Звіт у форматі JSON машиночитний
{
"data": {
"repo": {
"topics": [
"data-encryption",
"data-tagging",
"drm",
"end-to-end-encryption",
"file-encryption",
"go",
"golang",
"open-source",
"opensource",
"opentdf",
"tdf",
"zero-trust",
"zero-trust-security"
],
"is_fork": false,
"size_kb": 92679,
"has_wiki": false,
"homepage": null,
"languages": {
"Go": 6610822,
"Shell": 492709,
"Gherkin": 67517,
"PLpgSQL": 23468,
"Makefile": 8860,
"Dockerfile": 1473,
"Open Policy Agent": 1073
},
"pushed_at": "2026-07-21T21:43:33Z",
"created_at": "2023-12-04T17:34:44Z",
"owner_type": "Organization",
"updated_at": "2026-07-21T21:17:09Z",
"description": "Persistent data centric security that extends owner control wherever data travels",
"is_archived": false,
"is_disabled": false,
"license_spdx": "BSD-3-Clause-Clear",
"default_branch": "main",
"license_spdx_raw": "BSD-3-Clause-Clear",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://opentdf.io",
"name": "OpenTDF",
"type": "Organization",
"login": "opentdf",
"company": null,
"location": null,
"followers": 115,
"avatar_url": "https://avatars.githubusercontent.com/u/90051847?v=4",
"created_at": "2021-09-03T14:13:31Z",
"is_verified": null,
"public_repos": 11,
"account_age_days": 1782
},
"license": {
"state": "standard",
"spdx_id": "BSD-3-Clause-Clear",
"raw_spdx": "BSD-3-Clause-Clear",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "sdk/v0.27.0",
"kind": "other",
"published_at": "2026-07-21T21:17:14Z"
},
{
"tag": "protocol/go/v0.39.0",
"kind": "other",
"published_at": "2026-07-21T15:46:20Z"
},
{
"tag": "lib/fixtures/v0.6.0",
"kind": "other",
"published_at": "2026-07-21T14:19:54Z"
},
{
"tag": "protocol/go/v0.38.0",
"kind": "other",
"published_at": "2026-07-09T16:54:05Z"
},
{
"tag": "service/v0.20.0",
"kind": "other",
"published_at": "2026-07-07T21:16:34Z"
},
{
"tag": "otdfctl/v0.35.0",
"kind": "other",
"published_at": "2026-07-07T14:36:17Z"
},
{
"tag": "sdk/v0.26.0",
"kind": "other",
"published_at": "2026-07-02T20:43:49Z"
},
{
"tag": "protocol/go/v0.37.0",
"kind": "other",
"published_at": "2026-07-01T18:00:27Z"
},
{
"tag": "otdfctl/v0.34.0",
"kind": "other",
"published_at": "2026-07-01T16:42:30Z"
},
{
"tag": "service/v0.19.0",
"kind": "other",
"published_at": "2026-07-01T14:49:14Z"
},
{
"tag": "sdk/v0.25.0",
"kind": "other",
"published_at": "2026-06-29T20:27:57Z"
},
{
"tag": "lib/ocrypto/v0.14.0",
"kind": "other",
"published_at": "2026-06-29T18:02:36Z"
},
{
"tag": "protocol/go/v0.36.0",
"kind": "other",
"published_at": "2026-06-29T17:06:34Z"
},
{
"tag": "protocol/go/v0.35.0",
"kind": "other",
"published_at": "2026-06-25T18:31:03Z"
},
{
"tag": "service/v0.18.0",
"kind": "other",
"published_at": "2026-06-23T18:01:10Z"
},
{
"tag": "sdk/v0.24.0",
"kind": "other",
"published_at": "2026-06-23T16:34:09Z"
},
{
"tag": "lib/ocrypto/v0.13.0",
"kind": "other",
"published_at": "2026-06-23T14:04:22Z"
},
{
"tag": "sdk/v0.23.0",
"kind": "other",
"published_at": "2026-06-18T17:44:42Z"
},
{
"tag": "protocol/go/v0.34.0",
"kind": "other",
"published_at": "2026-06-17T20:02:12Z"
},
{
"tag": "sdk/v0.22.0",
"kind": "other",
"published_at": "2026-06-16T13:34:27Z"
},
{
"tag": "protocol/go/v0.33.1",
"kind": "other",
"published_at": "2026-06-15T17:17:26Z"
},
{
"tag": "protocol/go/v0.33.0",
"kind": "other",
"published_at": "2026-06-15T14:19:56Z"
},
{
"tag": "service/v0.17.0",
"kind": "other",
"published_at": "2026-06-11T18:40:49Z"
},
{
"tag": "otdfctl/v0.33.0",
"kind": "other",
"published_at": "2026-06-10T16:39:57Z"
},
{
"tag": "service/v0.16.0",
"kind": "other",
"published_at": "2026-06-02T15:36:49Z"
},
{
"tag": "sdk/v0.21.0",
"kind": "other",
"published_at": "2026-05-28T19:59:44Z"
},
{
"tag": "lib/ocrypto/v0.12.0",
"kind": "other",
"published_at": "2026-05-27T16:10:11Z"
},
{
"tag": "lib/ocrypto/v0.11.0",
"kind": "other",
"published_at": "2026-05-26T18:28:40Z"
},
{
"tag": "protocol/go/v0.32.0",
"kind": "other",
"published_at": "2026-05-26T15:36:53Z"
},
{
"tag": "otdfctl/v0.32.0",
"kind": "other",
"published_at": "2026-05-20T14:56:11Z"
},
{
"tag": "protocol/go/v0.31.0",
"kind": "other",
"published_at": "2026-05-19T22:00:53Z"
},
{
"tag": "sdk/v0.20.0",
"kind": "other",
"published_at": "2026-05-12T18:28:16Z"
},
{
"tag": "protocol/go/v0.30.0",
"kind": "other",
"published_at": "2026-05-11T17:53:17Z"
},
{
"tag": "service/v0.15.0",
"kind": "other",
"published_at": "2026-05-06T23:37:49Z"
},
{
"tag": "sdk/v0.19.0",
"kind": "other",
"published_at": "2026-05-06T22:12:31Z"
},
{
"tag": "protocol/go/v0.29.0",
"kind": "other",
"published_at": "2026-05-05T21:52:47Z"
},
{
"tag": "sdk/v0.18.0",
"kind": "other",
"published_at": "2026-04-29T19:34:03Z"
},
{
"tag": "protocol/go/v0.28.0",
"kind": "other",
"published_at": "2026-04-29T15:25:03Z"
},
{
"tag": "sdk/v0.17.0",
"kind": "other",
"published_at": "2026-04-24T17:00:25Z"
},
{
"tag": "protocol/go/v0.27.0",
"kind": "other",
"published_at": "2026-04-24T14:22:59Z"
},
{
"tag": "otdfctl/v0.31.0",
"kind": "other",
"published_at": "2026-04-22T19:04:53Z"
},
{
"tag": "protocol/go/v0.26.0",
"kind": "other",
"published_at": "2026-04-22T18:32:35Z"
},
{
"tag": "service/v0.14.0",
"kind": "other",
"published_at": "2026-04-21T19:04:53Z"
},
{
"tag": "lib/identifier/v0.4.0",
"kind": "other",
"published_at": "2026-04-21T17:59:16Z"
},
{
"tag": "sdk/v0.16.0",
"kind": "other",
"published_at": "2026-04-21T17:04:04Z"
},
{
"tag": "protocol/go/v0.25.0",
"kind": "other",
"published_at": "2026-04-20T15:44:04Z"
},
{
"tag": "protocol/go/v0.24.0",
"kind": "other",
"published_at": "2026-04-17T17:38:38Z"
},
{
"tag": "protocol/go/v0.23.0",
"kind": "other",
"published_at": "2026-04-07T19:32:28Z"
},
{
"tag": "protocol/go/v0.22.0",
"kind": "other",
"published_at": "2026-04-01T15:39:14Z"
},
{
"tag": "protocol/go/v0.21.0",
"kind": "other",
"published_at": "2026-03-26T20:51:32Z"
},
{
"tag": "sdk/v0.15.0",
"kind": "other",
"published_at": "2026-03-23T14:24:55Z"
},
{
"tag": "protocol/go/v0.20.0",
"kind": "other",
"published_at": "2026-03-19T17:22:05Z"
},
{
"tag": "lib/identifier/v0.3.0",
"kind": "other",
"published_at": "2026-03-16T16:15:07Z"
},
{
"tag": "protocol/go/v0.19.0",
"kind": "other",
"published_at": "2026-03-12T20:06:53Z"
},
{
"tag": "protocol/go/v0.18.0",
"kind": "other",
"published_at": "2026-03-12T16:30:43Z"
},
{
"tag": "sdk/v0.14.0",
"kind": "other",
"published_at": "2026-03-11T19:24:01Z"
},
{
"tag": "protocol/go/v0.17.0",
"kind": "other",
"published_at": "2026-03-06T17:49:50Z"
},
{
"tag": "service/v0.13.0",
"kind": "other",
"published_at": "2026-02-18T19:22:43Z"
},
{
"tag": "sdk/v0.13.0",
"kind": "other",
"published_at": "2026-02-17T22:18:39Z"
},
{
"tag": "protocol/go/v0.16.0",
"kind": "other",
"published_at": "2026-02-17T20:42:07Z"
},
{
"tag": "lib/ocrypto/v0.10.0",
"kind": "other",
"published_at": "2026-02-17T17:15:30Z"
},
{
"tag": "lib/fixtures/v0.5.0",
"kind": "other",
"published_at": "2026-01-28T17:15:57Z"
},
{
"tag": "service/v0.12.0",
"kind": "other",
"published_at": "2026-01-27T22:24:52Z"
},
{
"tag": "sdk/v0.12.0",
"kind": "other",
"published_at": "2026-01-27T14:37:16Z"
},
{
"tag": "lib/ocrypto/v0.9.0",
"kind": "other",
"published_at": "2026-01-26T21:06:31Z"
},
{
"tag": "protocol/go/v0.15.0",
"kind": "other",
"published_at": "2026-01-26T17:53:37Z"
},
{
"tag": "sdk/v0.11.0",
"kind": "other",
"published_at": "2026-01-06T18:55:41Z"
},
{
"tag": "lib/ocrypto/v0.8.0",
"kind": "other",
"published_at": "2025-12-19T19:51:24Z"
},
{
"tag": "lib/fixtures/v0.4.0",
"kind": "other",
"published_at": "2025-12-19T17:13:27Z"
},
{
"tag": "protocol/go/v0.14.0",
"kind": "other",
"published_at": "2025-12-19T16:47:06Z"
},
{
"tag": "service/v0.8.2",
"kind": "other",
"published_at": "2025-11-21T15:19:36Z"
},
{
"tag": "service/v0.11.6",
"kind": "other",
"published_at": "2025-11-19T18:53:14Z"
},
{
"tag": "service/v0.11.5",
"kind": "other",
"published_at": "2025-11-17T15:39:12Z"
},
{
"tag": "service/v0.11.4",
"kind": "other",
"published_at": "2025-11-14T20:52:30Z"
},
{
"tag": "service/v0.11.3",
"kind": "other",
"published_at": "2025-11-07T17:46:40Z"
},
{
"tag": "sdk/v0.10.1",
"kind": "other",
"published_at": "2025-11-04T20:52:40Z"
},
{
"tag": "service/v0.11.2",
"kind": "other",
"published_at": "2025-10-30T21:11:18Z"
},
{
"tag": "service/v0.11.1",
"kind": "other",
"published_at": "2025-10-29T19:30:04Z"
},
{
"tag": "service/v0.11.0",
"kind": "other",
"published_at": "2025-10-22T22:20:08Z"
},
{
"tag": "sdk/v0.10.0",
"kind": "other",
"published_at": "2025-10-21T22:50:16Z"
},
{
"tag": "service/v0.10.1",
"kind": "other",
"published_at": "2025-10-17T15:45:01Z"
},
{
"tag": "protocol/go/v0.13.0",
"kind": "other",
"published_at": "2025-10-16T19:12:47Z"
},
{
"tag": "lib/ocrypto/v0.7.0",
"kind": "other",
"published_at": "2025-10-16T16:48:50Z"
},
{
"tag": "protocol/go/v0.12.0",
"kind": "other",
"published_at": "2025-10-14T21:19:01Z"
},
{
"tag": "sdk/v0.9.0",
"kind": "other",
"published_at": "2025-10-10T17:30:49Z"
},
{
"tag": "lib/identifier/v0.2.0",
"kind": "other",
"published_at": "2025-09-26T22:01:47Z"
},
{
"tag": "sdk/v0.8.0",
"kind": "other",
"published_at": "2025-09-19T15:48:42Z"
},
{
"tag": "protocol/go/v0.11.0",
"kind": "other",
"published_at": "2025-09-18T21:20:35Z"
},
{
"tag": "service/v0.10.0",
"kind": "other",
"published_at": "2025-09-17T22:19:42Z"
},
{
"tag": "lib/identifier/v0.1.0",
"kind": "other",
"published_at": "2025-09-17T15:39:38Z"
},
{
"tag": "protocol/go/v0.10.0",
"kind": "other",
"published_at": "2025-09-16T20:56:54Z"
},
{
"tag": "protocol/go/v0.6.3",
"kind": "other",
"published_at": "2025-09-15T14:20:49Z"
},
{
"tag": "protocol/go/v0.9.0",
"kind": "other",
"published_at": "2025-09-12T14:53:37Z"
},
{
"tag": "lib/ocrypto/v0.6.0",
"kind": "other",
"published_at": "2025-09-11T16:58:33Z"
},
{
"tag": "protocol/go/v0.8.0",
"kind": "other",
"published_at": "2025-09-04T17:40:20Z"
},
{
"tag": "lib/ocrypto/v0.5.0",
"kind": "other",
"published_at": "2025-09-04T17:33:38Z"
},
{
"tag": "lib/ocrypto/v0.4.0",
"kind": "other",
"published_at": "2025-09-03T13:42:04Z"
},
{
"tag": "service/v0.9.0",
"kind": "other",
"published_at": "2025-08-27T18:07:00Z"
},
{
"tag": "sdk/v0.7.0",
"kind": "other",
"published_at": "2025-08-26T16:29:11Z"
},
{
"tag": "service/v0.8.1",
"kind": "other",
"published_at": "2025-08-12T17:53:30Z"
}
],
"recent_commits": [
{
"oid": "5bae1eb7a3b9d19d67845ac8239447eecf25e8ba",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.27.0](https://github.com/opentdf/platform/compare/sdk/v0.26.0...sdk/v0.27.0)\n(2026-07-21)\n\n\n### Features\n\n* **policy:** Add UnsafeUpdateKey rpc.\n([#3728](https://github.com/opentdf/platform/issues/3728))\n([c89b193](https://github.com/opentdf\n[…]\noogleapis/release-please#release-please).\n\n---------\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>\nCo-authored-by: Chris Reed <creed@virtru.com>",
"is_bot": true,
"headline": "chore(main): release sdk 0.27.0 (#3759)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-21T20:59:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9ac1640df7d8447cdaaa540d0eacc98daa3c832d",
"body": "### Proposed Changes\n\n1.) Update fixtures to v0.6.0\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### Testing Instructions\n\n\n\n<!-- This is an auto-generated comment: release notes\n[…]\nnd\nconsistency across service and integration environments.\n - No changes to user-facing functionality or application behavior.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "feat(core): Update fixtures (#3766)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-07-21T19:50:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e5d1489273b81b3e37ab88c32f1874907585404",
"body": "### Proposed Changes\n\n*\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### Testing Instructions\n\n\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Chores**\n* Updated the Go SDK’s platform protocol dependency to the latest\nsupported version.\n\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore(sdk): Update protocol/go. (#3761)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-07-21T16:42:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b20967825c4e523437e09f7a8fdb696619cb66c8",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.39.0](https://github.com/opentdf/platform/compare/protocol/go/v0.38.0...protocol/go/v0.39.0)\n(2026-07-21)\n\n\n### Features\n\n* **policy:** Add name and manager lookup\n([#3753](https://github.com/opentdf/platform/issues/3753))\n([bfbc65d](https:/\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.39.0 (#3748)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-21T15:30:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab1e1f92b16347cee59f21c6b76445a805dfa503",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.6.0](https://github.com/opentdf/platform/compare/lib/fixtures/v0.5.0...lib/fixtures/v0.6.0)\n(2026-07-21)\n\n\n### Bug Fixes\n\n* **authz:** use standard Keycloak token exchange\n([#3754](https://github.com/opentdf/platform/issues/3754))\n([de9ae0d]\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release lib/fixtures 0.6.0 (#3059)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-21T14:03:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c89b1933e3931bc1984711f2268c8adedd786db4",
"body": "## Summary\n\n- Add a new `UnsafeUpdateKey` proto, to enable the following flows:\n - Switching a key from `public_key` <-> `remote`\n - Switching provider configurations for a key\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n- **New Features\n[…]\nequest fields, response\nschemas, endpoint details, and safety warnings.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Chris Reed <creed@virtru.com>",
"is_bot": false,
"headline": "feat(policy): Add UnsafeUpdateKey rpc. (#3728)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-07-21T13:50:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "de9ae0dde552267470b44c4e09854034cbc70e84",
"body": "## Summary\n- Upgrade local/test standard Keycloak runtime paths to\n`ghcr.io/opentdf/keycloak-standard:26.4.0`, including\n`docker-compose.yaml`, OAuth testcontainers, and ERS Keycloak\nintegration tests.\n- Provision standard Keycloak token exchange by enabling\n`standard.token.exchange.enabled` on requ\n[…]\ned service README examples for standard token exchange\nbehavior.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nCo-authored-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": false,
"headline": "fix(authz): use standard Keycloak token exchange (#3754)",
"author_name": "Jp Ayyappan",
"author_login": "jp-ayyappan",
"committed_at": "2026-07-21T12:16:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "85a0e95ed0599fb86f95ae126d7d433e42816127",
"body": "### Proposed Changes\n\n*\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### Testing Instructions\n\n\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Su\n[…]\nr legacy name and manager lookup\noptions.\n* Improved consistency between the service definition and generated API\ndocumentation.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore(policy): Update key management api docs. (#3757)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-07-20T21:25:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "76305b04af3f1129dbe1ed337ef731de54be0457",
"body": "### Proposed Changes\n\n* Add a `Hook` extension point to `pkg/handlers` so callers can inject\nSDK options that depend on the resolved profile without replicating any\nof the profile resolution or credential validation flow.\n* Rename the internal `handlerOptsFunc` to the exported `HandlerOption`\nso dow\n[…]\nr hook registration, execution order,\nconfiguration context, and edge cases.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Ron Elliott <ron.elliott@virtru.com>",
"is_bot": false,
"headline": "feat(cli): expose handler hook for injecting SDK options (#3755)",
"author_name": "Ron Elliott",
"author_login": "ronelliott",
"committed_at": "2026-07-20T14:28:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bfbc65d6f56a7d28144379f535bd82ce61e62bdd",
"body": "1.) Add a new `name` + `manager` lookup to the\n`GetProviderConfiguration` rpc.\n\n## Problem\n\nCurrently if a `manager` is not provided when searching by `name` you\ncan receive non-deterministic results from the API, since our db\nconstraint is (name + manager). Meaning if I have combinations of the\nsam\n[…]\nPC and OpenAPI documentation for the new lookup format.\n* Marked the legacy name- and manager-based lookup fields as deprecated.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "feat(policy): Add name and manager lookup (#3753)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-07-20T14:07:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21e95e04c9f5903dc4c437d12ea790bbbf20bbb1",
"body": "### Proposed Changes\n\nImplements the `DynamicValueMapping` policy primitive end to end (the\nmodel chosen by the spike / ADR 0005). It raises entitlement authority\nfrom a concrete `AttributeValue` to the `AttributeDefinition`: a single\nmapping entitles dynamically-requested values by comparing the re\n[…]\n ADR/spike and schema/migration docs for dynamic value mappings.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): dynamic attribute value entitlement mappings (#3568)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-17T04:29:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "718320b2bbe1a03041ed70bb3b20eb3c30cf64fa",
"body": "## Summary\n- add optional subject mappings to CreateAttributeValue requests\n- create inline subject mappings in the same attribute-value transaction\npath\n\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n## Summary by CodeRabbit\n\n* **New Features**\n* Attribute values can n\n[…]\nttribute value and subject\nmappings use mismatched namespaces.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "feat(policy): create subject mappings with attribute values (#3741)",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-07-16T20:44:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "54d5c78bdf7a868e00ee83308a4593c86d1d4095",
"body": "…3749)\n\n## Summary\n- add service-level NamespacedPolicy validation tests for subject\nmappings and subject condition sets\n- add matching validation tests for actions, registered resources, and\nresource mappings\n- keep resource mapping group coverage at protovalidate level because\nnamespace is always \n[…]\nments and consistent error\nresponses for namespaced policies.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "chore(policy): tests for namespaced policy config flag enforcement (#…",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-07-15T19:31:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6cc2a1030eadd3b9e4ae8a1fa8d62854aa7b4182",
"body": "…egration (#3711)\n\nBumps [golang.org/x/net](https://github.com/golang/net) from 0.52.0 to\n0.55.0.\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/golang/net/commit/7770ec48d03fec35e378665337b4faca93c38423\"><code>7770ec4</code></a>\ngo.mod: update golang.org/x dependencies</l\n[…]\n0.52.0...v0.55.0\">compare\nview</a></li>\n</ul>\n</details>\n<br />\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golang.org/x/net from 0.52.0 to 0.55.0 in /test/int…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-15T18:42:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6dd5f649347fb2314c6090ea6d090a5c673d58a6",
"body": "…#3750)\n\n## Problem\n\nThe reusable `platform-xtest` job (e.g. [run\n29361028930](https://github.com/opentdf/platform/actions/runs/29361028930/job/87180916345?pr=3581),\njob `xct (v0.9.0, go@main)`) fails in **Check out and start up\nplatform** with:\n\n```\nError: stat opentdf.yaml: no such file or directo\n[…]\n even when optional post-quantum key files are unavailable.\n * Updated validation coverage for containerized startup scenarios.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(ci): always generate opentdf.yaml even when PQC keys are absent (…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-07-15T14:02:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "baba70913cfe615448ab05b465ecdaf037791889",
"body": "…ead APIs (#3745)\n\n## Summary\n\nDeprecates the `GetAttributeValuesByFqns` RPC (`option deprecated =\ntrue`), steering new use to the narrow read APIs:\n- `GetKeyMappingsByFqns` for client-side key splits\n- `GetEntitleableAttributesByFqns` for server-side entitlement\nresolution\n\nNon-breaking: the RPC st\n[…]\nxclusions to account for generated and deprecated API\nwrappers.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): deprecate GetAttributeValuesByFqns in favor of narrow r…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-13T12:53:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f32839689e257338babb91903298b3b0256385c",
"body": "## Summary\n\nPopulates the `namespace` field on\n`GetEntitleableAttributesByFqnsResponse.EntitleableDefinition`,\nconsuming the field added to `protocol/go` in #3727 (released as\nv0.38.0).\n\n- Bumps `service/go.mod` protocol/go v0.37.0 → v0.38.0.\n- `GetEntitleableAttributesByFqns` now sets each definiti\n[…]\nity and\nexpected empty grant/key fields in attribute responses.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): populate entitleable definition namespace (#3737)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-09T20:24:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "14dbb95c7dfa376ab7cde33517eb2e0e9768212d",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.38.0](https://github.com/opentdf/platform/compare/protocol/go/v0.37.0...protocol/go/v0.38.0)\n(2026-07-09)\n\n\n### Features\n\n* **policy:** add entitleable namespace field and narrow-read-API doc\ncorrections ([#3727](https://github.com/opentdf/p\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.38.0 (#3735)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-09T16:38:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f59431a8a632f9030187b664e03a48815709c361",
"body": "… CLI test cases (#3729)\n\n### Proposed Changes\n\nAlign recent CLI test cases changes with the mapping file for TestRail\nresults integration (kas-keys and namespaces updates).\n\nOriginal JIRA integration ticket: AB-2044\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or upda\n[…]\ncal-mode key\nalgorithms.\n* Added support mappings for namespace listing options, including\nsort/order flags and search behavior.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore(ci): AB-2044 - update TestRail mapping file with recently added…",
"author_name": "sievdokymov-virtru",
"author_login": "sievdokymov-virtru",
"committed_at": "2026-07-09T14:54:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0fc2f01fbb0d75b04d2a5dcb94e5acdea9f62b6f",
"body": "… corrections (#3727)\n\n## Summary\n\nProto shape + docs for the narrow attribute read APIs (PR 1 of the proto\n→ service → deprecation sequence).\n\n**Shape change**\n- Adds `namespace` (a `policy.Namespace`, identity only) to\n`GetEntitleableAttributesByFqnsResponse.EntitleableDefinition`. The\nAccess PDP \n[…]\n, helping clients work with namespaced policy data more\neasily.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): add entitleable namespace field and narrow-read-API doc…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-09T14:26:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9c32554958aef3572728c0465a047c7779a06d95",
"body": "…y (#3732)\n\n### Proposed Changes\n\n* make the platform service logger available to the casbin authz custom\nrole provider factories\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n###\n[…]\n helping with troubleshooting and reliability.\n* Updated related auth and server tests to match the new initialization\nbehavior.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(core): Pass the platform logger to the authz role provider factor…",
"author_name": "Elizabeth Healy",
"author_login": "elizabethhealy",
"committed_at": "2026-07-08T20:24:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dadccc2aedcbcb88bb3a43a6b31adec6aa2475fb",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.20.0](https://github.com/opentdf/platform/compare/service/v0.19.0...service/v0.20.0)\n(2026-07-07)\n\n\n### ⚠ BREAKING CHANGES\n\n* **policy:** undo subject mapping operator decomposition\n([#3685](https://github.com/opentdf/platform/issues/3685))\n\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release service 0.20.0 (#3702)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-07T20:58:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "29bea68a09558e70a38d8749b096d55a2a5995a3",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.35.0](https://github.com/opentdf/platform/compare/otdfctl/v0.34.0...otdfctl/v0.35.0)\n(2026-07-07)\n\n\n### Bug Fixes\n\n* **cli:** Pull namespace for OTs from attr val\n([#3725](https://github.com/opentdf/platform/issues/3725))\n([2146d0f](https://\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release otdfctl 0.35.0 (#3726)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-07T14:19:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eaee9b2da0191129e0d7a0413e6ea7294cad5b63",
"body": "## Proposed Changes\n\nService implementation of the narrow attribute read APIs. Stacked on\n#3634 (proto + generated code).\n\n- `GetKeyMappingsByFqns` / `GetEntitleableAttributesByFqns` DB methods\nwith value > definition > namespace key resolution (mirrors\n`sdk/granter.go`).\n- New lean `getSubjectMappi\n[…]\n value-level mappings take priority\nover higher-level fallbacks.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): implement narrow attribute read APIs (#3697)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-07T13:06:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2146d0f6774882c83887c7c5004159859e408f5c",
"body": "## Summary\n\nFixes namespaced policy migration for obligation triggers so the target\nnamespace is derived from the trigger’s attribute value, not the\nobligation\n value.\n\n## Changes\n\n- Updated obligation trigger target derivation in otdfctl\nnamespaced-policy migration.\n - Removed the now-unused obli\n[…]\n-trigger\nmigration and namespace resolution.\n* Added a new test to verify trigger targeting uses attribute-based\nnamespace data.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(cli): Pull namespace for OTs from attr val (#3725)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-07-06T18:51:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "95d7aa445a9cdec149ab17a9a62f56577688136c",
"body": "…#3721)\n\n## Summary\n\nBumps the two OpenTDF module pins in `service/go.mod` to their latest\nreleases:\n\n- `github.com/opentdf/platform/protocol/go` v0.36.0 → v0.37.0\n- `github.com/opentdf/platform/sdk` v0.25.0 → v0.26.0\n\n`main`'s service code already references `protocol/go` v0.37.0\n`sdkconnect` types\n[…]\newer versions, which may\ninclude stability and compatibility improvements.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "fix(deps): bump protocol/go to 0.37.0 and sdk to 0.26.0 in /service (…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-06T14:16:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8b6393436568b7dc2874479b5c3bd6d53109e658",
"body": "…3720)\n\n## Changes\n- Include attribute value FQN in GetSubjectMapping responses.\n- Align GetSubjectMapping attribute value shape with\nListSubjectMappings.\n- Assert subject mapping lookups return the embedded attribute value\nFQN.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n[…]\nribute values, reducing mismatches in displayed mapping\ndata.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "fix(policy): include attribute value fqn in subject mapping lookup (#…",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-07-02T21:58:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ce01c2cbe229759f160926af98235e4f09aef98",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.26.0](https://github.com/opentdf/platform/compare/sdk/v0.25.0...sdk/v0.26.0)\n(2026-07-02)\n\n\n### Features\n\n* **policy:** add narrow attribute read API protos and generated code\n([#3634](https://github.com/opentdf/platform/issues/3634))\n([5726\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release sdk 0.26.0 (#3703)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-02T20:27:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7a2320b30c7914b7e54600fc2390d41ce495a76b",
"body": "## Proposed Changes\n\nSwitch the SDK granter to resolve key splits through the new\n`GetKeyMappingsByFqns` RPC instead of walking the full attribute set\nfrom `GetAttributeValuesByFqns`.\n\n- `newGranterFromService` now calls `GetKeyMappingsByFqns` and feeds the\nreturned per-value rule + effective KAS ke\n[…]\nng and legacy grant inputs producing the\nexpected combined plan.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(sdk): resolve key splits via GetKeyMappingsByFqns (#3699)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-02T19:56:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1a812217eee7f1b3086c10a187a5965c95429b1f",
"body": "## Summary\n- Fix spelling and minor grammar issues in Markdown documentation and\nYAML config comments\n- Keep generated docs, code, proto, scripts, and build files out of this\nPR\n\n## Testing\n- git diff --check origin/main...HEAD\n- uvx codespell <changed Markdown/YAML files>\n\nSigned-off-by: jp-ayyappan <jp@as2max.com>",
"is_bot": false,
"headline": "chore(docs): fix typos in plaintext files (#3716)",
"author_name": "Jp Ayyappan",
"author_login": "jp-ayyappan",
"committed_at": "2026-07-02T18:44:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4277e9619491d3177ccafebbdf8c397378fe05ce",
"body": "…o 0.37.0 in /sdk (#3707)\n\nBumps `github.com/opentdf/platform/protocol/go` from 0.36.0 to 0.37.0 in\n`/sdk`.\n\nprotocol/go v0.37.0 (released from main) contains the narrow\nattribute-read RPC types (`GetKeyMappingsByFqns`,\n`GetEntitleableAttributesByFqns`). The sdk already consumes them via the\ngenerat\n[…]\nit\n\n* **Chores**\n * Updated an internal Go dependency to a newer version.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "fix(deps): bump github.com/opentdf/platform/protocol/go from 0.36.0 t…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-02T13:21:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "327f9a4af33fe6b5656b075f674effbfb97044d2",
"body": "### Proposed Changes\n\n* During CLI e2e test teardown, removes double 'profiles' command\ninvocation\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### Testing Instructions\n\n\n\n<!-- T\n[…]\nr profile scenarios (create, list, get, delete, defaults,\nendpoints, migrate, cleanup) with the revised command invocation style.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore(ci): otdfctl profiles e2e test teardown fix (#3700)",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-07-01T17:47:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "feab4e8381bd9a8b4353e79624c5e3b8c7f811e5",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.37.0](https://github.com/opentdf/platform/compare/protocol/go/v0.36.0...protocol/go/v0.37.0)\n(2026-07-01)\n\n\n### ⚠ BREAKING CHANGES\n\n* **policy:** undo subject mapping operator decomposition\n([#3685](https://github.com/opentdf/platform/issues\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.37.0 (#3701)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-01T17:43:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "572672007abd7e0a3598f8303661487cfb0d2db5",
"body": "… (#3634)\n\n## Proposed Changes\n\nProto and generated-code portion of the narrow attribute read APIs,\nsplit out so the heavy service implementation lands separately and\n`protocol/go` releases cleanly.\n\nAdds two RPCs to `AttributesService`:\n- **`GetKeyMappingsByFqns`** — per value FQN: the attribute ru\n[…]\nollow-up feature branch: switch the SDK granter to consume\n`GetKeyMappingsByFqns` and add an xtest proving key-split parity with\nthe previous SDK.\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): add narrow attribute read API protos and generated code…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-01T17:06:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67300d8a5f82aec79330ee02f0c03eb027bf735e",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.34.0](https://github.com/opentdf/platform/compare/otdfctl/v0.33.0...otdfctl/v0.34.0)\n(2026-07-01)\n\n\n### Features\n\n* **cli:** Add search to cli\n([#3616](https://github.com/opentdf/platform/issues/3616))\n([1fb2549](https://github.com/opentdf/p\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release otdfctl 0.34.0 (#3600)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-01T16:26:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "84f3b92a4f82dd527ef93de3361ec22990eae479",
"body": "## Summary\n\nUndo the subject mapping operator decomposition while keeping the\n`DynamicValueMapping` feature. The decomposed evaluator was never\nadopted on\n`main` (`EvaluateCondition` still switches on `operator`), so the added\nenum and\nfield surface is unused complexity.\n\n## Changes\n\n- Remove `Condi\n[…]\nved outdated condition and enum references from generated docs.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy)!: undo subject mapping operator decomposition (#3685)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-07-01T15:20:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "794f9dbbd4758adde69d52f59107161cf3cbc7ba",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.19.0](https://github.com/opentdf/platform/compare/service/v0.18.0...service/v0.19.0)\n(2026-06-30)\n\n\n### Features\n\n* **authz:** Authz-v2 docs\n([#3670](https://github.com/opentdf/platform/issues/3670))\n([4ab7fe8](https://github.com/opentdf/pla\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release service 0.19.0 (#3662)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-07-01T14:33:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0612ea897264e3c621ce076029a5e1e3f2d3971e",
"body": "…ions (DSPX-3397) (#3667)\n\n## Summary\n\nPart of DSPX-3397. Adds two independent inputs to the composite test\nactions so xtest can exercise DPoP end-to-end:\n\n- `dpop-challenge-enabled` (default `false`) → sets\n`server.auth.dpop.require_nonce: true`.\n- When receiving a resource request (i.e. a rewrap o\n[…]\ndation to accept only `true` or `false` for the new\nDPoP options.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": false,
"headline": "feat(ci): add DPoP nonce-challenge and enforcement inputs to test act…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-30T15:43:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed2a0a5cb69e0643164cd04f8be5ee7e76f5f0dc",
"body": "Removes redundant and verbose sections from `AGENTS.md` and `CLAUDE.md`\nto keep the agent instructions concise.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Documentation**\n* Updated repository contribution guidance to reflect the Go work\n[…]\ns and now call for signed commits.\n* Consolidated one guidance file into a single reference to the main\nrepository instructions.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore: simplify AGENTS.md / CLAUDE.md (#3692)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-30T15:21:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "daebadeaa8401fcd14a7faabfa6dd6aaca22aea8",
"body": "…7) (#3666)\n\n## Summary\n\nPart of DSPX-3397. Consolidates DPoP config: enforcement lived at the\ntop of the auth block (`server.auth.enforceDPoP`) while every other DPoP\nknob is nested under `server.auth.dpop`. This adds\n`server.auth.dpop.enforce` and deprecates the old top-level field.\n\n> **Stacked P\n[…]\n the migration window.\n\n## Testing\n- `go test ./service/internal/auth/...` passes (incl. the migration\ntest).\n- `golangci-lint` adds no new issues.\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": false,
"headline": "feat(authz): move DPoP enforcement into dpop.enforce config (DSPX-339…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-30T14:47:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f073b6a8fac4d0628253f4835e7b2dcaf40a4e8",
"body": "verifySRTSignature assumed RS256, so a signed request token signed with\nan EC DPoP key (ES256/384/512) failed verification with 'unable to\nverify request token'. No shipping SDK hit this yet because clients\ndecrypt via Bearer, but a DPoP-bound rewrap with an EC key cannot\nsucceed.\n\nRead the algorith\n[…]\ns.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: dmihalcik <dmihalcik@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(kas): verify rewrap SRT with its actual JWS algorithm (#3691)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-30T14:42:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d6b01c938054e99d747d5d1ee9f02422e7633f4f",
"body": "Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n6.6.1 to 8.1.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/astral-sh/setup-uv/releases\">astral-sh/setup-uv's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v8.1.0 🌈 New input <code>no-proj\n[…]\n\n---------\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": true,
"headline": "chore(ci): bump astral-sh/setup-uv from 6.6.1 to 8.1.0 (#3339)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T11:01:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ec2dc5cea80bc9b8ca614de1f9b66cbea0032cd1",
"body": "… in /otdfctl (#3690)\n\nBumps\n[github.com/opentdf/platform/sdk](https://github.com/opentdf/platform)\nfrom 0.22.0 to 0.25.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/sdk's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/sdk from 0.22.0 to 0.25.0…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T22:10:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b7f77aabff010a95b97e8c087f2475cd7c11003",
"body": "… in /service (#3687)\n\nBumps\n[github.com/opentdf/platform/sdk](https://github.com/opentdf/platform)\nfrom 0.24.0 to 0.25.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/sdk's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/sdk from 0.24.0 to 0.25.0…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T21:50:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0ac621acf31e201dc7fb23b93cb84d5e7344d48e",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.25.0](https://github.com/opentdf/platform/compare/sdk/v0.24.0...sdk/v0.25.0)\n(2026-06-29)\n\n\n### Features\n\n* **kas:** Adds FIPS-203 wrap with ML-KEM-768/1024\n([#3652](https://github.com/opentdf/platform/issues/3652))\n([06f30ef](https://github\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release sdk 0.25.0 (#3680)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-29T20:10:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78366f7c9c6f4ef251aa0b1084533580843fb942",
"body": "…o 0.14.0 in /sdk (#3684)\n\nBumps\n[github.com/opentdf/platform/lib/ocrypto](https://github.com/opentdf/platform)\nfrom 0.13.0 to 0.14.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/lib/ocrypto's\nrelea\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/lib/ocrypto from 0.13.0 t…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T18:28:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "80334205c0bd39a346c7abb276462d902eaa6286",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.14.0](https://github.com/opentdf/platform/compare/lib/ocrypto/v0.13.0...lib/ocrypto/v0.14.0)\n(2026-06-29)\n\n\n### Features\n\n* **kas:** Adds FIPS-203 wrap with ML-KEM-768/1024\n([#3652](https://github.com/opentdf/platform/issues/3652))\n([06f30ef\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release lib/ocrypto 0.14.0 (#3678)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-29T17:45:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b6cc5cda2ea9bc6a74f53c1ecf5de71aed514e13",
"body": "…o 0.36.0 in /sdk (#3681)\n\nBumps\n[github.com/opentdf/platform/protocol/go](https://github.com/opentdf/platform)\nfrom 0.34.0 to 0.36.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/protocol/go's\nrelea\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/protocol/go from 0.34.0 t…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T17:33:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b1fa5e87d38664a7218f94dfcfb6b8878967df79",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.36.0](https://github.com/opentdf/platform/compare/protocol/go/v0.35.0...protocol/go/v0.36.0)\n(2026-06-29)\n\n\n### Features\n\n* **kas:** Adds FIPS-203 wrap with ML-KEM-768/1024\n([#3652](https://github.com/opentdf/platform/issues/3652))\n([06f30ef\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.36.0 (#3679)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-29T16:49:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "06f30ef7f2eb6a5dce587efa906d4bd70b7cd8dc",
"body": "## ML-KEM 768/1024\n\nThe primary motivation for this work is ML-KEM 768 and 1024 support for\nkey wrapping and KAS/policy algorithm selection. These provide FIPS 3\ncompliant NIST 203 implementations, which will provide post-quantum\nresistance for TDFs created with this algorithm, just as the hybrids d\n[…]\ntation.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(kas): Adds FIPS-203 wrap with ML-KEM-768/1024 (#3652)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-29T15:11:19Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d7caacdc8e2d459baeee3af81ecf8a7cf6fea727",
"body": "…3397) (#3665)\n\n## Summary\n\nPart of DSPX-3397 (split out from the SDK DPoP work). Server-side fix\nonly.\n\nThe auth handlers previously attached a `WWW-Authenticate` response\nheader **only** when the failure was a `*DPoPNonceError`\n(`use_dpop_nonce`). Every other DPoP proof rejection — tampered `htu`\n\n[…]\nplus end-to-end challenge header assertions for\nboth HTTP and Connect flows.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": false,
"headline": "fix(authz): emit WWW-Authenticate DPoP on all proof rejections (DSPX-…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-26T19:46:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "06678e3670f6d9eb54501d9c9c40c4242b2c5e8c",
"body": "### Proposed Changes\n\n* Enhances cukes authorization test covererage to cover: attribute\nrules, enhanced obligations coverage, enhanced RR coverage, multi\nresource decisions\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ \n[…]\ni-resource decision request scenarios and assertions\n* Registered resource decisioning and attribute rules evaluation test\ncases\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "feat(ci): Enhance authorization bdd test coverage (#3298)",
"author_name": "Elizabeth Healy",
"author_login": "elizabethhealy",
"committed_at": "2026-06-25T22:39:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4ab7fe88c97c8bffdd168a92759b1dbdd1874f20",
"body": "1.) Initial guidance and documentation of Authorization V2\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Documentation**\n* Expanded and reorganized the auth package guide for easier navigation.\n* Added clearer explanations of authorization\n[…]\nt more clearly.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nCo-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(authz): Authz-v2 docs (#3670)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-25T20:19:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "03593e612859d993f51b95ba98d3bb3ddade26a8",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.35.0](https://github.com/opentdf/platform/compare/protocol/go/v0.34.0...protocol/go/v0.35.0)\n(2026-06-25)\n\n\n### Bug Fixes\n\n* **policy:** undo Condition.operator deprecation\n([#3668](https://github.com/opentdf/platform/issues/3668))\n([917f66a\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.35.0 (#3669)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-25T18:13:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "917f66a3dc3fa4df63d9b1a901ff75d88234d3f2",
"body": "## Summary\n\nRemoves the `deprecated = true` annotation from `Condition.operator` in\n`service/policy/objects.proto` and restores its original doc comment,\nthen regenerates `protocol/go` and the policy docs.\n\n## Why\n\n`Condition.operator` was deprecated in #3580 in favor of the decomposed\n`comparison` \n[…]\n.\n * Clarified that `operator` is the evaluation operator for a relation.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "fix(policy): undo Condition.operator deprecation (#3668)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-06-25T16:17:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41cee41ac9cee8c6d0730ca7c165ac9c22242ac4",
"body": "1.) Add `kas_uri` dimension to `ListKeys` rpc.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **New Features**\n * Added support for listing KAS keys through the registry API.\n* Expanded access control so key listings can be authorized by KAS\n[…]\ng Fixes**\n* Improved authorization handling for empty, missing, or invalid list\nresponses to prevent incorrect access decisions.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "feat(policy): Add kas_uri dimenstion to ListKeys. (#3663)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-25T13:56:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2a7095afb8bb55eb07b2ab877ace12389eeeba97",
"body": "1.) Follow v1 flow and add `role:unknown` for every request.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Bug Fixes**\n* Authorization now consistently evaluates requests with the default\nrole included, improving policy matching for all requests.\n* Requests can now match policies tied to the fallback role even when\nother roles are present.\n\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(authz): Add default role for every req. (#3664)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-25T13:21:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "03021fab10cf80da56d6e58274081cf32c39a689",
"body": "…audit logs (#3429)\n\n### Proposed Changes\n\n* add global audit config and add configured JWT claims to audit logs\nwith dotnotation paths to placement within the event object\n* uses custom struct tags for audit to define paths in the current\nschema that are `reserved` (immutable via configured JWT cla\n[…]\nma/validation, dot-notation\nhelpers, and IPC auth rehydration.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "feat(core): add global audit config and add configured JWT claims to …",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-06-24T17:44:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "005f9deb19357c9b08c83e77bc8431a3bee40c8e",
"body": "Reverts opentdf/platform#3625\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **New Features**\n* Added support for three hybrid post-quantum key algorithms: X-Wing,\nSecp256r1/MLKEM768, and Secp384r1/MLKEM1024.\n\n* **Documentation**\n* Updated ke\n[…]\nrt, and rotation documentation to reflect\nnew algorithm options.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": false,
"headline": "feat(core): Re-enable pq algorithms after format change (#3651)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-23T19:02:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bde7ca7d17fbdf0c50bc588899338301f39f25bb",
"body": "….5 in /tests-bdd (#3653)\n\nBumps\n[github.com/containerd/containerd/v2](https://github.com/containerd/containerd)\nfrom 2.2.4 to 2.2.5.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/containerd/containerd/releases\">github.com/containerd/containerd/v2's\nrelea\n[…]\nttps://github.com/opentdf/platform/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/containerd/containerd/v2 from 2.2.4 to 2.2…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-23T17:59:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "57d6a28349948b43317f9ca7a0a848fb2a78b512",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.18.0](https://github.com/opentdf/platform/compare/service/v0.17.0...service/v0.18.0)\n(2026-06-23)\n\n\n### ⚠ BREAKING CHANGES\n\n* **core:** conform hybrid PQ/T key formats to IETF drafts\n([#3563](https://github.com/opentdf/platform/issues/3563))\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release service 0.18.0 (#3601)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-23T17:45:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a47b3f1b9888e4cb0d4d1dacafa4e19ef1f0ca54",
"body": "### Proposed Changes\n\n*\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### Testing Instructions\n\n\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Chores**\n * Updated platform library dependencies to newer versions.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(deps): Update to latest sdk, protos, ocrypto. (#3658)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-23T17:05:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f12ca0c84fed44c9b852d9781b840dddee4afefb",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.24.0](https://github.com/opentdf/platform/compare/sdk/v0.23.0...sdk/v0.24.0)\n(2026-06-23)\n\n\n### ⚠ BREAKING CHANGES\n\n* **core:** conform hybrid PQ/T key formats to IETF drafts\n([#3563](https://github.com/opentdf/platform/issues/3563))\n\n### Fe\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release sdk 0.24.0 (#3648)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-23T16:16:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67c499259f646727e7127e20fe1174010477b2d0",
"body": "…o 0.13.0 in /sdk (#3654)\n\nBumps\n[github.com/opentdf/platform/lib/ocrypto](https://github.com/opentdf/platform)\nfrom 0.12.0 to 0.13.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/lib/ocrypto's\nrelea\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/lib/ocrypto from 0.12.0 t…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-23T15:05:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8702ac1760ba0952f3e6876dd733d7a20c9438cc",
"body": "## Summary\n\nAdds the new authorization v2 path for Casbin-backed policy decisions,\nincluding RPC + resource-dimension authorization, resolver-based request\n enrichment, and KAS key URI-scoped authorization.\n\n ## Changes\n\n- Added a pluggable internal authz interface with `Authorizer`,\n`Decision`, `\n[…]\ned unit and BDD coverage for v1/v2 authorization and dimension\nmatching.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Chris Reed <creed@virtru.com>",
"is_bot": false,
"headline": "feat(authz): enrich casbin authorization (#3614)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-23T14:19:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5aecff92fe04e50a37d8eefeb6c1109207a9fbc0",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.13.0](https://github.com/opentdf/platform/compare/lib/ocrypto/v0.12.0...lib/ocrypto/v0.13.0)\n(2026-06-22)\n\n\n### ⚠ BREAKING CHANGES\n\n* **core:** conform hybrid PQ/T key formats to IETF drafts\n([#3563](https://github.com/opentdf/platform/issue\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release lib/ocrypto 0.13.0 (#3532)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-23T13:49:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4af46879abafb4c93e9816d8f2a62cc1e8407d27",
"body": "### Proposed Changes\n\n- The previous configuration for the xtest job would run two versions of\nplatform and one version of go-sdk:\n - at the pull version and LTS versions of platform\n- This fixes it so there will be a third block of runs against the main\nversion of platform, and a fourth SDK type,\n[…]\n aligning platform and CLI\nE2E tests to specific commit references, improving test reliability and\nconsistency across pipelines.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore(ci): Lets xtest run against main platform and PR go-sdk (#3630)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-23T13:38:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a006469dc6e55455a2ce4715415671d39670ef6",
"body": "Implements comprehensive DPoP (Demonstrating Proof-of-Possession)\nsupport per [RFC 9449](https://www.rfc-editor.org/rfc/rfc9449.html) for\nthe OpenTDF platform service.\n\n> Note: Providing DPoP support at the application server may not fit\nyour deployment strategy! If you want a high-availability or\nm\n[…]\nations.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: Claude Sonnet 4.5 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(core): Adds comprehensive DPoP (RFC 9449) support (#3582)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-22T20:43:09Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0ec99ee84a44bb2798038d421cfd9167f73036bd",
"body": ">[!NOTE]\n>Adding a query timeout will be useful for protecting the database from\n>long running searches when substring search is added to the List RPCs.\n\nSummary\n\n- Added statement_timeout_seconds support to DB config so normal service\nDB connections set PostgreSQL statement_timeout.\n- Updated migra\n[…]\n logging.\n\n* **Tests**\n* Extended automated tests to verify statement timeout runtime parameter\nbehavior and migration overrides.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "feat(core): Add statement timeout parameter. (#3544)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-22T16:57:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc1856831383de1c5880121518c0fb83c429a5a5",
"body": "## Summary\n\nBrings the three hybrid PQ/T KEMs (X-Wing, P-256+ML-KEM-768,\nP-384+ML-KEM-1024) into interop with\n`draft-ietf-lamps-pq-composite-kem-14` and\n`draft-connolly-cfrg-xwing-kem-10` so we can honestly advertise the\nregistered AlgorithmIdentifier OIDs.\n\n- **PEM envelope**: hybrid keys now use s\n[…]\nroperties\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(core)!: conform hybrid PQ/T key formats to IETF drafts (#3563)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-22T16:47:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5841bbed6f1f9ffc2fb3acb3e54fdf281bf740b9",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.23.0](https://github.com/opentdf/platform/compare/sdk/v0.22.0...sdk/v0.23.0)\n(2026-06-18)\n\n\n### Features\n\n* **sdk:** DSPX-2754 add DynamicValueMapping service client wrapper\n([#3635](https://github.com/opentdf/platform/issues/3635))\n([4acf0c\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release sdk 0.23.0 (#3639)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-18T17:17:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "beaaac5e0abe3cd2f4e68e254c2ddf214b319698",
"body": "…3576)\n\n### Proposed Changes\n\nThird PR in the stacked series for\n[DSPX-2998](https://virtru.atlassian.net/browse/DSPX-2998). Adds otdfctl\nsupport for the new resource mapping namespace fields. **Stacked on\n#3567** (service) — review/merge that first.\n\n* `policy resource-mappings create` / `update`: \n[…]\ned resource mappings include\nthe expected namespace information.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(cli): DSPX-2998 namespace flags for resource mapping commands (#…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-06-18T16:07:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4acf0caea4d601fb372efcf663793af8395a9e78",
"body": "…#3635)\n\n### Proposed Changes\n\n* Add the `sdkconnect` client wrapper for the new\n`DynamicValueMappingService` and register it on the SDK.\n* Bump `protocol/go` to **v0.34.0** (released from #3580), which carries\nthe `policy/dynamicvaluemapping` package.\n\nThis is the **sdk** step of the DSPX-2754 cons\n[…]\ns no diff\n\n### Related\n\n- Jira: https://virtru.atlassian.net/browse/DSPX-2754\n- protocol PR: #3580 (merged) · consumer PR: #3568 (depends on this)\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(sdk): DSPX-2754 add DynamicValueMapping service client wrapper (…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-06-18T15:43:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe7f787944c774d16a03ecbfe92aa7c0e22575f4",
"body": "…ent id state (#3636)\n\nCloses #3631\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Bug Fixes**\n* Refined error handling and logging behavior in authentication metadata\nretrieval to appropriately categorize and report different error\nconditions.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(core): log at debug instead of error for expected IPC missing cli…",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-06-17T21:55:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4a7353d440635e83a8819676b028b257fa49f62e",
"body": "Signed-off-by: Dave Mihalcik <dmihalcik@virtru.com>\n\n### Proposed Changes\n\n* Disables the hybrid algorithms via otdfctl. This will skip e2e tests\nin xtest, allowing us to switch to the new format in #3563\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integrat\n[…]\ne and adjusted remaining test\nvectors to match current supported algorithms.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>",
"is_bot": false,
"headline": "feat(core): Disable pq algorithms due to format change (#3625)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-17T21:29:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da38619a60c9c75ed841443d911bb9cf0f51239e",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.34.0](https://github.com/opentdf/platform/compare/protocol/go/v0.33.0...protocol/go/v0.34.0)\n(2026-06-17)\n\n\n### ⚠ BREAKING CHANGES\n\n* **core:** Add min_len to search term.\n([#3604](https://github.com/opentdf/platform/issues/3604))\n\n### Featu\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.34.0 (#3606)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-17T19:45:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "090c0f65508058502d17a850691957b7beaee785",
"body": "…#3580)\n\n### Proposed Changes\n\n* Protocol-first half of the dynamic attribute value entitlement feature\n(DSPX-2754). Adds the `DynamicValueMapping` / `DynamicValueResolver`\nmessages and `DynamicValueOperatorEnum` to `objects.proto`, plus a\ndedicated `DynamicValueMappingService` in a new\n`policy.dyna\n[…]\nnal modification of resolvers,\nconditions, and permitted actions\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): DSPX-2754 DynamicValueMapping protos + generated code (…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-06-17T16:28:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "192d2acc0ab3fd322b8c103fc66eb2aa76c350a7",
"body": "… CLI test cases (#3624)\n\n### Proposed Changes\n\nAlign recent CLI test cases changes with the mapping file for TestRail\nresults integration\n\nOriginal JIRA integration ticket: AB-2044\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropria\n[…]\ncomprehensive testing for KAS key management operations and\npolicy migration workflows with dependency and multi-scope scenarios\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "chore(ci): AB-2044 - update TestRail mapping file with recently added…",
"author_name": "sievdokymov-virtru",
"author_login": "sievdokymov-virtru",
"committed_at": "2026-06-17T14:46:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2b6d54c1149f538ee1df3bdf17fb5e872b337b30",
"body": "### Proposed Changes\n\nSecond PR in the stacked series for\n[DSPX-2998](https://virtru.atlassian.net/browse/DSPX-2998). Implements\nthe service side (AC1 + AC2). **Stacked on #3565** (proto) —\nreview/merge that first.\n\n* Migration adds a nullable `namespace_id` (FK to\n`attribute_namespaces`, `ON DELETE\n[…]\npecification requirement when namespaced policy\nmode is enabled.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy): DSPX-2998 optionally namespace resource mappings (#3567)",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-06-17T14:45:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1fb2549a637af313cc4bd279b39f89d95d77a4b4",
"body": "## Summary\n\nAdds `--search` support to `otdfctl` policy list commands whose backing\nRPCs already support search filtering.\n\n ## Changes\n\n - Added `--search` to supported list commands:\n - `policy namespaces list`\n - `policy attributes list`\n - `policy obligations list`\n - `policy regis\n[…]\non and examples\nfor the new flag.\n* **Tests**\n* Added end-to-end coverage validating that `--search` returns only\nmatching items.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "feat(cli): Add search to cli (#3616)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-16T21:35:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "33b6fd7823bdcb1391d1bd4fb0211dfe1de704e6",
"body": "# General goal\n\nSearch for policy objects with a `List` req by specifying a Search\n`term`. The search `term` is simply that, a word or phrase. We do this\nby using the `LIKE` or `ILIKE` command depending on the specific RPC.\n\nThe following sanitization is done for each query:\n- Whitespace is removed \n[…]\nomment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Chris Reed <creed@virtru.com>\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(policy): Add the ability to do substring search (#3551)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-16T16:47:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23b639afe1a1207d6fd69f0d876ffcc783990c27",
"body": "… in /service (#3618)\n\nBumps\n[github.com/opentdf/platform/sdk](https://github.com/opentdf/platform)\nfrom 0.21.0 to 0.22.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/sdk's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/sdk from 0.21.0 to 0.22.0…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-16T15:18:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dee7f50511e7d076123cddc70c4cc61921bac061",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.22.0](https://github.com/opentdf/platform/compare/sdk/v0.21.0...sdk/v0.22.0)\n(2026-06-15)\n\n\n### Bug Fixes\n\n* **ci:** Prefer go.work for toolchain info\n([#3285](https://github.com/opentdf/platform/issues/3285))\n([3c05b22](https://github.com/o\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release sdk 0.22.0 (#3570)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-16T13:18:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d5cfc8d7e3978c0935f22b789945da6369e26846",
"body": "…o 0.33.1 in /sdk (#3609)\n\nBumps\n[github.com/opentdf/platform/protocol/go](https://github.com/opentdf/platform)\nfrom 0.32.0 to 0.33.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/opentdf/platform/releases\">github.com/opentdf/platform/protocol/go's\nrelea\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "fix(deps): bump github.com/opentdf/platform/protocol/go from 0.32.0 t…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T20:47:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "09e22dc6df01de211ca15d9f7c8dd54e7eec2abd",
"body": "1.) Set `min_len` of search term to 1 when the field is present\n2.) Remove `Search` from `ListRegisteredResourceValues` and\n`ListObligationTriggers`\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Bug Fixes**\n* Enforced minimum length valida\n[…]\nflicts in request messages.\n\n* **Refactor**\n* Updated request schemas to improve pagination handling in policy\nservice requests.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(core)!: Add min_len to search term. (#3604)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-15T16:56:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "96a89cd17f6bc15a8b57bc3910b0dc7751c8f7aa",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.33.0](https://github.com/opentdf/platform/compare/protocol/go/v0.32.0...protocol/go/v0.33.0)\n(2026-06-12)\n\n\n### ⚠ BREAKING CHANGES\n\n* **policy:** DSPX-2998 add namespace fields to resource mapping protos\n([#3565](https://github.com/opentdf/p\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release protocol/go 0.33.0 (#3533)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-15T14:04:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40f35df8b9ed6299498f03821475f88526d9a5eb",
"body": "1.) Add common search object that will be used for substring matching in\nPostgres.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **New Features**\n* Added optional search capability to list operations across multiple\nservices, including attri\n[…]\nsponse structure and schema organization for improved\nconsistency across services.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Chris Reed <creed@virtru.com>",
"is_bot": false,
"headline": "feat(core): Add search term information to protos. (#3547)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-12T19:12:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6f832d6fa6505083316897cc630c36d6e3ba2467",
"body": "### Proposed Changes\n\n1.) Fix issue where a `kid` created as a UUID was not respecting the kas\nflag, and being treated as an ID.\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### \n[…]\ns**\n* Added end-to-end tests for retrieving and rotating KAS keys when the\nuser key ID is a UUID and a KAS registry is specified.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->",
"is_bot": false,
"headline": "fix(cli): fix the get key command. (#3598)",
"author_name": "Chris Reed",
"author_login": "c-r33d",
"committed_at": "2026-06-12T13:46:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "91ecfea36e62d233733a1d2e8350b1cec6f23cb4",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.17.0](https://github.com/opentdf/platform/compare/service/v0.16.0...service/v0.17.0)\n(2026-06-11)\n\n\n### ⚠ BREAKING CHANGES\n\n* **policy:** DSPX-2998 add namespace fields to resource mapping protos\n([#3565](https://github.com/opentdf/platform/\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release service 0.17.0 (#3571)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-11T18:23:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2e82aa077515204f7538c9264b40586df69b4baa",
"body": "### Proposed Changes\n\n* Separate token validation (authn) and casbin authorization (authz)\nmiddlewares\n* Unify public route middleware check and set context state if public\nroute for downstream interceptors/middlewares\n* Reduce token parsing and claims handling by exposing context handlers\nto get ro\n[…]\nuthn/authz\nchaining, role resolution, and context propagation.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "feat(authz): split connect token claims and enforcement (#3592)",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-06-11T15:03:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9d16f8062e6164748a6a27c497272209b743339f",
"body": "Make Authorization v2 request limits configurable by moving max-count\nvalidation from proto CEL to service-side config.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n## Summary by CodeRabbit\n\n* **New Features**\n* Configurable request limits for entity chains, attribute-\n[…]\n boundary cases, nested errors, and proto-validation behavior.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "feat(authz): make v2 request limits configurable (#3508)",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-06-10T20:33:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e4a04ed6ee04a346a00a49d3c1f381295f9e9443",
"body": "…tos (#3565)\n\n### Proposed Changes\n\nFirst PR in a stacked series for\n[DSPX-2998](https://virtru.atlassian.net/browse/DSPX-2998) (Resource\nMappings & Resource Mapping Groups should be optionally namespaced).\nThis PR adds the proto contract only; the service implementation and\notdfctl/migration suppor\n[…]\nnamespace ID/FQN formats and\nmutual-exclusion/requirement rules.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Krish Suchak <suchak.krish@gmail.com>",
"is_bot": false,
"headline": "feat(policy)!: DSPX-2998 add namespace fields to resource mapping pro…",
"author_name": "Krish Suchak",
"author_login": "alkalescent",
"committed_at": "2026-06-10T19:46:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd924f5c7919d1cdfd4634e14fe963b48ccbf0f6",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[0.33.0](https://github.com/opentdf/platform/compare/otdfctl/v0.32.0...otdfctl/v0.33.0)\n(2026-06-09)\n\n\n### Features\n\n* **cli:** improve auth\n([#3466](https://github.com/opentdf/platform/issues/3466))\n([b244910](https://github.com/opentdf/platfo\n[…]\nrelease-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: opentdf-automation[bot] <149537512+opentdf-automation[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release otdfctl 0.33.0 (#3510)",
"author_name": "opentdf-automation[bot]",
"author_login": "opentdf-automation[bot]",
"committed_at": "2026-06-10T16:24:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4bbe9f14fc4eacb4cd4495ce3a12530b5b6ee5e0",
"body": "…t (#3594)\n\n## Summary\n\nWhen the xtest workflow calls `start-up-with-containers` with\n`pqc-enabled: true` against an older platform ref (e.g. `v0.9.0`), the\nplatform crashes on startup:\n\n```\nopen kas-xwing-private.pem: no such file or directory\n```\n\n**Root cause:** `init-temp-keys.sh` (from the `pqc\n[…]\nployment\nscenarios and reducing configuration errors.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nCo-authored-by: CoopAgent <coopagent@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(ci): DSPX-3499 skip PQC key config when platform lacks PQC suppor…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-10T15:48:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d446b35193b96e32dd4d102c79eab3f4d059c40",
"body": "…ctl (#3589)\n\n## Summary\n- Bumps `connectrpc.com/connect` from v1.19.2 to v1.20.0 in `sdk/`,\n`service/`, and `otdfctl/`\n- `protocol/go` is already on v1.20.0 — this aligns the rest of the repo\n- Resolves internal version skew that was blocking downstream consumers\n(virtru-sdk-go, DSP SDK) from upgra\n[…]\nity.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\nSigned-off-by: Mary Dickson <mary.dickson@virtru.com>\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "chore(deps): bump connectrpc/connect to v1.20.0 in sdk, service, otdf…",
"author_name": "Mary Dickson",
"author_login": "marythought",
"committed_at": "2026-06-09T14:39:48Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8f3c42903170e91d1cc6e8552a3fa0aaa6aadbe5",
"body": "### Proposed Changes\n\n*\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- [ ] I have added or updated integration tests (if appropriate)\n- [ ] I have added or updated documentation\n\n### Testing Instructions\n\n\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Su\n[…]\nting functionality and user-facing behavior\nremain unchanged.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "fix(cli): deprecate flaghelper for new flags (#3583)",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-06-08T16:14:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "11af44a5d4826ed281bf2e0e4e31d6ff6154b393",
"body": "… (#3579)\n\n## Summary\n\n- Updates the `curl` pin in `test/start-up-with-containers/action.yaml`\nfrom `watch-sh-fix` to `pqc-enabled` tag\n- The `watch-sh-fix` tag predates PQC support in `init-temp-keys.sh`, so\n`kas-xwing-private.pem` and related files were never generated\n- The `pqc-enabled` tag poin\n[…]\nnabled.\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(ci): update curl pin to pqc-enabled tag so PQC keys are generated…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-08T13:55:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "626ce47dd662cb8ff16898e3b6727001a4753d92",
"body": "### Proposed Changes\n\n* Adds `pqc-enabled` boolean parameter to `start-up-with-containers`\nand `start-additional-kas` actions, which when set to true will enable\nthe post-quantum and hybrid PQ/T wrapping option for TDFs\nin the KAS service.\n\n\n### Checklist\n\n- [ ] I have added or updated unit tests\n- \n[…]\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(ci): Enable pq/t service run action option (#3573)",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-05T15:33:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0de01df00caad86d2cb8a4fb9204a0e665ba7163",
"body": "Adds Casbin authorization context to permission denied warning logs,\nincluding the configured groups claim and extracted subject groups.\n\n<!-- This is an auto-generated comment: release notes by coderabbit.ai\n-->\n\n## Summary by CodeRabbit\n\n* **Refactor**\n* Improved authorization handling consistency\n[…]\nn-denied scenarios with and without authorization group data.\n\n<!-- end of auto-generated comment: release notes by coderabbit.ai -->\n\n---------\n\nSigned-off-by: jakedoublev <jake.vanvorhis@virtru.com>",
"is_bot": false,
"headline": "fix(authz): log casbin subject groups on denial (#3572)",
"author_name": "Jake Van Vorhis",
"author_login": "jakedoublev",
"committed_at": "2026-06-04T21:10:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c2b48167a45c37870ebd8e37c3cbb3d83174336c",
"body": "…6) (#3564)\n\n## Summary\n- Adds `INFO msg=\"kas trust mechanisms initialized\" mechanisms=[...]`\nlog line at KAS startup and on hot config reload\n- Algorithm list sourced from static metadata declared at manager\nregistration time\n- Filtered by preview-feature gating to match `rewrap.o\\` acceptance\nlogi\n[…]\n\n\nSigned-off-by: Dave Mihalcik <dmihalcik@virtru.com>\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(kas): emit INFO log of supported mechanisms at startup (DSPX-345…",
"author_name": "Dave Mihalcik",
"author_login": "dmihalcik-virtru",
"committed_at": "2026-06-04T21:04:38Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 100,
"commits_last_year": 598,
"latest_release_at": "2026-07-21T21:17:14Z",
"latest_release_tag": "sdk/v0.27.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 52,
"days_since_latest_release": 0,
"mean_days_between_releases": 2.3
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/opentdf/platform/sdk",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/opentdf/platform/sdk",
"is_deprecated": false,
"latest_version": "v0.27.0",
"repository_url": "https://github.com/opentdf/platform",
"versions_count": 76,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-21T20:59:37Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
},
{
"name": "github.com/opentdf/platform/otdfctl",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/opentdf/platform/otdfctl",
"is_deprecated": false,
"latest_version": "v0.35.0",
"repository_url": "https://github.com/opentdf/platform",
"versions_count": 52,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-07T14:19:20Z",
"latest_version_yanked": null,
"days_since_latest_publish": 14
},
{
"name": "github.com/opentdf/platform/service",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/opentdf/platform/service",
"is_deprecated": false,
"latest_version": "v0.20.0",
"repository_url": "https://github.com/opentdf/platform",
"versions_count": 76,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-07T20:58:39Z",
"latest_version_yanked": null,
"days_since_latest_publish": 14
}
]
},
"popularity": {
"forks": 37,
"stars": 50,
"watchers": 15,
"fork_history": {
"days": [
{
"date": "2024-04-05",
"count": 1
},
{
"date": "2024-04-06",
"count": 1
},
{
"date": "2024-04-23",
"count": 1
},
{
"date": "2024-05-16",
"count": 1
},
{
"date": "2024-08-02",
"count": 1
},
{
"date": "2024-09-22",
"count": 1
},
{
"date": "2024-09-25",
"count": 1
},
{
"date": "2024-10-04",
"count": 1
},
{
"date": "2024-10-16",
"count": 1
},
{
"date": "2024-10-22",
"count": 1
},
{
"date": "2024-11-18",
"count": 1
},
{
"date": "2025-02-11",
"count": 1
},
{
"date": "2025-02-18",
"count": 1
},
{
"date": "2025-04-03",
"count": 1
},
{
"date": "2025-05-02",
"count": 1
},
{
"date": "2025-05-06",
"count": 1
},
{
"date": "2025-06-04",
"count": 1
},
{
"date": "2025-08-23",
"count": 1
},
{
"date": "2025-08-28",
"count": 1
},
{
"date": "2025-09-15",
"count": 1
},
{
"date": "2025-09-17",
"count": 1
},
{
"date": "2025-10-01",
"count": 1
},
{
"date": "2026-02-22",
"count": 1
},
{
"date": "2026-02-26",
"count": 1
},
{
"date": "2026-03-07",
"count": 1
},
{
"date": "2026-03-12",
"count": 1
},
{
"date": "2026-04-04",
"count": 1
},
{
"date": "2026-04-06",
"count": 1
},
{
"date": "2026-04-11",
"count": 1
},
{
"date": "2026-04-23",
"count": 1
},
{
"date": "2026-04-24",
"count": 1
},
{
"date": "2026-07-01",
"count": 1
},
{
"date": "2026-07-17",
"count": 1
},
{
"date": "2026-07-19",
"count": 1
},
{
"date": "2026-07-20",
"count": 1
},
{
"date": "2026-07-21",
"count": 1
}
],
"complete": true,
"collected": 36,
"total_forks": 37
},
"star_history": {
"days": [
{
"date": "2024-01-04",
"count": 1
},
{
"date": "2024-01-19",
"count": 1
},
{
"date": "2024-02-16",
"count": 1
},
{
"date": "2024-04-08",
"count": 1
},
{
"date": "2024-04-15",
"count": 1
},
{
"date": "2024-04-23",
"count": 2
},
{
"date": "2024-04-29",
"count": 1
},
{
"date": "2024-05-02",
"count": 1
},
{
"date": "2024-05-10",
"count": 1
},
{
"date": "2024-05-24",
"count": 1
},
{
"date": "2024-06-24",
"count": 1
},
{
"date": "2024-07-30",
"count": 1
},
{
"date": "2024-08-20",
"count": 1
},
{
"date": "2024-09-18",
"count": 1
},
{
"date": "2024-10-11",
"count": 1
},
{
"date": "2024-11-11",
"count": 1
},
{
"date": "2024-12-05",
"count": 1
},
{
"date": "2024-12-10",
"count": 1
},
{
"date": "2025-01-16",
"count": 1
},
{
"date": "2025-04-01",
"count": 1
},
{
"date": "2025-04-24",
"count": 1
},
{
"date": "2025-04-29",
"count": 1
},
{
"date": "2025-05-02",
"count": 1
},
{
"date": "2025-05-21",
"count": 1
},
{
"date": "2025-05-27",
"count": 1
},
{
"date": "2025-06-02",
"count": 1
},
{
"date": "2025-06-19",
"count": 1
},
{
"date": "2025-06-20",
"count": 1
},
{
"date": "2025-06-26",
"count": 1
},
{
"date": "2025-06-27",
"count": 1
},
{
"date": "2025-06-30",
"count": 1
},
{
"date": "2025-07-25",
"count": 1
},
{
"date": "2025-07-26",
"count": 1
},
{
"date": "2025-08-04",
"count": 1
},
{
"date": "2025-08-08",
"count": 1
},
{
"date": "2025-08-28",
"count": 1
},
{
"date": "2025-09-08",
"count": 1
},
{
"date": "2025-10-21",
"count": 1
},
{
"date": "2025-10-24",
"count": 1
},
{
"date": "2025-10-27",
"count": 1
},
{
"date": "2025-12-02",
"count": 1
},
{
"date": "2026-02-03",
"count": 1
},
{
"date": "2026-03-09",
"count": 1
},
{
"date": "2026-03-18",
"count": 1
},
{
"date": "2026-04-25",
"count": 1
},
{
"date": "2026-05-10",
"count": 1
},
{
"date": "2026-06-24",
"count": 1
},
{
"date": "2026-07-07",
"count": 1
},
{
"date": "2026-07-11",
"count": 1
}
],
"complete": true,
"collected": 50,
"total_stars": 50
},
"open_issues_and_prs": 246
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile",
"otdfctl/Makefile"
],
"api_schema_files": [
"service/authorization/authorization.proto",
"service/authorization/v2/authorization.proto",
"service/common/common.proto",
"service/entity/entity.proto",
"service/entityresolution/entity_resolution.proto",
"service/entityresolution/v2/entity_resolution.proto",
"service/kas/kas.proto",
"service/logger/audit/test.proto",
"service/policy/actions/actions.proto",
"service/policy/attributes/attributes.proto",
"service/policy/dynamicvaluemapping/dynamic_value_mapping.proto",
"service/policy/kasregistry/key_access_server_registry.proto",
"service/policy/keymanagement/key_management.proto",
"service/policy/namespaces/namespaces.proto",
"service/policy/objects.proto",
"service/policy/obligations/obligations.proto",
"service/policy/registeredresources/registered_resources.proto",
"service/policy/resourcemapping/resource_mapping.proto",
"service/policy/selectors.proto",
"service/policy/subjectmapping/subject_mapping.proto",
"service/policy/unsafe/unsafe.proto",
"service/wellknownconfiguration/wellknown_configuration.proto"
],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"examples/go.mod",
"lib/fixtures/go.mod",
"lib/flattening/go.mod",
"lib/identifier/go.mod",
"lib/ocrypto/go.mod",
"otdfctl/go.mod",
"protocol/codegen/go.mod",
"protocol/go/go.mod",
"sdk/go.mod",
"service/go.mod",
"test/integration/go.mod",
"tests-bdd/go.mod"
],
"largest_source_bytes": 255537,
"source_files_sampled": 756,
"oversized_source_files": 23,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 3337
},
"dependencies": {
"manifests": [
"examples/go.mod",
"otdfctl/go.mod",
"sdk/go.mod",
"service/go.mod",
"tests-bdd/go.mod"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "google.golang.org/grpc",
"direct": true,
"version": "v1.81.1",
"severity": "critical",
"ecosystem": "go",
"cvss_score": 9.1,
"advisory_ids": [
"GHSA-hrxh-6v49-42gf"
],
"fixed_version": "1.82.1",
"advisory_count": 1,
"oldest_advisory_days": 0
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.48.0",
"severity": "critical",
"ecosystem": "go",
"cvss_score": 10,
"advisory_ids": [
"GHSA-45gg-vh54-h5m9",
"GHSA-5cgq-3rg8-m6cv",
"GHSA-78mq-xcr3-xm33",
"GHSA-89gr-r52h-f8rx",
"GHSA-9m57-25v3-79x9",
"GHSA-f5wc-c3c7-36mc",
"GHSA-jppx-rxg9-jmrx",
"GHSA-q4h4-gmj2-qvw2",
"GHSA-qpw4-5x99-6vjp",
"GHSA-rm3j-f69w-wqmq"
],
"fixed_version": "0.52.0",
"advisory_count": 27,
"oldest_advisory_days": 61
},
{
"name": "github.com/docker/docker",
"direct": false,
"version": "v28.5.2+incompatible",
"severity": "high",
"ecosystem": "go",
"cvss_score": 8.8,
"advisory_ids": [
"GHSA-pxq6-2prw-chj9",
"GHSA-rg2x-37c3-w2rh",
"GHSA-vp62-88p7-qqf5",
"GHSA-x744-4wpc-v9h2",
"GHSA-x86f-5xw2-fm2r",
"GO-2026-4883",
"GO-2026-4887",
"GO-2026-5617",
"GO-2026-5668",
"GO-2026-5746"
],
"fixed_version": "29.3.1",
"advisory_count": 10,
"oldest_advisory_days": 116
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.38.0",
"severity": "moderate",
"ecosystem": "go",
"cvss_score": 6.5,
"advisory_ids": [
"GHSA-5cv4-jp36-h3mw",
"GO-2026-4440",
"GO-2026-4441",
"GO-2026-4918",
"GO-2026-5025",
"GO-2026-5026",
"GO-2026-5027",
"GO-2026-5028",
"GO-2026-5029",
"GO-2026-5030"
],
"fixed_version": "1.26.3",
"advisory_count": 11,
"oldest_advisory_days": 166
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.51.0",
"severity": "moderate",
"ecosystem": "go",
"cvss_score": 6.5,
"advisory_ids": [
"GHSA-5cv4-jp36-h3mw",
"GO-2026-4918",
"GO-2026-5025",
"GO-2026-5026",
"GO-2026-5027",
"GO-2026-5028",
"GO-2026-5029",
"GO-2026-5030",
"GO-2026-5942"
],
"fixed_version": "1.26.3",
"advisory_count": 9,
"oldest_advisory_days": 75
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.54.0",
"severity": "moderate",
"ecosystem": "go",
"cvss_score": 6.5,
"advisory_ids": [
"GHSA-5cv4-jp36-h3mw",
"GO-2026-5025",
"GO-2026-5026",
"GO-2026-5027",
"GO-2026-5028",
"GO-2026-5029",
"GO-2026-5030",
"GO-2026-5942"
],
"fixed_version": "0.56.0",
"advisory_count": 8,
"oldest_advisory_days": 61
},
{
"name": "github.com/sigstore/sigstore-go",
"direct": false,
"version": "v1.1.4",
"severity": "moderate",
"ecosystem": "go",
"cvss_score": 5.9,
"advisory_ids": [
"GHSA-9vcr-p3rj-q5q6",
"GO-2026-5952"
],
"fixed_version": "1.2.0",
"advisory_count": 2,
"oldest_advisory_days": 12
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.55.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5942"
],
"fixed_version": "0.56.0",
"advisory_count": 1,
"oldest_advisory_days": 7
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.34.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5970"
],
"fixed_version": "0.39.0",
"advisory_count": 1,
"oldest_advisory_days": 7
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.37.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5970"
],
"fixed_version": "0.39.0",
"advisory_count": 1,
"oldest_advisory_days": 7
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.38.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5970"
],
"fixed_version": "0.39.0",
"advisory_count": 1,
"oldest_advisory_days": 7
},
{
"name": "github.com/yuin/goldmark",
"direct": false,
"version": "v1.7.8",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5320"
],
"fixed_version": "1.7.17",
"advisory_count": 1,
"oldest_advisory_days": 14
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.52.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 14
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5932"
],
"fixed_version": null,
"advisory_count": 1,
"oldest_advisory_days": 14
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.42.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5024"
],
"fixed_version": "0.44.0",
"advisory_count": 1,
"oldest_advisory_days": 60
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"high": 1,
"unknown": 8,
"critical": 2,
"moderate": 4
},
"advisory_count": 76,
"affected_count": 15,
"assessed_count": 379,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 8
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "github.com/adrg/frontmatter",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.0"
},
{
"name": "github.com/charmbracelet/bubbles",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.1-0.20250623103423-23b8fd6302d7"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/glamour",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.10.0"
},
{
"name": "github.com/charmbracelet/huh",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.8.0"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.1-0.20250404203927-76690c660834"
},
{
"name": "github.com/evertras/bubble-table",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.19.2"
},
{
"name": "github.com/gabriel-vasile/mimetype",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.13"
},
{
"name": "github.com/go-jose/go-jose/v3",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.5"
},
{
"name": "github.com/golang-jwt/jwt/v5",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v5.3.0"
},
{
"name": "github.com/google/uuid",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/jrschumacher/go-osprofiles",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20251201220924-3d077c5481e5"
},
{
"name": "github.com/opentdf/platform/lib/flattening",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.3"
},
{
"name": "github.com/opentdf/platform/lib/identifier",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.4.0"
},
{
"name": "github.com/opentdf/platform/lib/ocrypto",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.14.0"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "github.com/opentdf/platform/sdk",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.25.0"
},
{
"name": "github.com/spf13/cobra",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "github.com/stretchr/testify",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/zitadel/oidc/v3",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v3.45.1"
},
{
"name": "golang.org/x/oauth2",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "golang.org/x/term",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v0.43.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.81.1"
},
{
"name": "google.golang.org/protobuf",
"manifest": "otdfctl/go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "connectrpc.com/connect",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.20.0"
},
{
"name": "connectrpc.com/grpchealth",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "github.com/Masterminds/semver/v3",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v3.5.0"
},
{
"name": "github.com/google/uuid",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/gowebpki/jcs",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.1"
},
{
"name": "github.com/grpc-ecosystem/go-grpc-middleware/v2",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v2.3.3"
},
{
"name": "github.com/lestrrat-go/jwx/v2",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v2.1.6"
},
{
"name": "github.com/opentdf/platform/lib/ocrypto",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v0.14.0"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v0.39.0"
},
{
"name": "github.com/stretchr/testify",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/xeipuuv/gojsonschema",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.0"
},
{
"name": "golang.org/x/oauth2",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "golang.org/x/text",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v0.37.0"
},
{
"name": "golang.org/x/tools",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v0.44.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.81.1"
},
{
"name": "google.golang.org/protobuf",
"manifest": "sdk/go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "buf.build/go/protovalidate",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "connectrpc.com/connect",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.20.0"
},
{
"name": "connectrpc.com/grpchealth",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.4.0"
},
{
"name": "connectrpc.com/grpcreflect",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "connectrpc.com/otelconnect",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.0"
},
{
"name": "connectrpc.com/validate",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.0"
},
{
"name": "github.com/Masterminds/squirrel",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.4"
},
{
"name": "github.com/Nerzal/gocloak/v13",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v13.9.0"
},
{
"name": "github.com/bmatcuk/doublestar",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.4"
},
{
"name": "github.com/casbin/casbin/v2",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v2.108.0"
},
{
"name": "github.com/creasty/defaults",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.8.0"
},
{
"name": "github.com/dgraph-io/ristretto/v2",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.0"
},
{
"name": "github.com/eko/gocache/lib/v4",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v4.2.0"
},
{
"name": "github.com/eko/gocache/store/ristretto/v4",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v4.3.2"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.9.0"
},
{
"name": "github.com/go-chi/cors",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.2.1"
},
{
"name": "github.com/go-playground/validator/v10",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v10.26.0"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.0"
},
{
"name": "github.com/google/uuid",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/jackc/pgerrcode",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.0-20220416144525-469b46aa5efa"
},
{
"name": "github.com/jackc/pgx/v5",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v5.9.2"
},
{
"name": "github.com/lestrrat-go/jwx/v2",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v2.1.6"
},
{
"name": "github.com/lib/pq",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.9"
},
{
"name": "github.com/mattn/go-sqlite3",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.14.29"
},
{
"name": "github.com/open-policy-agent/opa",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.1"
},
{
"name": "github.com/opentdf/platform/lib/fixtures",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.6.0"
},
{
"name": "github.com/opentdf/platform/lib/flattening",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.1.3"
},
{
"name": "github.com/opentdf/platform/lib/identifier",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.4.0"
},
{
"name": "github.com/opentdf/platform/lib/ocrypto",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.14.0"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.38.0"
},
{
"name": "github.com/opentdf/platform/sdk",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.26.0"
},
{
"name": "github.com/pressly/goose/v3",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v3.24.3"
},
{
"name": "github.com/spf13/cobra",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.9.1"
},
{
"name": "github.com/spf13/viper",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.20.1"
},
{
"name": "github.com/stretchr/testify",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.1"
},
{
"name": "github.com/testcontainers/testcontainers-go",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.42.0"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.42.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.42.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.43.0"
},
{
"name": "golang.org/x/net",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.54.0"
},
{
"name": "google.golang.org/grpc",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.81.1"
},
{
"name": "google.golang.org/protobuf",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "gopkg.in/natefinch/lumberjack.v2",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v2.2.1"
},
{
"name": "gopkg.in/yaml.v2",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "github.com/go-ldap/ldap/v3",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v3.4.12"
},
{
"name": "golang.org/x/text",
"manifest": "service/go.mod",
"ecosystem": "go",
"version_constraint": "v0.37.0"
},
{
"name": "connectrpc.com/connect",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v1.20.0"
},
{
"name": "github.com/cucumber/godog",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.15.1"
},
{
"name": "github.com/google/uuid",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/jackc/pgx/v5",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v5.9.2"
},
{
"name": "github.com/opentdf/platform/lib/fixtures",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.3.0"
},
{
"name": "github.com/opentdf/platform/lib/identifier",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.0.2"
},
{
"name": "github.com/opentdf/platform/lib/ocrypto",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.10.0"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.30.0"
},
{
"name": "github.com/opentdf/platform/sdk",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.17.0"
},
{
"name": "github.com/opentdf/platform/service",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.7.2"
},
{
"name": "github.com/spf13/pflag",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.10"
},
{
"name": "github.com/testcontainers/testcontainers-go",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.42.0"
},
{
"name": "github.com/testcontainers/testcontainers-go/modules/compose",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.42.0"
},
{
"name": "golang.org/x/oauth2",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v0.36.0"
},
{
"name": "google.golang.org/protobuf",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v1.36.11"
},
{
"name": "gopkg.in/yaml.v2",
"manifest": "tests-bdd/go.mod",
"ecosystem": "go",
"version_constraint": "v2.4.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "buf.build/go/protovalidate",
"direct": true,
"version": "v0.13.1",
"ecosystem": "go"
},
{
"name": "buf.build/go/protovalidate",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/connect",
"direct": true,
"version": "v1.20.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/grpchealth",
"direct": true,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/grpcreflect",
"direct": true,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/otelconnect",
"direct": true,
"version": "v0.9.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/validate",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "connectrpc.com/validate",
"direct": true,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/adrg/frontmatter",
"direct": true,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/bmatcuk/doublestar",
"direct": true,
"version": "v1.3.4",
"ecosystem": "go"
},
{
"name": "github.com/casbin/casbin/v2",
"direct": true,
"version": "v2.108.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbles",
"direct": true,
"version": "v0.21.1-0.20250623103423-23b8fd6302d7",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbletea",
"direct": true,
"version": "v1.3.10",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/glamour",
"direct": true,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/huh",
"direct": true,
"version": "v0.8.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": true,
"version": "v1.1.1-0.20250404203927-76690c660834",
"ecosystem": "go"
},
{
"name": "github.com/creasty/defaults",
"direct": true,
"version": "v1.8.0",
"ecosystem": "go"
},
{
"name": "github.com/cucumber/godog",
"direct": true,
"version": "v0.15.1",
"ecosystem": "go"
},
{
"name": "github.com/dgraph-io/ristretto/v2",
"direct": true,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "github.com/eko/gocache/lib/v4",
"direct": true,
"version": "v4.2.0",
"ecosystem": "go"
},
{
"name": "github.com/eko/gocache/store/ristretto/v4",
"direct": true,
"version": "v4.2.2",
"ecosystem": "go"
},
{
"name": "github.com/eko/gocache/store/ristretto/v4",
"direct": true,
"version": "v4.3.2",
"ecosystem": "go"
},
{
"name": "github.com/evertras/bubble-table",
"direct": true,
"version": "v0.19.2",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsnotify",
"direct": true,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "github.com/gabriel-vasile/mimetype",
"direct": true,
"version": "v1.4.13",
"ecosystem": "go"
},
{
"name": "github.com/gabriel-vasile/mimetype",
"direct": true,
"version": "v1.4.8",
"ecosystem": "go"
},
{
"name": "github.com/gabriel-vasile/mimetype",
"direct": true,
"version": "v1.4.9",
"ecosystem": "go"
},
{
"name": "github.com/go-chi/cors",
"direct": true,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/go-jose/go-jose/v3",
"direct": true,
"version": "v3.0.5",
"ecosystem": "go"
},
{
"name": "github.com/go-ldap/ldap/v3",
"direct": true,
"version": "v3.4.12",
"ecosystem": "go"
},
{
"name": "github.com/go-playground/validator/v10",
"direct": true,
"version": "v10.26.0",
"ecosystem": "go"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"direct": true,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "github.com/go-viper/mapstructure/v2",
"direct": true,
"version": "v2.5.0",
"ecosystem": "go"
},
{
"name": "github.com/golang-jwt/jwt/v5",
"direct": true,
"version": "v5.2.2",
"ecosystem": "go"
},
{
"name": "github.com/golang-jwt/jwt/v5",
"direct": true,
"version": "v5.3.0",
"ecosystem": "go"
},
{
"name": "github.com/google/uuid",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/gowebpki/jcs",
"direct": true,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/grpc-ecosystem/go-grpc-middleware/v2",
"direct": true,
"version": "v2.3.3",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgerrcode",
"direct": true,
"version": "v0.0.0-20220416144525-469b46aa5efa",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgerrcode",
"direct": true,
"version": "v0.0.0-20240316143900-6e2875d9b438",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgx/v5",
"direct": true,
"version": "v5.9.2",
"ecosystem": "go"
},
{
"name": "github.com/jrschumacher/go-osprofiles",
"direct": true,
"version": "v0.0.0-20251201220924-3d077c5481e5",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/jwx/v2",
"direct": true,
"version": "v2.1.6",
"ecosystem": "go"
},
{
"name": "github.com/lib/pq",
"direct": true,
"version": "v1.10.9",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/semver/v3",
"direct": true,
"version": "v3.4.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/semver/v3",
"direct": true,
"version": "v3.5.0",
"ecosystem": "go"
},
{
"name": "github.com/masterminds/squirrel",
"direct": true,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-sqlite3",
"direct": true,
"version": "v1.14.29",
"ecosystem": "go"
},
{
"name": "github.com/nerzal/gocloak/v13",
"direct": true,
"version": "v13.9.0",
"ecosystem": "go"
},
{
"name": "github.com/open-policy-agent/opa",
"direct": true,
"version": "v1.10.1",
"ecosystem": "go"
},
{
"name": "github.com/open-policy-agent/opa",
"direct": true,
"version": "v1.5.1",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/fixtures",
"direct": true,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/fixtures",
"direct": true,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/flattening",
"direct": true,
"version": "v0.1.3",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/identifier",
"direct": true,
"version": "v0.0.2",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/identifier",
"direct": true,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/ocrypto",
"direct": true,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/lib/ocrypto",
"direct": true,
"version": "v0.14.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"direct": true,
"version": "v0.30.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"direct": true,
"version": "v0.36.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"direct": true,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/protocol/go",
"direct": true,
"version": "v0.39.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/sdk",
"direct": true,
"version": "v0.17.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/sdk",
"direct": true,
"version": "v0.25.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/sdk",
"direct": true,
"version": "v0.26.0",
"ecosystem": "go"
},
{
"name": "github.com/opentdf/platform/service",
"direct": true,
"version": "v0.7.2",
"ecosystem": "go"
},
{
"name": "github.com/pressly/goose/v3",
"direct": true,
"version": "v3.24.3",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.9.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": true,
"version": "v1.0.10",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": true,
"version": "v1.0.6",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": true,
"version": "v1.0.9",
"ecosystem": "go"
},
{
"name": "github.com/spf13/viper",
"direct": true,
"version": "v1.20.1",
"ecosystem": "go"
},
{
"name": "github.com/spf13/viper",
"direct": true,
"version": "v1.21.0",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/testify",
"direct": true,
"version": "v1.11.1",
"ecosystem": "go"
},
{
"name": "github.com/testcontainers/testcontainers-go",
"direct": true,
"version": "v0.42.0",
"ecosystem": "go"
},
{
"name": "github.com/testcontainers/testcontainers-go/modules/compose",
"direct": true,
"version": "v0.42.0",
"ecosystem": "go"
},
{
"name": "github.com/xeipuuv/gojsonschema",
"direct": true,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/zitadel/oidc/v3",
"direct": true,
"version": "v3.45.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel",
"direct": true,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
"direct": true,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
"direct": true,
"version": "v1.42.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
"direct": true,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
"direct": true,
"version": "v1.38.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
"direct": true,
"version": "v1.42.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"direct": true,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/trace",
"direct": true,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.51.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.54.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/net",
"direct": true,
"version": "v0.55.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/oauth2",
"direct": true,
"version": "v0.36.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": true,
"version": "v0.43.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/term",
"direct": true,
"version": "v0.44.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.34.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.37.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": true,
"version": "v0.38.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/tools",
"direct": true,
"version": "v0.44.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/grpc",
"direct": true,
"version": "v1.81.1",
"ecosystem": "go"
},
{
"name": "google.golang.org/protobuf",
"direct": true,
"version": "v1.36.11",
"ecosystem": "go"
},
{
"name": "gopkg.in/natefinch/lumberjack.v2",
"direct": true,
"version": "v2.2.1",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v2",
"direct": true,
"version": "v2.4.0",
"ecosystem": "go"
},
{
"name": "gopkg.in/yaml.v3",
"direct": true,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "al.essio.dev/pkg/shellescape",
"direct": false,
"version": "v1.5.1",
"ecosystem": "go"
},
{
"name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
"direct": false,
"version": "v1.36.11-20260415201107-50325440f8f2.1",
"ecosystem": "go"
},
{
"name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
"direct": false,
"version": "v1.36.6-20250603165357-b52ab10f4468.1",
"ecosystem": "go"
},
{
"name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
"direct": false,
"version": "v1.36.6-20250613105001-9f2d3c737feb.1",
"ecosystem": "go"
},
{
"name": "cel.dev/expr",
"direct": false,
"version": "v0.25.1",
"ecosystem": "go"
},
{
"name": "dario.cat/mergo",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/acarl005/stripansi",
"direct": false,
"version": "v0.0.0-20180116102854-5a71ef0e047d",
"ecosystem": "go"
},
{
"name": "github.com/agnivade/levenshtein",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "github.com/alecthomas/chroma/v2",
"direct": false,
"version": "v2.14.0",
"ecosystem": "go"
},
{
"name": "github.com/antlr4-go/antlr/v4",
"direct": false,
"version": "v4.13.1",
"ecosystem": "go"
},
{
"name": "github.com/atotto/clipboard",
"direct": false,
"version": "v0.1.4",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/aymerick/douceur",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-ansiterm",
"direct": false,
"version": "v0.0.0-20250102033503-faa5f7b0171c",
"ecosystem": "go"
},
{
"name": "github.com/azure/go-ntlmssp",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/beorn7/perks",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/bmatcuk/doublestar/v4",
"direct": false,
"version": "v4.6.1",
"ecosystem": "go"
},
{
"name": "github.com/bmatcuk/doublestar/v4",
"direct": false,
"version": "v4.8.1",
"ecosystem": "go"
},
{
"name": "github.com/buger/goterm",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/burntsushi/toml",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/casbin/govaluate",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/catppuccin/go",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/cenkalti/backoff/v4",
"direct": false,
"version": "v4.3.0",
"ecosystem": "go"
},
{
"name": "github.com/cenkalti/backoff/v5",
"direct": false,
"version": "v5.0.3",
"ecosystem": "go"
},
{
"name": "github.com/cespare/xxhash/v2",
"direct": false,
"version": "v2.3.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.2.3-0.20250311203215-f60798e515dc",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.10.1",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.13",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/exp/slice",
"direct": false,
"version": "v0.0.0-20250327172914-2fdc97757edf",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/exp/strings",
"direct": false,
"version": "v0.0.0-20240722160745-212f7b056ed0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/cloudflare/circl",
"direct": false,
"version": "v1.6.3",
"ecosystem": "go"
},
{
"name": "github.com/compose-spec/compose-go/v2",
"direct": false,
"version": "v2.10.2",
"ecosystem": "go"
},
{
"name": "github.com/containerd/console",
"direct": false,
"version": "v1.0.5",
"ecosystem": "go"
},
{
"name": "github.com/containerd/containerd/api",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/containerd/v2",
"direct": false,
"version": "v2.2.5",
"ecosystem": "go"
},
{
"name": "github.com/containerd/continuity",
"direct": false,
"version": "v0.4.5",
"ecosystem": "go"
},
{
"name": "github.com/containerd/errdefs",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/errdefs/pkg",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/log",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/containerd/platforms",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/containerd/platforms",
"direct": false,
"version": "v1.0.0-rc.1",
"ecosystem": "go"
},
{
"name": "github.com/containerd/platforms",
"direct": false,
"version": "v1.0.0-rc.4",
"ecosystem": "go"
},
{
"name": "github.com/containerd/ttrpc",
"direct": false,
"version": "v1.2.8",
"ecosystem": "go"
},
{
"name": "github.com/containerd/typeurl/v2",
"direct": false,
"version": "v2.2.3",
"ecosystem": "go"
},
{
"name": "github.com/cpuguy83/dockercfg",
"direct": false,
"version": "v0.3.2",
"ecosystem": "go"
},
{
"name": "github.com/cpuguy83/go-md2man/v2",
"direct": false,
"version": "v2.0.6",
"ecosystem": "go"
},
{
"name": "github.com/cucumber/gherkin/go/v26",
"direct": false,
"version": "v26.2.0",
"ecosystem": "go"
},
{
"name": "github.com/cucumber/messages/go/v21",
"direct": false,
"version": "v21.0.1",
"ecosystem": "go"
},
{
"name": "github.com/danieljoos/wincred",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/davecgh/go-spew",
"direct": false,
"version": "v1.1.2-0.20180830191138-d8f796af33cc",
"ecosystem": "go"
},
{
"name": "github.com/decred/dcrd/dcrec/secp256k1/v4",
"direct": false,
"version": "v4.4.0",
"ecosystem": "go"
},
{
"name": "github.com/defanglabs/secret-detector",
"direct": false,
"version": "v0.0.0-20250403165618-22662109213e",
"ecosystem": "go"
},
{
"name": "github.com/dgraph-io/ristretto",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/distribution/reference",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/dlclark/regexp2",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "github.com/docker/buildx",
"direct": false,
"version": "v0.33.0",
"ecosystem": "go"
},
{
"name": "github.com/docker/cli",
"direct": false,
"version": "v29.4.0+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/docker/compose/v5",
"direct": false,
"version": "v5.1.2",
"ecosystem": "go"
},
{
"name": "github.com/docker/docker",
"direct": false,
"version": "v28.5.2+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/docker/docker-credential-helpers",
"direct": false,
"version": "v0.9.5",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-connections",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/docker/go-units",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/ebitengine/purego",
"direct": false,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/eiannone/keyboard",
"direct": false,
"version": "v0.0.0-20220611211555-0d226195f203",
"ecosystem": "go"
},
{
"name": "github.com/erikgeiser/coninput",
"direct": false,
"version": "v0.0.0-20211004153227-1c3628e74d0f",
"ecosystem": "go"
},
{
"name": "github.com/felixge/httpsnoop",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/fsnotify/fsevents",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/fvbommel/sortorder",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/go-asn1-ber/asn1-ber",
"direct": false,
"version": "v1.5.8-0.20250403174932-29230038a667",
"ecosystem": "go"
},
{
"name": "github.com/go-ini/ini",
"direct": false,
"version": "v1.67.0",
"ecosystem": "go"
},
{
"name": "github.com/go-jose/go-jose/v4",
"direct": false,
"version": "v4.1.4",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/logr",
"direct": false,
"version": "v1.4.3",
"ecosystem": "go"
},
{
"name": "github.com/go-logr/stdr",
"direct": false,
"version": "v1.2.2",
"ecosystem": "go"
},
{
"name": "github.com/go-ole/go-ole",
"direct": false,
"version": "v1.2.6",
"ecosystem": "go"
},
{
"name": "github.com/go-ole/go-ole",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/go-playground/locales",
"direct": false,
"version": "v0.14.1",
"ecosystem": "go"
},
{
"name": "github.com/go-playground/universal-translator",
"direct": false,
"version": "v0.18.1",
"ecosystem": "go"
},
{
"name": "github.com/go-resty/resty/v2",
"direct": false,
"version": "v2.12.0",
"ecosystem": "go"
},
{
"name": "github.com/go-resty/resty/v2",
"direct": false,
"version": "v2.16.5",
"ecosystem": "go"
},
{
"name": "github.com/gobwas/glob",
"direct": false,
"version": "v0.2.3",
"ecosystem": "go"
},
{
"name": "github.com/goccy/go-json",
"direct": false,
"version": "v0.10.5",
"ecosystem": "go"
},
{
"name": "github.com/godbus/dbus/v5",
"direct": false,
"version": "v5.1.0",
"ecosystem": "go"
},
{
"name": "github.com/gofrs/flock",
"direct": false,
"version": "v0.13.0",
"ecosystem": "go"
},
{
"name": "github.com/gofrs/uuid",
"direct": false,
"version": "v4.3.1+incompatible",
"ecosystem": "go"
},
{
"name": "github.com/gogo/protobuf",
"direct": false,
"version": "v1.3.2",
"ecosystem": "go"
},
{
"name": "github.com/golang/mock",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/golang/mock",
"direct": false,
"version": "v1.7.0-rc.1",
"ecosystem": "go"
},
{
"name": "github.com/golang/protobuf",
"direct": false,
"version": "v1.5.4",
"ecosystem": "go"
},
{
"name": "github.com/google/cel-go",
"direct": false,
"version": "v0.25.0",
"ecosystem": "go"
},
{
"name": "github.com/google/cel-go",
"direct": false,
"version": "v0.26.1",
"ecosystem": "go"
},
{
"name": "github.com/google/go-cmp",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/google/shlex",
"direct": false,
"version": "v0.0.0-20191202100458-e7afc7fbc510",
"ecosystem": "go"
},
{
"name": "github.com/gorilla/css",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/gorilla/mux",
"direct": false,
"version": "v1.8.1",
"ecosystem": "go"
},
{
"name": "github.com/gorilla/securecookie",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/grpc-ecosystem/grpc-gateway/v2",
"direct": false,
"version": "v2.26.3",
"ecosystem": "go"
},
{
"name": "github.com/grpc-ecosystem/grpc-gateway/v2",
"direct": false,
"version": "v2.28.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/errwrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-cleanhttp",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-immutable-radix",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-memdb",
"direct": false,
"version": "v1.3.4",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-multierror",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/go-version",
"direct": false,
"version": "v1.9.0",
"ecosystem": "go"
},
{
"name": "github.com/hashicorp/golang-lru",
"direct": false,
"version": "v0.5.4",
"ecosystem": "go"
},
{
"name": "github.com/in-toto/attestation",
"direct": false,
"version": "v1.1.2",
"ecosystem": "go"
},
{
"name": "github.com/in-toto/in-toto-golang",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/inhies/go-bytesize",
"direct": false,
"version": "v0.0.0-20220417184213-4913239db9cf",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgpassfile",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/jackc/pgservicefile",
"direct": false,
"version": "v0.0.0-20240606120523-5a60cdf6a761",
"ecosystem": "go"
},
{
"name": "github.com/jackc/puddle/v2",
"direct": false,
"version": "v2.2.2",
"ecosystem": "go"
},
{
"name": "github.com/jonboulle/clockwork",
"direct": false,
"version": "v0.5.0",
"ecosystem": "go"
},
{
"name": "github.com/klauspost/compress",
"direct": false,
"version": "v1.18.5",
"ecosystem": "go"
},
{
"name": "github.com/kr/pretty",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/kr/text",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/lann/builder",
"direct": false,
"version": "v0.0.0-20180802200727-47ae307949d0",
"ecosystem": "go"
},
{
"name": "github.com/lann/ps",
"direct": false,
"version": "v0.0.0-20150810152359-62de8c46ede0",
"ecosystem": "go"
},
{
"name": "github.com/leodido/go-urn",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/blackmagic",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/dsig",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/dsig-secp256k1",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/httpcc",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/httprc",
"direct": false,
"version": "v1.0.6",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/httprc/v3",
"direct": false,
"version": "v3.0.1",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/iter",
"direct": false,
"version": "v1.0.2",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/jwx/v3",
"direct": false,
"version": "v3.0.11",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/option",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/lestrrat-go/option/v2",
"direct": false,
"version": "v2.0.0",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/lufia/plan9stats",
"direct": false,
"version": "v0.0.0-20211012122336-39d0f177ccd0",
"ecosystem": "go"
},
{
"name": "github.com/lufia/plan9stats",
"direct": false,
"version": "v0.0.0-20250317134145-8bc96cf8fc35",
"ecosystem": "go"
},
{
"name": "github.com/magiconair/properties",
"direct": false,
"version": "v1.8.10",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-localereader",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.16",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-shellwords",
"direct": false,
"version": "v1.0.12",
"ecosystem": "go"
},
{
"name": "github.com/mfridman/interpolate",
"direct": false,
"version": "v0.0.2",
"ecosystem": "go"
},
{
"name": "github.com/microcosm-cc/bluemonday",
"direct": false,
"version": "v1.0.27",
"ecosystem": "go"
},
{
"name": "github.com/microsoft/go-winio",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/miekg/dns",
"direct": false,
"version": "v1.1.58",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/hashstructure/v2",
"direct": false,
"version": "v2.0.2",
"ecosystem": "go"
},
{
"name": "github.com/moby/buildkit",
"direct": false,
"version": "v0.29.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/docker-image-spec",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/go-archive",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/locker",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/moby/api",
"direct": false,
"version": "v1.54.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/moby/client",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/patternmatcher",
"direct": false,
"version": "v0.6.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/atomicwriter",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/capability",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/sequential",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/signal",
"direct": false,
"version": "v0.7.1",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/symlink",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/user",
"direct": false,
"version": "v0.4.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/sys/userns",
"direct": false,
"version": "v0.1.0",
"ecosystem": "go"
},
{
"name": "github.com/moby/term",
"direct": false,
"version": "v0.5.2",
"ecosystem": "go"
},
{
"name": "github.com/morikuni/aec",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/muesli/ansi",
"direct": false,
"version": "v0.0.0-20230316100256-276c6243b2f6",
"ecosystem": "go"
},
{
"name": "github.com/muesli/cancelreader",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/reflow",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": false,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/muhlemmer/gu",
"direct": false,
"version": "v0.3.1",
"ecosystem": "go"
},
{
"name": "github.com/munnerz/goautoneg",
"direct": false,
"version": "v0.0.0-20191010083416-a7dc8b61c822",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/go-digest",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/opencontainers/image-spec",
"direct": false,
"version": "v1.1.1",
"ecosystem": "go"
},
{
"name": "github.com/opentracing/opentracing-go",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/pelletier/go-toml/v2",
"direct": false,
"version": "v2.2.4",
"ecosystem": "go"
},
{
"name": "github.com/pkg/errors",
"direct": false,
"version": "v0.9.1",
"ecosystem": "go"
},
{
"name": "github.com/planetscale/vtprotobuf",
"direct": false,
"version": "v0.6.1-0.20240319094008-0393e58bdf10",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/pmezard/go-difflib",
"direct": false,
"version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
"ecosystem": "go"
},
{
"name": "github.com/power-devops/perfstat",
"direct": false,
"version": "v0.0.0-20240221224432-82ca36839d55",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "v1.22.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_golang",
"direct": false,
"version": "v1.23.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/client_model",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "v0.62.0",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/common",
"direct": false,
"version": "v0.66.1",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.16.1",
"ecosystem": "go"
},
{
"name": "github.com/prometheus/procfs",
"direct": false,
"version": "v0.17.0",
"ecosystem": "go"
},
{
"name": "github.com/rcrowley/go-metrics",
"direct": false,
"version": "v0.0.0-20201227073835-cf1acfcdf475",
"ecosystem": "go"
},
{
"name": "github.com/rcrowley/go-metrics",
"direct": false,
"version": "v0.0.0-20250401214520-65e299d6c5c9",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/rogpeppe/go-internal",
"direct": false,
"version": "v1.12.0",
"ecosystem": "go"
},
{
"name": "github.com/rogpeppe/go-internal",
"direct": false,
"version": "v1.14.1",
"ecosystem": "go"
},
{
"name": "github.com/russross/blackfriday/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/sagikazarmark/locafero",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/sagikazarmark/locafero",
"direct": false,
"version": "v0.7.0",
"ecosystem": "go"
},
{
"name": "github.com/sahilm/fuzzy",
"direct": false,
"version": "v0.1.1",
"ecosystem": "go"
},
{
"name": "github.com/santhosh-tekuri/jsonschema/v6",
"direct": false,
"version": "v6.0.1",
"ecosystem": "go"
},
{
"name": "github.com/secure-systems-lab/go-securesystemslib",
"direct": false,
"version": "v0.10.0",
"ecosystem": "go"
},
{
"name": "github.com/segmentio/asm",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/segmentio/ksuid",
"direct": false,
"version": "v1.0.4",
"ecosystem": "go"
},
{
"name": "github.com/sethvargo/go-retry",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/shibumi/go-pathspec",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/shirou/gopsutil/v4",
"direct": false,
"version": "v4.26.3",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/sigstore",
"direct": false,
"version": "v1.10.4",
"ecosystem": "go"
},
{
"name": "github.com/sigstore/sigstore-go",
"direct": false,
"version": "v1.1.4",
"ecosystem": "go"
},
{
"name": "github.com/sirupsen/logrus",
"direct": false,
"version": "v1.9.3",
"ecosystem": "go"
},
{
"name": "github.com/sirupsen/logrus",
"direct": false,
"version": "v1.9.4",
"ecosystem": "go"
},
{
"name": "github.com/skratchdot/open-golang",
"direct": false,
"version": "v0.0.0-20200116055534-eef842397966",
"ecosystem": "go"
},
{
"name": "github.com/sourcegraph/conc",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/sourcegraph/conc",
"direct": false,
"version": "v0.3.1-0.20240121214520-5f936abd7ae8",
"ecosystem": "go"
},
{
"name": "github.com/spf13/afero",
"direct": false,
"version": "v1.12.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/afero",
"direct": false,
"version": "v1.15.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cast",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cast",
"direct": false,
"version": "v1.7.1",
"ecosystem": "go"
},
{
"name": "github.com/stoewer/go-strcase",
"direct": false,
"version": "v1.3.0",
"ecosystem": "go"
},
{
"name": "github.com/stoewer/go-strcase",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/objx",
"direct": false,
"version": "v0.5.3",
"ecosystem": "go"
},
{
"name": "github.com/subosito/gotenv",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/tchap/go-patricia/v2",
"direct": false,
"version": "v2.3.2",
"ecosystem": "go"
},
{
"name": "github.com/tchap/go-patricia/v2",
"direct": false,
"version": "v2.3.3",
"ecosystem": "go"
},
{
"name": "github.com/tilt-dev/fsnotify",
"direct": false,
"version": "v1.4.8-0.20220602155310-fff9c274a375",
"ecosystem": "go"
},
{
"name": "github.com/tklauser/go-sysconf",
"direct": false,
"version": "v0.3.16",
"ecosystem": "go"
},
{
"name": "github.com/tklauser/numcpus",
"direct": false,
"version": "v0.11.0",
"ecosystem": "go"
},
{
"name": "github.com/tonistiigi/dchapes-mode",
"direct": false,
"version": "v0.0.0-20250318174251-73d941a28323",
"ecosystem": "go"
},
{
"name": "github.com/tonistiigi/fsutil",
"direct": false,
"version": "v0.0.0-20251211185533-a2aa163d723f",
"ecosystem": "go"
},
{
"name": "github.com/tonistiigi/go-csvvalue",
"direct": false,
"version": "v0.0.0-20240814133006-030d3b2625d0",
"ecosystem": "go"
},
{
"name": "github.com/tonistiigi/units",
"direct": false,
"version": "v0.0.0-20180711220420-6950e57a87ea",
"ecosystem": "go"
},
{
"name": "github.com/tonistiigi/vt100",
"direct": false,
"version": "v0.0.0-20240514184818-90bafcd6abab",
"ecosystem": "go"
},
{
"name": "github.com/valyala/fastjson",
"direct": false,
"version": "v1.6.4",
"ecosystem": "go"
},
{
"name": "github.com/vektah/gqlparser/v2",
"direct": false,
"version": "v2.5.26",
"ecosystem": "go"
},
{
"name": "github.com/vektah/gqlparser/v2",
"direct": false,
"version": "v2.5.30",
"ecosystem": "go"
},
{
"name": "github.com/xeipuuv/gojsonpointer",
"direct": false,
"version": "v0.0.0-20190905194746-02993c407bfb",
"ecosystem": "go"
},
{
"name": "github.com/xeipuuv/gojsonreference",
"direct": false,
"version": "v0.0.0-20180127040603-bd5ef7bd5415",
"ecosystem": "go"
},
{
"name": "github.com/xhit/go-str2duration/v2",
"direct": false,
"version": "v2.1.0",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "github.com/yashtewari/glob-intersection",
"direct": false,
"version": "v0.2.0",
"ecosystem": "go"
},
{
"name": "github.com/yuin/goldmark",
"direct": false,
"version": "v1.7.8",
"ecosystem": "go"
},
{
"name": "github.com/yuin/goldmark-emoji",
"direct": false,
"version": "v1.0.5",
"ecosystem": "go"
},
{
"name": "github.com/yusufpapurcu/wmi",
"direct": false,
"version": "v1.2.4",
"ecosystem": "go"
},
{
"name": "github.com/zalando/go-keyring",
"direct": false,
"version": "v0.2.6",
"ecosystem": "go"
},
{
"name": "github.com/zitadel/logging",
"direct": false,
"version": "v0.6.2",
"ecosystem": "go"
},
{
"name": "github.com/zitadel/schema",
"direct": false,
"version": "v1.3.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/auto/sdk",
"direct": false,
"version": "v1.2.1",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
"direct": false,
"version": "v0.63.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/httptrace/otelhttptrace",
"direct": false,
"version": "v0.63.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
"direct": false,
"version": "v0.60.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
"direct": false,
"version": "v0.61.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
"direct": false,
"version": "v0.63.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
"direct": false,
"version": "v1.42.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/metric",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/otel/sdk/metric",
"direct": false,
"version": "v1.43.0",
"ecosystem": "go"
},
{
"name": "go.opentelemetry.io/proto/otlp",
"direct": false,
"version": "v1.10.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/mock",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "go.uber.org/multierr",
"direct": false,
"version": "v1.11.0",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v2",
"direct": false,
"version": "v2.4.3",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v3",
"direct": false,
"version": "v3.0.4",
"ecosystem": "go"
},
{
"name": "go.yaml.in/yaml/v4",
"direct": false,
"version": "v4.0.0-rc.4",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.48.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.52.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/crypto",
"direct": false,
"version": "v0.53.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": false,
"version": "v0.0.0-20250506013437-ce4c2cf36ca6",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": false,
"version": "v0.0.0-20250911091902-df9299821621",
"ecosystem": "go"
},
{
"name": "golang.org/x/mod",
"direct": false,
"version": "v0.35.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.20.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.21.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.42.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": false,
"version": "v0.46.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": false,
"version": "v0.14.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/time",
"direct": false,
"version": "v0.6.0",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"direct": false,
"version": "v0.0.0-20260226221140-a57be14db171",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/api",
"direct": false,
"version": "v0.0.0-20260401024825-9d38bb4040a9",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260226221140-a57be14db171",
"ecosystem": "go"
},
{
"name": "google.golang.org/genproto/googleapis/rpc",
"direct": false,
"version": "v0.0.0-20260401024825-9d38bb4040a9",
"ecosystem": "go"
},
{
"name": "gopkg.in/check.v1",
"direct": false,
"version": "v1.0.0-20201130134442-10cb98267c6c",
"ecosystem": "go"
},
{
"name": "gopkg.in/ini.v1",
"direct": false,
"version": "v1.67.0",
"ecosystem": "go"
},
{
"name": "gotest.tools/v3",
"direct": false,
"version": "v3.5.2",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/yaml",
"direct": false,
"version": "v1.4.0",
"ecosystem": "go"
},
{
"name": "sigs.k8s.io/yaml",
"direct": false,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "tags.cncf.io/container-device-interface",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
}
],
"collected": true,
"truncated": false,
"total_count": 379,
"direct_count": 103,
"indirect_count": 276
}
},
"maintainership": {
"issues": {
"open_prs": 131,
"merged_prs": 2168,
"open_issues": 115,
"closed_ratio": 0.823,
"closed_issues": 536,
"closed_unmerged_prs": 778
},
"bus_factor": 3,
"bot_contributors": 3,
"top_contributors": [
{
"type": "User",
"login": "dmihalcik-virtru",
"commits": 273,
"avatar_url": "https://avatars.githubusercontent.com/u/38867245?v=4"
},
{
"type": "User",
"login": "jakedoublev",
"commits": 229,
"avatar_url": "https://avatars.githubusercontent.com/u/83739412?v=4"
},
{
"type": "User",
"login": "strantalis",
"commits": 208,
"avatar_url": "https://avatars.githubusercontent.com/u/18211470?v=4"
},
{
"type": "User",
"login": "elizabethhealy",
"commits": 106,
"avatar_url": "https://avatars.githubusercontent.com/u/35498075?v=4"
},
{
"type": "User",
"login": "c-r33d",
"commits": 98,
"avatar_url": "https://avatars.githubusercontent.com/u/87077975?v=4"
},
{
"type": "User",
"login": "jrschumacher",
"commits": 61,
"avatar_url": "https://avatars.githubusercontent.com/u/46549?v=4"
},
{
"type": "User",
"login": "pflynn-virtru",
"commits": 59,
"avatar_url": "https://avatars.githubusercontent.com/u/43211074?v=4"
},
{
"type": "User",
"login": "alkalescent",
"commits": 58,
"avatar_url": "https://avatars.githubusercontent.com/u/42231639?v=4"
},
{
"type": "User",
"login": "ryanulit",
"commits": 42,
"avatar_url": "https://avatars.githubusercontent.com/u/7658058?v=4"
},
{
"type": "User",
"login": "sujankota",
"commits": 21,
"avatar_url": "https://avatars.githubusercontent.com/u/4155572?v=4"
}
],
"contributors_sampled": 39,
"top_contributor_share": 0.203
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"action-lint.yaml",
"backport.yaml",
"checks.yaml",
"codeql.yaml",
"create-release-branch.yaml",
"dco_merge_group.yaml",
"dependency-review.yaml",
"friendly-reminders.yaml",
"label.yaml",
"main-dependency-review.yaml",
"nightly-build.yaml",
"nightly-checks.yaml",
"pr-checks.yaml",
"release-build.yaml",
"release-otdfctl.yaml",
"release.yaml",
"reusable_backport.yaml",
"reusable_create-release-branch.yaml",
"reusable_release-please.yaml",
"sonarcloud.yml",
"stale.yaml",
"traffic.yaml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yaml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 5,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 12 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 7,
"reason": "dependency not pinned by hash detected -- score normalized to 7",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "34 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "5bae1eb7a3b9d19d67845ac8239447eecf25e8ba",
"ran_at": "2026-07-22T03:27:21Z",
"aggregate_score": 8.4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-22T01:08:26Z",
"oldest_open_prs": [
{
"number": 1568,
"created_at": "2024-09-23T20:58:04Z",
"last_comment_at": "2024-09-24T20:08:44Z",
"last_comment_author": "github-actions"
},
{
"number": 1600,
"created_at": "2024-10-01T23:15:50Z",
"last_comment_at": "2024-10-10T00:21:17Z",
"last_comment_author": "strantalis"
},
{
"number": 1664,
"created_at": "2024-10-17T19:05:36Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1671,
"created_at": "2024-10-21T13:53:35Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1807,
"created_at": "2024-12-03T18:05:03Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1838,
"created_at": "2025-01-07T17:57:15Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1907,
"created_at": "2025-02-06T14:30:05Z",
"last_comment_at": "2025-07-14T17:32:12Z",
"last_comment_author": "github-actions"
},
{
"number": 1928,
"created_at": "2025-02-20T14:51:29Z",
"last_comment_at": "2026-03-19T11:20:03Z",
"last_comment_author": "dschmidt"
},
{
"number": 1936,
"created_at": "2025-02-24T18:21:37Z",
"last_comment_at": "2025-09-19T16:23:43Z",
"last_comment_author": "pflynn-virtru"
},
{
"number": 1980,
"created_at": "2025-03-14T14:54:14Z",
"last_comment_at": "2026-07-21T12:47:58Z",
"last_comment_author": "github-actions"
},
{
"number": 2036,
"created_at": "2025-04-01T17:35:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2117,
"created_at": "2025-04-25T21:55:33Z",
"last_comment_at": "2025-04-25T22:00:07Z",
"last_comment_author": "github-actions"
},
{
"number": 2184,
"created_at": "2025-05-06T23:33:51Z",
"last_comment_at": "2025-05-07T14:47:06Z",
"last_comment_author": "github-actions"
},
{
"number": 2187,
"created_at": "2025-05-07T14:09:32Z",
"last_comment_at": "2025-05-07T19:30:48Z",
"last_comment_author": "github-actions"
},
{
"number": 2195,
"created_at": "2025-05-09T14:10:50Z",
"last_comment_at": "2025-05-29T17:47:44Z",
"last_comment_author": "github-actions"
},
{
"number": 2270,
"created_at": "2025-05-20T21:55:13Z",
"last_comment_at": "2025-06-05T23:30:22Z",
"last_comment_author": "github-actions"
},
{
"number": 2300,
"created_at": "2025-05-23T00:45:14Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 2327,
"created_at": "2025-05-28T17:49:31Z",
"last_comment_at": "2025-06-02T17:28:33Z",
"last_comment_author": "github-actions"
},
{
"number": 2349,
"created_at": "2025-06-02T20:40:46Z",
"last_comment_at": "2025-06-05T21:32:49Z",
"last_comment_author": "github-actions"
},
{
"number": 2375,
"created_at": "2025-06-04T16:35:31Z",
"last_comment_at": "2025-06-16T14:53:38Z",
"last_comment_author": "github-actions"
}
],
"last_merged_pr_at": "2026-07-21T21:16:58Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": [
{
"number": 165,
"created_at": "2024-02-08T21:26:04Z",
"last_comment_at": "2024-04-30T15:01:29Z",
"last_comment_author": "jrschumacher"
},
{
"number": 517,
"created_at": "2024-04-04T20:19:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 666,
"created_at": "2024-04-25T15:06:59Z",
"last_comment_at": "2024-07-14T15:40:37Z",
"last_comment_author": "damorris25"
},
{
"number": 745,
"created_at": "2024-05-06T16:39:43Z",
"last_comment_at": "2024-06-06T16:37:37Z",
"last_comment_author": "cassandrabailey293"
},
{
"number": 827,
"created_at": "2024-05-16T17:19:56Z",
"last_comment_at": "2024-06-24T14:58:03Z",
"last_comment_author": "dmihalcik-virtru"
},
{
"number": 839,
"created_at": "2024-05-20T14:17:09Z",
"last_comment_at": "2024-05-30T14:13:38Z",
"last_comment_author": "dmihalcik-virtru"
},
{
"number": 860,
"created_at": "2024-05-23T14:53:02Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 945,
"created_at": "2024-06-06T20:43:57Z",
"last_comment_at": "2024-06-06T20:50:40Z",
"last_comment_author": "jakedoublev"
},
{
"number": 948,
"created_at": "2024-06-07T13:39:42Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 949,
"created_at": "2024-06-07T14:26:55Z",
"last_comment_at": "2024-06-10T13:44:17Z",
"last_comment_author": "strantalis"
},
{
"number": 955,
"created_at": "2024-06-10T13:48:26Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 957,
"created_at": "2024-06-10T16:50:07Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1026,
"created_at": "2024-06-24T14:06:25Z",
"last_comment_at": "2024-06-25T17:48:34Z",
"last_comment_author": "strantalis"
},
{
"number": 1056,
"created_at": "2024-06-28T20:25:35Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1057,
"created_at": "2024-06-28T20:32:54Z",
"last_comment_at": "2025-01-28T03:39:35Z",
"last_comment_author": "jrschumacher"
},
{
"number": 1085,
"created_at": "2024-07-02T19:34:33Z",
"last_comment_at": "2025-01-28T03:40:36Z",
"last_comment_author": "jrschumacher"
},
{
"number": 1107,
"created_at": "2024-07-08T16:21:05Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1128,
"created_at": "2024-07-11T11:47:27Z",
"last_comment_at": "2025-01-28T14:02:58Z",
"last_comment_author": "jrschumacher"
},
{
"number": 1130,
"created_at": "2024-07-11T13:37:34Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1142,
"created_at": "2024-07-12T16:42:25Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/opentdf/platform",
"host": "github.com",
"name": "platform",
"owner": "opentdf"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"security": 78,
"vitality": 100,
"community": 68,
"governance": 79,
"engineering": 80
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 100,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"commits_last_year": 598,
"human_commit_share": 0.67,
"days_since_last_push": 0,
"active_weeks_last_year": 52
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "52/52 weeks with commits",
"points": 36,
"status": "met",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 52
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "598 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 598
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 100,
"latest_release_tag": "sdk/v0.27.0",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 2.3
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "100 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 100
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~2.3 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 2.3
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 68,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 47,
"inputs": {
"forks": 37,
"stars": 50,
"watchers": 15,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "below_threshold"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "50 stars",
"points": 27.4,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 50
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "37 forks",
"points": 13,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 37
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "15 watchers",
"points": 6.4,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 15
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (BSD-3-Clause-Clear)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "BSD-3-Clause-Clear"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 79,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "good",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"bus_factor": 3,
"contributors_sampled": 39,
"top_contributor_share": 0.203
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "3 contributor(s) cover half of all commits",
"points": 36,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 3
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 20% of commits",
"points": 17.9,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 20
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "39 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 39
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 12 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"merged_prs": 2168,
"open_issues": 115,
"closed_issues": 536,
"issue_closed_ratio": 0.823,
"closed_unmerged_prs": 778
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "82% of issues closed",
"points": 38.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 82
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "2168/2946 decided PRs merged",
"points": 28.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 2168,
"decided": 2946
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"followers": 115,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "opentdf",
"public_repos": 11,
"account_age_days": 1782
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "115 followers of opentdf",
"points": 14.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 115,
"login": "opentdf"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "11 public repos, account ~4 yr old",
"points": 17.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 11
}
},
{
"code": "account_age_years",
"params": {
"years": 4
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/opentdf/platform/sdk",
"github.com/opentdf/platform/otdfctl",
"github.com/opentdf/platform/service"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "3 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 3,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "76 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 76
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 80,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "22 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 22
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yaml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"data-encryption",
"data-tagging",
"drm",
"end-to-end-encryption",
"file-encryption",
"go",
"golang",
"open-source",
"opensource",
"opentdf",
"tdf",
"zero-trust",
"zero-trust-security"
],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "13 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 13
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 78,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "good",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 84,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 8.4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 3.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 12 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 3.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "34 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "moderate",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 379 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 379
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 53,
"inputs": {
"source": "osv",
"advisories": 76,
"affected_packages": 15,
"assessed_packages": 379,
"unassessed_packages": 0,
"affected_by_severity": "critical 2, high 1, moderate 4, unknown 8",
"direct_affected_packages": 8
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "8 affected: google.golang.org/grpc v1.81.1 (critical 9.1), golang.org/x/net v0.38.0 (moderate 6.5), golang.org/x/net v0.51.0 (moderate 6.5), +5 more",
"points": 5.3,
"status": "partial",
"details": [
{
"code": "advisories_affected",
"params": {
"count": 8,
"packages": "google.golang.org/grpc v1.81.1 (critical 9.1), golang.org/x/net v0.38.0 (moderate 6.5), golang.org/x/net v0.51.0 (moderate 6.5)"
}
},
{
"code": "advisories_affected_more",
"params": {
"count": 5
}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 166 days ago",
"points": 34.4,
"status": "partial",
"details": [
{
"code": "advisories_stale",
"params": {
"days": 90,
"count": 1,
"oldest": 166
}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 379,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 7
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 91,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 3337
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 67,
"sampled": 67
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 97,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": true,
"typed_language": true,
"bootstrap_files": [
"Makefile",
"otdfctl/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.08,
"toolchain_manifests": [
"examples/go.mod",
"lib/fixtures/go.mod",
"lib/flattening/go.mod",
"lib/identifier/go.mod",
"lib/ocrypto/go.mod",
"otdfctl/go.mod",
"protocol/codegen/go.mod",
"protocol/go/go.mod",
"sdk/go.mod",
"service/go.mod",
"test/integration/go.mod",
"tests-bdd/go.mod"
],
"dependency_bot_commit_share": 0.1
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile, otdfctl/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile, otdfctl/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yaml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yaml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "8 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 8,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "10 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 10,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 7",
"points": 7,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 255537,
"source_files_sampled": 756,
"oversized_source_files": 23
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "23/756 source files over 60KB",
"points": 53.3,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 756,
"oversized": 23
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "good",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": [
"service/authorization/authorization.proto",
"service/authorization/v2/authorization.proto",
"service/common/common.proto",
"service/entity/entity.proto",
"service/entityresolution/entity_resolution.proto",
"service/entityresolution/v2/entity_resolution.proto",
"service/kas/kas.proto",
"service/logger/audit/test.proto",
"service/policy/actions/actions.proto",
"service/policy/attributes/attributes.proto",
"service/policy/dynamicvaluemapping/dynamic_value_mapping.proto",
"service/policy/kasregistry/key_access_server_registry.proto",
"service/policy/keymanagement/key_management.proto",
"service/policy/namespaces/namespaces.proto",
"service/policy/objects.proto",
"service/policy/obligations/obligations.proto",
"service/policy/registeredresources/registered_resources.proto",
"service/policy/resourcemapping/resource_mapping.proto",
"service/policy/selectors.proto",
"service/policy/subjectmapping/subject_mapping.proto",
"service/policy/unsafe/unsafe.proto",
"service/wellknownconfiguration/wellknown_configuration.proto"
]
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": "service/authorization/authorization.proto, service/authorization/v2/authorization.proto, service/common/common.proto, service/entity/entity.proto, service/entityresolution/entity_resolution.proto, service/entityresolution/v2/entity_resolution.proto, service/kas/kas.proto, service/logger/audit/test.proto, service/policy/actions/actions.proto, service/policy/attributes/attributes.proto, service/policy/dynamicvaluemapping/dynamic_value_mapping.proto, service/policy/kasregistry/key_access_server_registry.proto, service/policy/keymanagement/key_management.proto, service/policy/namespaces/namespaces.proto, service/policy/objects.proto, service/policy/obligations/obligations.proto, service/policy/registeredresources/registered_resources.proto, service/policy/resourcemapping/resource_mapping.proto, service/policy/selectors.proto, service/policy/subjectmapping/subject_mapping.proto, service/policy/unsafe/unsafe.proto, service/wellknownconfiguration/wellknown_configuration.proto",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "service/authorization/authorization.proto, service/authorization/v2/authorization.proto, service/common/common.proto, service/entity/entity.proto, service/entityresolution/entity_resolution.proto, service/entityresolution/v2/entity_resolution.proto, service/kas/kas.proto, service/logger/audit/test.proto, service/policy/actions/actions.proto, service/policy/attributes/attributes.proto, service/policy/dynamicvaluemapping/dynamic_value_mapping.proto, service/policy/kasregistry/key_access_server_registry.proto, service/policy/keymanagement/key_management.proto, service/policy/namespaces/namespaces.proto, service/policy/objects.proto, service/policy/obligations/obligations.proto, service/policy/registeredresources/registered_resources.proto, service/policy/resourcemapping/resource_mapping.proto, service/policy/selectors.proto, service/policy/subjectmapping/subject_mapping.proto, service/policy/unsafe/unsafe.proto, service/wellknownconfiguration/wellknown_configuration.proto"
}
}
],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Could not fetch go package 'github.com/opentdf/platform/tests-bdd' from its registry"
],
"report_type": "repository",
"generated_at": "2026-07-22T03:28:01.017781Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/opentdf/platform.svg",
"full_name": "opentdf/platform",
"license_state": "standard",
"license_spdx": "BSD-3-Clause-Clear"
}