Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 1.13.0 · 2026-07-25 07:20 UTC

neha-bhargava / microsoft-authentication-library-for-python

Microsoft Authentication Library (MSAL) for Python makes it easy to authenticate to Microsoft Entra ID. General docs are available here https://learn.microsoft.com/entra/msal/python/ Stable APIs are documented here https://msal-python.readthedocs.io. Questions can be asked on www.stackoverflow.com with tag "msal" + "python".

PythonВласна ліцензія★ 0 зірок⑂ 0 форківз трав. 2026 р.форкПереглянути на GitHub ↗

neha-bhargava/microsoft-authentication-library-for-python має індекс здоров’я 43 зі 100, що відповідає смузі «У зоні ризику». Найвищий показник — Engineering Quality (68/100), найнижчий — Community & Adoption (9/100). Останнє оновлення було 56 днів тому. Більшість нещодавньої роботи виконує один учасник.

43
загалом / 100
У зоні ризику

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє середнє; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 49 («Під ризиком»). Готовність до ШІ не входить до індексу.

43
Відмінний85-100Зразковий; відповідає практично всім перевіреним критеріям
Добрий70-84Здоровий; незначні прогалини
Помірний50-69Прийнятний, але з помітними прогалинами; рекомендовано перевірку
У зоні ризику30-49Суттєві слабкі місця; впровадження потребує обережності
Критичний1-29Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Власність

Neha BhargavaОсобистий обліковий запис
6 підписників10 публічних репозиторіївз бер. 2020 р.@microsoft

Цей репозиторій належить особистому обліковому запису. Проєкт з єдиним власником несе більший ризик безперервності, ніж підтримуваний організацією.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікація
PyPImsalвказує на інший репозиторій — не оцінюється1.37.0211 811 7917356 днів тому

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

57Помірний · 22% загального індексу

Активність розробки

48У зоні ризику
Як обчислюється оцінка
18/36Свіжість push — останній push 56 дн. тому
15.2/36Ритм комітів — 22/52 тижнів із комітами
14.5/18Обсяг комітів — 40 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — project was created within the last 90 days. Please review its contents carefully
Використані вхідні дані
commits_last_year40
human_commit_share0,99
days_since_last_push56
active_weeks_last_year22
Як обчислюється оцінка
16.2/27Випускає релізи — 61 тегів версій (без релізів GitHub)
27/36Свіжість релізів — останній реліз 107 дн. тому
19.8/27Ритм релізів — реліз кожні ~58,2 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count61
latest_release_tag1.36.0
releases_from_tagsтак
days_since_latest_release107
mean_days_between_releases58,2
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

9Критичний · 18% загального індексу
Як обчислюється оцінка
0/60Зірки — 0 зірок
0/25Форки — 0 форків
0/15Спостерігачі — 0 спостерігачів
Використані вхідні дані
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
0/22.5README
16.9/22.5Ліцензія — файл ліцензії наявний, не є визнаною ліцензією
0/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
0/6.3Шаблон PR
Використані вхідні дані
has_readmeні
has_licenseні
has_contributingні
has_issue_templateні
has_code_of_conductні
has_pull_request_templateні

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

28Критичний · 24% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
2.4/22.5Розподіл комітів — головний контриб’ютор — автор 89% комітів
13.5/13.5Широта контриб’юторів — 41 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 3 contributing companies or organizations -- score normalized to 10
Використані вхідні дані
bus_factor1
contributors_sampled41
top_contributor_share0,893
Як обчислюється оцінка
0/46.8Вирішення issue — немає issue або даних
0/38.3Прийняття PR — немає вирішених pull request-ів або даних
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue, Прийняття PR. Залишкові ваги перенормовано.

Власність та опіка

45У зоні ризику
Як обчислюється оцінка
10/30Підтримка власника — особистий (користувацький) обліковий запис
0/20Верифікований домен — не застосовно до користувацьких облікових записів
6.1/25Охоплення власника — 6 підписників у neha-bhargava
19.6/25Послужний список — 10 публічних репозиторіїв, вік облікового запису ~6 р.
Використані вхідні дані
followers6
owner_typeUser
is_verified
owner_loginneha-bhargava
public_repos10
account_age_days2 332
Виключено з оцінювання (немає даних або не застосовно): Верифікований домен. Залишкові ваги перенормовано.

Інженерна якість

Чи наявні базові інженерні практики та документація?

68Помірний · 20% загального індексу
Як обчислюється оцінка
24/24Процеси CI — 2 процес(ів) CI
24/24Наявні тести
16/16Конфігурація лінтера — tox.ini
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsтак
has_editorconfigні
has_linter_configтак
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

50Помірний
Як обчислюється оцінка
0/30README
25/25Каталог документації
15/15Сайт документації / домашня сторінка — https://stackoverflow.com/questions/tagged/azure-ad-msal+python
0/10Опис репозиторію
0/10Теми
10/10Wiki
Використані вхідні дані
topics
has_wikiтак
homepagehttps://stackoverflow.com/questions/tagged/azure-ad-msal+python
has_readmeні
has_docs_dirтак
has_descriptionні

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

53Помірний · 16% загального індексу

Стан безпеки

41У зоні ризику
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5Ліцензія — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — немає даних
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate4,1
Виключено з оцінювання (немає даних або не застосовно): ci_tests, packaging, signed_releases. Залишкові ваги перенормовано.
Як обчислюється оцінка
35/35Прямі залежності без відомих сповіщень — жодна пряма залежність не має відомих сповіщень
25/25Непрямі залежності без відомих сповіщень — жодна непряма залежність не має відомих сповіщень
0/40Немає задавнених сповіщень — жодне сповіщення не має дати публікації
Використані вхідні дані
sourceosv
advisories0
affected_packages0
assessed_packages9
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
Виключено з оцінювання (немає даних або не застосовно): Немає задавнених сповіщень. Залишкові ваги перенормовано. Звірено з runtime-замиканням залежностей pypi:msal@1.37.0 — тим, що тягне за собою встановлення опублікованого пакета, — 9 пакетів. Досяжність не аналізується.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Незалежний, експериментальний бейдж — вага 0.0, тож він подається окремо і не впливає на загальний індекс здоров'я.

49У зоні ризику · 0% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
24.8/40Читабельна історія комітів — намір зазначено у 46 з 99 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,465
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
18/18Розгортання однією командою — docs/Makefile
22/22Автоматизовані тести
11/11Конфігурація лінтера / форматера — tox.ini
0/11Статична перевірка типів
0/10Відтворюване середовище
10/10Підтверджена практика роботи з агентами — 10 з останніх 100 комітів створено агентом або з його зазначенням
8/8Автоматизоване супроводження — 1 з останніх 100 комітів — автоматичні оновлення залежностей
0/10OpenSSF Scorecard: Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
Використані вхідні дані
has_nixні
has_testsтак
lockfiles
has_dockerfileні
typed_languageні
bootstrap_filesdocs/Makefile
has_devcontainerні
has_linter_configтак
typecheck_configs
agent_commit_share0,1
toolchain_manifests
dependency_bot_commit_share0,01
Як обчислюється оцінка
0/45Типізований код — Python без конфігурації перевірки типів
52.5/55Керовані розміри файлів — 3/65 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languagePython
largest_source_bytes140 501
source_files_sampled65
oversized_source_files3
Як обчислюється оцінка
0/40Схема API (OpenAPI/GraphQL/proto)
0/20Сервер MCP
40/40Придатні до запуску приклади — sample
Використані вхідні дані
example_dirssample
has_mcp_signalні
api_schema_files

Ключові факти

0зірок GitHub
41контриб'юторів
40комітів за останні 12 місяців
56днів від останнього пушу
61релізів
1бас-фактор
0відкритих issue
PyPIпакетних екосистем

Попередження щодо збору даних

  • Community profile unavailable
  • pypi package 'msal' points at a different repository (https://github.com/AzureAD/microsoft-authentication-library-for-python); excluded from ecosystem scoring
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Докладніше

OpenSSF Scorecard 4.1 / 10
4.1сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-25 07:20 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
н/дPackagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
Прямі залежності 3
РеєстрПакетОбмеження версіїМаніфест
PyPIrequests>=2.0.0,<3setup.cfg
PyPIPyJWT>=1.0.0,<3setup.cfg
PyPIcryptography>=2.5,<51setup.cfg
Усі залежності не зібрано

Не вдалося зібрати розв'язаний набір залежностей для цього звіту: GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

Сповіщення про залежності 0

Встановлення pypi:msal@1.37.0 тягне 9 пакетів, прямих і транзитивних: 0 мають відомі сповіщення, з них 0 — прямі залежності.

Жодне відоме сповіщення не стосується оцінених залежностей.

Сповіщення означає, що версія, записана в графі залежностей, потрапляє в уражений діапазон. Досяжність не аналізується, а граф містить піниї розробки й тестування — знахідка може стосуватися інструментів, а не поставленого коду.

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 3914,
      "has_wiki": true,
      "homepage": "https://stackoverflow.com/questions/tagged/azure-ad-msal+python",
      "languages": {
        "Shell": 741,
        "Python": 763117
      },
      "pushed_at": "2026-05-29T17:17:45Z",
      "created_at": "2026-05-29T22:48:02Z",
      "owner_type": "User",
      "updated_at": "2026-05-29T22:48:03Z",
      "description": "Microsoft Authentication Library (MSAL) for Python makes it easy to authenticate to Microsoft Entra ID. General docs are available here https://learn.microsoft.com/entra/msal/python/ Stable APIs are documented here https://msal-python.readthedocs.io. Questions can be asked on www.stackoverflow.com with tag \"msal\" + \"python\".",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "dev",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Neha Bhargava",
      "type": "User",
      "login": "neha-bhargava",
      "company": "@microsoft ",
      "location": "Redmond, WA",
      "followers": 6,
      "avatar_url": "https://avatars.githubusercontent.com/u/61847233?v=4",
      "created_at": "2020-03-05T19:17:42Z",
      "is_verified": null,
      "public_repos": 10,
      "account_age_days": 2332
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "1.36.0",
          "kind": "minor",
          "published_at": "2026-04-08T18:14:52Z"
        },
        {
          "tag": "1.35.1",
          "kind": "patch",
          "published_at": "2026-03-04T21:39:36Z"
        },
        {
          "tag": "1.35.0",
          "kind": "minor",
          "published_at": "2026-02-24T10:43:37Z"
        },
        {
          "tag": "1.34.0",
          "kind": "minor",
          "published_at": "2025-09-22T22:53:10Z"
        },
        {
          "tag": "1.33.0",
          "kind": "minor",
          "published_at": "2025-07-22T01:34:10Z"
        },
        {
          "tag": "1.32.3",
          "kind": "patch",
          "published_at": "2025-04-25T12:39:11Z"
        },
        {
          "tag": "1.32.2",
          "kind": "patch",
          "published_at": "2025-04-25T01:51:53Z"
        },
        {
          "tag": "1.32.1",
          "kind": "patch",
          "published_at": "2025-04-24T16:41:04Z"
        },
        {
          "tag": "1.32.0",
          "kind": "minor",
          "published_at": "2025-03-11T22:49:30Z"
        },
        {
          "tag": "1.31.1",
          "kind": "patch",
          "published_at": "2024-11-01T04:01:25Z"
        },
        {
          "tag": "1.31.0",
          "kind": "minor",
          "published_at": "2024-09-06T15:51:45Z"
        },
        {
          "tag": "1.30.0",
          "kind": "minor",
          "published_at": "2024-07-17T03:51:38Z"
        },
        {
          "tag": "1.29.0",
          "kind": "minor",
          "published_at": "2024-06-22T01:56:52Z"
        },
        {
          "tag": "1.28.1",
          "kind": "patch",
          "published_at": "2024-06-11T09:18:48Z"
        },
        {
          "tag": "1.28.0",
          "kind": "minor",
          "published_at": "2024-03-19T06:48:45Z"
        },
        {
          "tag": "1.27.0",
          "kind": "minor",
          "published_at": "2024-02-22T20:18:54Z"
        },
        {
          "tag": "1.26.0",
          "kind": "minor",
          "published_at": "2023-12-05T08:59:20Z"
        },
        {
          "tag": "1.25.0",
          "kind": "minor",
          "published_at": "2023-11-03T23:47:00Z"
        },
        {
          "tag": "1.24.1",
          "kind": "patch",
          "published_at": "2023-09-29T07:42:24Z"
        },
        {
          "tag": "1.24.0",
          "kind": "minor",
          "published_at": "2023-09-12T16:35:03Z"
        },
        {
          "tag": "1.23.0",
          "kind": "minor",
          "published_at": "2023-07-22T17:08:32Z"
        },
        {
          "tag": "1.22.0",
          "kind": "minor",
          "published_at": "2023-04-17T16:50:46Z"
        },
        {
          "tag": "1.21.0",
          "kind": "minor",
          "published_at": "2023-01-31T20:17:14Z"
        },
        {
          "tag": "1.20.0",
          "kind": "minor",
          "published_at": "2022-10-07T04:49:22Z"
        },
        {
          "tag": "1.19.0",
          "kind": "minor",
          "published_at": "2022-09-21T04:09:56Z"
        },
        {
          "tag": "1.18.0",
          "kind": "minor",
          "published_at": "2022-05-31T20:32:08Z"
        },
        {
          "tag": "1.17.0",
          "kind": "minor",
          "published_at": "2022-02-11T20:13:42Z"
        },
        {
          "tag": "1.16.0",
          "kind": "minor",
          "published_at": "2021-10-29T22:30:27Z"
        },
        {
          "tag": "1.15.0",
          "kind": "minor",
          "published_at": "2021-10-01T21:53:34Z"
        },
        {
          "tag": "1.14.0",
          "kind": "minor",
          "published_at": "2021-08-26T18:41:57Z"
        },
        {
          "tag": "1.13.0",
          "kind": "minor",
          "published_at": "2021-07-20T22:05:17Z"
        },
        {
          "tag": "1.12.0",
          "kind": "minor",
          "published_at": "2021-05-19T19:42:11Z"
        },
        {
          "tag": "1.11.0",
          "kind": "minor",
          "published_at": "2021-04-09T14:55:23Z"
        },
        {
          "tag": "1.10.0",
          "kind": "minor",
          "published_at": "2021-03-08T20:39:15Z"
        },
        {
          "tag": "1.9.0",
          "kind": "minor",
          "published_at": "2021-02-09T07:44:35Z"
        },
        {
          "tag": "1.8.0",
          "kind": "minor",
          "published_at": "2020-12-16T01:51:03Z"
        },
        {
          "tag": "1.7.0",
          "kind": "minor",
          "published_at": "2020-12-07T17:43:57Z"
        },
        {
          "tag": "1.6.0",
          "kind": "minor",
          "published_at": "2020-11-02T06:28:09Z"
        },
        {
          "tag": "1.5.1",
          "kind": "patch",
          "published_at": "2020-10-21T19:48:54Z"
        },
        {
          "tag": "1.5.0",
          "kind": "minor",
          "published_at": "2020-09-03T21:46:33Z"
        },
        {
          "tag": "1.4.3",
          "kind": "patch",
          "published_at": "2020-07-25T01:02:55Z"
        },
        {
          "tag": "1.4.2",
          "kind": "patch",
          "published_at": "2020-07-23T22:22:44Z"
        },
        {
          "tag": "1.4.1",
          "kind": "patch",
          "published_at": "2020-06-26T21:41:58Z"
        },
        {
          "tag": "1.4.0",
          "kind": "minor",
          "published_at": "2020-06-25T22:21:47Z"
        },
        {
          "tag": "1.3.0",
          "kind": "minor",
          "published_at": "2020-05-15T03:23:26Z"
        },
        {
          "tag": "1.2.0",
          "kind": "minor",
          "published_at": "2020-03-31T19:45:27Z"
        },
        {
          "tag": "1.1.0",
          "kind": "minor",
          "published_at": "2020-01-23T23:09:09Z"
        },
        {
          "tag": "1.0.0",
          "kind": "major",
          "published_at": "2019-11-01T23:14:04Z"
        },
        {
          "tag": "0.9.0",
          "kind": "minor",
          "published_at": "2019-10-31T19:00:13Z"
        },
        {
          "tag": "0.8.0",
          "kind": "minor",
          "published_at": "2019-10-19T00:10:07Z"
        },
        {
          "tag": "0.7.0",
          "kind": "minor",
          "published_at": "2019-09-25T22:57:37Z"
        },
        {
          "tag": "0.6.1",
          "kind": "patch",
          "published_at": "2019-08-13T20:42:29Z"
        },
        {
          "tag": "0.6.0",
          "kind": "minor",
          "published_at": "2019-07-31T18:52:40Z"
        },
        {
          "tag": "0.5.1",
          "kind": "patch",
          "published_at": "2019-07-10T22:05:50Z"
        },
        {
          "tag": "0.5.0",
          "kind": "minor",
          "published_at": "2019-07-08T21:00:22Z"
        },
        {
          "tag": "0.4.1",
          "kind": "patch",
          "published_at": "2019-06-18T18:05:06Z"
        },
        {
          "tag": "0.4.0",
          "kind": "minor",
          "published_at": "2019-05-22T19:23:30Z"
        },
        {
          "tag": "0.3.1",
          "kind": "patch",
          "published_at": "2019-04-16T23:56:32Z"
        },
        {
          "tag": "0.3.0",
          "kind": "minor",
          "published_at": "2019-04-02T21:55:37Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2019-03-05T21:06:19Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2018-12-12T19:28:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ebb980f1636e1b3a097ec6dbfd197fb88c5b9e7a",
          "body": null,
          "is_bot": false,
          "headline": "Update version to 1.37.0 (#922)",
          "author_name": "Avery-Dunn",
          "author_login": "Avery-Dunn",
          "committed_at": "2026-05-29T17:17:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c504b419a5a604a761d80d3f46365077ed8e6a21",
          "body": "…(#895)\n\n* Add ADO pipeline hyperlinks to CI-AND-RELEASE-PIPELINES.md\n\n* Add Python 3.8 to ADO CI matrix\n\n* Move benchmarks from GH Actions to ADO; remove cb job from GH workflow\n\n* Remove GH Actions CI/CD workflow — tests and publish fully covered by ADO pipelines 3064 and 3067\n\n* Address Copilot r\n[…]\ned the version for sku for rc\n\n* Update template-pipeline-stages.yml\n\n* Update template-pipeline-stages.yml\n\n* Resolved comments\n\n---------\nCo-authored-by: Nilesh Choudhary <nichoudhary@microsoft.com>",
          "is_bot": false,
          "headline": "Migrate CI/CD from GitHub Actions to ADO; remove GH Actions workflow …",
          "author_name": "Ryan Auld",
          "author_login": "RyAuld",
          "committed_at": "2026-05-21T22:14:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "192a82dcd6c5371ece4f14f9701b0134b2e92a07",
          "body": "* Added a soft warning if callback is not callable\n\n* updated crypto version max to 51\n\n* removed support for 3.8 and added doc\n\n* Updated in warning placement\n\n* updated a fix for get()",
          "is_bot": false,
          "headline": "Removed support for Python 3.8 (#910)",
          "author_name": "Nilesh Choudhary",
          "author_login": "4gust",
          "committed_at": "2026-05-21T15:53:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08aa7fd273e93933617e74be842da15d3e36bf25",
          "body": "…(#918)\n\n* First draft of FIC support\n\n* Small fixes and feedback\n\n* PR feedback\n\n* PR feedback\n\n* Add integration tests\n\n* Adjust SNI behavior around .pfx files\n\n* Revert pfx changes and disable tests",
          "is_bot": false,
          "headline": "Add User Federated Identity Credential (user_fic) grant type support …",
          "author_name": "Avery-Dunn",
          "author_login": "Avery-Dunn",
          "committed_at": "2026-05-20T21:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4f58ec792571d9b0e015a8d20661a0554a9536d",
          "body": "Document the MSI v2 mTLS flow in Python, detailing the problem, solution, and technical findings related to using KeyGuard-protected certificates.",
          "is_bot": false,
          "headline": "Add documentation for MSI v2 mTLS in Python (#904)",
          "author_name": "Gladwin Johnson",
          "author_login": "gladjohn",
          "committed_at": "2026-05-20T08:14:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5866feb9b1158547f3379fe33ca5c89f65fafd84",
          "body": "Add design document for MSI v2 In-Memory Key Approach, detailing goals, .NET reference implementation, Python implementation design, comparison with KeyGuard, and API design.",
          "is_bot": false,
          "headline": "Create design document for MSI v2 In-Memory Key Approach (#905)",
          "author_name": "Gladwin Johnson",
          "author_login": "gladjohn",
          "committed_at": "2026-05-20T08:12:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "651d54b8bc3c0882f9dd4771f76b86b1a7c99373",
          "body": "Bump the minimum required version of pymsalruntime from\n0.14/0.17/0.18 to 0.20.6 across all supported platforms\n(Windows, macOS, Linux).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Update pymsalruntime minimum version to 0.20.6 (#919)",
          "author_name": "fengga",
          "author_login": "fengga",
          "committed_at": "2026-05-20T08:08:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "895b581704dbd66c47ec2590d57ff7aff503a235",
          "body": null,
          "is_bot": false,
          "headline": "Use unsigned redirect uri for mac broker flows (#907)",
          "author_name": "fengga",
          "author_login": "fengga",
          "committed_at": "2026-05-12T17:55:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ea1eaaae97f416254bfe7f606d6c6babb80afed",
          "body": "…#913)\n\n* Switch FMI tests from disabled IDLABS_APP_FMI to MISE-App-FMICLIENT\n\n- Client ID: 4df2cbbb -> 3bf56293 (MISE-App-FMICLIENT in id4slab1 tenant)\n- Tenant ID: f645ad92 -> 10c419d4 (id4slab1.onmicrosoft.com)\n- FMI Scope: 3091264c -> aa464f73 (MISE-App-FMIResource)\n- Note: TestFMIIntegration (R\n[…]\n\ncausing a hard failure unrelated to our changes.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Switch FMI tests from disabled IDLABS_APP_FMI to MISE-App-FMICLIENT (…",
          "author_name": "Ryan Auld",
          "author_login": "RyAuld",
          "committed_at": "2026-05-11T22:37:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "faf5dce2f72a5716c12b901eb52dea27e30d3e58",
          "body": "* Initial plan\n\n* Bump cryptography dependency ceiling to <50 (N+3)\n\nAgent-Logs-Url: https://github.com/AzureAD/microsoft-authentication-library-for-python/sessions/f2f7ccee-f03f-4253-b23a-c0fc969f0a1c\n\nCo-authored-by: gladjohn <90415114+gladjohn@users.noreply.github.com>\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: gladjohn <90415114+gladjohn@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Bump cryptography dependency ceiling to <50 (N+3) (#906)",
          "author_name": "Copilot",
          "author_login": "Copilot",
          "committed_at": "2026-04-27T14:22:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "016092efe77035ba6ab4b75000a20ecdb0acdc8d",
          "body": "* Initial plan\n\n* Add MSAL client metadata headers to IMDS managed identity requests\n\nAdd x-client-SKU, x-client-Ver, and x-ms-client-request-id headers to\n_obtain_token_on_azure_vm() for IMDS token requests. Update existing\nIMDS tests to assert the new headers and validate UUID correlation IDs.\n\nAg\n[…]\ngladjohn@users.noreply.github.com>\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: gladjohn <90415114+gladjohn@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Forward MSAL client metadata headers through IMDS to ESTS (#902)",
          "author_name": "Copilot",
          "author_login": "Copilot",
          "committed_at": "2026-04-14T15:21:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67136fe2115b8279e33037af3a986fb264a8545f",
          "body": "* Escape username to protect against xml injection vulnerability\n\n* Add test",
          "is_bot": false,
          "headline": "Escape username parameter (#901)",
          "author_name": "Dharshan BJ",
          "author_login": "DharshanBJ",
          "committed_at": "2026-04-10T17:47:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3ba722660e838f58659f8f501a2624044266247",
          "body": "* added a additional check for domain checking in b2c\n\n* updated comment",
          "is_bot": false,
          "headline": "Fix OIDC issuer domain spoofing in B2C host validation (#896)",
          "author_name": "Nilesh Choudhary",
          "author_login": "4gust",
          "committed_at": "2026-04-07T17:07:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a92f2498d221c673d6e725e7f99d958bd189c5a",
          "body": "…neration (#894)\n\n* Use cryptographically secure randomness for PKCE, state, and nonce generation\n\n* Update tests/test_oidc.py\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n* Update tests/test_oidc.py\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n* U\n[…]\n+ashok672@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Use cryptographically secure randomness for PKCE, state, and nonce ge…",
          "author_name": "Ashok Kumar Ramakrishnan",
          "author_login": "ashok672",
          "committed_at": "2026-04-07T16:41:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ecf515a542feb3bcdfa34ed69144c793ed3be4b6",
          "body": "* Added withFmi method for cca app\n\n* Added Cache support for fmi keys\n\n* updated the cache key ext\n\n* updated cache key excluded\n\n* Update msal/token_cache.py\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>\n\n* updated API for fmi\n\n---------\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>",
          "is_bot": false,
          "headline": "Added withFmi method for cca app (#876)",
          "author_name": "Nilesh Choudhary",
          "author_login": "4gust",
          "committed_at": "2026-04-07T16:36:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb7806838f0bc13f2f38fd1bf62a1f8991bbe197",
          "body": "…in permissions (#884)\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Potential fix for code scanning alert no. 74: Workflow does not conta…",
          "author_name": "Avery-Dunn",
          "author_login": "Avery-Dunn",
          "committed_at": "2026-04-07T16:35:32Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6de712edbf3310aa4af163a51ac8b9eeb9dbe65c",
          "body": "* Add documentation for Managed Identity v2 Hackathon\n\nDocument the results and outcomes of the Managed Identity v2 Multi-Language Implementation Hackathon, highlighting the achievements and deliverables.\n\n* Apply suggestions from code review\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply\n[…]\nikes/prototype/2026_MS_SecurityHackathon_MSIV2.md\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Add documentation for Managed Identity v2 Hackathon (#885)",
          "author_name": "Gladwin Johnson",
          "author_login": "gladjohn",
          "committed_at": "2026-04-07T16:28:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1f71ede35133ed2a2fa707928e60de6d4f067566",
          "body": "* Add ADO CI/release pipelines with SDL, e2e tests, and ESRP publish support\n\n* Use Python runpy to read __version__ in Validate stage instead of grep/sed\n\n* Remove duplicate _clean_env in test_e2e.py; import from lab_config instead\n\n* Pass LabAuth secret via env var to avoid bash command substituti\n[…]\nRELEASE-PIPELINES.md\n\n* Address review comments: rename _clean_env to clean_env, fix __all__, fix doc diagram, drop redundant import os\n\n* Clarify cron comment: 07:45 UTC = 11:45 PM PST / 12:45 AM PDT",
          "is_bot": false,
          "headline": "Add ADO CI, SDL, and release pipelines with e2e test enablement (#890)",
          "author_name": "Ryan Auld",
          "author_login": "RyAuld",
          "committed_at": "2026-03-31T17:46:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4e692c5acaa798bd3f24f8178b042fd9a98ab0d",
          "body": "* Fix PoP flow in the test app\n\nCurrently the test app sends both PoP parameters (see placeholder_auth_scheme definition)\nand also passes req_cnf and token type. There parameters are not\ncompatible. If application passes PoP parameters, then MSAL (or the\nbroker) owns the key and does the signing of \n[…]\n728472+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Petar Dimov <petard@ntdev.microsoft.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Fix the PoP flow in the console app (#887)",
          "author_name": "PetarSDimov",
          "author_login": "PetarSDimov",
          "committed_at": "2026-03-25T17:10:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2de45aeb534a05cfff0d85e96c4f330c102ef607",
          "body": "* Instance discovery remains cloud local on known clouds\n\n* More changes and address PR comments\n\n* Try to fix tests\n\n---------\n\nCo-authored-by: Feng Gao <fengga@microsoft.com>",
          "is_bot": false,
          "headline": "Instance discovery remains cloud local on known clouds (#875)",
          "author_name": "Bogdan Gavril",
          "author_login": "bgavrilMS",
          "committed_at": "2026-02-27T13:41:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09c8821cca91fc01345f080b1c75b124b1ad47f1",
          "body": null,
          "is_bot": false,
          "headline": "Create RELEASE_GUIDE.md (#880)",
          "author_name": "Nilesh Choudhary",
          "author_login": "4gust",
          "committed_at": "2026-02-24T11:38:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1310faca65e452b09e347fdee52da1fe400ce48f",
          "body": "* removed some log that were alerted\n\n* Added back logging of the oidc url",
          "is_bot": false,
          "headline": "Removed logs that were causing Alerts (#878)",
          "author_name": "Nilesh Choudhary",
          "author_login": "4gust",
          "committed_at": "2026-02-24T10:26:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "733a83cc09a85192607cc012b51638d4bcce76f7",
          "body": "* Security: Remove unsafe PowerShell fallback in WSL\n\n* Remove unnecessary blank lines in authcode.py\n\n---------\n\nCo-authored-by: Ashok Kumar Ramakrishnan <83938949+ashok672@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Security: Remove unsafe PowerShell fallback in WSL (#866)",
          "author_name": "Rin",
          "author_login": "RinZ27",
          "committed_at": "2026-02-23T13:04:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7e0e11368457ee6ef6c44df75e5218ac984eef9",
          "body": "* Add OIDC issuer validation and related tests\n\n* Remove check on known hosts and adjust error message towards regular authority API\n\n* Updated the trusted  host list and added region check logic\n\n* Update test_authority.py\n\n* Updated the version for crypto, as 48 is deperecated\n\n* Updated one condi\n[…]\necking on host checking\n\n* adding issuer for some missing tests\n\n* Update authority.py\n\n* updated with new regional cloud URL's\n\n---------\n\nCo-authored-by: Nilesh Choudhary <nichoudhary@microsoft.com>",
          "is_bot": false,
          "headline": "Add OIDC issuer validation (#840)",
          "author_name": "Avery-Dunn",
          "author_login": "Avery-Dunn",
          "committed_at": "2026-02-19T13:29:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58cf0736d48a9bbc2c855983705c1b5f278709ec",
          "body": "* Separate manual tests and remove unused settings from E2E\n\n* Remove non sn/i test case\n\n* Remove unused test\n\n* Improve ADO logs\n\n* Skip some tests on ADO",
          "is_bot": false,
          "headline": "Separate manual tests and remove unused settings from E2E (#874)",
          "author_name": "Bogdan Gavril",
          "author_login": "bgavrilMS",
          "committed_at": "2026-02-18T10:04:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0963357b113cad6455ae5b3cd22c049f358ade7",
          "body": "* Remove usage of Lab API for integration test config\n\n* Add missing dependencies\n\n* Potential fix for code scanning alert no. 79: Clear-text logging of sensitive information\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Remove usage of Lab API for integration test config (#870)",
          "author_name": "Avery-Dunn",
          "author_login": "Avery-Dunn",
          "committed_at": "2026-02-06T19:26:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "60d340147af1996c899053a9150b25b4635d04aa",
          "body": "… (#868)\n\n* Initial changes\n\n* Deprecate response_mode parameter, better messages and more robust test\n\n* Update test_response_mode.py\n\n* Update authcode.py\n\n* Update application.py\n\n* Fix test failure in  state_mismatch test\n\n* Fix for review comments\n\n* Update authcode.py\n\n* Update test_response_m\n[…]\nfy response_mode=form_post in a better spot\n\n* Treat parameter-less HTTP GET as error, while still keeping the welcome page and abort feature\n\n---------\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>",
          "is_bot": false,
          "headline": "Add form_post response mode support for system browser authentication…",
          "author_name": "Ashok Kumar Ramakrishnan",
          "author_login": "ashok672",
          "committed_at": "2026-02-04T00:45:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eac15a91aa3922319ff0ba3d86ef9031b44f4a67",
          "body": "SHA1 thumbprint in client assertion remains the only recognized way for some IDPs that MSAL supports, like ADFS.",
          "is_bot": false,
          "headline": "Suppress CodeQL warning (#867)",
          "author_name": "Bogdan Gavril",
          "author_login": "bgavrilMS",
          "committed_at": "2026-01-06T16:57:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3464e6cb13f29bd730f49fc2ddf1c7a25b7c398",
          "body": null,
          "is_bot": false,
          "headline": "Explicitly remove issuer from the OIDC discovery",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-11-14T23:11:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02d8b4c735dc1ad6eefff8506151d6bb3df898a0",
          "body": null,
          "is_bot": false,
          "headline": "Support Python 3.14",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-11-01T03:00:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0dec594f18b76afb422396e710b0834cbac352b",
          "body": "…made-optional\n\nThumbprint for certificate made optional",
          "is_bot": false,
          "headline": "Merge pull request #835 from vi7us/vitcurda/20250624/cert-thumbprint-…",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-11-01T02:38:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c50ec4a7d168bdec6b2773bba496afcfb0921d2",
          "body": null,
          "is_bot": false,
          "headline": "Cleaner implementation and precise docs on SHA256",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-10-31T21:42:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbeb4948b6e16b505f3b9ea1d9bfe9e3371f07b3",
          "body": "update as per discussion",
          "is_bot": false,
          "headline": "certificate made optionall",
          "author_name": "Vit Curda",
          "author_login": null,
          "committed_at": "2025-10-28T21:32:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14bcad3e79b34c1b077d874abc1502e012426f00",
          "body": null,
          "is_bot": false,
          "headline": "Remove the reliance on socket.getfqdn()",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-10-22T22:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83c102f266f3d9d25b26ac1e91e1abb6280634d6",
          "body": "This is not a breaking change, because the pre-existing implementation\nwill error out anyway, but with a less meaningful exception.",
          "is_bot": false,
          "headline": "Explicitly rejecting empty hostname",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-10-22T22:00:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85c0f06ad19534cae6fd4cd6fc0ea1c84c2e9708",
          "body": null,
          "is_bot": false,
          "headline": "Consolidate 6 boxes into 4",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-10-20T22:00:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3d4a0419836d633452f2bea3de2b128fab0689b",
          "body": null,
          "is_bot": false,
          "headline": "Document how to use sha256 for client credential",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-10-20T22:00:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59fa195804532bbc5708e13fa5b6245827d469b6",
          "body": null,
          "is_bot": false,
          "headline": "Update pymsalruntime version range to handle the latest 0.20.0 release",
          "author_name": "Dharshan BJ",
          "author_login": "DharshanBJ",
          "committed_at": "2025-10-15T18:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a138a5a56444f3a52c5bf33751cc32ad006d126",
          "body": null,
          "is_bot": false,
          "headline": "Demonstrates the behavior of mismatching scope",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-10-03T17:41:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "562d72e295f807bba99d5eee9029591d9ccee60c",
          "body": "* ROPC deprecation\n\n* sample edit\n\n* reenable e2e tests\n\n* reenable tests\n\n* edit\n\n* remove import\n\n* fix wording\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>\n\n* edits\n\n* add comment\n\n* format\n\n* docstring changes\n\n---------\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>",
          "is_bot": false,
          "headline": "ROPC deprecation (#855)",
          "author_name": "Ugonna Akali",
          "author_login": "Ugonnaak1",
          "committed_at": "2025-09-30T17:47:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f803aec300d13f4a55c78941409c60befb2c8f1f",
          "body": "* ADFS labs were decommissioned since late July 2025\n\n* MSAL Python 1.34.0b1\n\n* Declare support for Python 3.13\n\n* Bumping cryptography which also drops Python 3.7\n\n* 1.34.0b1 + minor changes = 1.34.0",
          "is_bot": false,
          "headline": "Release 1.34.0 (#853)",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-09-22T23:49:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2337a69a680139cac54521cfbe4fedef137a2b06",
          "body": "Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.4.2 to 1.13.0.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/v1.4.2...v1.13.0)\n\n---\nupdated-dependencies:\n- depen\n[…]\nndency-version: 1.13.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump pypa/gh-action-pypi-publish in /.github/workflows (#849)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-09-06T06:57:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cff139e0d84038f43cfb7d285fb1adbc16fc900f",
          "body": null,
          "is_bot": false,
          "headline": "Set Redirect Uri for broker silent flow on Linux platform (#846)",
          "author_name": "xinyuxu1026",
          "author_login": "xinyuxu1026",
          "committed_at": "2025-08-29T18:49:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bebbdd4b61b5d858980bf34eae2825dfec30a54d",
          "body": null,
          "is_bot": false,
          "headline": "ADFS labs were decommissioned since late July 2025",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-08-20T16:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "923a7321a53df28e6acce1c5c182b59262bd9ca0",
          "body": null,
          "is_bot": false,
          "headline": "MSAL Python 1.33.0 (#841)",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-07-22T19:39:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70fd4d1599fc15c876c8eaccd29b9f7ae73fecd6",
          "body": "* Add claims challenge parameter in initiate_device_flow\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update msal/oauth2cli/oauth2.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update oauth2.py\n\n* Update oauth2.py\n\n---------\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>",
          "is_bot": false,
          "headline": "Add claims challenge parameter in initiate_device_flow (#839)",
          "author_name": "Ashok Kumar Ramakrishnan",
          "author_login": "ashok672",
          "committed_at": "2025-07-18T07:45:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1d8cd71145a8b1889b490f9b0dfbe4b1ac3a7f1",
          "body": null,
          "is_bot": false,
          "headline": "Use lowercase environment value during searching",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-06-14T02:34:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d49296c1b2a929a6ab11380e237daa89a5298512",
          "body": null,
          "is_bot": false,
          "headline": "Bump version number (#827)",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-06-04T12:02:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c632c82808e7a3a73635718d92a8c3fc09dc871",
          "body": "A recent customer troubleshooting case reveals that the Linux broker\nneeds a specific redirect_uri as its prerequisite",
          "is_bot": false,
          "headline": "Linux broker needs a specific redirect_uri",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-06-02T19:51:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1c3848456696920fb5fb21c1a25a5e9323e443",
          "body": null,
          "is_bot": false,
          "headline": "Cryptography shipped a new version during weekend",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-05-20T09:59:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "deb61fa1f67d6863c4137a3a0c04db791b0d3a72",
          "body": null,
          "is_bot": false,
          "headline": "Improve test cases to test header-less response",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-05-15T23:51:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62855d4a3ffe7b7dcc0b3d08e1e4896be66701a7",
          "body": null,
          "is_bot": false,
          "headline": "Properly throw MsalServiceError exception",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-05-15T23:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db889c7da3226ea7717f26b6f0613b19c635f507",
          "body": null,
          "is_bot": false,
          "headline": "Remind developers about http_cache's unstable format",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-05-09T02:03:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a1a0ff6570137e18ac8f3ed6f1e5d21d9fbf2e9",
          "body": null,
          "is_bot": false,
          "headline": "Add dependency management suggestions",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-05-06T19:38:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37d9af53b75800044926b8c6aa4e5b4317cf5c5b",
          "body": "Merge release 1.32.3 back to dev branch",
          "is_bot": false,
          "headline": "Merge pull request #816 from AzureAD/release-1.32.3",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-05-05T21:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd4fe699256bd4b16ecc3e1b36bf04b511814e23",
          "body": null,
          "is_bot": false,
          "headline": "MSAL Python 1.32.3",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-25T12:39:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c87ba934f24471f9642a58588dff8650192117f",
          "body": null,
          "is_bot": false,
          "headline": "Allow more http response headers",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-25T12:11:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e60467c22a79bc0e613283024216e553230b4fda",
          "body": null,
          "is_bot": false,
          "headline": "MSAL 1.32.2",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-25T01:51:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04b5245c3db12390abf59cc58493f3b8f8ed725b",
          "body": null,
          "is_bot": false,
          "headline": "Tolerate an http response object with no headers",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-25T00:39:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9156a30f6fded731ac48ad7f7e0d63246198ba74",
          "body": null,
          "is_bot": false,
          "headline": "MSAL Python 1.32.1",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-24T16:41:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c3cd281736c8a2aa436b71ed2c260662fd35b3d",
          "body": null,
          "is_bot": false,
          "headline": "Improve IndividualCache test cases",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-24T04:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29d1ac1558d6f87754fef71ed950bd806919d803",
          "body": null,
          "is_bot": false,
          "headline": "Only cache desirable data in http cache",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-24T04:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1321e3793eebd35aac7b80b64e3a6aa49a32a51a",
          "body": "* Fix username/password assert in broker test\n\nSigned-off-by: Emmanuel Ferdman <emmanuelferdman@gmail.com>\n\n* Update tests/broker-test.py\n\nCo-authored-by: Ray Luo <rayluo.mba@gmail.com>\n\n---------\n\nSigned-off-by: Emmanuel Ferdman <emmanuelferdman@gmail.com>\nCo-authored-by: Ray Luo <rayluo.mba@gmail.com>",
          "is_bot": false,
          "headline": "Fix username/password validation in broker test (#807)",
          "author_name": "Emmanuel Ferdman",
          "author_login": "emmanuel-ferdman",
          "committed_at": "2025-04-14T22:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4eb7bd105b2281a253ab94d4b81f56ca1504f500",
          "body": "* Enable broker support on Linux\n\n* update version number\n\n* Update sample/interactive_sample.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update tests/broker-test.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com\n[…]\ny Luo <rayluo@microsoft.com>\n\n* Bump up msal py version to 1.33\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n---------\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>",
          "is_bot": false,
          "headline": "Enable broker support on Linux for WSL (#766)",
          "author_name": "Dharshan BJ",
          "author_login": "DharshanBJ",
          "committed_at": "2025-04-07T19:48:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bcc54a99e42b41239efc80235b51822fbbf2ef81",
          "body": "Update deprecated TokenCache API usage",
          "is_bot": false,
          "headline": "Merge pull request #805 from pvaneck/update-deprecated-api",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-04T22:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28a67a7ab551e6010a7b69c7c9d7b68aa69f69fc",
          "body": null,
          "is_bot": false,
          "headline": "Use v1.29+ TokenCache.search() instead of find()",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-04T22:07:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45e39669ca8e3fd768610d748235c3775ca4db84",
          "body": "There was a place in `ManagedIdentityClient` where the `TokenCache.find`\nmethod was still being used, leading to some deprecation warnings being\nprinted. This updates that to use `TokenCache.search`.\n\nSigned-off-by: Paul Van Eck <paulvaneck@microsoft.com>",
          "is_bot": false,
          "headline": "Update deprecated TokenCache API usage",
          "author_name": "Paul Van Eck",
          "author_login": "pvaneck",
          "committed_at": "2025-04-04T22:07:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f9747fa995e55fe4034308d9d23133523827e09",
          "body": null,
          "is_bot": false,
          "headline": "ManagedIdentityClient sends xms_cc and token_sha256_to_refresh to SF",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-04-03T03:18:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30dce4ecc63d93ef34b89c052aab1a1231395ce6",
          "body": "This used to cause issue with MSAL 1.32 and MSAL EX <= 1.2 running\ninside read-only container",
          "is_bot": false,
          "headline": "Swallow exception during optional check",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-29T08:31:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4db4a8c2d740c5315f60f07a7e1ee58667b2a759",
          "body": "…microsoft-authentication-library-for-python/issues/97",
          "is_bot": false,
          "headline": "This typo fix will probably resolve https://github.com/MicrosoftDocs/…",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-25T02:38:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "137dee46c9189b9d02105d92f8dcac5fd39a9266",
          "body": null,
          "is_bot": false,
          "headline": "Update error hints for where to get OBO test apps",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-12T21:46:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b92b4f18cb176231ae494639d24aeb19bd457d73",
          "body": null,
          "is_bot": false,
          "headline": "Bumping version number to 1.32.0",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-11T22:49:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04e740e32bf18047109b1c1892671f0f177428e0",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'release-1.31.2' into merge",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-11T20:00:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "689e8624b5987be529ab91f8786a1105ee505f23",
          "body": null,
          "is_bot": false,
          "headline": "Support pod identity",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-11T00:35:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb3e21cf501587dccb71676a3d06f9ea24476102",
          "body": null,
          "is_bot": false,
          "headline": "ADFSv2 and ADFSv3 labs are decommissioned",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-03-10T23:54:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6d3d0d22a61b5b71a4a501dfb57aaa21462c4e6",
          "body": null,
          "is_bot": false,
          "headline": "Skip authority discovery in test_application.py",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-21T07:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f22994f93e1f49d6fb6234bbc8a7a1c90604b247",
          "body": "…only arguments",
          "is_bot": false,
          "headline": "enable_broker_on_windows and enable_broker_on_mac present as keyword-…",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-20T20:05:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e2a4ec0d4af3bf44c1f1608903440e5f6e75aa9",
          "body": null,
          "is_bot": false,
          "headline": "Specify verify=True to hopefully satisfy CodeQL",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-20T19:21:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a565ba20e5bc83b65219086f3e55302d59b0ea00",
          "body": null,
          "is_bot": false,
          "headline": "E2e attempts broker albeit PyMsalRuntime init fails",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-20T09:15:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f15c399b6c34f1dbf838ccf077286290b3ee4d0",
          "body": null,
          "is_bot": false,
          "headline": "Fix incorrect login_hint detection",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-20T05:37:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d168cfd77e0f28bc16302698344db07c1f9e5d8",
          "body": null,
          "is_bot": false,
          "headline": "We have long been switched to use Github actions",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-13T19:41:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0340f5e78d49195917c5682f082e461e9825a2a9",
          "body": null,
          "is_bot": false,
          "headline": "Enable Issue-Sentinel to scan for similar issues (#790)",
          "author_name": "Dharshan BJ",
          "author_login": "DharshanBJ",
          "committed_at": "2025-02-11T21:33:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "971f110cddaf1a98f4021340282fa5fa1d4d699a",
          "body": null,
          "is_bot": false,
          "headline": "Add test case to show that OBO supports SP",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-08T05:14:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c84adf6723491edd4905a477e6e8da4df266313",
          "body": null,
          "is_bot": false,
          "headline": "Adds dSTS authority (as if it were an oidc_authority)",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-08T00:52:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6508d992f4bbfcae21c7f1175c24e4076ade0ad5",
          "body": null,
          "is_bot": false,
          "headline": "Try to suppress another verify=False",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-02-07T23:57:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a37d3a329f7329fe0761579d7a52240ff1cd2fa3",
          "body": "* Pass Sku and Ver to MsalRuntime\r\n\r\n* edit suggestions\r\n\r\n* suggestion edits\r\n\r\n* whitespace",
          "is_bot": false,
          "headline": "Pass Sku and Ver to MsalRuntime (#786)",
          "author_name": "Ugonna Akali",
          "author_login": "Ugonnaak1",
          "committed_at": "2025-02-07T01:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf27fc6d28320dc1384b98ca7bd9844a3a6f809f",
          "body": null,
          "is_bot": false,
          "headline": "MSAL Python 1.31.2b1",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-28T05:19:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "388b86d31559cda8be9b797fefe61dc11dc7c757",
          "body": null,
          "is_bot": false,
          "headline": "Pin ubuntu 22.04 so that we can still test on Py37",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-27T05:14:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f27f4b227e6c7ed336a8ce6fcd606c581f806cd2",
          "body": null,
          "is_bot": false,
          "headline": "Supports GUID/scope and https://contoso.com//scope",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-26T04:51:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5420c59aaa9b1fd657ce0c7b5f3168ce732c6045",
          "body": null,
          "is_bot": false,
          "headline": "Relax the upper bound after testing the latest one",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-25T02:14:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f3d1336751a19cb8a7c0575e68ffbea66581008",
          "body": null,
          "is_bot": false,
          "headline": "Update the hint of where to get a lab certificate",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-23T21:32:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3803ae22c8c712fd6f74db8576f219e31c94039d",
          "body": null,
          "is_bot": false,
          "headline": "Suppress a false positive CodeQL alarm",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-15T18:16:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37badb876e1dc7c23022445f241bc8bf954c49f2",
          "body": null,
          "is_bot": false,
          "headline": "Py3.7 is unavailable on ubuntu 24.04",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2025-01-15T06:00:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7b3175631c03c5b5476aaf29239c31878ab80b23",
          "body": "[skip ci]",
          "is_bot": false,
          "headline": "Set up CI with Azure Pipelines",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2024-12-02T18:53:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5196d84f2aaf6d9927259d78815d5c1c21f9cc8",
          "body": null,
          "is_bot": false,
          "headline": "Relax the upper bound after testing the latest one",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2024-12-02T18:43:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5f8b67b7496effdae0da79cd62e1b6d7fb36997",
          "body": null,
          "is_bot": false,
          "headline": "Remove Dockerfile containing 3rd party image",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2024-12-02T18:43:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60007ac58d94947287ba15be36e83ea1978b4cc1",
          "body": null,
          "is_bot": false,
          "headline": "Some helpers to test Python 3.14 via docker",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2024-11-27T08:08:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d85e8a20b1fd1b28ae9bd8b77bb93fdade6f8b7",
          "body": null,
          "is_bot": false,
          "headline": "SystemAssigned",
          "author_name": "jiasli",
          "author_login": "jiasli",
          "committed_at": "2024-11-21T03:51:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec3c5006852dc2dd75b08c1e572792aa1955d8b0",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch 'release-1.31.1' into dev",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2024-11-21T03:42:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7826ea8ffc998ae66b0f340ebd53e52ddd20d1f0",
          "body": "…)\" (#769)\n\nThis reverts commit 7db6c2ccdd121ad730517ebd5e6195feec06ed41.",
          "is_bot": false,
          "headline": "Revert \"allow MI endpoint changing through environment variable (#754…",
          "author_name": "Ray Luo",
          "author_login": "rayluo",
          "committed_at": "2024-11-19T23:02:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 61,
      "commits_last_year": 40,
      "latest_release_at": "2026-04-08T18:14:52Z",
      "latest_release_tag": "1.36.0",
      "releases_from_tags": true,
      "days_since_last_push": 56,
      "active_weeks_last_year": 22,
      "days_since_latest_release": 107,
      "mean_days_between_releases": 58.2
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "msal",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "Development Status :: 5 - Production/Stable",
            "License :: OSI Approved :: MIT License",
            "Operating System :: OS Independent",
            "Programming Language :: Python",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3 :: Only",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.14",
            "Programming Language :: Python :: 3.9"
          ],
          "ecosystem": "pypi",
          "matches_repo": false,
          "registry_url": "https://pypi.org/project/msal/",
          "is_deprecated": false,
          "latest_version": "1.37.0",
          "repository_url": "https://github.com/AzureAD/microsoft-authentication-library-for-python",
          "versions_count": 73,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 211811791,
          "first_published_at": "2018-12-12T19:53:29.898022Z",
          "latest_published_at": "2026-05-29T19:49:05.561373Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 56
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "sample"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "docs/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 140501,
      "source_files_sampled": 65,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "docs/requirements.txt",
        "requirements.txt",
        "setup.cfg",
        "setup.py"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 9,
        "malicious_count": 0,
        "assessed_package": "pypi:msal@1.37.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "requests",
          "manifest": "setup.cfg",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0.0,<3"
        },
        {
          "name": "PyJWT",
          "manifest": "setup.cfg",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0.0,<3"
        },
        {
          "name": "cryptography",
          "manifest": "setup.cfg",
          "ecosystem": "pypi",
          "version_constraint": ">=2.5,<51"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "rayluo",
          "commits": 1131,
          "avatar_url": "https://avatars.githubusercontent.com/u/821550?v=4"
        },
        {
          "type": "User",
          "login": "abhidnya13",
          "commits": 55,
          "avatar_url": "https://avatars.githubusercontent.com/u/12730799?v=4"
        },
        {
          "type": "User",
          "login": "bgavrilMS",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/12273384?v=4"
        },
        {
          "type": "User",
          "login": "fengga",
          "commits": 7,
          "avatar_url": "https://avatars.githubusercontent.com/u/62267180?v=4"
        },
        {
          "type": "User",
          "login": "DharshanBJ",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/22018221?v=4"
        },
        {
          "type": "User",
          "login": "Avery-Dunn",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/62066438?v=4"
        },
        {
          "type": "User",
          "login": "4gust",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/107404295?v=4"
        },
        {
          "type": "User",
          "login": "tonybaloney",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/1532417?v=4"
        },
        {
          "type": "User",
          "login": "ashok672",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/83938949?v=4"
        },
        {
          "type": "User",
          "login": "chlowell",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/10964656?v=4"
        }
      ],
      "contributors_sampled": 41,
      "top_contributor_share": 0.893
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "RunIssueSentinel.yml",
        "python-package.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "tox.ini"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ebb980f1636e1b3a097ec6dbfd197fb88c5b9e7a",
        "ran_at": "2026-07-25T07:20:40Z",
        "aggregate_score": 4.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/neha-bhargava/microsoft-authentication-library-for-python",
    "host": "github.com",
    "name": "microsoft-authentication-library-for-python",
    "owner": "neha-bhargava"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 43,
      "inputs": {
        "security": 53,
        "vitality": 57,
        "community": 9,
        "governance": 28,
        "engineering": 68
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 57,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "at_risk",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "commits_last_year": 40,
              "human_commit_share": 0.99,
              "days_since_last_push": 56,
              "active_weeks_last_year": 22
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 56 days ago",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 56
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "22/52 weeks with commits",
                "points": 15.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "40 commits in the last year",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 40
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 70,
            "inputs": {
              "releases_count": 61,
              "latest_release_tag": "1.36.0",
              "releases_from_tags": true,
              "days_since_latest_release": 107,
              "mean_days_between_releases": 58.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "61 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 61
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 107 days ago",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 107
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~58.2 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 58.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 9,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 19,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "critical",
        "name": "Sustainability & Governance",
        "value": 28,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 41,
              "top_contributor_share": 0.893
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 89% of commits",
                "points": 2.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 89
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "41 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 41
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 45,
            "inputs": {
              "followers": 6,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "neha-bhargava",
              "public_repos": 10,
              "account_age_days": 2332
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "6 followers of neha-bhargava",
                "points": 6.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 6,
                      "login": "neha-bhargava"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "10 public repos, account ~6 yr old",
                "points": 19.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 10
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 6
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 68,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "tox.ini",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tox.ini"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://stackoverflow.com/questions/tagged/azure-ad-msal+python",
              "has_readme": false,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://stackoverflow.com/questions/tagged/azure-ad-msal+python",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 53,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 4.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the pypi:msal@1.37.0 runtime dependency closure — what installing the published package pulls in — 9 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "pypi:msal@1.37.0",
                  "assessed": 9
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 9,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 9,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 14
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 49,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.465,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "46 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 24.8,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 46,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [
                "docs/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.1,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.01
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "docs/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "tox.ini",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "tox.ini"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "10 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 10,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "1 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 140501,
              "source_files_sampled": 65,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/65 source files over 60KB",
                "points": 52.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 65,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "sample"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "sample",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "sample"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable",
    "pypi package 'msal' points at a different repository (https://github.com/AzureAD/microsoft-authentication-library-for-python); excluded from ecosystem scoring",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T07:20:57.222223Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/neha-bhargava/microsoft-authentication-library-for-python.svg",
  "full_name": "neha-bhargava/microsoft-authentication-library-for-python",
  "license_state": "custom",
  "license_spdx": null
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v1.13.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаPyPI.