengine, all: remove LazyWG, use wireguard-go callback API for on-de…",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-30T02:46:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b313bffbe7e5fe31694f2127621c04790f2216fa",
"body": "…stControl\n\nThe test was flaky under stress with \"AddRawMapResponse N: node not\nconnected\" failures. The root cause was in testcontrol's addDebugMessage:\nit conflated \"no streaming poll registered\" with \"wake-up channel buffer\nmomentarily full\". The single-slot updatesCh is just a lossy wake-up\nsign\n[…]\nn CI)\" stack\ndumps emitted by controlhttp.(*Dialer).forceNoise443 under CI.\n\nFixes #19583\n\nChange-Id: Ib2334376585e8d6562f000a0b71dea0117acb0ff\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "control/tsp, tstest/integration/testcontrol: deflake TestMapAgainstTe…",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T23:11:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "978b6a81b286201d968dff19ae1afc98acf09d03",
"body": "78627c1 introduced starting up and preserving the DERP server from\ncache, but also changed it so the initial ReSTUN would not fire when\nsetting the DERPMap.\n\nChange this so when not working from a cache, the ReSTUN will always\nfire during startup.\n\nUpdates #19585\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
"is_bot": false,
"headline": "ipn/ipnlocal: always ReSTUN when starting up without a cache (#19586)",
"author_name": "Claus Lensbøl",
"author_login": "cmol",
"committed_at": "2026-04-29T22:56:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0a9728fe2abcb5219589915a116ba15afbec56f",
"body": "As of 0e9f9e2bd it is possible to have an infinity per-client limit,\nwith finite global.\n\nUpdates tailscale/corp#40962\n\nSigned-off-by: Jordan Whited <jordan@tailscale.com>",
"is_bot": false,
"headline": "derp/derpserver: fix Server.UpdateRateLimits docs",
"author_name": "Jordan Whited",
"author_login": "jwhited",
"committed_at": "2026-04-29T21:43:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e9f9e2bd80712f2deec48930633813151614e92",
"body": "This commit enables the operator to set a global rate limit without any\nper-client.\n\nUpdates tailscale/corp#40962\n\nSigned-off-by: Jordan Whited <jordan@tailscale.com>",
"is_bot": false,
"headline": "derp/derpserver: support global rate limiting independent of per-client",
"author_name": "Jordan Whited",
"author_login": "jwhited",
"committed_at": "2026-04-29T21:15:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "15cba0a3f66fc2f5a481ec9d986f94e9a95d2935",
"body": "Add a vmtest that brings up two gokrazy nodes A and B behind two\nOne2OneNAT networks (so direct UDP works in both directions and any\nslowness can't be blamed on NAT traversal), establishes a WireGuard\ntunnel A → B with TSMP, then rotates B's disco key four times and\nasserts that the data plane recov\n[…]\n retry transient\n failures rather than fataling the test.\n\nUpdates #12639\nUpdates #13038\n\nChange-Id: I3644f27fc30e52990ba25a3983498cc582ddb958\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: add TestDiscoKeyChange",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T19:58:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "22ff402da93f1487f9de72a413014500a39003cf",
"body": "…utReSTUN\n\nCommit 78627c132f changed the signature of magicsock.Conn.SetDERPMap to\ntake an additional bool doReStun parameter. Avoid both the boolean\nparameter and the API signature change by restoring SetDERPMap to its\noriginal single-argument form and adding a new SetDERPMapWithoutReSTUN\nmethod for the cache-loading caller that wants to skip the post-set\nReSTUN.\n\nUpdates #19490\n\nChange-Id: I97d9e82156bfc546ccf59756d1ea52f039b5de06\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "wgengine/magicsock: restore SetDERPMap signature, add SetDERPMapWitho…",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T19:46:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "26c56338c68235956decad7459cea54e9099c991",
"body": "…e7bd2da",
"is_bot": false,
"headline": "chore: Cumulative updates from MESH 5a0f75cb16c9a42a838bb759a3e194822…",
"author_name": "Dan Staples",
"author_login": "dismantl",
"committed_at": "2026-04-29T18:45:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1cd8bcc82734620931f6d2bc0cbe90c057e4439d",
"body": "Updates: tailscale/corp#40648\nSigned-off-by: Adriano Sela Aviles <adriano@tailscale.com>",
"is_bot": false,
"headline": "tailcfg: extend services model for client application actions",
"author_name": "Adriano Sela Aviles",
"author_login": "adrianosela",
"committed_at": "2026-04-29T18:33:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70f0b261b6f96192cd2a4e0974ee3bf8f6d7cbda",
"body": "…log change\n\nWhen we switched to monogok in 371d6369cd25afb, we lost our gokrazy fork's\nchange to let the syslog be configured from the Linux cmdline.\n\nThat's sent upstream in gokrazy/gokrazy#275 but still in review. Meanwhile,\nrevert to a fork, while still keeping monogok. Monogok was updated to\nsu\n[…]\nthe log polling loop out of pending PR #19568\nand go ack to using syslog.\n\nUpdates #13038\n\nChange-Id: I36931ee8eecc40d6165ad036c6181dfb07b86ba2\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "go.mod, gokrazy: bump to fork of gokrazy/gokrazy init process for sys…",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T18:27:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "01d0bdd25366a095ec5a07e14baaef438d309f2b",
"body": "Expvars track count of rate limiters exceeding their threshold.\nCovers (1) global rate limiter and (2) total of local rate limiters.\n\nAlso publish optional rate-limit metrics during ExpVar() call\nif -rate-config is specified. Fixes current rate-limit metrics\nbeing published outside of \"derp\" in /debug/vars.\n\nUpdates tailscale/corp#38509\n\nChange-Id: Ic7f5a1e890d0d7d3d7b679daa4b5f8926a6a6964\nSigned-off-by: Alex Valiushko <alexvaliushko@tailscale.com>",
"is_bot": false,
"headline": "cmd/derper,derp: add metrics for rate limit hits (#19560)",
"author_name": "Alex Valiushko",
"author_login": "illotum",
"committed_at": "2026-04-29T17:29:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be7cce74ba97f2f31820168aed0ea4c8e73e3367",
"body": "…ch (#19575)\n\nThe mismatch behaviour of falling back to a previous key could end up\nbreaking connections when the netmap update took longer than the 2\nseconds allowed in controlClient.auto for netmap updates, or if the\ncontrolClient context was canceled. This could end up breaking\nlegitimate updates\n[…]\nom control.\n\nInstead, log the event, and let the connection be reset to that of the\nkey as that is safer.\n\nIssue found by @bradfitz.\n\nUpdates #19574\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
"is_bot": false,
"headline": "wgengine/userspace: do not fall back to old key on tsmpLearned mismat…",
"author_name": "Claus Lensbøl",
"author_login": "cmol",
"committed_at": "2026-04-29T17:23:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd6ae2fad4be801b3610358fc52c5df4bdcfd736",
"body": "Two cloud-platform nodes (e.g. sr-a and sr-b in TestSiteToSite) boot in\nparallel via errgroup and both call ensureCompiled and the inline image\npreparation block, racing to Begin() the same shared *Step (which is\ndeduped by name in Env.Step). The second goroutine panics:\n\n panic: Step \"Compile li\n[…]\ns Begin/work/End.\n\nFixes commit 02ffe5baa8ccb2b81c4cfba3b59653e2cff10e01.\n\nUpdates #13038\n\nChange-Id: If710bcc9e0aafebf0ad5b61553bae11458d976d7\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: serialize per-platform setup with sync.Once",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T16:54:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02ffe5baa8ccb2b81c4cfba3b59653e2cff10e01",
"body": "Cache a pre-booted macOS VM snapshot on disk so subsequent test runs\nrestore from the snapshot instead of cold-booting. The snapshot is keyed\nby the Tart base image digest and a code version constant\n(macOSSnapshotCodeVersion); bumping either invalidates the cache.\n\nSnapshot preparation (one-time):\n\n[…]\ne\n- Fix Makefile: set -o pipefail so xcodebuild failures aren't swallowed\n\nUpdates #13038\n\nChange-Id: Icbab73b57af7df3ae96136fb49cda2536310f31b\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: add macOS VM snapshot caching for fast test starts",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T15:17:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7b53550fe6fb11a5dce69ce61cee108c3607273a",
"body": "…(#19565)\n\nUpon deciding to update the LastSeen timestamp, we weren't checking that the\nfield we are replacing into was non-nil. Rather than add an additional check,\njust allocate a fresh pointer for the updated time.\n\nUpdates #19564\n\nChange-Id: I589ebe65175fc7677c04a31dd6c4670e2531ee62\nSigned-off-by: M. J. Fromberger <fromberger@tailscale.com>",
"is_bot": false,
"headline": "control/controlclient: fix a nil-indirection bug in DERP key pruning …",
"author_name": "M. J. Fromberger",
"author_login": "creachadair",
"committed_at": "2026-04-29T14:57:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a29e42135b793660e4e658aa4f2bc8155420de36",
"body": "This commit modifies the `DNSConfig` resource to allow customisation of\nthe `spec.nodeSelector` field in the nameserver pods.\n\nCloses: https://github.com/tailscale/tailscale/issues/19419\n\nSigned-off-by: David Bond <davidsbond93@gmail.com>",
"is_bot": false,
"headline": "cmd/k8s-operator: add nodeSelector to `DNSConfig` resource (#19429)",
"author_name": "David Bond",
"author_login": "davidsbond",
"committed_at": "2026-04-29T14:56:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4cec06b8f2c65c832ed71a902481c80dbe80695c",
"body": "When --vmtest-web is set, Host.app is launched with --screenshot-port 0\nto start a localhost HTTP server that captures the VZVirtualMachineView\ndisplay. The Go test harness parses the SCREENSHOT_PORT=<port> line from\nstdout, then polls every 2 seconds for JPEG thumbnails and pushes them\nover WebSock\n[…]\ny're large\nand only the latest matters, stored in NodeStatus.Screenshot).\n\nUpdates #13038\n\nChange-Id: I9bc67ddd1cc72948b33c555d4be3d8db06a41f6d\nSigned-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>",
"is_bot": false,
"headline": "tstest/natlab/vmtest: add macOS VM screenshot streaming to web UI",
"author_name": "Brad Fitzpatrick",
"author_login": "bradfitz",
"committed_at": "2026-04-29T14:48:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78627c132f6795ed85729bac97a4ed6bca1c8295",
"body": "…#19491)\n\nWith netmap caching, the home DERP of the self node was neither saved to\nthe cache or loaded from it, making nodes not stick to a DERP when\nstarting without a connection to control.\n\nInstead, make sure that when a cache is available, load that cache,\nbefore looking for DERP servers. This i\n[…]\nished.\n\nMaking DERP only change when connected to control is handled by existing\ncode from f072d017bd8241675aa946a27fc1827f570435cb.\n\nUpdates #19490\n\nSigned-off-by: Claus Lensbøl <claus@tailscale.com>",
"is_bot": false,
"headline": "wgengine/magicsock,ipn/ipnlocal: store and load homeDERP from cache (…",
"author_name": "Claus Lensbøl",
"author_login": "cmol",
"committed_at": "2026-04-29T14:24:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1841a93ab2c30d6ce79af53d3ccf0b3d9f1c2897",
"body": "…laky (again)\n\nThis test is still flaking on macOS, so mark it as such so we can track\nand investigate further.\n\nUpdates #7707\n\nChange-Id: I640da3c1068a90a9815caab2df9431bceb01f846\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
"is_bot": false,
"headline": "ssh/tailssh: mark TestSSHRecordingCancelsSessionsOnUploadFailure as f…",
"author_name": "Alex Chan",
"author_login": "alexwlchan",
"committed_at": "2026-04-29T13:22:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb91bb842c189d0ebe7ea87e6744b5484f1f3511",
"body": "Seamless key renewal has been the default in all clients since 1.90.\nWe retained the ability to disable it from the control plane as a\nprecaution, but we haven't seen any issues that require us to disable it.\n\nWe're now removing all the code for non-seamless key renewal, because we\ndon't expect to t\n[…]\nntested in the\nfield for three releases so might contain latent bugs!\n\nUpdates tailscale/corp#33042\n\nChange-Id: I4b80bf07a3a50298d1c303743484169accc8844b\nSigned-off-by: Alex Chan <alexc@tailscale.com>",
"is_bot": false,
"headline": "all: remove everything related to non-seamless key renewal",
"author_name": "Alex Chan",
"author_login": "alexwlchan",
"committed_at": "2026-04-29T09:03:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40088602c960a53961db129526b98d473373071a",
"body": "Fixes #19566\n\nSigned-off-by: Noel O'Brien <noel@tailscale.com>",
"is_bot": false,
"headline": "cmd/hello: remove hello.ipn.dev (#19567)",
"author_name": "Noel O'Brien",
"author_login": "noelob",
"committed_at": "2026-04-29T00:54:29Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 95,
"commits_last_year": 1292,
"latest_release_at": "2026-02-13T19:41:21Z",
"latest_release_tag": "v1.94.2",
"releases_from_tags": true,
"days_since_last_push": 9,
"active_weeks_last_year": 46,
"days_since_latest_release": 165,
"mean_days_between_releases": 8.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "tailscale.com",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": null,
"registry_url": "https://pkg.go.dev/tailscale.com",
"is_deprecated": false,
"latest_version": "v1.102.0",
"repository_url": null,
"versions_count": 232,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-23T18:54:05Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": true,
"example_dirs": [
"example",
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"docs/k8s/Makefile",
"gokrazy/Makefile",
"tool/goexe/Makefile",
"tstest/tailmac/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"client/web/tsconfig.json",
"cmd/tsconnect/tsconfig.json"
],
"toolchain_manifests": [
"go.mod",
"tool/goexe/Cargo.toml"
],
"largest_source_bytes": 276136,
"source_files_sampled": 2180,
"oversized_source_files": 23,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "filippo.io/mkcert",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.4"
},
{
"name": "fyne.io/systray",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1-0.20250812065214-4856ac3adc3c"
},
{
"name": "github.com/BARGHEST-ngo/amnezia-wireguard-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.0-alpha.2"
},
{
"name": "github.com/BARGHEST-ngo/androidqf_mesh",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.0"
},
{
"name": "github.com/Kodeworks/golang-image-ico",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20141118225523-73f0f4cfade9"
},
{
"name": "github.com/akutz/memconn",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.0"
},
{
"name": "github.com/alexbrainman/sspi",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20231016080023-1a75b4708caa"
},
{
"name": "github.com/andybalholm/brotli",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/atotto/clipboard",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.4"
},
{
"name": "github.com/aws/aws-sdk-go-v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.41.0"
},
{
"name": "github.com/aws/aws-sdk-go-v2/config",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.29.5"
},
{
"name": "github.com/aws/aws-sdk-go-v2/feature/s3/manager",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.17.58"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/s3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.75.3"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/ssm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.7"
},
{
"name": "github.com/axiomhq/hyperloglog",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240319100328-84253e514e02"
},
{
"name": "github.com/botherder/go-savetime",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.0"
},
{
"name": "github.com/bradfitz/go-tool-cache",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260216153636-9e5201344fe5"
},
{
"name": "github.com/bradfitz/monogok",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260429173803-229ef7981a6b"
},
{
"name": "github.com/bramvdbogaerde/go-scp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "github.com/cilium/ebpf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.16.0"
},
{
"name": "github.com/coder/websocket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.12"
},
{
"name": "github.com/coreos/go-iptables",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.1-0.20240112124308-65c67c9f46e6"
},
{
"name": "github.com/coreos/go-systemd",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20191104093116-d3cd4ed1dbcf"
},
{
"name": "github.com/creachadair/mds",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.25.9"
},
{
"name": "github.com/creachadair/msync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.1"
},
{
"name": "github.com/creachadair/taskgroup",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.13.2"
},
{
"name": "github.com/creack/pty",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.24"
},
{
"name": "github.com/dblohm7/wingoes",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240119213807-a09d6be7affa"
},
{
"name": "github.com/digitalocean/go-smbios",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20180907143718-390a4f403a8e"
},
{
"name": "github.com/distribution/reference",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.0"
},
{
"name": "github.com/djherbis/times",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/dsnet/try",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.3"
},
{
"name": "github.com/elastic/crd-ref-docs",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.12"
},
{
"name": "github.com/evanw/esbuild",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.19.11"
},
{
"name": "github.com/fogleman/gg",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "github.com/frankban/quicktest",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.14.6"
},
{
"name": "github.com/fxamacker/cbor/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.9.0"
},
{
"name": "github.com/gaissmai/bart",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.26.1"
},
{
"name": "github.com/go-json-experiment/json",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250813024750-ebf49471dced"
},
{
"name": "github.com/go-logr/zapr",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "github.com/go-ole/go-ole",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "github.com/go4org/hashtriemap",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20251130024219-545ba229f689"
},
{
"name": "github.com/go4org/plan9netshell",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250324183649-788daa080737"
},
{
"name": "github.com/godbus/dbus/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.1.1-0.20230522191255-76236955d466"
},
{
"name": "github.com/gokrazy/breakglass",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20251229072214-9dbc0478d486"
},
{
"name": "github.com/gokrazy/gokrazy",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260418085648-c38c3134b8a7"
},
{
"name": "github.com/gokrazy/kernel.arm64",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260403054012-807489e0272a"
},
{
"name": "github.com/gokrazy/serial-busybox",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250119153030-ac58ba7574e7"
},
{
"name": "github.com/golang/groupcache",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20241129210726-2c02b8208cf8"
},
{
"name": "github.com/golang/snappy",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.4"
},
{
"name": "github.com/golangci/golangci-lint",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.57.1"
},
{
"name": "github.com/google/go-cmp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/google/go-containerregistry",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.5"
},
{
"name": "github.com/google/go-tpm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.4"
},
{
"name": "github.com/google/gopacket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.19"
},
{
"name": "github.com/google/nftables",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.1-0.20240414091927-5e242ec57806"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/goreleaser/nfpm/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.33.1"
},
{
"name": "github.com/hashicorp/go-hclog",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.2"
},
{
"name": "github.com/hashicorp/raft",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.2"
},
{
"name": "github.com/hashicorp/raft-boltdb/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.3.1"
},
{
"name": "github.com/hdevalence/ed25519consensus",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.0"
},
{
"name": "github.com/huin/goupnp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "github.com/i582/cfmt",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "github.com/illarion/gonotify/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.2"
},
{
"name": "github.com/inetaf/tcpproxy",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250203165043-ded522cbd03f"
},
{
"name": "github.com/insomniacslk/dhcp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20231206064809-8c70d406f6d2"
},
{
"name": "github.com/jellydator/ttlcache/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.1.0"
},
{
"name": "github.com/jsimonetti/rtnetlink",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "github.com/kballard/go-shellquote",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20180428030007-95032a82bc51"
},
{
"name": "github.com/kdomanski/iso9660",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.4.0"
},
{
"name": "github.com/klauspost/compress",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.18.5"
},
{
"name": "github.com/kortschak/wol",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20200729010619-da482cc4850a"
},
{
"name": "github.com/mattn/go-colorable",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.13"
},
{
"name": "github.com/mattn/go-isatty",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.20"
},
{
"name": "github.com/mdlayher/genetlink",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.2"
},
{
"name": "github.com/mdlayher/netlink",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.3-0.20250113171957-fbb4dce95f42"
},
{
"name": "github.com/mdlayher/sdnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/miekg/dns",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.58"
},
{
"name": "github.com/mitchellh/go-ps",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/peterbourgon/ff/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.4.0"
},
{
"name": "github.com/pires/go-proxyproto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.8.1"
},
{
"name": "github.com/pkg/errors",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.1"
},
{
"name": "github.com/pkg/sftp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.13.6"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.23.0"
},
{
"name": "github.com/prometheus/common",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.65.0"
},
{
"name": "github.com/prometheus/prometheus",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.49.2-0.20240125131847-c3b8ef1694ff"
},
{
"name": "github.com/robert-nix/ansihtml",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.1"
},
{
"name": "github.com/safchain/ethtool",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/skip2/go-qrcode",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20200617195104-da1b6568686e"
},
{
"name": "github.com/studio-b12/gowebdav",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.0"
},
{
"name": "github.com/tailscale/certstore",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.1-0.20260409135935-3638fb84b77d"
},
{
"name": "github.com/tailscale/depaware",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20251001183927-9c2ad255ef3f"
},
{
"name": "github.com/tailscale/gliderssh",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.4-0.20260330083525-c1389c70ff89"
},
{
"name": "github.com/tailscale/goexpect",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20210902213824-6e8c725cea41"
},
{
"name": "github.com/tailscale/gokrazy-kernel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240728225134-3d23beabda2e"
},
{
"name": "github.com/tailscale/golang-x-crypto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250404221719-a5573b049869"
},
{
"name": "github.com/tailscale/hujson",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260302212456-ecc657c15afd"
},
{
"name": "github.com/tailscale/mkctr",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260107121656-ea857e3e500b"
},
{
"name": "github.com/tailscale/netlink",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.1-0.20240822203006-4d49adab4de7"
},
{
"name": "github.com/tailscale/peercred",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250107143737-35a0c7bd7edc"
},
{
"name": "github.com/tailscale/setec",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20251203133219-2ab774e4129a"
},
{
"name": "github.com/tailscale/ts-gokrazy",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260429180033-fe741c6deb44"
},
{
"name": "github.com/tailscale/web-client-prebuilt",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250124233751-d4cd19a26976"
},
{
"name": "github.com/tailscale/wf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240214030419-6fbb0a674ee6"
},
{
"name": "github.com/tailscale/xnet",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240729143630-8497ac4dab2e"
},
{
"name": "github.com/tc-hib/winres",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.1"
},
{
"name": "github.com/tcnksm/go-httpstat",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.0"
},
{
"name": "github.com/toqueteos/webbrowser",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.0"
},
{
"name": "github.com/u-root/u-root",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.14.0"
},
{
"name": "github.com/vishvananda/netns",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.5"
},
{
"name": "go.uber.org/zap",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.27.0"
},
{
"name": "go4.org/mem",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20240501181205-ae6ca9944745"
},
{
"name": "go4.org/netipx",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20231129151722-fdeea329fbba"
},
{
"name": "golang.org/x/crypto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.50.0"
},
{
"name": "golang.org/x/exp",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250620022241-b7579e27df2b"
},
{
"name": "golang.org/x/mod",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.35.0"
},
{
"name": "golang.org/x/net",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.53.0"
},
{
"name": "golang.org/x/oauth2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "golang.org/x/sync",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.20.0"
},
{
"name": "golang.org/x/sys",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.43.0"
},
{
"name": "golang.org/x/term",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.42.0"
},
{
"name": "golang.org/x/time",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.12.0"
},
{
"name": "golang.org/x/tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.44.0"
},
{
"name": "golang.zx2c4.com/wintun",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20230126152724-0fa3db229ce2"
},
{
"name": "golang.zx2c4.com/wireguard/windows",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.3"
},
{
"name": "gopkg.in/square/go-jose.v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.6.0"
},
{
"name": "gvisor.dev/gvisor",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20260224225140-573d5e7127a8"
},
{
"name": "helm.sh/helm/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.19.0"
},
{
"name": "honnef.co/go/tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "k8s.io/api",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.34.0"
},
{
"name": "k8s.io/apimachinery",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.34.0"
},
{
"name": "k8s.io/apiserver",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.34.0"
},
{
"name": "k8s.io/client-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.34.0"
},
{
"name": "sigs.k8s.io/controller-runtime",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.19.4"
},
{
"name": "sigs.k8s.io/controller-tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.17.0"
},
{
"name": "sigs.k8s.io/kind",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.30.0"
},
{
"name": "sigs.k8s.io/yaml",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "software.sslmate.com/src/go-pkcs12",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.4.0"
},
{
"name": "tailscale.com/client/tailscale/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.9.0"
},
{
"name": "github.com/AlekSi/pointer",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.0"
},
{
"name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.16.27"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sts",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.41.5"
},
{
"name": "github.com/aws/smithy-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.24.0"
},
{
"name": "github.com/fatih/color",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.18.0"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.9.0"
},
{
"name": "github.com/gorilla/csrf",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.7.3"
},
{
"name": "github.com/mdlayher/socket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.0"
},
{
"name": "github.com/prometheus/client_model",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.2"
},
{
"name": "github.com/sourcegraph/go-diff",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.0"
},
{
"name": "github.com/stretchr/testify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/tailscale/go-winio",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20231025203758-c4f33415bf55"
},
{
"name": "github.com/ulikunitz/xz",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.5.15"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "k8s.io/apiextensions-apiserver",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.34.0"
},
{
"name": "k8s.io/utils",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20250604170112-4c0f3b243397"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 7,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 3,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "bradfitz",
"commits": 3319,
"avatar_url": "https://avatars.githubusercontent.com/u/2621?v=4"
},
{
"type": "User",
"login": "danderson",
"commits": 881,
"avatar_url": "https://avatars.githubusercontent.com/u/1918?v=4"
},
{
"type": "User",
"login": "josharian",
"commits": 401,
"avatar_url": "https://avatars.githubusercontent.com/u/67496?v=4"
},
{
"type": "User",
"login": "raggi",
"commits": 267,
"avatar_url": "https://avatars.githubusercontent.com/u/348?v=4"
},
{
"type": "User",
"login": "andrew-d",
"commits": 267,
"avatar_url": "https://avatars.githubusercontent.com/u/1079173?v=4"
},
{
"type": "User",
"login": "jwhited",
"commits": 244,
"avatar_url": "https://avatars.githubusercontent.com/u/10344482?v=4"
},
{
"type": "User",
"login": "awly",
"commits": 211,
"avatar_url": "https://avatars.githubusercontent.com/u/1146263?v=4"
},
{
"type": "User",
"login": "irbekrm",
"commits": 208,
"avatar_url": "https://avatars.githubusercontent.com/u/24879183?v=4"
},
{
"type": "User",
"login": "dsnet",
"commits": 193,
"avatar_url": "https://avatars.githubusercontent.com/u/6354026?v=4"
},
{
"type": "User",
"login": "crawshaw",
"commits": 186,
"avatar_url": "https://avatars.githubusercontent.com/u/161319?v=4"
}
],
"contributors_sampled": 99,
"top_contributor_share": 0.367
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"checklocks.yml",
"cigocacher.yml",
"codeql-analysis.yml",
"docker-base.yml",
"docker-file-build.yml",
"flakehub-publish-tagged.yml",
"golangci-lint.yml",
"govulncheck.yml",
"installer.yml",
"kubemanifests.yaml",
"natlab-basic.yml",
"natlab-test.yml",
"pin-github-actions.yml",
"request-dataplane-review.yml",
"ssh-integrationtest.yml",
"test.yml",
"update-flake.yml",
"update-webclient-prebuilt.yml",
"vet.yml",
"webclient.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Cargo.lock",
"go.sum",
"yarn.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 6,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 2,
"reason": "Found 6/22 approved changesets -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 33 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 7,
"reason": "dependency not pinned by hash detected -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "97 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "96abef288847c5b4ce4869c8c18a828c31f37bb9",
"ran_at": "2026-07-29T14:56:41Z",
"aggregate_score": 5.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T13:58:37Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-20T13:57:48Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/BARGHEST-ngo/tailscale-patched",
"host": "github.com",
"name": "tailscale-patched",
"owner": "BARGHEST-ngo"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 67,
"inputs": {
"security": 56,
"vitality": 79,
"community": 40,
"governance": 74,
"engineering": 80
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 79,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"commits_last_year": 1292,
"human_commit_share": 1,
"days_since_last_push": 9,
"active_weeks_last_year": 46
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 9 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 9
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "46/52 weeks with commits",
"points": 31.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 46
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "1292 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 1292
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "good",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 78,
"inputs": {
"releases_count": 95,
"latest_release_tag": "v1.94.2",
"releases_from_tags": true,
"days_since_latest_release": 165,
"mean_days_between_releases": 8.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "95 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 95
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 165 days ago",
"points": 27,
"status": "partial",
"details": [
{
"code": "release_recency",
"params": {
"days": 165
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~8.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 8.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 40,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (BSD-3-Clause)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "BSD-3-Clause"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 74,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "good",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 74,
"inputs": {
"bus_factor": 3,
"contributors_sampled": 99,
"top_contributor_share": 0.367
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "3 contributor(s) cover half of all commits",
"points": 36,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 3
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 37% of commits",
"points": 14.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 37
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "99 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 99
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 33 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 77,
"inputs": {
"merged_prs": 7,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "7/7 decided PRs merged",
"points": 38.2,
"status": "met",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 7,
"decided": 7
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 6/22 approved changesets -- score normalized to 2",
"points": 3,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 51,
"inputs": {
"followers": 31,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "BARGHEST-ngo",
"public_repos": 10,
"account_age_days": 496
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "31 followers of BARGHEST-ngo",
"points": 10.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 31,
"login": "BARGHEST-ngo"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "10 public repos, account ~1 yr old",
"points": 10.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 10
}
},
{
"code": "account_age_years",
"params": {
"years": 1
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"tailscale.com"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "232 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 232
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 80,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "20 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 20
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 56,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 56,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 5.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 6/22 approved changesets -- score normalized to 2",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 33 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 3.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "97 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 18
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 66,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.89,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "89 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 89,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_nix": true,
"has_tests": true,
"lockfiles": [
"Cargo.lock",
"go.sum",
"yarn.lock"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"docs/k8s/Makefile",
"gokrazy/Makefile",
"tool/goexe/Makefile",
"tstest/tailmac/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"client/web/tsconfig.json",
"cmd/tsconnect/tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod",
"tool/goexe/Cargo.toml"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, docs/k8s/Makefile, gokrazy/Makefile, tool/goexe/Makefile, tstest/tailmac/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, docs/k8s/Makefile, gokrazy/Makefile, tool/goexe/Makefile, tstest/tailmac/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "client/web/tsconfig.json, cmd/tsconnect/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "client/web/tsconfig.json, cmd/tsconnect/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, Nix, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, Nix, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "dependency automation configured, none observed in the sampled commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "dependency_bot_config_only",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 7,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 276136,
"source_files_sampled": 2180,
"oversized_source_files": 23
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "23/2180 source files over 60KB",
"points": 54.4,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 2180,
"oversized": 23
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"example",
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "example, examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "example, examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-29T14:57:06.061922Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/BARGHEST-ngo/tailscale-patched.svg",
"full_name": "BARGHEST-ngo/tailscale-patched",
"license_state": "standard",
"license_spdx": "BSD-3-Clause"
}