Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [
"cli-tool",
"python",
"venv",
"virtual-environment"
],
"is_fork": false,
"size_kb": 2825,
"has_wiki": false,
"homepage": null,
"languages": {
"Go": 102415,
"Shell": 2474,
"Makefile": 1099,
"Dockerfile": 980
},
"pushed_at": "2026-07-24T10:06:27Z",
"created_at": "2025-01-25T21:45:20Z",
"owner_type": "User",
"updated_at": "2026-08-01T18:41:38Z",
"description": "A powerful CLI tool for managing Python virtual environments with ease.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://jacopobonomi.github.io",
"name": "Jacopo Bonomi",
"type": "User",
"login": "jacopobonomi",
"company": "Giunti Editore S.p.a",
"location": "Florence",
"followers": 25,
"avatar_url": "https://avatars.githubusercontent.com/u/16934164?v=4",
"created_at": "2016-01-28T08:28:44Z",
"is_verified": null,
"public_repos": 28,
"account_age_days": 3838
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-07-20T14:29:08Z"
},
{
"tag": "v2026.07.20",
"kind": "patch",
"published_at": "2026-07-20T13:10:37Z"
},
{
"tag": "v2026.07.18",
"kind": "patch",
"published_at": "2026-07-18T13:30:53Z"
},
{
"tag": "v2025.03.05",
"kind": "patch",
"published_at": "2025-03-05T21:49:35Z"
},
{
"tag": "v2025.01.29",
"kind": "patch",
"published_at": "2025-01-29T15:25:08Z"
},
{
"tag": "v",
"kind": "other",
"published_at": "2025-01-26T10:25:16Z"
},
{
"tag": "v2025.01.26",
"kind": "patch",
"published_at": "2025-01-26T10:17:07Z"
}
],
"recent_commits": [
{
"oid": "ed28192a4eb5f3a7d9456be37233f26749b0ae26",
"body": null,
"is_bot": false,
"headline": "docs: add Homebrew tap install instructions",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-24T10:06:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d30a40cc1bfb6d5e97798c34e6ecb1c78af8e744",
"body": "…eanup\n\nSecurity:\n- Add ValidateName and enforce it in requireVenv/Create/Rename: venv\n names are now restricted to [A-Za-z0-9._-] (no leading dot/dash).\n Previously an empty name resolved to the base dir itself, so the MCP\n remove_venv tool called without a name would RemoveAll(~/.venvs), and\n \n[…]\nhe no-op cryptography->cryptography alias entry; gofmt the tree.\n\nTests: name validation (empty/traversal regressions on both Manager and\nMCP dispatch), PEP 503 normalization, MCP tool catalog sanity.",
"is_bot": false,
"headline": "fix: validate venv names, PEP 503 comparison, recursive watch, MCP cl…",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-22T15:57:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a79502fd3ec23bb8f1ef31ab1f9fff84bb802750",
"body": null,
"is_bot": false,
"headline": "docs: add Glama MCP server badge",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-21T09:21:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe0f1c6fa6f2167021bee4f94da495d677961925",
"body": "- SECURITY.md: private disclosure via GitHub Security Advisories,\n in-scope/out-of-scope enumerated.\n- .github/ISSUE_TEMPLATE/{bug_report,feature_request}.yml + config.yml\n disabling blank issues and redirecting security reports.\n- release.yml: trigger on tag push (v*.*.*) instead of every push to\n[…]\n action versions; enforces\n fail_on_unmatched_files. Prior workflow created a v$(date) release\n on every main push and never triggered on actual tags, which is why\n v0.1.0 shipped without binaries.",
"is_bot": false,
"headline": "chore: add SECURITY.md, issue templates, tag-triggered release workflow",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:56:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea87f420b1df7c882ba0f4e5a2b9f03073e40780",
"body": "go.mod requires 1.24.2 (transitively via bubbletea deps). Dockerfile\nwas on golang:1.21-alpine and failed 'go mod download'. CI was passing\nbecause setup-go auto-upgrades toolchain, but local builds and Glama\nintrospection need the pin corrected.\n\nVerified: docker build + MCP initialize + tools/list handshake OK.",
"is_bot": false,
"headline": "chore: bump Go to 1.24 in Dockerfile and CI (matches go.mod requirement)",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:40:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37755d1085b7b633e9f7df1c71f6c932cf7ba0a8",
"body": "Multi-stage build: Go builder + python:3.12-alpine runtime so pip-based\ntools (create_venv, install_packages, exec_ephemeral) work end-to-end.\nEntrypoint is 'venv-manager mcp' — JSON-RPC 2.0 on stdio, responds to\nGlama's initialize + tools/list introspection.",
"is_bot": false,
"headline": "chore: add Dockerfile for Glama MCP server introspection",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:36:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ae4c377c89470914611830baf72a72015c4e677",
"body": null,
"is_bot": false,
"headline": "docs: drop Go Report Card badge (service is sunset)",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:30:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a8bf8eb19f0ecdc84e15ede309eeccce5eed265",
"body": "TestListSnapshotsSortsNewestFirst failed on CI when two back-to-back\nos.WriteFile calls produced identical nanosecond mtimes. Fix at two\nlevels:\n\n- Manager.ListSnapshots now falls back to descending ID (which embeds\n the timestamp) when CreatedAt ties.\n- The test sets explicit mtimes with os.Chtimes so it exercises the\n time-based branch, not the tie-break.\n\nAlso adds README badges (CI, Go Report Card, pkg.go.dev, License,\nRelease) and a CHANGELOG.md, in preparation for the v0.1.0 tag.",
"is_bot": false,
"headline": "fix(test): make snapshot sort deterministic under CI mtime collisions",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:27:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bfec709732314a2b88f817cd0e30b562bd004d41",
"body": "- Lead with the watch/MCP/ephemeral story instead of feature bullets\n- Full MCP tool table with typed args\n- Concrete describe JSON example (freeze_hash for drift detection in O(1))\n- Watcher pipeline documented step by step\n- Compact commands table + architecture map\n- Drop marketing prose; keep it dense and technical",
"is_bot": false,
"headline": "docs(README): AI-oriented technical rewrite; embed demo.gif",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:15:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93a54aa948db19c5bbf6fbcb1c8dd0661af75ae5",
"body": "- Makefile 'demo' target: builds fresh binary, creates a scratch venv,\n runs vhs against a simple tape, cleans up.\n- Tape reworked to be pure vhs commands (no sourced setup) so vhs's\n Type parser doesn't choke.\n- Pins PATH to /bin so the tape always exercises the current\n code, not whatever venv-\n[…]\nause of the previous broken GIFs: the global binary lacked\n the 'watch tolerates missing target' fix).\n- Verified end-to-end: GIF shows the full AI-writes-code + watch\n auto-install + describe flow.",
"is_bot": false,
"headline": "feat(demo): working AI watch-mode GIF via 'make demo'",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T14:02:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8bd70fdeccf98901f374aac07f5c3686897eebe2",
"body": "VHS's Type parser choked on backslash-escaped quotes and colons.\nSourcing a helper script sidesteps the parser entirely.",
"is_bot": false,
"headline": "fix(demo): move complex setup out of the .tape into setup.sh",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T13:47:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cbb700119961f11f31402aab69611f2c899cbc03",
"body": null,
"is_bot": false,
"headline": "chore: extend .gitignore with .DS_Store and local test binaries",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T13:43:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d3c0c48c9da843e53d9faac9e5e89c764ac1cd6",
"body": null,
"is_bot": false,
"headline": "chore: gitignore macOS + local binaries; untrack accidental .DS_Store",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T13:43:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ea61acbde4c92bc8d2318c3fd6422cb6e4326e4",
"body": "- scripts/demo/demo.tape: automated GIF generation with vhs\n- scripts/demo/ai_writes_code.sh: simulates an AI agent progressively\n adding third-party imports, so watch mode can be seen picking them up\n- scripts/demo/README.md: two paths (VHS automated, or asciinema+Claude\n Desktop for the real MCP story)\n- watch: handle non-existent target gracefully — watch the parent dir\n and defer the initial scan until the file appears",
"is_bot": false,
"headline": "feat(demo): VHS tape for AI watch mode + watch tolerates missing target",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T13:42:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d05fd3bb6be3ea6ce3b31ba752e379e74560cd9",
"body": "Walk kept descending into just-removed directories, causing lstat\nENOENT errors on the .pyc files inside. Skip the subtree instead.\n\nCaught by end-to-end smoke testing all commands.",
"is_bot": false,
"headline": "fix(clean): return filepath.SkipDir after removing __pycache__",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T13:24:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e41f2de33188429612463525b68bc052bdaa564",
"body": "- snapshot/snapshots/rollback: pip-freeze state captured under\n <venv>/.venv-manager/snapshots/, restore uninstalls + reinstalls from\n the snapshot file. Newest-first listing, optional labels.\n- scan <path>: extract top-level imports via regex + triple-string\n skipping, filter stdlib, resolve com\n[…]\nshot (sanitize, sort). Integration tests under\n //go:build integration exercise create/install/describe and\n snapshot->install->rollback against real Python; new CI job runs\n them with Python 3.12.",
"is_bot": false,
"headline": "feat: snapshot/rollback, import scan, watch mode + integration tests",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-20T13:10:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc5c0436d3b3603591500d090b9dd84497c039ca",
"body": "- describe <name>: full JSON snapshot (python version, packages, size,\n activation commands per shell, freeze hash) — one call for agents\n- exec [--with pkgs] [--sandbox] -- <cmd>: ephemeral venv à la uvx/pipx run.\n Sandbox uses sandbox-exec on macOS and bwrap on Linux; blocks network\n and restri\n[…]\nal venv\n- mcp: minimal Model Context Protocol server over stdio (JSON-RPC 2.0)\n exposing list/create/remove/describe/install/run/exec/doctor as tools\n consumable by Claude Desktop, Cursor, Zed, etc.",
"is_bot": false,
"headline": "feat(ai): add describe, ephemeral exec with sandbox, and MCP server",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-18T13:38:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "555aae7ed4215c4f6247d1757c1141b4b1f16657",
"body": "Adds `venv-manager tui`: split-pane browser with a filterable list of\nvenvs on the left and package details on the right. Keybindings for\nrefresh, delete, clean cache, and load details. Sizes computed lazily.",
"is_bot": false,
"headline": "feat(tui): interactive TUI powered by Bubble Tea",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-18T13:33:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a5ea37115c1a74a62da1a727ce09acb4bab96d1",
"body": "…backend, tests & CI\n\n- Refactor: extract platform helpers (VenvBinDir/VenvExe/PipPath/PythonPath),\n remove duplicated Windows checks from manager\n- New commands: run, doctor, prune, rename, export, import, config\n- Config file at ~/.config/venv-manager/config.json (XDG-aware)\n- Optional uv backend\n[…]\nackages, size, doctor, prune, export\n- Upgrade collects per-package errors instead of aborting on first\n- Unit tests for manager, utils, config\n- GitHub Actions CI (vet + test -race on Ubuntu + macOS)",
"is_bot": false,
"headline": "feat: add run/doctor/prune/rename/export/import commands, config, uv …",
"author_name": "jacopobonomi",
"author_login": "jacopobonomi",
"committed_at": "2026-07-18T13:30:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3c5a7c8112a1989ef41d9a8319593ce2d9620650",
"body": null,
"is_bot": false,
"headline": "feat(size): add size check for environment or globally",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-03-05T22:02:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dc9b6ecfc73bf637aa90edf544b37f1ff1dcd596",
"body": "…ackage to better manage command and cli",
"is_bot": false,
"headline": "feat(shell-completion): added shell completion and migrate to cobra p…",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-03-05T21:49:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "475f9eb50eb6696a7a6f7e07a76cc87f38cf39a6",
"body": null,
"is_bot": false,
"headline": "feat(README): change README",
"author_name": "Jacopo Bonomi",
"author_login": "jacopobonomi",
"committed_at": "2025-01-29T15:30:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a19f4b560f22b641df10ca7c78446054e4091f1",
"body": null,
"is_bot": false,
"headline": "feat(README): add terminal example in README",
"author_name": "Jacopo Bonomi",
"author_login": "jacopobonomi",
"committed_at": "2025-01-29T15:24:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8cd8bcc689ffa313e75986f5aa80818897734e6",
"body": null,
"is_bot": false,
"headline": "feat(install): one command install",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-26T10:31:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7fc3f8a5971cb9099c1aaa16a627cfd0d2aeceb",
"body": null,
"is_bot": false,
"headline": "fix(release): manage other architecture for build",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-26T10:23:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff716c251b5be4e7d18b22dfc8310aae8dbc1806",
"body": null,
"is_bot": false,
"headline": "feat(workflow): add also workflow",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-26T10:12:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2291e442d5171493d269452603bc8100deafdc01",
"body": null,
"is_bot": false,
"headline": "feat(readme): add readme not completed",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-26T10:11:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "859eedf36c84a811ec98400a38bf9ae19044a03a",
"body": null,
"is_bot": false,
"headline": "feat(license): create MIT LICENSE",
"author_name": "Jacopo Bonomi",
"author_login": "jacopobonomi",
"committed_at": "2025-01-26T10:09:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "35499b415548d564a459d05a632eca71337fc11d",
"body": "…ents colors and install and uninstall script improvment",
"is_bot": false,
"headline": "feat(scripts, comments, packages): add packages command, improve comm…",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-25T22:15:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "58973046ee2ff798a856d3722f95f60cd8a56a22",
"body": null,
"is_bot": false,
"headline": "fix(gitignore): error on gitignore for test",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-25T21:47:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64470b7789d7000bc0d26e3a9936954b6b7f5804",
"body": null,
"is_bot": false,
"headline": "first commit",
"author_name": "Bonomi Jacopo",
"author_login": "jacopobonomi",
"committed_at": "2025-01-25T21:45:09Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 7,
"commits_last_year": 19,
"latest_release_at": "2026-07-20T14:29:08Z",
"latest_release_tag": "v0.1.0",
"releases_from_tags": false,
"days_since_last_push": 8,
"active_weeks_last_year": 2,
"days_since_latest_release": 12,
"mean_days_between_releases": 90
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 57,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 0,
"stars": 47,
"watchers": 1,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 18618,
"source_files_sampled": 22,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.38.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5024"
],
"fixed_version": "0.44.0",
"advisory_count": 1,
"oldest_advisory_days": 71
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.3.8",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5970"
],
"fixed_version": "0.39.0",
"advisory_count": 1,
"oldest_advisory_days": 18
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 2
},
"advisory_count": 2,
"affected_count": 2,
"assessed_count": 29,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/charmbracelet/bubbles",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.1"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.9.1"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/charmbracelet/bubbles",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbletea",
"direct": true,
"version": "v1.3.10",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": true,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": true,
"version": "v1.10.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.9.1",
"ecosystem": "go"
},
{
"name": "github.com/atotto/clipboard",
"direct": false,
"version": "v0.1.4",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.4.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.11.6",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.15",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/displaywidth",
"direct": false,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/stringish",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/clipperhouse/uax29/v2",
"direct": false,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/erikgeiser/coninput",
"direct": false,
"version": "v0.0.0-20211004153227-1c3628e74d0f",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-localereader",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.19",
"ecosystem": "go"
},
{
"name": "github.com/muesli/ansi",
"direct": false,
"version": "v0.0.0-20230316100256-276c6243b2f6",
"ecosystem": "go"
},
{
"name": "github.com/muesli/cancelreader",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": false,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/sahilm/fuzzy",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": false,
"version": "v1.0.6",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.3.8",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 29,
"direct_count": 5,
"indirect_count": 24
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "jacopobonomi",
"commits": 31,
"avatar_url": "https://avatars.githubusercontent.com/u/16934164?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"release.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 3 contributing companies or organizations -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 8,
"reason": "2 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "ed28192a4eb5f3a7d9456be37233f26749b0ae26",
"ran_at": "2026-08-02T02:56:10Z",
"aggregate_score": 4.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-24T10:07:11Z",
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/jacopobonomi/venv_manager",
"host": "github.com",
"name": "venv_manager",
"owner": "jacopobonomi"
},
"metrics": {
"overall": {
"key": "overall",
"band": "weak",
"name": "Overall health",
"note": "The weighted overall 47 is calibrated to 45 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 47,
"calibrated": 45,
"calibration": "2026-08-02"
}
}
],
"value": 45,
"inputs": {
"security": 54,
"vitality": 64,
"community": 38,
"governance": 25,
"calibration": "2026-08-02",
"engineering": 56,
"ai_readiness": 60,
"weighted_overall_raw": 47
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "moderate",
"name": "Vitality",
"value": 64,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 52,
"inputs": {
"commits_last_year": 19,
"human_commit_share": 1,
"days_since_last_push": 8,
"active_weeks_last_year": 2
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 8 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "2/52 weeks with commits",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 2
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "19 commits in the last year",
"points": 11.7,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 19
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"releases_count": 7,
"latest_release_tag": "v0.1.0",
"releases_from_tags": false,
"days_since_latest_release": 12,
"mean_days_between_releases": 90
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "7 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 7
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 12 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 12
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~90 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 90
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 11,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 11 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 11
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "weak",
"name": "Community & Adoption",
"value": 38,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 27,
"inputs": {
"forks": 0,
"stars": 47,
"watchers": 1,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "47 stars",
"points": 27,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 47
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "1 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 1
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 25,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"pr_acceptance",
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 0,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 54,
"inputs": {
"followers": 25,
"owner_type": "User",
"is_verified": null,
"owner_login": "jacopobonomi",
"public_repos": 28,
"account_age_days": 3838
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "25 followers of jacopobonomi",
"points": 10.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 25,
"login": "jacopobonomi"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "28 public repos, account ~10 yr old",
"points": 22.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 28
}
},
{
"code": "account_age_years",
"params": {
"years": 10
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 56,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [
"cli-tool",
"python",
"venv",
"virtual-environment"
],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "4 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 4
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 54,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 42,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 4.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "19 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "2 existing vulnerabilities detected",
"points": 6,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 29 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 29
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 2,
"affected_packages": 2,
"assessed_packages": 29,
"unassessed_packages": 0,
"affected_by_severity": "unknown 2",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 29,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 4
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 60,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.968,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "30 of 31 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 30,
"sampled": 31
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 31",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 31
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 18618,
"source_files_sampled": 22,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/22 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 22,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"application"
],
"labels": [
"cli",
"tui"
],
"scores": {
"cli": 8,
"tui": 4
},
"primary": "cli",
"evidence": [
{
"tier": "dependencies",
"label": "cli",
"source": "dep:github.com/spf13/cobra",
"weight": 4
},
{
"tier": "dependencies",
"label": "tui",
"source": "dep:github.com/charmbracelet/bubbletea",
"weight": 4
},
{
"tier": "description",
"label": "cli",
"source": "description:cli",
"weight": 2
},
{
"tier": "tags",
"label": "cli",
"source": "tag:cli-tool",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": true,
"consumed_by_code": false
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"Could not fetch go package 'github.com/jacopobonomi/venv-manager' from its registry"
],
"report_type": "repository",
"generated_at": "2026-08-02T02:56:14.200347Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/jacopobonomi/venv_manager.svg",
"full_name": "jacopobonomi/venv_manager",
"license_state": "standard",
"license_spdx": "MIT"
}