Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-24 04:55 UTC

TYPO3 / phar-stream-wrapper

Interceptors for PHP's native phar:// stream handling in order to enhance security.

PHPMIT★ 59 зірок⑂ 12 форківз серп. 2018 р.Переглянути на GitHub ↗

TYPO3/phar-stream-wrapper має індекс здоров’я 49 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Sustainability & Governance (62/100), найнижчий — Vitality (25/100). Останнє оновлення було 242 дні тому. Більшість нещодавньої роботи виконує один учасник.

49
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

49
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

TYPO3 GitHub DepartmentОрганізація
117 підписників23 публічні репозиторіїз трав. 2009 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
Packagisttypo3/phar-stream-wrapperv4.0.0114 70927591 день томуphpsecuritypharstream-wrapper

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

25Критичний · 22% загального індексу
Як обчислюється оцінка
3.6/36Свіжість push — останній push 242 дн. тому
0.7/36Ритм комітів — 1/52 тижнів із комітами
2.7/18Обсяг комітів — 1 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Використані вхідні дані
commits_last_year1
human_commit_share0,98
days_since_last_push242
active_weeks_last_year1
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 26 релізів
7.2/36Свіжість релізів — останній реліз 591 дн. тому
12.6/27Ритм релізів — реліз кожні ~197,5 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count26
latest_release_tagv4.0.0
releases_from_tagsні
days_since_latest_release591
mean_days_between_releases197,5
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

52Помірний · 18% загального індексу
Як обчислюється оцінка
28.6/60Зірки — 59 зірок
8.7/25Форки — 12 форків
5/15Спостерігачі — 9 спостерігачів
Використані вхідні дані
forks12
stars59
watchers9
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні
Як обчислюється оцінка
67.5/80Щомісячні завантаження — 114 709 завантажень/місяць у packagist
4.7/20Залежні пакети в реєстрі — залежних пакетів: 4
Використані вхідні дані
packagestypo3/phar-stream-wrapper
dependents4
ecosystemspackagist
total_downloads38 496 394
monthly_downloads114 709

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

62Помірний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
2.5/22.5Розподіл комітів — головний контриб’ютор — автор 89% комітів
10.8/13.5Широта контриб’юторів — 8 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 9 contributing companies or organizations
Використані вхідні дані
bus_factor1
contributors_sampled8
top_contributor_share0,89
Як обчислюється оцінка
46.8/46.8Вирішення issue — закрито 100% issue
32.8/38.3Прийняття PR — злито 54/63 вирішених PR
1.5/15OpenSSF Scorecard: Code-Review — Found 2/16 approved changesets -- score normalized to 1
Використані вхідні дані
merged_prs54
open_issues0
closed_issues20
issue_closed_ratio1
closed_unmerged_prs9
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
14.9/25Охоплення власника — 117 підписників у TYPO3
22.1/25Послужний список — 23 публічних репозиторіїв, вік облікового запису ~17 р.
Використані вхідні дані
followers117
owner_typeOrganization
is_verified
owner_loginTYPO3
public_repos23
account_age_days6 267
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у packagist
14/35Свіжість публікацій — остання публікація 591 дн. тому
20/20Історія версій — 27 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagestypo3/phar-stream-wrapper
ecosystemspackagist
any_deprecatedні
min_days_since_publish591

Інженерна якість

Чи наявні базові інженерні практики та документація?

53Помірний · 20% загального індексу

Інженерні практики

48У зоні ризику
Як обчислюється оцінка
24/24Процеси CI — 2 процес(ів) CI
24/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — 0 out of 8 merged PRs checked by a CI test -- score normalized to 0
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configні
has_precommit_configні

Документація

60Помірний
Як обчислюється оцінка
30/30README
0/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
10/10Теми — 6 тем
10/10Wiki
Використані вхідні дані
topicsphp, phar, stream-wrapper, security, insecure-deserialization, deserialization
has_wikiтак
homepage
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

53Помірний · 16% загального індексу

Стан безпеки

53Помірний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — немає даних
0/2.5CI-Tests — 0 out of 8 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 2/16 approved changesets -- score normalized to 1
2.5/2.5Contributors — project has 9 contributing companies or organizations
0/10Dangerous-Workflow — немає даних
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
0/5Packaging — немає даних
0/5Pinned-Dependencies — немає даних
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — немає даних
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate5,3
Виключено з оцінювання (немає даних або не застосовно): branch_protection, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

29Критичний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
10.3/40Читабельна історія комітів — намір зазначено у 19 з 98 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,194
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
22/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
0/11Статична перевірка типів
0/10Відтворюване середовище
0/10Підтверджена практика роботи з агентами — серед останніх 100 комітів немає створених агентом
8/8Автоматизоване супроводження — 2 з останніх 100 комітів — автоматичні оновлення залежностей
0/10OpenSSF Scorecard: Pinned-Dependencies — немає даних
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileні
typed_languageні
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0,02
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Pinned-Dependencies. Залишкові ваги перенормовано.
Як обчислюється оцінка
0/45Типізований код — PHP без конфігурації перевірки типів
55/55Керовані розміри файлів — 0/39 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languagePHP
largest_source_bytes16 118
source_files_sampled39
oversized_source_files0

Ключові факти

59зірок GitHub
8контриб'юторів
1комітів за останні 12 місяців
242днів від останнього пушу
26релізів
1бас-фактор
0відкритих issue
Packagistпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • No resolved dependencies carried a version and a supported ecosystem

Докладніше

Історія зірок і форків 0 ★ / 12 ⇿
0Зірки
12Форки
22Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

0246810121212018-092021-082024-08
Мажорні 2Мінорні 4Патчі 16

Кожна точка охоплює 6 днів.

OpenSSF Scorecard 5.3 / 10
5.3сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-24 04:54 UTC

10Binary-Artifactsno binaries found in the repo
н/дBranch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
0CI-Tests0 out of 8 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 2/16 approved changesets -- score normalized to 1
10Contributorsproject has 9 contributing companies or organizations
н/дDangerous-Workflowno workflows found
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintained0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
н/дPackagingpackaging workflow not detected
н/дPinned-Dependenciesno dependencies found
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
н/дSigned-Releasesno releases found
н/дToken-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Усі залежності 4

Повний розв'язаний набір залежностей із графа залежностей GitHub: 0 прямих і 4 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
Packagistext-jsonнепряма
Packagistext-xdebugнепряма
Packagistphpнепряма
Packagistphpunit/phpunitнепряма
Сповіщення про залежності не оцінено

Звірка сповіщень не відбулася для цього звіту: No resolved dependencies carried a version and a supported ecosystem

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "php",
        "phar",
        "stream-wrapper",
        "security",
        "insecure-deserialization",
        "deserialization"
      ],
      "is_fork": false,
      "size_kb": 2298,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "PHP": 115442
      },
      "pushed_at": "2025-11-24T03:27:56Z",
      "created_at": "2018-08-26T07:33:56Z",
      "owner_type": "Organization",
      "updated_at": "2025-10-28T02:11:14Z",
      "description": "Interceptors for PHP's native phar:// stream handling in order to enhance security.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "master",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://typo3.org",
      "name": "TYPO3 GitHub Department",
      "type": "Organization",
      "login": "TYPO3",
      "company": null,
      "location": null,
      "followers": 117,
      "avatar_url": "https://avatars.githubusercontent.com/u/88698?v=4",
      "created_at": "2009-05-26T11:58:25Z",
      "is_verified": null,
      "public_repos": 23,
      "account_age_days": 6267
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v4.0.0",
          "kind": "major",
          "published_at": "2024-12-10T00:08:24Z"
        },
        {
          "tag": "v3.1.8",
          "kind": "patch",
          "published_at": "2024-12-10T00:03:38Z"
        },
        {
          "tag": "v2.2.2",
          "kind": "patch",
          "published_at": "2021-09-21T07:28:42Z"
        },
        {
          "tag": "v3.1.7",
          "kind": "patch",
          "published_at": "2021-09-20T19:23:24Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2020-11-11T22:21:55Z"
        },
        {
          "tag": "v3.1.6",
          "kind": "patch",
          "published_at": "2020-11-07T09:35:16Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2020-07-27T09:27:50Z"
        },
        {
          "tag": "v2.1.5",
          "kind": "patch",
          "published_at": "2020-06-19T18:50:39Z"
        },
        {
          "tag": "v3.1.5",
          "kind": "patch",
          "published_at": "2020-06-19T18:51:15Z"
        },
        {
          "tag": "v2.1.4",
          "kind": "patch",
          "published_at": "2020-01-28T22:51:16Z"
        },
        {
          "tag": "v3.1.4",
          "kind": "patch",
          "published_at": "2020-01-28T22:51:34Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2019-10-18T12:07:10Z"
        },
        {
          "tag": "v3.1.3",
          "kind": "patch",
          "published_at": "2019-10-18T12:02:48Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2019-05-14T13:26:58Z"
        },
        {
          "tag": "v3.1.2",
          "kind": "patch",
          "published_at": "2019-05-14T13:27:31Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2019-05-06T09:41:04Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2019-05-06T09:40:22Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2019-03-04T19:45:51Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2019-03-04T19:47:34Z"
        },
        {
          "tag": "v3.0.1",
          "kind": "patch",
          "published_at": "2018-10-18T08:59:21Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2018-10-18T08:58:51Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2018-09-07T15:29:37Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2018-09-07T15:18:55Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2018-09-07T14:32:35Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2018-08-30T08:14:21Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2018-08-26T20:28:51Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "5f66161e82446cdb2b3127fcd91328859796d2f9",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v5)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "[TASK] Bump actions/checkout from 4 to 5 (#83)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-30T17:35:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "402a6c0f4ac838721f953d8dfc12c478a6469ca5",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Create SECURITY.md",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-10T00:51:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7d0771268336acb1eb3583e42781aac46d81e3c",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Update PHP 8 note in README.md",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-10T00:47:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce4b6e9873d4dd7dce2a397511713bf14977fdf2",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust styling in README.md",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-10T00:00:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "770ad611f6582ea111cb8863392e83fac1ae98d6",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Update v4 instructions & PHP 8 deserialization info",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:58:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d743eabde8d50a8577ee8e0c4bdaae846a0928de",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust README.md",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:50:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45d3193b67a9c355e2f7f540cf90db1563f8baba",
          "body": "This reverts commit 7b44f627396757cb52dba1385a684b00af5df6f4.\n\npackagist.org applies a different order having alias string with `v`",
          "is_bot": false,
          "headline": "Revert \"[TASK] Adjust v4.x-dev branch alias\"",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b44f627396757cb52dba1385a684b00af5df6f4",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust v4.x-dev branch alias",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:45:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57e80dc841fa6028cb72c927dab2d92aaca22cba",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Define 4.x-dev branch alias",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:44:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9ddb4e2d5a9bb43eb8332115a0077262391b4af",
          "body": "[TASK] Raise compatibility to PHP 7.1-8.4",
          "is_bot": false,
          "headline": "Merge pull request #78 from ohader/php84",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:43:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b29a9988cd93af2fee4cf80390eec0bed9a0c0e5",
          "body": null,
          "is_bot": false,
          "headline": "[!!!][TASK] Apply nullable and void types were applicable",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:28:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9dd6e2e69fa9f98d5e146cac94e626f2b457c939",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Declare constants visibility",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:17:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46709aab709ecaf3e13d5a9d987ca28e4395bf49",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Establish support for PHP 7.1-8.4",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:10:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b427a4d7cfcac38163ae9f93ccd5adace2f30ad6",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Drop PHP < 7.4 from GH actions",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:10:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8807a8c79875b910a94445d06a0e763a43e92c2e",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Use correct phpunit binary",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:10:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a6cf5bfbdada96cfbc7d27aeb5a12ee124fbd26",
          "body": null,
          "is_bot": false,
          "headline": "[!!!][TASK] Drop support for PHP < 7.4",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:10:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea4a1259c853540de03ba985db928d3073f34773",
          "body": "* drop symfony/phpunit-bridge, using phpunit/phpunit instead\n* drop phpspec/prophecy, using mocks instead",
          "is_bot": false,
          "headline": "[TASK] Adjust tests for phpunit/phpunit",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:10:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abf3ba680600ac53613b3ca88c9f2edaf0b305c2",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Remove PHP 8.2 specific GH action steps",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:09:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf8b85654941d7b08d61346189d4416bcc1992c7",
          "body": "* drops PHP 7.0 compatibility (due to not having nullable types)\n* introduces PHP 8.4 compatibility",
          "is_bot": false,
          "headline": "[TASK] Raise compatibility to PHP 7.1-8.4",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:09:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a931b28f422a60052db85c0a84a05a366453b2c0",
          "body": "* adjust method/function signatures were applicable\n* remove superfluous phpdoc comments\n* simplify conditions",
          "is_bot": false,
          "headline": "[TASK] Clean up code",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T23:06:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e23a30177411eb0a758d804a0c6f70978abf649b",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Set compatibility to PHP 7.0-8.3",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T21:04:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "130abacc1a7c2acc1c5c7e14b4e19b955e53ceaf",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Set Windows test range to PHP 7.0-8.3",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T21:04:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3e01d53f6d658788bfa548495e77ac5d8bdd929",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 2 to 4.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v2...v4)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 2 to 4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2024-12-09T20:58:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18cef0fd5dc5656b5d7e89bbfa5adf4b099d6359",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add GH dependabot to check GH actions",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-12-09T20:54:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e3d17d6143438d360ce9f12f300ba97d66888ff",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Update reference to PHP 8.0 tests",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-08-07T10:58:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68ba4856d455a1a3486f9824f944f2e5de8c5409",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Enable PHP 8.3 in test matrix",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-08-07T10:56:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb0bb2a5a8cd2c250cd2668fa63749acec3f3af5",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add references for deserialization in PHP 8.0",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2024-08-07T10:56:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0ac6a5a9abf8d740d3dc1012950b4a453ea009a",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add PHP 8.2 to test matrix",
          "author_name": "Christian Kuhn",
          "author_login": "lolli42",
          "committed_at": "2022-08-02T09:51:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d304de5703ce9c97627e16dfd5b466093cd9479",
          "body": "This seems to be the easiest solution to make tests\ncompatible with all PHP versions including 8.1 at\nthe same time.",
          "is_bot": false,
          "headline": "[TASK] Disable symfony phpunit result cache in tests",
          "author_name": "Christian Kuhn",
          "author_login": "lolli42",
          "committed_at": "2021-10-18T11:46:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "148a5f7193167172cc7f6be7dc140867b36f8a1b",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Run tests with PHP 8.1",
          "author_name": "Christian Kuhn",
          "author_login": "lolli42",
          "committed_at": "2021-10-18T11:46:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cc2f04a4e2f5c7e9cc02a3bdf80fae0f3e11a8c",
          "body": "Fixes: #68",
          "is_bot": false,
          "headline": "[BUGFIX] Avoid processing at actual end-of-file",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2021-09-20T19:19:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7f28f44ff0033ba6e39dddc180cdcd2d7930bab",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add README.md badge",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2021-09-16T10:48:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c35df2c705b57a679354949009c8f552af7863b2",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Remove v2 branch from GitHub actions",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2021-09-16T10:23:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c5607ac2d4f6938c6e3f01e27a698d7fc41f305",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add GitHub actions running tests & drop TravisCI, AppVeyor",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2021-09-16T09:36:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60131cb573a1e478cfecd34e4ea38e3b31505f75",
          "body": "* fix PHP 8.0-RC1, 7.4.12, 7.3.24 notices calling `stream_wrapper_restore`\r\n* run tests on `symfony/phpunit-bridge` instead of `phpunit/phpunit`",
          "is_bot": false,
          "headline": "Merge pull request #65 from alexpott/php8-compatibility",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-11-07T09:06:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4ba66d9bb1de6a26b8eb0842755b918fd7ef40f",
          "body": "* since PHP 8.0-RC1\n* since PHP 7.3.24\n* since PHP 7.4.12\n* see https://github.com/php/php-src/commit/5ed0602ec622274bf5672304ae414e5ecb2e5167\n* see https://github.com/php/php-src/pull/6183",
          "is_bot": false,
          "headline": "[BUGFIX] Address changed behavior in PHP's stream_wrapper_restore()",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-11-06T20:44:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6bdc21ef85240ef393daf422e39e8d9e43560e5",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Clean up code",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-11-06T20:44:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22058b0113a094b78161d6d0c195c1a0d88d950b",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Use composer v1 explicitly for AppVeyor tests",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-11-06T17:53:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b2c7258ea8f4ddacafece7f8b1a3d8e369df947",
          "body": "* fix PHP 8.0 notices calling `stream_wrapper_restore`\n* run tests on `symfony/phpunit-bridge` instead of `phpunit/phpunit`\n* adjust CI related topics caused by previous changes",
          "is_bot": false,
          "headline": "PHP 8.0 compatibility",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2020-11-06T17:07:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea5c600a8483862499df5f4204ffd482e9068fa2",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Update URL in README.md",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-06-19T19:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81a713c1e165baa7c09e46cc6799cee24ce45988",
          "body": "There are some environments where `opcache.restrict_api`(https://www.php.net/manual/en/opcache.configuration.php#ini.opcache.restrict-api)\nis enabled for security/stability reasons. Using them produces PHP warnings like\n\n```\nPHP Warning:  Zend OPcache API is restricted by \"restrict_api\" configuration\ndirective in /tmp/vendor/typo3/phar-stream-wrapper/src/Helper.php on line 34\n```",
          "is_bot": false,
          "headline": "[TASK] Silence PHP opcache warnings",
          "author_name": "Alexander Concha",
          "author_login": "xknown",
          "committed_at": "2020-06-19T18:43:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a7b56de76873035af1708b4a2699f9678c0ac633",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust composer process for AppVeyor",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-06-19T17:59:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5c4dd1d6dbca6a40edc510dab1fd5a146061765",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Remove deprecated TravisCI sudo setting",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-06-19T17:59:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b68f964d9e8233636c089e472d7a9042162d2b4a",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust PHP 7.4snapshot in TravisCI matrix",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2020-06-19T17:59:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0c1b495cfac064f4f5c4bcb6bf67bb7f345ed04",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust .gitattributes export behavior",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-12-10T11:53:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da6821f9980d8301b39cf597dac2091c3b220a65",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Avoid exporting AppVeyor configuration",
          "author_name": "Dave Long",
          "author_login": "longwave",
          "committed_at": "2019-12-10T11:53:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "586ff60beea128e069a5dc271d3d8133a9bc460a",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Ensure cli-tool symlink is regenerated in tests",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-10-18T11:57:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f13361bb6a812ad84e2420f2ff0179c9f1b60bc",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Remove PHP 7.4 workaround in tests",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-10-18T11:57:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21021fdb402167dbf70b49382a79941753a69b06",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Update Phar builder script",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-10-17T18:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49d41252f47c35ae9df3d4edab5f8b4b1f829175",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Skip STDERR assertion for PHP 7.4",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-10-17T18:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33ec7dcaeaf03fcc4ba48c15703ddfa3ade07447",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Enable reporting of failing PHP 7.4 tests",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-10-17T18:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69f2f1e5a2f1b16987b28e5e178d1fbb4c10f804",
          "body": null,
          "is_bot": false,
          "headline": "[BUGFIX] Consider application/gzip file type",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-10-17T18:15:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6db092fdf4ba203d7e061698dc8f94af599748b7",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Addjust Travis CI configuration, add PHP 7.4snapshot",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-08-12T11:52:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27899b820ae69c5005175b46e0ad5987ce01b519",
          "body": "Replace deprecated curly brace array notation with common square braces.\n\nFixes: #48",
          "is_bot": false,
          "headline": "[TASK] Ensure PHP 7.4 compatibility for string offsets",
          "author_name": "Ryan Aslett",
          "author_login": "ryanaslett",
          "committed_at": "2019-08-12T07:58:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48304f75f1b7aaa3b5c6cecba9c51c1e212b072e",
          "body": "Related: #48",
          "is_bot": false,
          "headline": "[TASK] Adjust Chocolatey PHP version selection",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-08-12T07:51:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df7609a2f6cc4013d7bd12f1a2412d127b28f771",
          "body": "Resolves: #44",
          "is_bot": false,
          "headline": "[TASK] Extend test cases",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-14T13:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7427decaf800f35b10c1e3342c5bed0e028fd8aa",
          "body": "Resolves: #42",
          "is_bot": false,
          "headline": "[BUGFIX] Avoid analysing non-phar files on alias resolving",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-14T12:43:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a8c0049281cf4d568d5109a79b3feaf1d9e92e5c",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add AppVeyor status badge",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-14T11:25:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9b4ecb57d4ccf1a2d5147c7aab719f7e1606307",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Use AppVeyor to test on Windows",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-05-14T10:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05895d9518a2a08ce89441d871d1d842adc04a0d",
          "body": "Resolves: #34",
          "is_bot": false,
          "headline": "[BUGFIX] Normalize resolved Windows path to Unix-style",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-13T15:46:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0903beed1e1cb830604b75529104be3b00c95587",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Ensure valid file resource",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-13T13:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "957735dc1e129c04ef72bd5dc396f14f7be00d8d",
          "body": "If fileinfo ext is not available use a fallback method to determine mimetype of a compressed phar file",
          "is_bot": false,
          "headline": "Merge pull request #33 from alexpott/remove-fileinfo-dependency",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-13T12:11:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eca8f4272d80d8c00be43173ef375d1ef31b6383",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add comments to fallback mime-type resolving",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-13T11:44:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d2045cbd4c3c14f1213545f476655a53d73ad84",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Apply tiny code style changes",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-13T09:02:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4f04992947fbc5ee65d2d14c72d665a62891ab5",
          "body": "Related: #35",
          "is_bot": false,
          "headline": "[TASK] Avoid using superfluous ASSERT_INTERNAL_INVOCATION",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-13T07:06:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd7b2e9df4b1b284a22d1449e6a0816e304785a9",
          "body": null,
          "is_bot": false,
          "headline": "Whoops composer.json was not valid",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-05-10T23:18:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6a62a4660c444b9417bf8147d44764682b92fd3",
          "body": null,
          "is_bot": false,
          "headline": "Allow alternate mime type guessers to be used",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-05-10T23:15:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3925aa25acb215a4e59a8ed8c412854cd1f625ea",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Expose dev-master as v3.x-dev",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-08T21:22:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d71faa08628ef49d1e819f894bf196c124aae01e",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Adjust links in README.md",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-08T12:57:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fff6f5e037882f816cd41a9f5ccd8d8f97bfdebf",
          "body": "* PharInvocation has to be confirmed now\n* avoid Phar archive parsing in Phar\\Reader\n* extend interface Collectable::has(PharInvocation)\n* enhance overall performance for PharMetaDataInterceptor",
          "is_bot": false,
          "headline": "[!!!][TASK] Reduce superfluous calls to Phar\\Reader",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-05T17:30:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb6607fb147f607e0e0cca1d7e3896814f7c5616",
          "body": "* Consider direct alias invocation without being registered\n  Invoking an aliased phar like `phar:///path/to/phar.phar/autoload.php`\n  would allow to extract and register a potential alias name of the base\n  name at `/path/to/phar.phar`. Using alias names directly inside phar\n  archive does provide \n[…]\nconsidered as the base\n  name of the Phar archive.\n  This change reduces superfluous calls to `is_file` when splitting\n  the path in order to resolve the actual base name.\n\nResolves: #21\nResolves: #23",
          "is_bot": false,
          "headline": "[BUGFIX] Enhance alias resolving and reduce file system invocation",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-05T17:30:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d31e4f8f04f10d6eff594002b8af988eabb1b8a8",
          "body": "These tests just reflect the status quo without changing anything.",
          "is_bot": false,
          "headline": "[TASK] Add performance measurement tests",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-05-05T17:30:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbc6f74f8cb81d08e9c56948773bcce7a5f383a5",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add proper type hint in PHPdoc comment",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-04-27T21:43:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbfff6d56145eebe7676becae71bb0bf331c5107",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add PHP 7.3 testing",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-04-27T12:15:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4edb5514813d845664c69b44300c2714349d9b0",
          "body": "* adjust container alias resolving (actually different alias name\n  assignments would lead to error in real PHP processing)\n* extend test cases for low-level Reader API",
          "is_bot": false,
          "headline": "[BUGFIX] Enhance low-level Phar archive reader",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-04-27T11:34:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccce11b962007d87b64b1b1dbe063a32ff7ace79",
          "body": "Previously the end of the phar stub was determined in a way which allowed\nto introduce a fake manifest tricking the phar reader to think there is\nno or only harmless metadata (or other wrong information).\n\nFix is to remove flaws in the end of stub detection which also aligns\nwith the file format doc\n[…]\nata.\n\nNOTE: attacks w/ the alias information in the manifest have not been\n      checked even though they might have been affected as well.\n\n[1]: https://www.php.net/manual/en/phar.fileformat.stub.php",
          "is_bot": false,
          "headline": "Improve end of stub detection, closes #24",
          "author_name": "Tom Klingenberg",
          "author_login": "ktomk",
          "committed_at": "2019-04-27T11:30:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fcc6997ec52c1ac37cc59305300531f6a17e537",
          "body": "* use compromised archives that really triggering action\n* generalize invocation and loading behavior\n* extend examples for alias Phar archives\n\nResolves: #26",
          "is_bot": false,
          "headline": "[TASK] Enhance variety of test fixtures",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-04-27T09:54:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19edc4e0ca5174764e3c946431b8b00326304944",
          "body": null,
          "is_bot": false,
          "headline": "Set theme jekyll-theme-slate",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T23:18:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43236eb18ef9ec322baedcadc675baeb6844e26a",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add missign include for type annotation",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T23:01:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffcee8dc684e237d6ba7560090e5a9aeb9b6f694",
          "body": "[TASK] Refactor Phar alias map handling",
          "is_bot": false,
          "headline": "Merge pull request #17 from TYPO3/task/phar-inception",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T16:23:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c664e3143dbc07a421426138491b9a665a4206f1",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Expose collection, decouple from resolver",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T14:56:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a98ac972dd5760611ecd71f1e8bffcfff1309c61",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Reduce amount of custom public methods",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T14:50:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd915a21eaf01cb99a73e0c48c821483faba5fd4",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Rename learn to collect",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T14:03:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "763818201e2a518ea30d9df57581f4eac249f115",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Rename stack to collection",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-03-01T14:02:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76613dd929316e892184dad01a1ec5c86965d3b0",
          "body": null,
          "is_bot": false,
          "headline": "[BUGFIX] Use correct bitmasks in assertions",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T14:44:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc65b3e15bda698ce7d4eb665655560b507876a0",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add PharInvocation.equals",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T13:56:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5ed610e64cfb3623ce4b91074ee0ed9cd923069",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add Resolver internal invocation flag",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T12:46:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca8074b41ec946afb058a14f9e89f59c6900c54b",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add Stack command flags",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T12:45:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "476966371d9f9308dcc1d33d721559dbed0b5c0a",
          "body": null,
          "is_bot": false,
          "headline": "[BUGFIX] Identify direct CLI invocation",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T11:09:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2765c841f25855f3e693db849f9fbaa859af6050",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Refactor invocation resolving",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T10:39:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6df1f674cbff08dca06a301b8b3411df084066d9",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Invoke Manager directly",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T10:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1e01fea9393a7639d07567cfe3823dc434feed1",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Add PHPdoc comment",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T10:31:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6e4d96cec8973126a52ecfb25f1b14208c32de4",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Rename test case",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-28T10:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff877c9c87753c2aecbfefdc5ac08c0bac1327c6",
          "body": "Scope: \"Inception\" - Phar in Phar in Phar in ...",
          "is_bot": false,
          "headline": "[WIP][TASK] Refactor Phar alias map handling",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-27T12:56:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "936a10cdf9edcaf2b0fa7ce33ee61a589e4f74a9",
          "body": "Move alias learning so only aliases of valid phar files are learnt",
          "is_bot": false,
          "headline": "Merge pull request #16 from alexpott/learn-alias-when-valid",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-27T12:17:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "498d783d723555c52d1949a5e96216667aa516f7",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Streamline alias learning",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-27T11:45:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b72459e5c91805de53ba2fe80e4251f8bd839c5c",
          "body": null,
          "is_bot": false,
          "headline": "Move alias learning so only aliases of valid phar files are learnt",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-02-13T15:26:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d69b2afce515299403a699ec87341caa5a89cb71",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Update documentation",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-12T17:20:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d26de1c98b19664a53143ee6d50b3e402e9a9abf",
          "body": "Simplify potential backports from master to v2 branch.",
          "is_bot": false,
          "headline": "[TASK] Streamline path definition in tests",
          "author_name": "Oliver Hader",
          "author_login": "ohader",
          "committed_at": "2019-02-12T15:48:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d8d65791c2fa559f53b1e160f4a2bd5de5d779b",
          "body": null,
          "is_bot": false,
          "headline": "[TASK] Make reviews of *.phar files easier",
          "author_name": "Alex Pott",
          "author_login": "alexpott",
          "committed_at": "2019-02-12T15:42:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 26,
      "commits_last_year": 1,
      "latest_release_at": "2024-12-10T00:08:24Z",
      "latest_release_tag": "v4.0.0",
      "releases_from_tags": false,
      "days_since_last_push": 242,
      "active_weeks_last_year": 1,
      "days_since_latest_release": 591,
      "mean_days_between_releases": 197.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "typo3/phar-stream-wrapper",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "php",
            "security",
            "phar",
            "stream-wrapper"
          ],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/typo3/phar-stream-wrapper",
          "is_deprecated": false,
          "latest_version": "v4.0.0",
          "repository_url": "https://github.com/TYPO3/phar-stream-wrapper",
          "versions_count": 27,
          "total_downloads": 38496394,
          "dependents_count": 4,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 114709,
          "first_published_at": null,
          "latest_published_at": "2024-12-10T00:00:25Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 591
        }
      ]
    },
    "popularity": {
      "forks": 12,
      "stars": 59,
      "watchers": 9,
      "fork_history": {
        "days": [
          {
            "date": "2018-09-04",
            "count": 1
          },
          {
            "date": "2018-09-13",
            "count": 1
          },
          {
            "date": "2018-11-30",
            "count": 1
          },
          {
            "date": "2019-03-31",
            "count": 1
          },
          {
            "date": "2019-10-11",
            "count": 1
          },
          {
            "date": "2019-11-20",
            "count": 1
          },
          {
            "date": "2020-03-17",
            "count": 1
          },
          {
            "date": "2020-05-26",
            "count": 1
          },
          {
            "date": "2020-11-06",
            "count": 1
          },
          {
            "date": "2021-10-17",
            "count": 1
          },
          {
            "date": "2023-11-16",
            "count": 1
          },
          {
            "date": "2024-08-27",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 12,
        "total_forks": 12
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 16118,
      "source_files_sampled": 39,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 4,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "packagist"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "ext-json",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "ext-xdebug",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "php",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpunit/phpunit",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 4,
        "direct_count": 0,
        "indirect_count": 4
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 54,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 20,
        "closed_unmerged_prs": 9
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "ohader",
          "commits": 129,
          "avatar_url": "https://avatars.githubusercontent.com/u/402145?v=4"
        },
        {
          "type": "User",
          "login": "alexpott",
          "commits": 8,
          "avatar_url": "https://avatars.githubusercontent.com/u/769634?v=4"
        },
        {
          "type": "User",
          "login": "lolli42",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/2178068?v=4"
        },
        {
          "type": "User",
          "login": "xknown",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/1081870?v=4"
        },
        {
          "type": "User",
          "login": "longwave",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/197817?v=4"
        },
        {
          "type": "User",
          "login": "ausi",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/367169?v=4"
        },
        {
          "type": "User",
          "login": "ryanaslett",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/101536?v=4"
        },
        {
          "type": "User",
          "login": "ktomk",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/352517?v=4"
        }
      ],
      "contributors_sampled": 8,
      "top_contributor_share": 0.89
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "tests-ubuntu.yml",
        "tests-windows.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 8 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 2/16 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 9 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "5f66161e82446cdb2b3127fcd91328859796d2f9",
        "ran_at": "2026-07-24T04:54:54Z",
        "aggregate_score": 5.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-06-08T11:32:00Z",
      "oldest_open_prs": [
        {
          "number": 84,
          "created_at": "2025-11-24T03:27:56Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2025-09-30T17:35:18Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/TYPO3/phar-stream-wrapper",
    "host": "github.com",
    "name": "phar-stream-wrapper",
    "owner": "TYPO3"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 49,
      "inputs": {
        "security": 53,
        "vitality": 25,
        "community": 52,
        "governance": 62,
        "engineering": 53
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "critical",
        "name": "Vitality",
        "value": 25,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "critical",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 7,
            "inputs": {
              "commits_last_year": 1,
              "human_commit_share": 0.98,
              "days_since_last_push": 242,
              "active_weeks_last_year": 1
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 242 days ago",
                "points": 3.6,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 242
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "1/52 weeks with commits",
                "points": 0.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "1 commits in the last year",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "moderate",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "releases_count": 26,
              "latest_release_tag": "v4.0.0",
              "releases_from_tags": false,
              "days_since_latest_release": 591,
              "mean_days_between_releases": 197.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "26 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 591 days ago",
                "points": 7.2,
                "status": "partial",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 591
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~197.5 days",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 197.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "dormant",
              "guards": [],
              "signals": [
                "scorecard_unmaintained"
              ],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": 1,
              "unanswered_open_issues": 0,
              "days_since_last_merged_pr": 296,
              "days_since_last_human_commit": 591,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "no human commit for 591 days, with nothing left unanswered",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_quiet",
                    "params": {
                      "days": 591
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 52,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "forks": 12,
              "stars": 59,
              "watchers": 9,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "59 stars",
                "points": 28.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 59
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "12 forks",
                "points": 8.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "9 watchers",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "packages": [
                "typo3/phar-stream-wrapper"
              ],
              "dependents": 4,
              "ecosystems": "packagist",
              "total_downloads": 38496394,
              "monthly_downloads": 114709
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "114,709 downloads/month across packagist",
                "points": 67.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 114709,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "4 packages depend on it",
                "points": 4.7,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 62,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 32,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 8,
              "top_contributor_share": 0.89
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 89% of commits",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 89
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "8 contributors",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 54,
              "open_issues": 0,
              "closed_issues": 20,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 9
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "54/63 decided PRs merged",
                "points": 32.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 54,
                      "decided": 63
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 2/16 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 67,
            "inputs": {
              "followers": 117,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "TYPO3",
              "public_repos": 23,
              "account_age_days": 6267
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "117 followers of TYPO3",
                "points": 14.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 117,
                      "login": "TYPO3"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "23 public repos, account ~17 yr old",
                "points": 22.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 23
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 17
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "good",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "packages": [
                "typo3/phar-stream-wrapper"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 591
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 591 days ago",
                "points": 14,
                "status": "partial",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 591
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "27 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 27
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 53,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 8 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "topics": [
                "php",
                "phar",
                "stream-wrapper",
                "security",
                "insecure-deserialization",
                "deserialization"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 53,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 5.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 8 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 2/16 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 9 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 13
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "critical",
        "name": "AI Readiness",
        "value": 29,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.194,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "19 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 10.3,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 19,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 33,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 16118,
              "source_files_sampled": 39,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/39 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 39,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-24T04:55:09.526300Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/TYPO3/phar-stream-wrapper.svg",
  "full_name": "TYPO3/phar-stream-wrapper",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаPackagist.