Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-30 17:50 UTC

fivetwenty-io / proxmox-apiclient-go

Proxmox PVE API Client for Go

GoЛіцензію не виявлено★ 0 зірок⑂ 0 форківз серп. 2025 р.Переглянути на GitHub ↗

fivetwenty-io/proxmox-apiclient-go має індекс здоров’я 53 зі 100, що відповідає смузі «Помірний». Найвищий показник — Engineering Quality (74/100), найнижчий — Community & Adoption (22/100). Останнє оновлення було 10 днів тому. Більшість нещодавньої роботи виконує один учасник.

53
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

53
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

FiveTwenty Inc.Організація
2 підписники23 публічні репозиторіїз січ. 2023 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
Gogithub.com/fivetwenty-io/proxmox-apiclient-go/v3v3.8.2-2910 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

73Добрий · 22% загального індексу
Як обчислюється оцінка
28.8/36Свіжість push — останній push 10 дн. тому
7.6/36Ритм комітів — 11/52 тижнів із комітами
16.5/18Обсяг комітів — 67 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year67
human_commit_share1
days_since_last_push10
active_weeks_last_year11
Як обчислюється оцінка
16.2/27Випускає релізи — 29 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 10 дн. тому
27/27Ритм релізів — реліз кожні ~3,1 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count29
latest_release_tagv3.8.2
releases_from_tagsтак
days_since_latest_release10
mean_days_between_releases3,1
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

22Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

Здоров'я спільноти

45У зоні ризику
Як обчислюється оцінка
22.5/22.5README
0/22.5Ліцензія — файлу ліцензії не виявлено
18/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseні
has_contributingтак
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

39У зоні ризику · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
0/22.5Розподіл комітів — головний контриб’ютор — автор 100% комітів
1.4/13.5Широта контриб’юторів — 1 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 5 contributing companies or organizations
Використані вхідні дані
bus_factor1
contributors_sampled1
top_contributor_share1
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
0/38.3Прийняття PR — злито 0/4 вирішених PR
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs4
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue. Залишкові ваги перенормовано.
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
3.4/25Охоплення власника — 2 підписників у fivetwenty-io
17.1/25Послужний список — 23 публічних репозиторіїв, вік облікового запису ~3 р.
Використані вхідні дані
followers2
owner_typeOrganization
is_verified
owner_loginfivetwenty-io
public_repos23
account_age_days1 288

Супровід пакетів

100Відмінний
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у go
35/35Свіжість публікацій — остання публікація 10 дн. тому
20/20Історія версій — 29 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesgithub.com/fivetwenty-io/proxmox-apiclient-go/v3
ecosystemsgo
any_deprecatedні
min_days_since_publish10

Інженерна якість

Чи наявні базові інженерні практики та документація?

74Добрий · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 3 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — .golangci.yml
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

65Помірний
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
0/10Теми
0/10Wiki
Використані вхідні дані
topics
has_wikiні
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

58Помірний · 16% загального індексу

Стан безпеки

58Помірний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
0/2.5Ліцензія — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — немає даних
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool detected: CodeQL
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate5,8
Виключено з оцінювання (немає даних або не застосовно): ci_tests, packaging, signed_releases. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

63Помірний · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 61 з 67 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,91
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
18/18Розгортання однією командою — Makefile
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — .golangci.yml
11/11Статична перевірка типів — Go (статично типізована)
10/10Відтворюване середовище — lockfile
0/10Підтверджена практика роботи з агентами — серед останніх 67 комітів немає створених агентом
5/8Автоматизоване супроводження — автоматизацію залежностей налаштовано, але у вибірці комітів її не видно
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfilesgo.sum
has_dockerfileні
typed_languageтак
bootstrap_filesMakefile
has_devcontainerні
has_linter_configтак
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
Як обчислюється оцінка
45/45Типізований код — Go (статично типізована)
50.4/55Керовані розміри файлів — 16/192 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languageGo
largest_source_bytes804 668
source_files_sampled192
oversized_source_files16
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
0/20Сервер MCP
40/40Придатні до запуску приклади — examples
Використані вхідні дані
example_dirsexamples
has_mcp_signalні
api_schema_files

Ключові факти

0зірок GitHub
1контриб'юторів
67комітів за останні 12 місяців
10днів від останнього пушу
29релізів
1бас-фактор
0відкритих issue
Goпакетних екосистем

Попередження щодо збору даних

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 5.8 / 10
5.8сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-30 17:50 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
н/дPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool detected: CodeQL
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Прямі залежності 3
РеєстрПакетОбмеження версіїМаніфест
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogo.uber.org/zapv1.27.0go.mod
Gogolang.org/x/termv0.34.0go.mod
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 6644,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 1241298,
        "Makefile": 12296
      },
      "pushed_at": "2026-07-20T12:55:26Z",
      "created_at": "2025-08-20T03:16:13Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T12:56:44Z",
      "description": "Proxmox PVE API Client for Go",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://fivetwenty.io",
      "name": "FiveTwenty Inc.",
      "type": "Organization",
      "login": "fivetwenty-io",
      "company": null,
      "location": "United States of America",
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/123042834?v=4",
      "created_at": "2023-01-19T02:24:31Z",
      "is_verified": null,
      "public_repos": 23,
      "account_age_days": 1288
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.8.2",
          "kind": "patch",
          "published_at": "2026-07-20T12:55:18Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2026-07-10T01:20:45Z"
        },
        {
          "tag": "v3.8.0",
          "kind": "minor",
          "published_at": "2026-07-09T18:47:49Z"
        },
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2026-07-09T12:26:16Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-07-08T21:20:42Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-07-07T23:18:02Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-07-07T17:57:45Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2026-07-04T09:58:05Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-07-04T01:21:14Z"
        },
        {
          "tag": "v3.2.10",
          "kind": "patch",
          "published_at": "2026-06-22T16:30:41Z"
        },
        {
          "tag": "v3.2.9",
          "kind": "patch",
          "published_at": "2026-06-22T15:55:13Z"
        },
        {
          "tag": "v3.2.8",
          "kind": "patch",
          "published_at": "2026-06-22T12:57:50Z"
        },
        {
          "tag": "v3.2.7",
          "kind": "patch",
          "published_at": "2026-06-04T21:49:28Z"
        },
        {
          "tag": "v3.2.6",
          "kind": "patch",
          "published_at": "2026-06-04T19:31:09Z"
        },
        {
          "tag": "v3.2.5",
          "kind": "patch",
          "published_at": "2026-06-03T20:04:55Z"
        },
        {
          "tag": "v3.2.4",
          "kind": "patch",
          "published_at": "2026-06-03T13:41:49Z"
        },
        {
          "tag": "v3.2.3",
          "kind": "patch",
          "published_at": "2026-06-02T13:28:04Z"
        },
        {
          "tag": "v3.2.2",
          "kind": "patch",
          "published_at": "2026-06-02T12:56:09Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2026-06-02T03:27:02Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-06-02T02:26:05Z"
        },
        {
          "tag": "v3.1.7",
          "kind": "patch",
          "published_at": "2026-05-21T14:01:34Z"
        },
        {
          "tag": "v3.1.6",
          "kind": "patch",
          "published_at": "2026-05-20T19:25:31Z"
        },
        {
          "tag": "v3.1.5",
          "kind": "patch",
          "published_at": "2026-05-19T22:31:28Z"
        },
        {
          "tag": "v3.1.4",
          "kind": "patch",
          "published_at": "2026-05-19T21:21:32Z"
        },
        {
          "tag": "v3.1.3",
          "kind": "patch",
          "published_at": "2026-05-19T20:30:12Z"
        },
        {
          "tag": "v3.1.2",
          "kind": "patch",
          "published_at": "2026-05-19T13:37:39Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2026-05-19T13:20:01Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-05-18T18:28:44Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2025-11-19T20:20:55Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "0f40c15f70a2f02e769200b257036e0d32f2a894",
          "body": "A failed DNS lookup or a failed TCP dial means the request never reached\nthe server, so retrying can only reproduce the same failure at the same\ncost. An unreachable host was dialed four times, which turned a host that\nsilently drops SYNs into a multi-minute wait before any error surfaced.\n\nClassify\n[…]\ne makes the outermost layer, so\nit counted the whole retry loop as a single call and asserted nothing.\nMove it inside retryMiddleware and drive it with a post-connect error so\nit tests what it claims.",
          "is_bot": false,
          "headline": "fix(http): stop retrying failures to establish a connection",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-20T12:55:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4696c1505be53dd9a6fbaa90fb125ca6f6067358",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog for v3.8.1",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-10T01:20:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d46e3b2f326b5175b018ae771302970607ed9624",
          "body": "The Rust-based products (Proxmox Backup Server, Proxmox Datacenter\nManager) parse the API token Authorization value as TOKENID:TOKENSECRET\n(proxmox-auth-api splits on ':'), while PVE's Perl parser expects\nTOKENID=SECRET. GetHeaders emitted the '=' form unconditionally, so\ntoken authentication agains\n[…]\nAPIToken.\n\nAdd end-to-end Authorization header assertions for PVE, PBS, and PDM\nclients against real HTTP test servers, tightening the existing PBS/PDM\nprefix-only checks to pin the full header value.",
          "is_bot": false,
          "headline": "fix(auth): use colon token secret separator for PBS and PDM API tokens",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-10T01:15:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a50cd0a34434ae6c4b0b62b49e2d8f1b4dd78b52",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog for v3.8.0",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T18:47:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "329f84595de25842bee2af4b5b48ff7a4b134008",
          "body": "…HTTP\n\nGenerated methods whose isResponseEmptyOk is true (array/aliased-\nRawMessage returns, e.g. access.ListAcl) fall back to a zero-value\nresponse when resp.Data is nil; methods with a populated required\nobject return schema (e.g. access.GetUsersToken) instead return an\nerror. The generated smoke tests always send a non-nil \"data\" value,\nso neither branch was previously exercised at runtime. Cover both over\na real HTTP round trip: null data, no \"data\" key at all, and the\nstrict error path.",
          "is_bot": false,
          "headline": "test: exercise the nil-data tolerant and strict decode branches over …",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T18:41:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0821dafe97a071afac2243660ee6586c757a4ff4",
          "body": "…hema\n\nThe pdm-apidoc.json entry for GET /pve/remotes/{remote}/updates declares\n\"returns\": {\"type\": \"null\"} because the PDM Rust handler's #[api(...)]\nmacro omits its \"returns:\" key, even though the handler returns real\ndata. Transcribe the schema from pdm-api-types' RemoteUpdateSummary\n(nodes, remote-type, status, optional status-message) so the generated\nresponse is a typed struct instead of an aliased []json.RawMessage, and\nso a real object-shaped body decodes correctly.",
          "is_bot": false,
          "headline": "fix(pdm): type the pve remote updates response from the PDM source sc…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T18:38:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7bfac3cfeb7222fa175e3cb2252d5651076d7e75",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog for v3.7.0",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T12:26:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a7dac8a5d66fd6c2a2f73fb21b4adae99c4daff",
          "body": "Matches the generated smoke test's package convention and avoids\ninline error handling in the hand-written LXC/QEMU regression test.",
          "is_bot": false,
          "headline": "test(pdm): move sparse config round-trip test to the pve_test package",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T12:11:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6a2393c8a39d65eba333792d36262fb3e8d82bd",
          "body": "…emas\n\nThe PDM apidoc enumerates every possible slot for numbered-slot guest\nconfig families (dev0..dev255, mp0..mp255, net0..net31, unused,\nipconfig, scsi, virtio, hostpci, usb, virtiofs, sata, serial, parallel)\nwithout ever marking the unused ones \"optional\", so RETURNS schema\nstructs generated no\n[…]\nes keeps\nsingle word+digits names like \"sha256\" or \"smbios1\" out of the\nheuristic, and requiring a zero suffix excludes small fixed pairs like\nAD/LDAP's \"server1\"/\"server2\" that are not slot families.",
          "is_bot": false,
          "headline": "fix(pvegen): treat numbered slot properties as optional in return sch…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T12:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ee1ac174e7b12e12b40dadb12b330ed7a89acd3",
          "body": "Generated POST/PUT methods built their form body by marshaling the whole\nparams struct to JSON and re-decoding it into a map[string]interface{}.\nThat round-trip destroyed json.RawMessage fields: an object-valued field\ndecoded into a Go map and was then serialized as a Proxmox\ncomma-joined \"k=v,k=v\" \n[…]\nginal typed param via\njson.Marshal (which compacts the RawMessage's JSON text) and replaces\nthe map entry with that string. Scalar params, []string params, and\nmap-valued Raw API params are untouched.",
          "is_bot": false,
          "headline": "fix(http): send json.RawMessage params as JSON text form values",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T11:54:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eeba90c28ae6356c29c1401340c0677b84437ce8",
          "body": "Populate the pdm dialect's returnsOverrides table for the PDM\nremote-proxy and listing endpoints whose vendored pdm-apidoc.json\nentry declares \"returns\": {\"type\": \"null\"} even though every one of\nthem returns real data: node/journal listing, the auto-install\nprepared-answer lookup, the PVE/PBS remot\n[…]\n\"value\" field optional so it\ngenerates as *string, matching the documented \"only present when\nregenerate=true\" contract.\n\nRegenerated pkg/pdm/{access,autoinstall,nodes,pbs,pve} from the\nupdated table.",
          "is_bot": false,
          "headline": "fix(pdm): correct return schemas for data-bearing and mistyped endpoints",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T11:37:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca1c513e32bf89506ec283b0ef21b093fc2bc290",
          "body": "Add a returnsOverrides map[string]*schema to dialectConfig, keyed\n\"VERB /path\" like the existing methodNameOverrides table, and consult\nit in collectEndpoints right after the endpoint's info is read from\nthe tree. This is the single choke point every downstream consumer\n(responseGoType, renderObject\n[…]\nly returns a value\nwhen regenerate=true) legitimately return no data, and the generator\nwas previously always treating a populated object schema as strict,\nproducing a hard error on a successful call.",
          "is_bot": false,
          "headline": "feat(pvegen): support per-endpoint returns-schema overrides",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T11:36:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb3b0ee19be80eca9b2569c6ad6afb582e0f1ae1",
          "body": "Pulls in the crypto/tls fix for GO-2026-5856; govulncheck is clean\nagainst the 1.26.5 standard library.",
          "is_bot": false,
          "headline": "chore: require Go 1.26.5 toolchain",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:20:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df45d73a0c1ddfc4284b0c3f2ca6eb4c2932ce5f",
          "body": "Hoist the \"GET /version\" methodNameOverrides key shared by the pve,\npbs, and pdm dialects into overrideGetVersion, alongside the existing\nmethodPrefixGet/namespaceVersion/namespaceRoot constants.",
          "is_bot": false,
          "headline": "refactor(pvegen): name the GET /version override key constant",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:15:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dc43938437200e770b2bc5e7d2151ef6e9c4df9",
          "body": "Match _data/README.md's terminology for the 327 PDM bindings\n(\"method-operations\") instead of \"endpoints\" in the README's PDM\nsection and the CHANGELOG v3.6.0 entry.",
          "is_bot": false,
          "headline": "docs: use method-operations terminology for the PDM binding count",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:11:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9da4fa663a03c225861bc34886bd8f000c75159b",
          "body": "Include pkg/pdm in verify-generated's drift check and diff output\nalongside pkg/api and pkg/pbs, and add the generated pkg/pdm\nsubdirectories to GOSEC_EXCLUDE_DIRS to match the existing pkg/api\nand pkg/pbs entries. Update the pkgImportRoot doc comment in\ncmd/pvegen/main.go to mention pkg/pdm.",
          "is_bot": false,
          "headline": "chore: extend generate and security gates to pkg/pdm",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:11:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76b73dff4a705d3b965bb199638d7d3b4d7a2194",
          "body": null,
          "is_bot": false,
          "headline": "docs: document pkg/pdm bindings and backfill the v3.5.0 changelog entry",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:02:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90795709c8a090a292e0327dde45ab2ee4123f2d",
          "body": "…IToken, PDMAuthCookie)",
          "is_bot": false,
          "headline": "feat(pdm): add client preset with PDM wire defaults (port 8443, PDMAP…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T20:58:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "357f700f283f2ce4b0f324ce921a48a0400cb868",
          "body": "…g/pdm",
          "is_bot": false,
          "headline": "feat(pdm): add generated Proxmox Datacenter Manager bindings under pk…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T20:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7bc1af9beb813e24f4317de0ce6de8b5c317d41",
          "body": null,
          "is_bot": false,
          "headline": "feat(pdm): vendor Proxmox Datacenter Manager 1.1.6 API specification",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T20:49:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26d04713d0104cbdac364cbd7a974ddcb2569a16",
          "body": "PVE renders documented integers inconsistently: a value documented as an\ninteger may arrive as a JSON number or as a string (the firewall rule\nposition on /cluster/firewall/groups/{group}/{pos} is a concrete case).\nPlain int64 response fields fail to decode such payloads.\n\nMirror the existing PVEBoo\n[…]\ntring, null) that marshals\nback out as a native JSON number, and retype generated response integer\nfields via responseIntType in pvegen. Request params keep plain int64 so\nquery encoding is unchanged.",
          "is_bot": false,
          "headline": "Add tolerant client.PVEInt for response integer fields",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-07T23:18:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1842fbc53b5fbc209fd903766b3d04ea8fb29510",
          "body": "Add typed bindings for the PBS JSON API (346 endpoints across access,\nadmin, config, nodes, tape, status, version, ping, pull, and push),\ngenerated from the vendored _data/pbs-apidoc.json. The HTTP/2\nchunk-protocol endpoints (/backup, /reader) and the GET / directory\nindex are excluded.\n\ncmd/pvegen \n[…]\ntrip asserting the PBSAPIToken Authorization header.\n\nverify-generated and the gosec/golangci generated-code exclusions now\ncover pkg/pbs; README, _data/README, and CHANGELOG document the new\nsurface.",
          "is_bot": false,
          "headline": "feat(pbs): add generated Proxmox Backup Server bindings under pkg/pbs",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-07T17:57:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "182ad66cb142a01a0c48c88795f8709f78c8772f",
          "body": "The library is growing Proxmox Backup Server support alongside PVE, so\nthe module moves from fivetwenty-io/pve-apiclient-go/v3 to\nfivetwenty-io/proxmox-apiclient-go/v3. No Go API changes.\n\n- Rewrite module path in go.mod, all imports, and pvegen output\n- Update User-Agent to proxmox-apiclient-go/1.0\n[…]\ng/proxmox-apiclient-go/\n  with automatic fallback to the legacy pve-apiclient-go location\n- Fix goreleaser release target owner (proxmox -> fivetwenty-io)\n- Document the path migration in MIGRATION.md",
          "is_bot": false,
          "headline": "Rename module to proxmox-apiclient-go",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-07T17:06:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f3e97d7186667da8e9cd00e966f9767db14608e",
          "body": null,
          "is_bot": false,
          "headline": "Bump golang.org/x/sys to v0.44.0",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T09:58:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad7e756619590192f37c6ceb2a337bb8de99bf11",
          "body": "Add a README section explaining the relationship between the generated\npkg/api bindings, the hand-written convenience packages, and the\nclient/transport layers. Replace inaccurate or missing package doc\ncomments on qemu, lxc, network, storage, tasks, cloudinit, pool, batch,\nand compatibility with descriptions of what each package actually does.",
          "is_bot": false,
          "headline": "Document package layering and correct package doc comments",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "632d3cd91e913da415b811529bd35f27b17b96f0",
          "body": "Brings lxc in line with the other typed API packages, which all expose\nan interface plus constructor for mockability.",
          "is_bot": false,
          "headline": "Add Service interface and NewService constructor to lxc package",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab24bf4d461e74677084077a070b8c871fc03ad1",
          "body": "…ardening\n\nSetTimeout and SetKeepAlive on the public client now reach the\nunderlying HTTP transport instead of being silently dropped, CSRF\ntokens are propagated on ticket-authenticated write requests, and\nAPITokenName/CSRFToken accessors are exposed. Retries apply random\njitter to backoff delays to\n[…]\ncannot bypass\ncertificate verification. Cached HTTP responses report exact sizes to\nthe cache via CacheSize. New options cover manual fingerprint\nverification callbacks and the fingerprint cache path.",
          "is_bot": false,
          "headline": "Wire client options through the transport; add retry jitter and TLS h…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7583a97cf69078d38d6b8da8549e4b760f6463c",
          "body": "Manual verification was a stub that always rejected. Unknown\nfingerprints can now be routed to a caller-supplied callback carrying\nhost, port, and certificate details, and accepted fingerprints are\ntrusted for the session. The trust-on-first-use fingerprint cache is\nnow actually loaded and saved (NewVerifierWithCache), with writes\nperformed under the verifier lock.",
          "is_bot": false,
          "headline": "Implement manual fingerprint verification and persist the TOFU cache",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e4306ba8a484ab6f1903b4aa77e3ce8fbe504ab",
          "body": "…ntries\n\nSize accounting marshaled every value to JSON on Set, costing CPU and\ninflating byte payloads ~33% via base64, which skewed evictions. Sizes\nare now computed type-aware, and values may implement the new Sizer\ninterface (CacheSize() int64) to report exact sizes. Corrupt list\nelements no longer panic eviction paths; they are removed and counted\nin CacheStats.Corrupted.",
          "is_bot": false,
          "headline": "Estimate cache entry sizes without JSON marshaling; survive corrupt e…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8aef3b16e621545685531450830ea97b3861129d",
          "body": "Read previously discarded any decoded data that did not fit the caller's\nbuffer, silently corrupting streams read with small buffers. The\nremainder is now buffered and returned by subsequent reads. Add package\ndocumentation describing the streaming model.",
          "is_bot": false,
          "headline": "Buffer unread remainder in stream Reader to honor io.Reader contract",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a7acd23ef7c87f38d1f11557b8e51a41e8b278d",
          "body": "Set read/write deadlines before the handshake rather than after, so a\nstalled server cannot hang Connect indefinitely. Message handlers are\ntracked by entry so RemoveHandler removes the exact handler registered\ninstead of matching by function pointer. Handler dispatch is bounded by\na semaphore (Config.MaxConcurrentHandlers) so a slow handler cannot\nspawn unbounded goroutines, and read deadlines are refreshed per frame.",
          "is_bot": false,
          "headline": "Fix websocket handshake deadlines, handler removal, and dispatch bounds",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa56e3e69e8c7c1694b45573ed73bf6ff2a72b6b",
          "body": "Login, TFA submission, and logout previously trusted any response body\nregardless of status code. Each now verifies a 2xx status before\ndecoding, and response bodies are read through a 4096-byte bounded\nreader so a misbehaving server cannot exhaust memory.\n\nNewTicketAuthenticatorFromTicket parses th\n[…]\n to anchor renewal timing, falling back to the current time\nwhen unparsable. Password prompts read through an injectable descriptor\nso non-terminal input falls back to line reading instead of failing.",
          "is_bot": false,
          "headline": "Gate auth flows on HTTP status and bound response body reads",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "390b0634539f08e52a8924ce49c1b8aa0b704f15",
          "body": "Replace the outcome-agnostic generated smoke tests with behavioral ones:\neach endpoint subtest now runs against a mock server and asserts the HTTP\nmethod, encoded path and parameters, response decoding, API error\npropagation, and the nil-context guard (via a typed nil variable so\nstaticcheck SA1012 \n[…]\ntor gains testgen.go plus unit tests for name sanitization,\npath expression building, and sample-value selection. Anchor the pvegen\nignore pattern to the repo root so cmd/pvegen sources are trackable.",
          "is_bot": false,
          "headline": "Generate behavioral smoke tests for API bindings",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bb75f4b8ec4ee27bddb9c18312a6d8da80e0804",
          "body": "The internal HTTPClient interface and internalHTTPAdapter already carry\nSetHeader/RemoveHeader, but they were never surfaced on the public Client.\nAdd them to the Client interface and forward from *client to httpClient so\ncallers can set a custom User-Agent (or other headers) at construction time\nwithout reaching into internal packages.",
          "is_bot": false,
          "headline": "Expose SetHeader/RemoveHeader on the public Client interface",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-22T16:30:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a531754dc900db86028e8113e374aa2e093f75dd",
          "body": "Release v3.2.9.\n\nAdded:\n- Client.Close()/HTTPClient.Close() release the cache cleanup goroutine\n  and close idle connections; idempotent.\n\nFixed:\n- Cache no longer panics on a second Close() (close-once).\n- Stream no longer leaks a per-stream goroutine; removed an inert metrics\n  collector that prod\n[…]\nr-focused tests plus a\n  regression test per fix above.\n- Tightened lint config (varnamelen short-name allowances, recvcheck\n  exclusion for the Marshal/Unmarshal pair) and fixed substantive findings.",
          "is_bot": false,
          "headline": "Add Close(), fix cache/stream/pool/auth/batch bugs, lift coverage",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-22T15:55:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac2043c90d29cd0b63ce4b30f63c76b896eac667",
          "body": "…ation\n\nRequest params were marshaled to JSON and decoded into map[string]interface{}\nwith a plain json.Unmarshal, turning every number into float64. The form\nencoder's fallback (fmt.Sprintf(\"%v\", float64)) then rendered any value >= 1e6\nin scientific notation (e.g. bwlimit=1048576 -> \"1.048576e+06\"\n[…]\ner and keep their exact digits. Add json.Number, float64,\nand float32 cases to the form encoder that emit plain decimal, which also\nhardens any body map decoded without UseNumber. Regenerate bindings.",
          "is_bot": false,
          "headline": "fix(http): encode large integer params in decimal, not scientific not…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-22T12:57:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8dea091cda036e195cb4a34100c7a3cee8782d8c",
          "body": null,
          "is_bot": false,
          "headline": "Bump Go version to 1.26.4",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-08T19:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "740e6bd526c9ade394d00e34c0e34f5dc7c8f571",
          "body": "…ort knobs\n\ntasks.Service gains GetStatus(ctx, node, upid) for single-shot status reads\nwithout polling, enabling callers to drive progress-aware adaptive intervals.\nStatus struct gains Progress float64 (range [0,1]) populated by parseProgress\nwhich tolerates float64/int/int64 JSON variants from PVE\n[…]\nec. createHTTPTransport applies each when non-zero; all-zero\npreserves byte-identical behaviour to the prior transport (KeepAlive fallback,\nLongTimeout idle, no DialContext, no TLS handshake timeout).",
          "is_bot": false,
          "headline": "Add GetStatus/Progress adaptive-poll API and configurable HTTP transp…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-04T21:49:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3598952c263d32846c31e9bd65f6c5c18b7203aa",
          "body": "term.ReadPassword received syscall.Stdin directly, which is an int on\nUnix but a syscall.Handle (uintptr) on Windows, breaking windows/* builds.\nConvert to int explicitly so the call compiles on every GOOS.",
          "is_bot": false,
          "headline": "Fix windows cross-compilation in PromptPassword",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-04T19:31:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "023019cfb5f98c85e690562465443fbe3e9a7dc5",
          "body": "PVE renders documented numbers inconsistently — the pressure-stall (PSI)\nmetrics on container and VM status arrive as JSON strings rather than\nnumbers — which made typed status responses fail to decode real payloads\nwith 'cannot unmarshal string ... into float64'. Add a tolerant PVEFloat\ntype (accep\n[…]\n empty string as 0, marshals as\na native JSON number) and emit it from the generator for response float\nfields; request params keep plain float64. Regenerated bindings retype 24\nresponse float fields.",
          "is_bot": false,
          "headline": "Add tolerant client.PVEFloat for response number fields",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-03T20:04:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b13945e3b63f85db34807c25e1b2e1e40fbdb67",
          "body": "The Proxmox VE API renders booleans inconsistently across endpoints:\nas a JSON boolean, a number (1/0), or a string (\"1\"/\"0\", \"true\"/\"false\",\n\"yes\"/\"no\", \"\"). Typed get-by-id responses with *bool fields (QEMU status\nagent, user enable, role privileges, ...) failed to decode real payloads\nwith \"canno\n[…]\nw emits *client.PVEBool\nfor boolean fields in response structs while request parameter structs keep\nplain bool, so query encoding is unchanged. Regenerated bindings retype 150\nresponse boolean fields.",
          "is_bot": false,
          "headline": "Decode PVE's loosely-typed response booleans",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-03T13:41:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5926c6a8d35683ab00d0da8f8862c60601dae224",
          "body": "Custom headers:\n- Back Client.SetHeader/RemoveHeader with a mutex-guarded header map instead\n  of no-op stubs. Headers are applied to every request via applyCustomHeaders\n  in both the standard and upload request builders, after the default headers\n  (so callers may override User-Agent) and before a\n[…]\ntrics/Timeout/Header/Compression middlewares)\n  that was never wired into the client; the active request pipeline lives in\n  client.go. Drop its tests and the now-unused log import and sentinel error.",
          "is_bot": false,
          "headline": "Implement custom request headers; remove unused middleware framework",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T13:28:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bfb8b514b7251b08c5d104a6c9e1d1712cc915a3",
          "body": "Correctness:\n- compatibility: GetDeprecatedFeatures looked up the feature matrix by display\n  name instead of the map key, so it always returned empty; key it like\n  GetNewFeatures does.\n- qemu: Snapshot copied snapname into the caller's opts map; build a fresh map.\n- tasks: the poller returned a ha\n[…]\nin the streaming benchmark instead of deferring\n  inside the b.N loop.\n- Make the websocket ping test assert pings actually fire.\n- gofmt previously unformatted test files and the zap logging adapter.",
          "is_bot": false,
          "headline": "Quality review and remediation",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T12:56:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0476b159698d1fc0eb5609c059d0800080837677",
          "body": "…ed fixtures\n\nRename short-scoped variables to descriptive names, add t.Parallel to\nparallel-safe tests, defer response-body closes, use two-value type\nassertions, propagate real contexts, and extract repeated literals into\nshared constants across the suite and examples. Behavior of the code under\ntest is unchanged.",
          "is_bot": false,
          "headline": "test: descriptive names, parallel-safe subtests, closed bodies, dedup…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:27:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae08d8da41af88bb0b95f2dd62d73c3582323011",
          "body": "Wrap errors crossing package boundaries (WebSocket Conn I/O and proxy POST,\nstream close) so failures carry context; promote repeated content-type,\nlog-field, realm, and protocol literals to named constants; convert an\nif/else chain to a switch; and split oversized transport, streaming, and\ndisk-attach helpers into focused sub-functions. No exported API or behavior\nchange.",
          "is_bot": false,
          "headline": "refactor: wrap boundary errors, extract constants, reduce complexity",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:26:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35067be42c7f1a1ccd6313b9a5c06cfaa0f3d5c5",
          "body": "Rename terse locals to descriptive names, extract render helpers to lower\nfunction length and cognitive complexity, introduce named constants and\nsentinel errors, and preallocate where size is known. Verified byte-for-byte\nidentical output via go generate (zero drift in pkg/api/*_gen.go).",
          "is_bot": false,
          "headline": "refactor(pvegen): clarify generator internals; emitted output unchanged",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:26:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f65a143b8bff5e7609cb2513de983ad206d13b1",
          "body": "…domain-inherent rules\n\nMirror a single gosec scope across the Makefile and CI: skip generator-\nemitted bindings (pkg/api/*_gen.go) and rules that are inherent to a\nProxmox API client rather than defects — G117 (request structs marshal\ncredentials), G123 (deliberate certificate pinning), G402 (opt-in\nInsecureSkipVerify), G704 (HTTP to a caller-configured host). Add the\nmatching gosec exclusions to .golangci.yml and migrate gomodguard to\ngomodguard_v2.",
          "is_bot": false,
          "headline": "build: scope gosec and golangci-lint, exclude generated bindings and …",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:26:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28aa38dde5f5f995dd175cb40d13a0244d0ee0ae",
          "body": "Regenerate typed bindings from the Proxmox VE 9.2 spec (444 endpoints /\n675 method-operations). Adds cluster-wide QEMU listing, QEMU CPU flags,\ncustom CPU model CRUD, and Nodes().DeleteCephFs, plus optional SDN\nfabric/controller/zone and access-domain parameters. All additive; no\nexported symbol rem\n[…]\nation (NewTicketAuthenticatorFromTicket);\n  propagate UpdateTicket/UpdateCSRFToken to the active authenticator.\n\nRefresh _data/apidoc.json to 9.2 and document the bracket-matched\nextraction procedure.",
          "is_bot": false,
          "headline": "feat: cover PVE 9.2 API surface and harden transport",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T02:26:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d731027327399700615fc7e95c97ef1d9d9fc558",
          "body": "PVE stores disk values in option-string format: the volid is followed\nby comma-separated options (e.g. \"data:vm-9003-disk-0,size=64G\"). The\nprior exact string match returned (¬\"\", false) for every disk that PVE\nhad decorated with a size or other option, leading callers to treat\nthe disk as not attached and re-attach it at a fresh slot — a\nduplicate that surfaces as ambiguous attachment (\"disk found on N VMs\")\nat the next config scan.\n\nMatch equality first, then the \"<volid>,\" prefix.",
          "is_bot": false,
          "headline": "fix(qemu): FindDiskIDByVolID matches PVE option-string disk values",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-21T14:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ca26039f54efb1a4b3655e56d386cad40ae981a",
          "body": "PVE's DELETE /nodes/{node}/storage/{storage}/content/{volume} queues an\nasynchronous `imgdel` task that runs under the per-storage lockfile.\nDeleteVolume and DeleteVolumeIfExists were throwing away the returned\nUPID, so callers had no way to await completion. When the storage lock\nis contended (e.g.\n[…]\n the\nUPID. Existing methods are kept and now delegate to the async variants\n(discarding the UPID), with doc-comment warnings about the queued-imgdel\nhazard for delete-then-reupload-same-name patterns.",
          "is_bot": false,
          "headline": "fix(storage): expose imgdel UPID for delete-then-upload safety",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-20T19:25:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "819f73328ff31c0be3f5caa5b57653ac53b7c3d9",
          "body": "PVE rejects /nodes/<node>/storage/<storage>/upload with HTTP 400\nwhen \"filename\" appears both in the multipart form fields AND as the\nfile part name. Pass it only as the part name, matching the fix\nalready applied to Storage().Upload.\n\nAffects both Attach (user-data upload) and AttachWithNetwork\n(network-data upload).",
          "is_bot": false,
          "headline": "fix(cloudinit): Attach must not send filename as form field",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T22:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f0335e233a20ea4b22d212d55c7ed344abcfffa",
          "body": "PVE rejects the request with HTTP 400 when the `filename` part name\nappears both as a form-data field and as the multipart file part name.\nThe file part already carries the destination name via its own filename\nattribute; the explicit form field is redundant and breaks the upload.",
          "is_bot": false,
          "headline": "fix(storage): Upload must not send filename as form field",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T21:21:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf43ceb6c9e704774afa987de3217eaaa284a19",
          "body": "Upload sends a file to a PVE storage pool as a given content type and\nreturns the upload UPID. DeleteVolumeIfExists mirrors DeleteVolume but\nreports whether the volume was present, returning (false, nil) on 404\ninstead of silently swallowing it.",
          "is_bot": false,
          "headline": "feat(storage): add Upload + DeleteVolumeIfExists",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T20:30:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267b2211819dd243f4315004b6b71c0665545b45",
          "body": "PVE's PUT /qemu/{vmid}/config with delete:scsiN does not actually\nremove the disk reference from the VM config — it demotes the disk\nto a new unusedN slot. A subsequent DELETE /qemu/{vmid} then\ndestroys every disk still referenced (unusedN included), silently\nnuking persistent volumes the caller int\n[…]\ns can\ntreat \"detach\" as fully detached and rely on it surviving a later\nVM destroy.\n\nTests cover the two-PUT sweep, the no-op direct unusedN detach,\nand confirm bare volid vs \"volid,options\" matching.",
          "is_bot": false,
          "headline": "fix(qemu): sweep unusedN slot after DetachDisk",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:37:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c63b4ff10824f40b55243f0429acbc32d31653ba",
          "body": "PVE's /nodes/{node}/qemu/{vmid}/resize endpoint accepts PUT, not POST.\nResizeDisk was calling postUPID, which returned HTTP 405 against any\nmodern PVE.\n\nInline a PutCtx call that handles the two response shapes the endpoint\nemits (bare UPID string or object with \"upid\" key) and update the\nexisting httptest mock to expect PUT.",
          "is_bot": false,
          "headline": "fix(qemu): use PUT for /resize endpoint",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:20:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a25233360a1871919f7d664724ec0b391e36a866",
          "body": "POST /nodes/{node}/storage/{storage}/content rejects two of the params\nthe SDK was sending and expects a different shape for size:\n\n  - \"content\" is not in the schema and triggers\n    \"property is not defined in schema\" against any real PVE node.\n  - \"size\" must be a string with optional 'M' or 'G' \n[…]\n\"content\", switch size to \"<n>G\" string form, and only include\nformat when the caller supplied one. Behavior is now compatible with\nthe full storage-type matrix (dir/nfs/cifs/rbd/lvm/lvmthin/zfspool).",
          "is_bot": false,
          "headline": "fix(storage): align CreateVolume params with PVE /content schema",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:19:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99161034b512564df580c517c8e2f43238f00d04",
          "body": "SSLVerifyNone / SSLVerifyPeer / SSLVerifyHost / SSLVerifyFull were\ndeclared in the same const block as ProtocolHTTP / ProtocolHTTPS.\nBecause the protocol constants are explicit string values rather than\ntyped assignments, iota continues incrementing through them — so\nSSLVerifyNone = iota evaluated t\n[…]\nelf-signed PVE clusters failed.\n\nMove the SSL constants into their own const block so iota restarts at\n0. No API change; callers that already used client.SSLVerifyNone now\nget the documented behavior.",
          "is_bot": false,
          "headline": "fix(client): split SSLVerifyMode iota into dedicated const block",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:19:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b74e6779db32890a4d7bd3a7378e905e3dcf0dac",
          "body": "The form-encoding fix landed in RequestBuilder.AddFormParam\n(internal/http/request.go) but the production hot path used by all\n666 generated bindings goes through buildRequestWithContext, which\nstill serialized params via fmt.Sprintf(\"%v\", value).\n\nEffect on the live wire: booleans serialized as \"tr\n[…]\nptest server and assert the wire\nformat directly, not via the encoder helper.\n\nAlso fixes pkg/stream/stream_test.go:499 (err := redeclaration that\nprevented stream tests from building under newer Go).",
          "is_bot": false,
          "headline": "fix: form-encoding bypass in production request path",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-18T18:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af3a0cf21f71f5f16319978e45f464aa90d8cf7d",
          "body": "Generates typed bindings for all 667 PVE 9.x endpoints, implements 12\nWebSocket/streaming methods, fixes correctness bugs, raises coverage on\npreviously-untested packages, and adds user-facing docs.\n\nGenerated coverage:\n- cmd/pvegen extended from single-namespace emitter to data-driven\n  walk over a\n[…]\nmat, websocket concurrency)\n\nAll 27 packages pass go build, go vet, go test -race -count=1.\nHand-written library coverage 71.8%; generated bindings cover the\nfull 667-endpoint surface via smoke tests.",
          "is_bot": false,
          "headline": "feat: full PVE 9.x coverage, WebSocket support, user docs",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-18T18:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee18e87f892d2460f783882f06e0bffe4577cb87",
          "body": "Bug fixes:\n- APIToken auth header now splits USER@REALM!ID=SECRET via\n  auth.ParseAPIToken instead of doubling the raw string into Token.ID\n  and Token.Secret.\n- TicketAuthenticator gains sync.RWMutex; all ticket-field accesses\n  guarded. 4 race-detector tests at 50–100 goroutines.\n- Form encoding a\n[…]\npoints)\n- Smoke namespace pkg/api/version with typed Service\n- make generate + make verify-generated targets, idempotent\n\nModule path stays at v3. All packages: go build, go vet, go test -race\nexit 0.",
          "is_bot": false,
          "headline": "feat: codegen pipeline, auth fixes, form encoding",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-18T18:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb7181dea87ff8c587cfa1a6b57d688427fa8169",
          "body": "- Add missing imports (strings, errors) to fix compilation errors\n- Fix errcheck warning in cache.go by explicitly ignoring hash write error\n- Fix variable shadowing in detector_test.go (use = instead of :=)",
          "is_bot": false,
          "headline": "fix: Post-rebase compilation and linting fixes",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-11-19T20:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9118a11861a6e2b2a96b835685e7e2a84cc9dae0",
          "body": null,
          "is_bot": false,
          "headline": "Updated functionality based on parity with perl",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-11-19T15:45:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0853239860c51361e9b7222af947775664e6040",
          "body": null,
          "is_bot": false,
          "headline": "Proxmox VE API client library for Go",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-11-19T15:45:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b37a02a84603cff5eeb4756ee4b81f4b593e8a3",
          "body": null,
          "is_bot": false,
          "headline": "golangci-lint passes",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-09-08T16:11:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c79136c9aa79e8a35e5abbf01ec95dfd171ff7d",
          "body": "- Module path is github.com/fivetwenty-io/pve-apicilent-go\n- Update all import statements and references across codebase\n- Update documentation links and examples\n- Update CI/CD configuration files",
          "is_bot": false,
          "headline": "refactor: Module path, documentation",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-08-20T20:01:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a18849ae5d09c4427ebb9c601b6640f42e1858eb",
          "body": "Implements a full-featured Go client library for the Proxmox VE API with:\n- Complete authentication support (tickets, API tokens, TFA)\n- SSL fingerprint verification and certificate caching\n- Connection pooling and batch operations\n- WebSocket support for real-time console access\n- Stream API suppor\n[…]\nmentations demonstrating basic, auth, and advanced usage\n- Extensive test coverage with unit and integration tests\n- CI/CD pipelines with GitHub Actions\n- Documentation for migration and compatibility",
          "is_bot": false,
          "headline": "feat: Add Proxmox VE API client library for Go",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-08-20T03:15:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef4e687dd6fa391ea68b31ef7584c945c8ad5b61",
          "body": null,
          "is_bot": false,
          "headline": "Initial repository.",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-08-18T17:03:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 29,
      "commits_last_year": 67,
      "latest_release_at": "2026-07-20T12:55:18Z",
      "latest_release_tag": "v3.8.2",
      "releases_from_tags": true,
      "days_since_last_push": 10,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 10,
      "mean_days_between_releases": 3.1
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/fivetwenty-io/proxmox-apiclient-go/v3",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/fivetwenty-io/proxmox-apiclient-go/v3",
          "is_deprecated": false,
          "latest_version": "v3.8.2",
          "repository_url": "https://github.com/fivetwenty-io/proxmox-apiclient-go",
          "versions_count": 29,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T12:55:18Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 804668,
      "source_files_sampled": 192,
      "oversized_source_files": 16,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 7,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 4
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "wayneeseguin",
          "commits": 67,
          "avatar_url": "https://avatars.githubusercontent.com/u/18?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool detected: CodeQL",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "0f40c15f70a2f02e769200b257036e0d32f2a894",
        "ran_at": "2026-07-30T17:50:10Z",
        "aggregate_score": 5.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T12:56:26Z",
      "oldest_open_prs": [
        {
          "number": 1,
          "created_at": "2025-08-20T04:48:42Z",
          "last_comment_at": "2025-08-20T04:48:43Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 2,
          "created_at": "2025-08-20T04:49:41Z",
          "last_comment_at": "2025-08-20T04:49:41Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 4,
          "created_at": "2025-08-20T05:35:41Z",
          "last_comment_at": "2025-08-20T05:35:41Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 5,
          "created_at": "2025-08-20T05:35:44Z",
          "last_comment_at": "2025-08-20T05:35:44Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 7,
          "created_at": "2025-10-13T22:31:15Z",
          "last_comment_at": "2025-10-13T22:31:15Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 10,
          "created_at": "2025-12-08T22:24:44Z",
          "last_comment_at": "2025-12-08T22:24:44Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 11,
          "created_at": "2025-12-08T22:24:47Z",
          "last_comment_at": "2025-12-08T22:24:47Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/fivetwenty-io/proxmox-apiclient-go",
    "host": "github.com",
    "name": "proxmox-apiclient-go",
    "owner": "fivetwenty-io"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 58,
        "vitality": 73,
        "community": 22,
        "governance": 39,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 73,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "commits_last_year": 67,
              "human_commit_share": 1,
              "days_since_last_push": 10,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 10 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "67 commits in the last year",
                "points": 16.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 67
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 29,
              "latest_release_tag": "v3.8.2",
              "releases_from_tags": true,
              "days_since_latest_release": 10,
              "mean_days_between_releases": 3.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "29 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 10 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 10,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 10 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 22,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 39,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 4
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/4 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 4
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "fivetwenty-io",
              "public_repos": 23,
              "account_age_days": 1288
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of fivetwenty-io",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "fivetwenty-io"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "23 public repos, account ~3 yr old",
                "points": 17.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 23
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/fivetwenty-io/proxmox-apiclient-go/v3"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 10
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 10 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "29 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 58,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 5.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected: CodeQL",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 63,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.91,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "61 of 67 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 61,
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 67",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 95,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 804668,
              "source_files_sampled": 192,
              "oversized_source_files": 16
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "16/192 source files over 60KB",
                "points": 50.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 192,
                      "oversized": 16
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T17:50:15.107507Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/fivetwenty-io/proxmox-apiclient-go.svg",
  "full_name": "fivetwenty-io/proxmox-apiclient-go",
  "license_state": "absent",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаGo.