Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.31.0 · метрики 2.5.0 · 2026-08-05 08:53 UTC

github-community-projects / ospo-reusable-workflows

Centralized Reusable GitHub Actions

DockerfileMIT★ 21 зірка⑂ 3 форкиз груд. 2024 р.Переглянути на GitHub ↗

github-community-projects/ospo-reusable-workflows має індекс здоров’я 84 зі 100, що відповідає смузі «Відмінний». Найвищий показник — Vitality (94/100), найнижчий — AI Readiness (34/100). Останнє оновлення було 6 днів тому. Більшість нещодавньої роботи виконує один учасник.

84
загалом / 100
Відмінний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє зважене середнє, відкаліброване за розподілом публічного реєстру, тож діапазони мають перцентильний зміст; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 34 («У зоні ризику»).

84
Винятковий93-100Верхній щабель реєстру (≈ топ-5%); відповідає практично всім перевіреним критеріям
Відмінний80-92Сильний за всіма напрямами; незначні прогалини
Добрий65-79Здоровий; прогалини обмежені та керовані
Помірний50-64Прийнятний, але з помітними прогалинами; рекомендовано перевірку
Слабкий35-49Суттєві недоліки в кількох сферах
У зоні ризику20-34Суттєві слабкі місця; впровадження потребує обережності
Критичний1-19Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Зважений загальний бал 71 калібровано до 84 за шкалою опублікованого індексу (калібрування реєстру 2026-08-02).

Власність

GitHubОрганізація
102 підписники18 публічних репозиторіївз лист. 2023 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

94Винятковий · 21% загального індексу
Як обчислюється оцінка
36/36Свіжість push — останній push 6 дн. тому
26.3/36Ритм комітів — 38/52 тижнів із комітами
18/18Обсяг комітів — 113 комітів за останній рік
10/10OpenSSF Scorecard: Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Використані вхідні дані
commits_last_year113
human_commit_share0,34
days_since_last_push6
active_weeks_last_year38
Як обчислюється оцінка
27/27Випускає релізи — опубліковано 37 релізів
36/36Свіжість релізів — останній реліз 6 дн. тому
27/27Ритм релізів — реліз кожні ~14,8 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count37
latest_release_tagv1.2.3
releases_from_tagsні
days_since_latest_release6
mean_days_between_releases14,8
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

61Помірний · 17% загального індексу
Як обчислюється оцінка
21.1/60Зірки — 21 зірок
2.5/25Форки — 3 форків
10.6/15Спостерігачі — 83 спостерігачів
Використані вхідні дані
forks3
stars21
watchers83
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
18/18Настанови CONTRIBUTING
13.5/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
readme_badges0
has_contributingтак
has_issue_templateні
has_code_of_conductтак
readme_badge_services
has_pull_request_templateтак

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

54Помірний · 23% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
5/22.5Розподіл комітів — головний контриб’ютор — автор 78% комітів
4.1/13.5Широта контриб’юторів — 3 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 19 contributing companies or organizations
Використані вхідні дані
bus_factor1
contributors_sampled3
top_contributor_share0,776
Як обчислюється оцінка
25.2/42Вирішення issue — закрито 60% issue
28.3/30Прийняття PR — злито 136/144 вирішених PR
0/13Newcomer PR acceptance — за 30 дн. не вирішено жодного PR від новачка
15/15OpenSSF Scorecard: Code-Review — all changesets reviewed
Використані вхідні дані
merged_prs136
open_issues2
closed_issues3
prs_merged_7d1
prs_decided_7d1
prs_merged_30d2
prs_decided_30d3
issue_closed_ratio0,6
closed_unmerged_prs8
first_time_authors_30d0
first_time_prs_merged_30d0
first_time_prs_decided_30d0
Виключено з оцінювання (немає даних або не застосовно): newcomer_pr_acceptance. Залишкові ваги перенормовано.
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
14.5/25Охоплення власника — 102 підписників у github-community-projects
14.7/25Послужний список — 18 публічних репозиторіїв, вік облікового запису ~2 р.
Використані вхідні дані
followers102
owner_typeOrganization
is_verified
owner_logingithub-community-projects
public_repos18
account_age_days988

Інженерна якість

Чи наявні базові інженерні практики та документація?

72Добрий · 19% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 14 процес(ів) CI
0/24Наявні тести
16/16Конфігурація лінтера
9.6/9.6Pre-commit-хуки
0/6.4.editorconfig
20/20OpenSSF Scorecard: CI-Tests — 28 out of 28 merged PRs checked by a CI test -- score normalized to 10
Використані вхідні дані
has_ciтак
has_testsні
has_editorconfigні
has_linter_configтак
has_precommit_configтак
Як обчислюється оцінка
30/30README
25/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
10/10Теми — 4 тем
0/10Wiki
Використані вхідні дані
topicsauto-labeling, conventional-commits, github-actions, releases
has_wikiні
homepage
has_readmeтак
has_docs_dirтак
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

86Відмінний · 16% загального індексу

Стан безпеки

86Відмінний
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 28 out of 28 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 19 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — немає даних
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — немає даних
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate8,6
Виключено з оцінювання (немає даних або не застосовно): packaging, signed_releases. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Має свідомо малу вагу (4%): агентний інструментарій — реальний сигнал супроводу, але репозиторій без нього все одно може отримати 100/100.

34У зоні ризику · 4% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 34 з 34 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
0/22Автоматизовані тести
11/11Конфігурація лінтера / форматера
0/11Статична перевірка типів
10/10Відтворюване середовище — Dockerfile
4/10Підтверджена практика роботи з агентами — 2 з останніх 100 комітів створено агентом або з його зазначенням
8/8Автоматизоване супроводження — 66 з останніх 100 комітів — автоматичні оновлення залежностей
9/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
Використані вхідні дані
has_nixні
has_testsні
lockfiles
has_dockerfileтак
typed_languageні
bootstrap_files
has_devcontainerні
has_linter_configтак
typecheck_configs
agent_commit_share0,02
toolchain_manifests
dependency_bot_commit_share0,66
Як обчислюється оцінка
0/45Типізований код — Dockerfile без конфігурації перевірки типів
0/55Керовані розміри файлів — файлів вихідного коду не виявлено
Використані вхідні дані
primary_languageDockerfile
largest_source_bytes
source_files_sampled0
oversized_source_files0
Виключено з оцінювання (немає даних або не застосовно): Керовані розміри файлів. Залишкові ваги перенормовано.

Ключові факти

21зірок GitHub
3контриб'юторів
113комітів за останні 12 місяців
6днів від останнього пушу
37релізів
1бас-фактор
2відкритих issue
пакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

Докладніше

Історія зірок і форків 0 ★ / 3 ⇿
0Зірки
3Форки
15Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

12233312025-042025-122026-07
Мажорні 1Мінорні 4Патчі 10

Кожна точка охоплює 2 днів.

OpenSSF Scorecard 8.6 / 10
8.6сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-08-05 08:52 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests28 out of 28 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 19 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
н/дPackagingpackaging workflow not detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
н/дSigned-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Усі залежності 0

Повний розв'язаний набір залежностей із графа залежностей GitHub: 0 прямих і 0 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
Сповіщення про залежності не оцінено

Звірка сповіщень не відбулася для цього звіту: No resolved dependencies to assess

Звіт у форматі JSON машиночитний
{
  "data": {
    "icon": {
      "bytes": 6675,
      "width": 200,
      "height": 200,
      "rejected": [],
      "collected": true,
      "media_type": "image/png",
      "source_url": "https://avatars.githubusercontent.com/u/151565802?v=4&s=256",
      "source_type": "avatar",
      "content_hash": "e11f9840f56122d183881c97480cd882ebe2ca972166d36e21fe578bea05e011",
      "candidates_considered": 1
    },
    "repo": {
      "topics": [
        "auto-labeling",
        "conventional-commits",
        "github-actions",
        "releases"
      ],
      "is_fork": false,
      "size_kb": 305,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Dockerfile": 255
      },
      "pushed_at": "2026-07-30T04:26:34Z",
      "created_at": "2024-12-22T00:04:05Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-30T04:26:44Z",
      "description": "Centralized Reusable GitHub Actions",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Dockerfile",
      "significant_languages": [
        "Dockerfile"
      ]
    },
    "owner": {
      "blog": null,
      "name": "GitHub",
      "type": "Organization",
      "login": "github-community-projects",
      "company": null,
      "location": null,
      "followers": 102,
      "avatar_url": "https://avatars.githubusercontent.com/u/151565802?v=4",
      "created_at": "2023-11-20T18:08:56Z",
      "is_verified": null,
      "public_repos": 18,
      "account_age_days": 988
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.2.3",
          "kind": "patch",
          "published_at": "2026-07-29T22:22:52Z"
        },
        {
          "tag": "v1.2.2",
          "kind": "patch",
          "published_at": "2026-07-08T18:56:43Z"
        },
        {
          "tag": "v1.2.1",
          "kind": "patch",
          "published_at": "2026-06-22T21:23:13Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2026-06-22T21:06:09Z"
        },
        {
          "tag": "v1.1.0",
          "kind": "minor",
          "published_at": "2026-05-28T00:28:45Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-05-11T00:53:07Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-05-10T22:56:30Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-05-08T15:56:32Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-20T18:14:29Z"
        },
        {
          "tag": "v0.5.8",
          "kind": "patch",
          "published_at": "2026-03-19T02:28:55Z"
        },
        {
          "tag": "v0.5.7",
          "kind": "patch",
          "published_at": "2026-03-17T03:44:08Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-03-15T23:00:50Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2025-12-16T03:46:58Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2025-09-18T04:47:25Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2025-08-20T14:01:45Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2025-08-05T15:10:58Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2025-05-30T14:05:57Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2025-04-07T23:38:46Z"
        },
        {
          "tag": "v0.4.6",
          "kind": "patch",
          "published_at": "2025-02-20T04:22:57Z"
        },
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2025-01-25T17:13:31Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2025-01-25T16:39:00Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2025-01-25T16:14:27Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2025-01-25T09:11:04Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2025-01-25T05:50:49Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2025-01-25T05:32:36Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2025-01-21T18:53:46Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2025-01-11T07:19:08Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2025-01-05T07:44:22Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2025-01-04T17:40:37Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2025-01-03T16:02:18Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2025-01-03T05:18:50Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2025-01-03T05:07:12Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2025-01-03T04:55:01Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2025-01-03T04:41:44Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2025-01-03T04:16:58Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2025-01-03T04:07:05Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2025-01-03T03:57:34Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "25891ed12c80c983b2f3b3c335ed8e560d7baea9",
          "body": "Bumps the dependencies group with 3 updates: [release-drafter/release-drafter/autolabeler](https://github.com/release-drafter/release-drafter), [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) and [docker/login-action](https://github.com/docker/login-action).\n\n\nU\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 3 updates (#178)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-30T04:26:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13d124b245cf85ba41d9dd58d6888979043f1a29",
          "body": "The auto-author-assign and mark-ready-when-ready workflows trigger on\npull_request, so PRs from forks get a read-only GITHUB_TOKEN and both jobs\nfail (assignees API denied; contents: write denied). Switch both to\npull_request_target, which runs in the base-repo context with a read-write\ntoken even f\n[…]\nhether pull_request_target is acceptable here versus gating the jobs to skip\non fork PRs (which would drop the feature for external contributors instead).\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix(ci): run PR automation via pull_request_target for fork PRs (#169)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-07-29T22:21:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9167ef4833a9f2712399652e0a1f7168a5897463",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action in the dependencies group (#176)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-29T02:49:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d564618b70368ea3e321283503cd7086a1e521a6",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump actions/stale from 10.4.0 to 11.0.0 (#177)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-29T02:48:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29ff622bc9bede4aa4d3ae7f2203b4b394e5f392",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action in the dependencies group (#175)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-25T02:46:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ce7494f4e7469c13ff7b29f65c010003d06b6cd",
          "body": "Bumps the dependencies group with 1 update: [docker/login-action](https://github.com/docker/login-action).\n\n\nUpdates `docker/login-action` from 4.4.0 to 4.5.0\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/af1e73f918a0318\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action in the dependencies group (#174)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T10:23:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6e342b2069ea1d3245b64478c949cabdaf14220",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump actions/labeler from 6.2.0 to 7.0.0 (#173)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T05:33:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f12589199fc0d574eb13366a89c73ed698cd39b8",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 3 updates (#172)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T02:51:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea261f1242b9d48164608e461718922a401809cb",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#171)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-17T02:46:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf25712671a0238b43ec91870a6d60228048d480",
          "body": "Bumps the dependencies group with 2 updates: [actions/labeler](https://github.com/actions/labeler) and [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `actions/labeler` from 6.1.0 to 6.2.0\n- [Release notes](https://github.com/actions/labeler/releases)\n- [Commits](https://github.com/acti\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 2 updates (#170)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-11T03:42:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5193129233b450e9174d4d92fcc467919a989882",
          "body": "…al (#168)",
          "is_bot": false,
          "headline": "fix(release): pin checkout ref to base repo to avoid v7 fork-PR refus…",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-07-08T18:55:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d05a9107745320f48d352810644eada6bbe6e1b",
          "body": "…up (#166)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.19.4 to 2.20.0\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T06:09:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "438f71098c47cda9d7a83895f997e6947cbcd9b9",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action in the dependencies group (#165)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-04T03:06:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11dd5e835679982ef1f2b2b04256755cc91b4961",
          "body": "Bumps the dependencies group with 2 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [docker/login-action](https://github.com/docker/login-action).\n\n\nUpdates `docker/setup-buildx-action` from 4.1.0 to 4.2.0\n- [Release notes](https://github.com/docker/setup-bui\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 2 updates (#164)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-03T16:22:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "058dbc6e260e823971cdc8d7b7533b5518ee54a2",
          "body": "…(#163)\n\nBumps the dependencies group with 1 update: [docker/build-push-action](https://github.com/docker/build-push-action).\n\n\nUpdates `docker/build-push-action` from 7.2.0 to 7.3.0\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-p\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/build-push-action in the dependencies group …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-02T13:46:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f5f55a6cf269378ff2db64c80f4515a52e4917b",
          "body": "…oup (#162)\n\nBumps the dependencies group with 1 update: [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `goreleaser/goreleaser-action` from 7.2.2 to 7.2.3\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://githu\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action in the dependencies gr…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T03:15:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e04ca4c5ab93b9ab04d33c256bfa1f4ccdfdc80f",
          "body": "Bumps the dependencies group with 1 update: [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance).\n\n\nUpdates `actions/attest-build-provenance` from 4.1.0 to 4.1.1\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://gith\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/attest-build-provenance (#161)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-27T03:00:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47b31ad408ed26da05cccde562815d7c1eacf587",
          "body": "Bumps the dependencies group with 2 updates: [release-drafter/release-drafter/autolabeler](https://github.com/release-drafter/release-drafter) and [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter/autolabeler` from 7.4.0\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 2 updates (#160)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-26T03:12:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "982bcd8e7cf04eda77f1a65418950ea664a3d525",
          "body": "…hub_actions/dependencies-9b7bde0b82\n\nchore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 in the dependencies group",
          "is_bot": false,
          "headline": "Merge pull request #159 from github-community-projects/dependabot/git…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-06-25T05:27:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c64e60bdd6ba2e5680ee110b3374cbe4de6cd655",
          "body": "Bumps the dependencies group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.4.0 to 6.5.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e\n[…]\ngo\n  dependency-version: 6.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go in the dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-25T02:44:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7fc8753b3666b929250bb6241ce4b2d35f316a11",
          "body": "…158)\n\n## What/Why\n\nThe old GitHub Actions `contains()` expression was case-insensitive, but\nthe bash replacement introduced in #156 compared labels case-sensitively.\nLowercase labels with `${PR_LABELS,,}` to preserve the original semantics.\n\n## Proof it works\n\nactionlint and shellcheck both pass wi\n[…]\n one-liner fix. AI-assisted (Claude Opus 4.6).\n\n## Review focus\n\nConfirm `${PR_LABELS,,}` (bash 4+ lowercase expansion) works on the\nubuntu-latest runner.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix(release): use case-insensitive label matching in check_release (#…",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-06-22T21:21:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc84e76ecffde328292b1774abd14e783726f493",
          "body": "Bumps alpine from 3.24.0 to 3.24.1.\n\n---\nupdated-dependencies:\n- dependency-name: alpine\n  dependency-version: 3.24.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump alpine from 3.24.0 to 3.24.1 (#157)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T21:06:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f7adbde142b474add23fb65218dbb9e0d8e18f1",
          "body": "* feat(release): add release-only-with-label input\n\n## What/Why\n\nAdd a `release-only-with-label` boolean input to the release workflow so\nconsumers can restrict release triggers to only the `release` label,\nignoring `breaking`, `feature`, and `vuln` as triggers. Defaults to\n`false` to preserve exist\n[…]\nh label-matching logic in check_release matches the\nprevious GitHub Actions expression semantics.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>\n\n---------\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "feat(release): add release-only-with-label input (#156)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-06-22T21:04:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1af8482927f03f93d0858464a5a3b4471891f18d",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#155)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-19T03:36:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adb45eec06f1efa6d68fb3e84ea51f2bd16f7ed7",
          "body": "…hub_actions/dependencies-24b7a65592\n\nchore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 in the dependencies group",
          "is_bot": false,
          "headline": "Merge pull request #154 from github-community-projects/dependabot/git…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-06-17T05:16:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba6090c037408a398e2386637cda2b75afbeb685",
          "body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 7.3.1 to 7.4.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n  dependency-version: 7.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-17T02:44:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "944d6ea41e46d658f24ee69696eae11c69b0845d",
          "body": "…oup (#153)\n\nBumps the dependencies group with 1 update: [toshimaru/auto-author-assign](https://github.com/toshimaru/auto-author-assign).\n\n\nUpdates `toshimaru/auto-author-assign` from 3.0.2 to 3.0.3\n- [Release notes](https://github.com/toshimaru/auto-author-assign/releases)\n- [Changelog](https://git\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-16T11:43:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "02af89f34ffe961746cf541e4591d2f963ed4c80",
          "body": "…oup (#152)\n\nBumps the dependencies group with 1 update: alpine.\n\n\nUpdates `alpine` from 3.23.4 to 3.24.0\n\n---\nupdated-dependencies:\n- dependency-name: alpine\n  dependency-version: 3.24.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump alpine from 3.23.4 to 3.24.0 in the dependencies gr…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-15T21:00:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac95e33e92f631a5c5d4eb102ca1a959c187844d",
          "body": "Bumps the dependencies group with 1 update: [mikefarah/yq](https://github.com/mikefarah/yq).\n\n\nUpdates `mikefarah/yq` from 4.53.2 to 4.53.3\n- [Release notes](https://github.com/mikefarah/yq/releases)\n- [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt)\n- [Commits](https://git\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump mikefarah/yq in the dependencies group (#151)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-09T06:54:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "615f069ab92e5489691e2f41735a36f383753bfb",
          "body": "Bumps the dependencies group with 1 update: [actions/checkout](https://github.com/actions/checkout).\n\n\nUpdates `actions/checkout` from 6.0.2 to 6.0.3\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout in the dependencies group (#150)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T23:12:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "12d9407a7c8903499cbd1dcf91d20bd4faa2eb2e",
          "body": "…up (#148)",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-28T04:13:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d7a83e6fc8275128984b0ed3defa4b8cdc40f85",
          "body": "* feat(release): add SBOM-to-archive attestation linkage\n\n## What\n\nAdd a new `attest_sboms` matrix job that runs `actions/attest-sbom` per\n(archive, SBOM) pair after `release_goreleaser` produces artifacts.\nExpose `sbom_matrix` and `is_public` as outputs from `release_goreleaser`,\nupload `dist/` as \n[…]\noff-by: Jason Meridth <jmeridth@gmail.com>\n\n---------\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>\nSigned-off-by: Jason Meridth <jmeridth@gmail.com>\nCo-authored-by: Zack Koppert <zkoppert@github.com>",
          "is_bot": false,
          "headline": "feat(release): add SBOM-to-archive attestation linkage (#141)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-05-28T00:27:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50ddb991a26ceb4cc84e344efae73edd78a472eb",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter (#147)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T09:53:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf3675aa51a735662ad365889795a7d6b1af1f28",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump alpine from 3.23.3 to 3.23.4 (#146)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-24T22:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a6c89b8f8bdf240e7cfa0e2c03313761acb93ff",
          "body": "…dates (#145)",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group across 1 directory with 4 up…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-23T21:01:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bacd386ee8af27b7185b4ebbae51bc7172cb9353",
          "body": "Bumps the dependencies group with 1 update: [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `actions/stale` from 10.2.0 to 10.3.0\n- [Release notes](https://github.com/actions/stale/releases)\n- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)\n- [Commits](https://githu\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/stale in the dependencies group (#143)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-21T19:18:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0baf7384e0dad7158b50c0e2a9024895147001db",
          "body": "Bumps the dependencies group with 2 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner) and [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `step-security/harden-runner` from 2.19.2 to 2.19.3\n- [Release notes](https://gith\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 2 updates (#142)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-19T21:01:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "08173095a682519c9f66a28222ba4534b1821303",
          "body": "…up (#140)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.19.1 to 2.19.2\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T22:55:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7fa297f22ebc26182bb0af24619d4db53d69eaa",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 3 updates (#139)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-12T09:24:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e92cb6053ace495fe40a5f185988557afcdcecbc",
          "body": "… (#138)\n\n* fix(release): create discussion only after publish succeeds\n\n## What\n\nMove the release_discussion job to run after publish_release succeeds instead of in parallel with the build jobs. The publish_release job no longer depends on release_discussion.\n\n## Why\n\nPreviously, the discussion was\n[…]\n` remains `false`, so scope is still optional; this only widens the allowed set when one is used.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>\n\n---------\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix(ci): order discussion after publish + auto-install syft for SBOMs…",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-05-11T00:51:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "592067a69a43d2285f933753d89a7c9d51b96530",
          "body": "## What\n\nCollapse the three separate release workflows (release.yaml, release-image.yaml, release-discussion.yaml) into a single release.yaml reusable workflow using a draft-first pattern: create draft, push tags, build artifacts (optional GoReleaser, optional Docker image), create discussion, then \n[…]\nevel if secrets are missing (job-level if: cannot read secrets).\n- publish_release uses -F draft=false (capital F) to send a boolean rather than a string.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "refactor: consolidate release pipeline with draft-first pattern (#124)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-05-10T22:55:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84f2a3cc902bb62f5e751f74ea4f03f5628f23b0",
          "body": "…hub_actions/dependencies-ce6d608e45\n\nchore(deps): bump release-drafter/release-drafter from 7.2.1 to 7.3.0 in the dependencies group",
          "is_bot": false,
          "headline": "Merge pull request #137 from github-community-projects/dependabot/git…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-05-09T21:15:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60e51a56cb66a793a5a50c8008db91516023a13c",
          "body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 7.2.1 to 7.3.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n  dependency-version: 7.3.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-09T02:42:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "51be22c58e3d4b33b4fbdc1dcf257c481695ce36",
          "body": "…fter_breaking\n\nfeat(ci): add Breaking Changes category",
          "is_bot": false,
          "headline": "Merge pull request #134 from github-community-projects/jm_release_dra…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-05-08T15:56:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12a913b6a85adf454f5fdea92f9aa9c383342017",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump kenyonj/mark-ready-when-ready (#135)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-08T03:21:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5220699f20641a32c1d969839425904b5cecf90f",
          "body": "## What\n\nAdd a new \"💥 Breaking Changes\" category to the release-drafter template, ordered first so it sits above Features. The category collects PRs labeled `breaking`.\n\n## Why\n\nThe `breaking` label already drives a major version bump via version-resolver, but breaking changes were silently bucketed\n[…]\n PR carrying both `breaking` and `feature` labels will appear under Breaking Changes only (release-drafter places each PR in the first matching category).\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "feat(release-drafter): add Breaking Changes category",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-05-07T22:23:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "54923ceee831514b3558d4acefcdfaaf25fe8f62",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump actions/labeler in the dependencies group (#133)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T07:11:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42d143b55b5738da0d146df949b6e2bfcf2535c8",
          "body": "…up (#132)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.19.0 to 2.19.1\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-05T09:46:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb615e677fd3976abafddfbcaad2fa74fe795785",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter (#131)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-30T07:24:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d6b72fc61d52102d4da439085f89361c8e90864",
          "body": "…oup (#130)",
          "is_bot": true,
          "headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-28T10:10:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54dd5deed5930485bf9ca925a3f81e72d59b7cfe",
          "body": "…up (#129)",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-21T02:48:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5badafa2b710edcdc8616819f9ae2a1edb69260",
          "body": "…up (#128)",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-16T03:14:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "353391961adcad1270aa655d549fdf57d68a48df",
          "body": "…(#127)",
          "is_bot": true,
          "headline": "chore(deps): bump docker/build-push-action in the dependencies group …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-11T02:43:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad222460db38d66d512c6f5c51218c0b3d8466d2",
          "body": "Bumps the dependencies group with 2 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner) and [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `step-security/harden-runner` from 2.16.1 to 2.17.0\n- [Release notes](https:\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group with 2 updates (#126)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-10T03:44:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "465a8648d16d710aab3e224ea0eb5fca579e6e4b",
          "body": "Bumps [kenyonj/mark-ready-when-ready](https://github.com/kenyonj/mark-ready-when-ready) from b6279addd55dd13208965a9eff24b2cf1989a8ef to 0ef6176fc2ddef5bab6cb4ab9517a37f0c153ba4.\n- [Release notes](https://github.com/kenyonj/mark-ready-when-ready/releases)\n- [Commits](https://github.com/kenyonj/mark-\n[…]\n6cb4ab9517a37f0c153ba4\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump kenyonj/mark-ready-when-ready (#125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-08T02:58:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f5dcee1eb036b788c9773f863b255cc7da1910b",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action in the dependencies group (#123)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-03T03:10:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fb884f8eb6fe77f9b59d5fcb6bb3487c918f309",
          "body": "…up (#122)",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T02:47:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0cf79bd8756e0a9c1555bf4975eae7ce7a8e8dc",
          "body": "…on_updater\n\nfeat: add automatic major version tag update to release workflow",
          "is_bot": false,
          "headline": "Merge pull request #120 from github-community-projects/jm_major_versi…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-20T18:14:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2ce2ae3707aec01dd31e1c98dd565d03b385585c",
          "body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "doc: update release doc with new update-major-tag input",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-20T03:27:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1e8f0827f6d22df7a230b6de2bce7ed7e0be69c",
          "body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix: cleanup of old major-version-updater",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-20T03:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bc46d499c518406c22e58ac9b61a05c0b654985",
          "body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix: persist credentials so username can be found on git push",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-20T02:46:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1360e492f68a14c8c3d06569a6c755ef896fc2f2",
          "body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix: add claude local settings to gitignore",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-20T02:31:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "389119e175b13aa57e1d6f7587086799ba42d53a",
          "body": "## What\n\nAdded an `update_major_tag` job to the reusable release workflow that\nforce-updates the major version tag (e.g., `v1`) to point at the latest\nfull semver tag (e.g., `v1.2.3`) after each release. This is controlled\nby a new `update-major-tag` boolean input that defaults to `true`.\n\n## Why\n\nC\n[…]\n.yaml` workflow\n- The calling workflow must have `contents: write` permission for the force-push to succeed (already required by the `create_release` job)\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "feat: add automatic major version tag update to release workflow",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-20T02:28:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "469b195f0864a07e52dbf33dd5a145fccf5058c0",
          "body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 7.1.0 to 7.1.1\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\nersion-update:semver-patch\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter (#119)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-19T02:50:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d90c7aff008ad7aa4a87b1e23849a5a8691e356",
          "body": "… (#117)",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter from 6.4.0 to 7.1.0…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-18T11:39:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed4846f2be1a6bcca82dd1a5f8e8d176fb4e19ea",
          "body": "Bumps [kenyonj/mark-ready-when-ready](https://github.com/kenyonj/mark-ready-when-ready) from 33b13c51ba23786efb933701ef253352baf05bdd to b6279addd55dd13208965a9eff24b2cf1989a8ef.\n- [Release notes](https://github.com/kenyonj/mark-ready-when-ready/releases)\n- [Commits](https://github.com/kenyonj/mark-\n[…]\n965a9eff24b2cf1989a8ef\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump kenyonj/mark-ready-when-ready (#114)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-17T04:01:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4300b59f723a568597c68ec332b1b0174cea7f1",
          "body": "…up (#113)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.15.1 to 2.16.0\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-17T03:58:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6381f5d691a1ecf7d80126b0393a803224afd9ba",
          "body": "## What\n\nReverted the auto-labeler workflow from the release-drafter v7 autolabeler\nsub-action back to the v6.4.0 main action with disable-releaser: true.\n\n## Why\n\nThe v7 autolabeler sub-action hardcodes a strict check for the pull_request\nevent and rejects pull_request_target. Since this reusable w\n[…]\norkflow; only the autolabeler is pinned to v6\n- Consider opening an upstream issue on release-drafter to support pull_request_target in the v7 autolabeler\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix: revert autolabeler to release-drafter v6.4.0 (#115)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-17T03:43:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30db3296210fe74bc1214e5710f8db5ac6d3a1ad",
          "body": "… (#109)\n\n* chore(deps): bump release-drafter/release-drafter from 6.4.0 to 7.0.0\n\nBumps [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) from 6.4.0 to 7.0.0.\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://githu\n[…]\nbot] <support@github.com>\nSigned-off-by: jmeridth <jmeridth@gmail.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter from 6.4.0 to 7.0.0…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-15T23:00:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23927bfee44244f3242122814e8e5ac070dc6670",
          "body": null,
          "is_bot": false,
          "headline": "ci: harden CI runners and pin actions to SHA digests (#110)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-14T11:24:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c8d3bdec034700ad7c4d91de7955c087bf94011",
          "body": "…when_ready\n\nci: add mark-ready-when-ready workflow",
          "is_bot": false,
          "headline": "Merge pull request #108 from github-community-projects/jm_mark_ready_…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-13T22:06:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ac5bac210100ae8effcf870ddc75d7caf6e229f",
          "body": "## Summary\n\nAdds the [mark-ready-when-ready](https://github.com/kenyonj/mark-ready-when-ready) GitHub Action workflow.\n\nWhen a draft PR has the **Mark Ready When Ready** label applied, this workflow:\n1. Watches for all required checks to pass (two rounds with a pause between)\n2. Verifies results via\n[…]\nA `33b13c5` (includes `contents: write` permission fix)\n- Requires `contents: write` permission for `GITHUB_TOKEN` to call `markPullRequestReadyForReview`\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "ci: add mark-ready-when-ready workflow",
          "author_name": "jmeridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-13T21:46:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c5f863d5f9c249ed39e253e857791d6c6e5bad4",
          "body": null,
          "is_bot": false,
          "headline": "chore: clean up CI config, contributing docs, and PR template (#107)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2026-03-11T07:16:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a0a6feb06180b88c25525cda612f44931ca5dc2",
          "body": "Pin alpine base image to alpine:3.23.3 with SHA256 digest to ensure\nreproducible and secure builds, resolving code scanning alert #3.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix: pin Docker base image to SHA256 digest (#106)",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-10T19:42:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "850f161539b6c770012adc3a703a6ae3d812ae7c",
          "body": "…cts (#105)\n\n* build: update references after org transfer to github-community-projects\n\n- Replace all github/ospo-reusable-workflows refs with\n  github-community-projects/ospo-reusable-workflows across 10 files\n- Update CODEOWNERS from @github/ospo-github-actions to @zkoppert @jmeridth\n- Fix CONTRI\n[…]\n@gmail.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Jason Meridth <jmeridth@gmail.com>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "build: update references after org transfer to github-community-proje…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-10T19:41:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "df5b322d04d2bd507ad44a770744b2357abd2954",
          "body": "…ncies-9732075219\n\nchore(deps): bump release-drafter/release-drafter from 6.3.0 to 6.4.0 in the dependencies group",
          "is_bot": false,
          "headline": "Merge pull request #104 from github/dependabot/github_actions/depende…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-10T04:34:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0459ffd7ebe6ae8e66f1f014363a5e5086e6f8f8",
          "body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 6.3.0 to 6.4.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n  dependency-version: 6.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-10T02:44:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4207841bec4e1e360a791af5f8f90e7ff8fa28dd",
          "body": "…ncies-a2c0030222\n\nchore(deps): bump release-drafter/release-drafter from 6.2.0 to 6.3.0 in the dependencies group",
          "is_bot": false,
          "headline": "Merge pull request #102 from github/dependabot/github_actions/depende…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-07T06:17:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cd4071ba59fb1d538d5094298ec241fd0975c73",
          "body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 6.2.0 to 6.3.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n  dependency-version: 6.3.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump release-drafter/release-drafter",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-07T03:42:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f06feadec8e069088ed5298caaca32b23de04bc6",
          "body": "…build-push-action-7.0.0\n\nchore(deps): bump docker/build-push-action from 6.19.2 to 7.0.0",
          "is_bot": false,
          "headline": "Merge pull request #100 from github/dependabot/github_actions/docker/…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-06T04:55:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b189cdce3822d90b8ce86e7d7e194932932265ad",
          "body": "…setup-buildx-action-4.0.0\n\nchore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0",
          "is_bot": false,
          "headline": "Merge pull request #101 from github/dependabot/github_actions/docker/…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-06T04:55:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9a1c60d82702d0ee7f8fbee5ab8f512623a60a9",
          "body": "Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.12.0 to 4.0.0.\n- [Release notes](https://github.com/docker/setup-buildx-action/releases)\n- [Commits](https://github.com/docker/setup-buildx-action/compare/8d2750c68a42422c14e847fe6c8ac0403b4cbd6f...4d04d5d9486b7\n[…]\ncy-name: docker/setup-buildx-action\n  dependency-version: 4.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-06T03:44:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3465916cecbab84d730364fc2018af804b402759",
          "body": "Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6.19.2 to 7.0.0.\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-push-action/compare/10e90e3645eae34f1e60eeb005ba3a3d33f178e8...d08e5c354a6adb9ed3448\n[…]\nency-name: docker/build-push-action\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/build-push-action from 6.19.2 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-06T03:44:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "65fc946a71a872575cc356aa0ad44d4064654363",
          "body": "…ogin-action-4.0.0\n\nchore(deps): bump docker/login-action from 3.7.0 to 4.0.0",
          "is_bot": false,
          "headline": "Merge pull request #99 from github/dependabot/github_actions/docker/l…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-03-05T19:01:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d08d18fc2a456c284065ab158d989fb3b0c5164f",
          "body": "Bumps [docker/login-action](https://github.com/docker/login-action) from 3.7.0 to 4.0.0.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...b45d80f862d83dbcd57f89517bcf500b2ab88fb2)\n\n[…]\nependency-name: docker/login-action\n  dependency-version: 4.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action from 3.7.0 to 4.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-05T03:44:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a53fd45227459b1584ce1cf28b1274dc2cb0a02e",
          "body": "…attest-build-provenance-4",
          "is_bot": false,
          "headline": "Merge pull request #98 from github/dependabot/github_actions/actions/…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-02-26T03:47:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "049d938ca31f362f54afdf303e30ab7e8442cc35",
          "body": "Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4.\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)\n- [Commits](https://github.co\n[…]\nname: actions/attest-build-provenance\n  dependency-version: '4'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/attest-build-provenance from 3 to 4",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-26T03:43:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1787f300d56450330861a36a8dd50efa11971183",
          "body": "…cies-ff3cf51067",
          "is_bot": false,
          "headline": "Merge pull request #97 from github/dependabot/github_actions/dependen…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-02-21T04:22:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cf1a5043bf8b4b956fef4f473554ff20357ad66",
          "body": "…dates\n\nBumps the dependencies group with 2 updates in the / directory: [docker/build-push-action](https://github.com/docker/build-push-action) and [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `docker/build-push-action` from 6.18.0 to 6.19.2\n- [Release notes](https://github.com/docke\n[…]\ne\n  dependency-version: 10.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group across 1 directory with 2 up…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-17T03:44:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c74366e5337d8e3518925c227640d92f30f24c8",
          "body": "…cies-7ed0a7b455\n\nchore(deps): bump the dependencies group across 1 directory with 2 updates",
          "is_bot": false,
          "headline": "Merge pull request #95 from github/dependabot/github_actions/dependen…",
          "author_name": "Zack Koppert",
          "author_login": "zkoppert",
          "committed_at": "2026-02-02T19:54:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd0de19ae95833b9d0b5b777a675a1ab29cd4954",
          "body": "…dates\n\nBumps the dependencies group with 2 updates in the / directory: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) and [docker/login-action](https://github.com/docker/login-action).\n\n\nUpdates `release-drafter/release-drafter` from 6.1.0 to 6.2.0\n- [Release \n[…]\non\n  dependency-version: 3.7.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump the dependencies group across 1 directory with 2 up…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-01-29T03:43:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "425eb4597e2ee48576ee11b6a0eb0bf630d7d63d",
          "body": "…oup (#93)",
          "is_bot": true,
          "headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-28T15:46:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be95309923487509f8df484b932560dac1cf0788",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump toshimaru/auto-author-assign from 2.1.2 to 3.0.0 (#92)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-23T10:20:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7e692137c777843c975004facd93934e37a14c1",
          "body": "…p (#91)",
          "is_bot": true,
          "headline": "chore(deps): bump docker/setup-buildx-action in the dependencies grou…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-20T11:55:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b691dff6b68489c8548e1295d125c93c9c29a4e",
          "body": "…oup (#89)",
          "is_bot": true,
          "headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-16T03:46:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "326810ccf68e02946fa8b51141900ce0fccbd59d",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump actions/stale in the dependencies group (#88)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-04T03:40:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f93c1cab84c95a516e5a836323471c70ae1360a",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 5 to 6 (#87)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-24T13:45:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f81b19525b174210351d8c53b2efe6a316984f8",
          "body": "Bumps the dependencies group with 1 update: [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `actions/stale` from 10.0.0 to 10.1.0\n- [Release notes](https://github.com/actions/stale/releases)\n- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)\n- [Commits](https://githu\n[…]\nersion-update:semver-minor\n  dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/stale in the dependencies group (#85)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-04T02:06:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fbfe59323885c0e09c606d14ec8d49496d838f3a",
          "body": null,
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action in the dependencies group (#84)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-30T05:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26eec20abba5ae806698592c79628f6906da372c",
          "body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
          "is_bot": false,
          "headline": "fix: releases when release label by itself without semver label (#81)",
          "author_name": "Jason Meridth",
          "author_login": "jmeridth",
          "committed_at": "2025-09-18T04:47:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 37,
      "commits_last_year": 113,
      "latest_release_at": "2026-07-29T22:22:52Z",
      "latest_release_tag": "v1.2.3",
      "releases_from_tags": false,
      "days_since_last_push": 6,
      "active_weeks_last_year": 38,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 14.8
    },
    "artifacts": {
      "collected": true,
      "structure": [
        "tree.dockerfile"
      ],
      "declarations": []
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "readme_badges": {
        "hosts": [],
        "total": 0,
        "header": 0,
        "collected": true,
        "has_inspect_badge": false
      },
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 3,
      "stars": 21,
      "watchers": 83,
      "fork_history": {
        "days": [
          {
            "date": "2025-04-28",
            "count": 1
          },
          {
            "date": "2025-08-25",
            "count": 1
          },
          {
            "date": "2026-07-08",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 3,
        "total_forks": 3
      },
      "star_history": null,
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": null,
      "source_files_sampled": 0,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": "No resolved dependencies to assess",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [],
        "collected": true,
        "truncated": false,
        "total_count": 0,
        "direct_count": 0,
        "indirect_count": 0
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 136,
        "open_issues": 2,
        "closed_ratio": 0.6,
        "closed_issues": 3,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "jmeridth",
          "commits": 66,
          "avatar_url": "https://avatars.githubusercontent.com/u/35014?v=4"
        },
        {
          "type": "User",
          "login": "zkoppert",
          "commits": 18,
          "avatar_url": "https://avatars.githubusercontent.com/u/6935431?v=4"
        },
        {
          "type": "User",
          "login": "ahpook",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/56753?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.776
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "actionlint.yaml",
        "auto-author-assign.yaml",
        "auto-labeler.yaml",
        "labeler.yaml",
        "mark-ready-when-ready.yml",
        "pr-title.yaml",
        "release-discussion.yaml",
        "release-image.yaml",
        "release.yaml",
        "stale.yaml",
        "test-auto-labeler.yaml",
        "test-labeler.yaml",
        "test-pr-title.yaml",
        "test-release.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "28 out of 28 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 19 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "25891ed12c80c983b2f3b3c335ed8e560d7baea9",
        "ran_at": "2026-08-05T08:52:45Z",
        "aggregate_score": 8.6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "recent_prs": {
        "merged_7d": 1,
        "decided_7d": 1,
        "merged_30d": 2,
        "authors_30d": 1,
        "decided_30d": 3,
        "sample_size": 60,
        "window_days": 30,
        "sample_exhausted": false,
        "authors_probed_30d": 1,
        "newcomer_merged_30d": 0,
        "bot_prs_excluded_30d": 10,
        "newcomer_authors_30d": 0,
        "newcomer_decided_30d": 0
      },
      "ci_last_run_at": "2026-08-05T02:45:54Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-30T04:26:32Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 70,
          "created_at": "2025-08-20T22:34:16Z",
          "last_comment_at": "2025-09-11T02:03:01Z",
          "last_comment_author": "github-actions"
        },
        {
          "number": 149,
          "created_at": "2026-06-02T11:07:39Z",
          "last_comment_at": "2026-07-07T13:59:19Z",
          "last_comment_author": "jmeridth"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/github-community-projects/ospo-reusable-workflows",
    "host": "github.com",
    "name": "ospo-reusable-workflows",
    "owner": "github-community-projects"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "excellent",
      "name": "Overall health",
      "note": "The weighted overall 71 is calibrated to 84 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 71,
            "calibrated": 84,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 84,
      "inputs": {
        "security": 86,
        "vitality": 94,
        "community": 61,
        "governance": 54,
        "calibration": "2026-08-02",
        "engineering": 72,
        "ai_readiness": 34,
        "weighted_overall_raw": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "exceptional",
        "name": "Vitality",
        "value": 94,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "commits_last_year": 113,
              "human_commit_share": 0.34,
              "days_since_last_push": 6,
              "active_weeks_last_year": 38
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "38/52 weeks with commits",
                "points": 26.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 38
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "113 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 113
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 37,
              "latest_release_tag": "v1.2.3",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 14.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "37 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 37
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~14.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 14.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 6,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 6 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 61,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "forks": 3,
              "stars": 21,
              "watchers": 83,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "21 stars",
                "points": 21.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "3 forks",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "83 watchers",
                "points": 10.6,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 83
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": 0,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 28,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.776
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 78% of commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 78
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 19 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 79,
            "inputs": {
              "merged_prs": 136,
              "open_issues": 2,
              "closed_issues": 3,
              "prs_merged_7d": 1,
              "prs_decided_7d": 1,
              "prs_merged_30d": 2,
              "prs_decided_30d": 3,
              "issue_closed_ratio": 0.6,
              "closed_unmerged_prs": 8,
              "first_time_authors_30d": 0,
              "first_time_prs_merged_30d": 0,
              "first_time_prs_decided_30d": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "60% of issues closed",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 60
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "136/144 decided PRs merged",
                "points": 28.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 136,
                      "decided": 144
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 59,
            "inputs": {
              "followers": 102,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "github-community-projects",
              "public_repos": 18,
              "account_age_days": 988
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "102 followers of github-community-projects",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 102,
                      "login": "github-community-projects"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "18 public repos, account ~2 yr old",
                "points": 14.7,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 18
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "14 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "28 out of 28 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "auto-labeling",
                "conventional-commits",
                "github-actions",
                "releases"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "excellent",
        "name": "Security",
        "value": 86,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "excellent",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 86,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 8.6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "28 out of 28 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 19 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 12
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 34,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "34 of 34 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 34,
                      "sampled": 34
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "weak",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.66
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "66 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 66,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "critical",
            "name": "Code legibility for models",
            "note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "manageable_file_sizes"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "primary_language": "Dockerfile",
              "largest_source_bytes": null,
              "source_files_sampled": 0,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Dockerfile without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Dockerfile"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "no source files detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_source_files",
                    "params": {}
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [],
      "labels": [],
      "scores": {},
      "primary": null,
      "evidence": [],
      "artifacts": [],
      "confidence": "none",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": false
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-05T08:53:15.958589Z",
  "schema_version": "0.31.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/github-community-projects/ospo-reusable-workflows.svg",
  "full_name": "github-community-projects/ospo-reusable-workflows",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v2.5.0, схема v0.31.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистика.