Звіт у форматі JSON машиночитний
{
"data": {
"icon": {
"bytes": 29265,
"width": 159,
"height": 159,
"rejected": [],
"collected": true,
"media_type": "image/png",
"source_url": "https://avatars.githubusercontent.com/u/46885541?v=4&s=256",
"source_type": "avatar",
"content_hash": "c9929a89b314880e330a910698ad7d53ccb93859b2db58ff92bc031149a99c83",
"candidates_considered": 1
},
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 89,
"has_wiki": true,
"homepage": null,
"languages": {
"JavaScript": 48291
},
"pushed_at": "2026-07-25T18:56:29Z",
"created_at": "2019-05-02T16:59:49Z",
"owner_type": "Organization",
"updated_at": "2026-07-25T18:56:33Z",
"description": "Version read/write plugin for release-it",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "JavaScript",
"significant_languages": [
"JavaScript"
]
},
"owner": {
"blog": "https://webpro.nl",
"name": "Release It!",
"type": "Organization",
"login": "release-it",
"company": null,
"location": "Netherlands",
"followers": 53,
"avatar_url": "https://avatars.githubusercontent.com/u/46885541?v=4",
"created_at": "2019-01-21T07:58:47Z",
"is_verified": null,
"public_repos": 7,
"account_age_days": 2753
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "8.0.0",
"kind": "major",
"published_at": "2026-07-25T18:56:30Z"
},
{
"tag": "7.0.6",
"kind": "patch",
"published_at": "2026-05-30T06:19:17Z"
},
{
"tag": "7.0.5",
"kind": "patch",
"published_at": "2025-04-19T12:51:28Z"
},
{
"tag": "7.0.4",
"kind": "patch",
"published_at": "2025-04-18T09:40:49Z"
},
{
"tag": "7.0.3",
"kind": "patch",
"published_at": "2025-04-18T06:57:40Z"
},
{
"tag": "7.0.2",
"kind": "patch",
"published_at": "2025-03-13T06:20:00Z"
},
{
"tag": "7.0.1",
"kind": "patch",
"published_at": "2025-01-20T11:03:06Z"
},
{
"tag": "7.0.0",
"kind": "major",
"published_at": "2025-01-08T15:58:25Z"
},
{
"tag": "6.0.1",
"kind": "patch",
"published_at": "2023-11-11T14:53:02Z"
},
{
"tag": "6.0.0",
"kind": "major",
"published_at": "2023-11-11T14:51:47Z"
},
{
"tag": "5.1.0",
"kind": "minor",
"published_at": "2023-07-29T08:44:02Z"
}
],
"recent_commits": [
{
"oid": "2f8ae9d711132f914ed91c640f8bb02b4a524cad",
"body": null,
"is_bot": false,
"headline": "Release 8.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-07-25T18:56:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0fbeba8b223d59b6daaefbd383e58836c5092a84",
"body": null,
"is_bot": false,
"headline": "Upgrade dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-07-25T18:53:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ccd1b6fb5b83661db8308a7cbe00f513847e4ece",
"body": null,
"is_bot": false,
"headline": "Cover mixed manifest output updates (resolve #46)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-07-25T13:22:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a24c906aadaa21d3b02ae600fa8a2d76af40dc0e",
"body": null,
"is_bot": false,
"headline": "Release 7.0.6",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-05-30T06:19:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d391306849231c7db87ffe954d808d8241b05a6d",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-05-30T05:03:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0267f38169e930401f20b186c607c00ee5400e36",
"body": null,
"is_bot": false,
"headline": "Escape version when replacing in text files (resolves #36)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-05-30T05:03:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "299acdc10cc1b7789adb058d4b3e3c0db7e5976f",
"body": "see https://nvd.nist.gov/vuln/detail/CVE-2025-64718",
"is_bot": false,
"headline": "chore (deps): bump js-yaml to ^4.4.1 to avoid CVE-2025-64718 (#47)",
"author_name": "sam92",
"author_login": "sam92",
"committed_at": "2026-05-29T13:56:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5af1ec1de74260194666690388ed86b7cbb6c736",
"body": "…ix' (#50)\n\n#49",
"is_bot": false,
"headline": "test: update README and tests to use 'versionPrefix' instead of 'pref…",
"author_name": "Juan Carlos Blanco Delgado",
"author_login": "juancarlosjr97",
"committed_at": "2026-05-29T13:55:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "89152efb8754402ff3d2f1e54ee401338f7ae060",
"body": null,
"is_bot": false,
"headline": "ci: run tests on Node 24 and 26 (#51)",
"author_name": "Roman",
"author_login": "gameroman",
"committed_at": "2026-05-29T11:26:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ee5ad69ae7cddead7f0a8b468945c3fe39f8633",
"body": "* test: add tests demonstrating limitations of the toml regex edit\n\n* fix(toml): adhere to target path when patching toml formatted files\n\nIntroduces `@decimalturn/toml-patch` to update TOML versions without\ndestroying original formatting or stripping inline comments.\n\nWhile this package has a small\n[…]\nt than alternative\noptions (like `@shopify/toml-patch`), it offers a stable semver release.\n\n* test: refactor toml tests to align more with json tests\n\n* test: refactor toml test to reduce boilerplate",
"is_bot": false,
"headline": "Fix TOML path targeting and formatting loss with toml-patch (#53)",
"author_name": "James Barr",
"author_login": "JamesMBarr",
"committed_at": "2026-05-23T08:12:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e3eb23ba8f549abe023df9d3a621f8519b3ae9c2",
"body": null,
"is_bot": false,
"headline": "Support release-it 20",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2026-05-23T08:02:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db20bab3ae84ad960020d0e09b33bbe75edb97c2",
"body": null,
"is_bot": false,
"headline": "Release 7.0.5",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-19T12:51:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "07de07ca9e50c0edb6c5af2e7cef8dbfd5d5a33d",
"body": null,
"is_bot": false,
"headline": "Fix toml/win newline issue (resolves #44)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-19T12:50:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e89648a1b5c378f9ef291e17644ac0cffcd0fd5a",
"body": null,
"is_bot": false,
"headline": "Release 7.0.4",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T09:40:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28efd133cfacca6e03efdba748b7517a80ec8a9e",
"body": null,
"is_bot": false,
"headline": "Use commit.subject in release notes line",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T09:40:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c110741bbea3ef7e3f163dfbea14b234ee2424f2",
"body": null,
"is_bot": false,
"headline": "Async factory",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T09:38:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c08a3aeda82a62f579a96219fe645bd802196c34",
"body": "* fix: make changes to toml using regexp\n\n* test: add test case",
"is_bot": false,
"headline": "fix: toml formatting (#43)",
"author_name": "alex-pirogov",
"author_login": "alex-pirogov",
"committed_at": "2025-04-18T09:37:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1e7a7f131dd70fb171f18dbb505f34e8c474f09",
"body": null,
"is_bot": false,
"headline": "Remove cache layer",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T09:36:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "05c336fa8e15041246f77876a07284b49a1bc6a3",
"body": null,
"is_bot": false,
"headline": "Release 7.0.3",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T06:57:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7f8a01959d3a0e0e70164be8bd6637d0ae977b3",
"body": null,
"is_bot": false,
"headline": "Async factory",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T06:57:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "049f8e55c947b3898fa2bad6e870777f90d9432a",
"body": null,
"is_bot": false,
"headline": "Support release-it v19",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-04-18T06:57:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "53c079c47ecfd77a59bc33bcd7e44c3ca309d4d0",
"body": null,
"is_bot": false,
"headline": "Release 7.0.2",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-03-13T06:19:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e277d8c506f06648182fa9fe91dd7ec6a873e49f",
"body": null,
"is_bot": false,
"headline": "Fix range of release-it peer dep",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-03-13T06:19:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4a40828cb56657cc360170ab4e2e828f3eb8912",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-03-13T06:19:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c40ebaba0cd83277237505eb2381f1db7780847b",
"body": null,
"is_bot": false,
"headline": "Release 7.0.1",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-20T11:03:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c29b3a57bed85dbe8348e9977af565be4ef578f9",
"body": null,
"is_bot": false,
"headline": "Remove node v18 from test matrix",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-20T11:01:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f26b414de64f8f61f3fa3c9c188a8e69883845d",
"body": null,
"is_bot": false,
"headline": "Fix test cmd + test in node v22",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-20T10:58:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f19ffb52a599df055c4a1efc1409f445eee0273e",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-20T10:57:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c25cdc3442c9a21004e79f1e6dbae1fc7c9f0e9",
"body": null,
"is_bot": false,
"headline": "Housekeeping",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-20T10:49:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3d67258c33ea7572400b1bca37ecfe09a4e2a7a",
"body": null,
"is_bot": false,
"headline": "fix(#41): update xml file write to use same logic as html (#42)",
"author_name": "pbarton-andovercos",
"author_login": "PaulBartonADVR",
"committed_at": "2025-01-20T10:46:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78e207047e6a2c842b50ba5e4df0ad739237fff8",
"body": null,
"is_bot": false,
"headline": "Format readme.md",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-14T17:08:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fab654f775564fa645de32d617ba22aeffc9ca43",
"body": null,
"is_bot": false,
"headline": "Release 7.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-08T15:58:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b4b4f4f9c07e786b7758cdc9025b2ddad26dc4a",
"body": null,
"is_bot": false,
"headline": "Add/try new release-it `github.releaseNotes` feature",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-08T15:57:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9554e338c3ac69ebaf0ebdcd0b6fa273430f0509",
"body": null,
"is_bot": false,
"headline": "Add installed-check + update engines.node",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2025-01-08T15:57:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9daf66a5a4a7a33cebcc424d6cf832df17480643",
"body": "* feat: add xml and html file type support\r\n\r\nCloses #39\r\n\r\n* fix: bad version numbers in readme from old outdated bron test run\r\n\r\n* docs: update to add html file type details\r\n\r\n* fix: remove unneccessary condition for xml\r\n\r\n* test: add read/write test for ini type with section\r\n\r\n* feat: add pla\n[…]\n\ncheerio improved the performance by more than 2x and is just as fast as the other file types now\r\n\r\n* docs: add missing mimetype support to readme\r\n\r\n* test: fix EOL cross-platform issue in json test",
"is_bot": false,
"headline": "feat: add xml and html file type support (#40)",
"author_name": "pbarton-andovercos",
"author_login": "PaulBartonADVR",
"committed_at": "2025-01-08T15:54:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "884cb63c964cbe0ad12e45c20a84610fee00d207",
"body": null,
"is_bot": false,
"headline": "Release 6.0.1",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-11-11T14:52:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b07d00a28fb64696b6c764d475c048ee36c6eb5",
"body": null,
"is_bot": false,
"headline": "Oops",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-11-11T14:52:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d29ba16d28fcb5c193940400013cb994cea6f31",
"body": null,
"is_bot": false,
"headline": "Release 6.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-11-11T14:51:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c443a13f4d5371b700349b831ab1ec79d2963b7e",
"body": null,
"is_bot": false,
"headline": "Drop support for Node.js 14 + 16",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-11-11T14:50:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a66492842cd65fe5601041b0755206986b55d171",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-11-11T14:50:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aa54402d23013286ab9305728820c90c9bfe95df",
"body": null,
"is_bot": false,
"headline": "feat: Add `versionPrefix` (#35)",
"author_name": "Marcin Nowak-Liebiediew",
"author_login": null,
"committed_at": "2023-11-11T14:49:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "188e37a84f2b08a056cf0b082a47596bdb996982",
"body": null,
"is_bot": false,
"headline": "Release 5.1.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-29T08:43:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "483c0c4b6b78bc3313f8ef2f0b2212287e25c9e3",
"body": null,
"is_bot": false,
"headline": "Add github release + comments",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-29T08:43:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1cbe8d614dbe4c92579593014116986d45246ea",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-29T08:42:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df70c88883a028e6aff32349cd7603b01a876c9d",
"body": null,
"is_bot": false,
"headline": "Assert parsed version before stringify it (fixes #33)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-29T08:42:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78e686bc1d3015e03f489afafb2418c82009d700",
"body": "* feat: add consumeWholeFile option for output file\r\n\r\n* test: add tests for consumeWholeFile output option\r\n\r\n* docs: describe the use of consumeWholeFile output option",
"is_bot": false,
"headline": "Add a feature for overwriting the whole output file (#32)",
"author_name": "Ian G",
"author_login": "imgrant",
"committed_at": "2023-07-29T08:37:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a8beeeea75d046e4e012622476b416909541f975",
"body": null,
"is_bot": false,
"headline": "Patch lodash.set (#28)",
"author_name": "Vergil Penkov",
"author_login": "vergilfromadyen",
"committed_at": "2023-07-29T08:36:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7a53a9010d6ed05a526c4d5112d961b32e714e2b",
"body": null,
"is_bot": false,
"headline": "Release 5.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-09T12:39:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2d8f4807e977b716c69ea7bde80378647331133e",
"body": null,
"is_bot": false,
"headline": "Major bump with release-it v16/Node.js v16",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-09T12:38:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f7cf4cf7db8a0ed8c496857694f22ab33da90a58",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-09T12:37:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5166c6b9b9da871e27f8474d149b8151e4b062fb",
"body": null,
"is_bot": false,
"headline": "Remove test.only",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-07-09T12:35:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "183aae7f49578da96daadd92f2b3bc9a78f606ce",
"body": null,
"is_bot": false,
"headline": "Add note about setting options from CLI",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-02-15T17:21:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ef8a219ee10d00339e8add1bb1dfa0f8773441d",
"body": "…n (closes #30)",
"is_bot": false,
"headline": "Add note about potential package.json#version conflict with npm plugi…",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-01-22T14:24:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2248567ec3d00dee6d52d1b66a6bc7c47e8ce1ae",
"body": null,
"is_bot": false,
"headline": "Release 4.0.2",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-01-05T17:36:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3f0fff12c779125dabf236a3f9fba070aaf03cb",
"body": null,
"is_bot": false,
"headline": "Minor refactorings",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-01-05T17:35:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0e7b97ed96890cf91cb7e88be9cb86dc7f86467",
"body": null,
"is_bot": false,
"headline": "Fix mime type precedence over file extension (fixes #23)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-01-05T17:35:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4da200ebe40eb165707276be56cbbba4e9877911",
"body": null,
"is_bot": false,
"headline": "Release 4.0.1",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-01-04T13:16:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b8eb0569240e330965e7c8c29c30bd6cfbcbf364",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2023-01-04T13:14:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e418c731a48039dd83a0efefe8b3f8b32fa31af3",
"body": "* test: fix error ERR_PACKAGE_PATH_NOT_EXPORTED\r\n\r\n* style: correct imports order\r\n\r\n* fix: update release-it version for correct exports\r\n\r\n* feat: extend exports with package.json\r\n\r\n* chore: test on node 18 lts too",
"is_bot": false,
"headline": "Fix test path not exported (#26)",
"author_name": "Alexis THOMAS",
"author_login": "ath0mas",
"committed_at": "2023-01-04T11:45:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5c2e3b6b2894d4a47d25c521ab11de3ebe77506a",
"body": null,
"is_bot": false,
"headline": "Release 4.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-04-30T12:57:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65470331712779161e1f38458393e8201b8a18f5",
"body": "# Conflicts:\n#\t.github/workflows/test.yml",
"is_bot": false,
"headline": "Merge branch 'feature/es-modules'",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-04-30T12:55:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c9ada72422e24dccc8e48b9d226acf96ba171e2",
"body": null,
"is_bot": false,
"headline": "Release 4.0.0-esm.1",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-04-18T22:56:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dea30af989d2c2056e21e73e753d33ede5f6a5e9",
"body": null,
"is_bot": false,
"headline": "Apply OS EOL newlines in specs",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-04-18T22:49:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ef10eebbea1a28064e82c8b82757ba197951d653",
"body": null,
"is_bot": false,
"headline": "ESM-targeted housekeeping",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-04-18T22:35:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c8164b172ab93b256fceb3cc251f893f680b35bb",
"body": null,
"is_bot": false,
"headline": "Remove caching (may conflict cross-OS)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:22:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "39845605fe4aeea28b57939aeb6b42669afdb080",
"body": null,
"is_bot": false,
"headline": "Run tests on macos and windows as well (and not odd Node.js)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:13:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ded1e51b09eae79e93d2950805e8c2ba1887ab15",
"body": null,
"is_bot": false,
"headline": "Release 4.0.0-esm.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:07:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "672db5c5c03b29bc92fbd98758e6332d5c303353",
"body": "# Conflicts:\n#\tpackage.json",
"is_bot": false,
"headline": "Merge branch 'master' into feature/es-modules",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:05:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c991954376105d04617f6a306f9361ee54fa4f1",
"body": null,
"is_bot": false,
"headline": "Tweak action a bit",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:04:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3cfe9b0524201f580b1e9c175057aaa978cb6e66",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:00:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1a574c93593bbf444c98d2b89386a6cac0a1d4b",
"body": null,
"is_bot": false,
"headline": "Run tests on push",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T14:00:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ceecf28d79230a1b12872f7c565999cd14c93503",
"body": null,
"is_bot": false,
"headline": "Add .prettierrc",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T13:42:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b6db7e4ffb42694fecf2032c10ef2f0078a141ea",
"body": null,
"is_bot": false,
"headline": "Setup github actions and dependabot (#17)",
"author_name": "Jair Henrique",
"author_login": "jairhenrique",
"committed_at": "2022-01-16T13:42:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28ed12a0976b2f57b9d9b83025d9a6187f73ebc2",
"body": "`mock-fs` is only used for tests",
"is_bot": false,
"headline": "mock-fs should be declared in devDependencies (#21)",
"author_name": "Alexis THOMAS",
"author_login": "ath0mas",
"committed_at": "2022-01-16T13:41:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b42e8303d456fd07b9885f5488e50030e26c9885",
"body": null,
"is_bot": false,
"headline": "Move to esm (#19)",
"author_name": "Jair Henrique",
"author_login": "jairhenrique",
"committed_at": "2022-01-16T13:39:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "01bf9c6c03ae819865e5b1df15bcbf73e980fa3a",
"body": null,
"is_bot": false,
"headline": "Add .prettierrc",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2022-01-16T07:26:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "517aacfe35aaad9f2f4302d4f52f677b4c33b661",
"body": null,
"is_bot": false,
"headline": "Release 3.0.1",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2021-07-16T10:24:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c35522e30f424ff3e6c9074862c539a2870d7e22",
"body": "* fix deprecated yaml.safeDump\r\n\r\n* remove additional newline at the end of YAML",
"is_bot": false,
"headline": "fix deprecated yaml.safeDump (#15)",
"author_name": "pzamzow",
"author_login": "pzamzow",
"committed_at": "2021-07-16T10:22:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "44cbbcdf0f4eb4c04257ebec37f1c262cc24aeeb",
"body": null,
"is_bot": false,
"headline": "Release 3.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2021-07-14T20:56:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "094950db4c0033981295b227692d1869a5eb04cb",
"body": null,
"is_bot": false,
"headline": "Rename mock file",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2021-07-14T20:53:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a8f3ab1cea180f31d6f9ab56d55e2df8c1e960eb",
"body": null,
"is_bot": false,
"headline": "Parse version (and strip prefix) before using it (fixes #13)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2021-07-14T20:51:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "30be1ad878f1980b26838c869a47fb82461c4547",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2021-07-14T20:48:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1aca8bcc04ae8078b00bf626ef8d283dd1b6a773",
"body": null,
"is_bot": false,
"headline": "Release 2.0.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-09-03T20:22:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "735531a0e58fcb0f10c4ab8d69f624fbbc6c3e1b",
"body": null,
"is_bot": false,
"headline": "Update dependency",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-09-03T20:22:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "57b42babb50b6bb975fcbba465a0aafaa61fcc97",
"body": null,
"is_bot": false,
"headline": "Migrate to release-it v14",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-09-03T20:21:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d0a93c04aab11a0131e127a597fd528d8f4013c",
"body": null,
"is_bot": false,
"headline": "Update docs",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-08-17T08:23:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba77bca2c4fc31e5412626df2979c13fab62ccd4",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-08-17T08:14:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "633223a9862445df9c2d93261898be2e93e38afa",
"body": null,
"is_bot": false,
"headline": "Release 1.4.1",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-07-25T07:06:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a36669845c98b8693830708dce22028a74ccb25",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-07-25T07:06:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cbbfa1e9198d3a76a7f9604dcba68f8164e922c",
"body": null,
"is_bot": false,
"headline": "Fix EOL (closes #12)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-07-25T07:05:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0cc7742c748520ab6276780f8c9eec79154a617",
"body": null,
"is_bot": false,
"headline": "Release 1.4.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-16T06:03:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1fe4709c0467ea78f462c5b35638e0f7795b3860",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-16T06:03:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8d92b996c5de958ed7797de85080f15de2928b9f",
"body": null,
"is_bot": false,
"headline": "Support writing to multiple paths within out files",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-16T06:02:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4965b5d0daa21551651f6275e44603ffa68811e6",
"body": null,
"is_bot": false,
"headline": "Release 1.3.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-16T05:47:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d26534a628e44bbc02084d6103481341ddf85373",
"body": null,
"is_bot": false,
"headline": "Add fast-glob and support for multiple out files (closes #8, closes #9)",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-16T05:46:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "609045a678a2050acdd059c0d5f75935fee2bd77",
"body": null,
"is_bot": false,
"headline": "Remove console.log",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-16T05:36:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbca4007585dc3f8f7840d95e5f5e09184e5bb4d",
"body": null,
"is_bot": false,
"headline": "Release 1.2.0",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-13T08:39:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "911732a5da5430c5540b7d0ed2fb692677548b51",
"body": null,
"is_bot": false,
"headline": "Update dependencies",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-13T08:39:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70a24073605fbab4712b00b80345e7d646656568",
"body": null,
"is_bot": false,
"headline": "Fall back to file type based on extension + major refactoring",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-13T08:39:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "696b2a1cc516b99b0b5c86b3b0949e18fb93ed29",
"body": null,
"is_bot": false,
"headline": "Formatting",
"author_name": "Lars Kappert",
"author_login": "webpro",
"committed_at": "2020-06-13T07:26:10Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 11,
"commits_last_year": 11,
"latest_release_at": "2026-07-25T18:56:30Z",
"latest_release_tag": "8.0.0",
"releases_from_tags": false,
"days_since_last_push": 11,
"active_weeks_last_year": 3,
"days_since_latest_release": 11,
"mean_days_between_releases": 109.7
},
"artifacts": {
"collected": true,
"structure": [],
"declarations": [
{
"name": "@release-it/bumper",
"path": "package.json",
"tokens": [
"npm.entry",
"npm.peer_dependencies"
],
"ecosystem": "npm"
}
]
},
"community": {
"has_readme": true,
"has_license": true,
"readme_badges": {
"hosts": [],
"total": 0,
"header": 0,
"collected": true,
"has_inspect_badge": false
},
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "@release-it/bumper",
"exists": true,
"license": "MIT",
"keywords": [
"release",
"release-it",
"release-it-plugin",
"version",
"bump",
"increment",
"manifest"
],
"ecosystem": "npm",
"categories": [],
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/@release-it/bumper",
"declared_type": null,
"is_deprecated": false,
"latest_version": "8.0.0",
"repository_url": "https://github.com/release-it/bumper",
"versions_count": 33,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 285492,
"first_published_at": "2019-05-02T17:02:14.673000Z",
"latest_published_at": "2026-07-25T18:56:22.816000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 11
}
]
},
"popularity": {
"forks": 22,
"stars": 52,
"watchers": 1,
"fork_history": {
"days": [
{
"date": "2019-06-03",
"count": 1
},
{
"date": "2019-09-05",
"count": 1
},
{
"date": "2020-03-02",
"count": 1
},
{
"date": "2020-05-12",
"count": 1
},
{
"date": "2020-06-11",
"count": 1
},
{
"date": "2021-07-16",
"count": 1
},
{
"date": "2021-11-13",
"count": 1
},
{
"date": "2021-12-30",
"count": 1
},
{
"date": "2022-08-30",
"count": 1
},
{
"date": "2023-01-09",
"count": 1
},
{
"date": "2023-07-13",
"count": 1
},
{
"date": "2023-10-12",
"count": 1
},
{
"date": "2024-04-28",
"count": 1
},
{
"date": "2024-05-28",
"count": 1
},
{
"date": "2024-09-06",
"count": 1
},
{
"date": "2024-12-26",
"count": 1
},
{
"date": "2025-05-29",
"count": 1
},
{
"date": "2025-11-21",
"count": 1
},
{
"date": "2026-01-06",
"count": 1
},
{
"date": "2026-05-15",
"count": 1
},
{
"date": "2026-05-17",
"count": 1
}
],
"complete": true,
"collected": 21,
"total_forks": 22
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 7340,
"source_files_sampled": 11,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 49,
"malicious_count": 0,
"assessed_package": "npm:@release-it/bumper@8.0.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@decimalturn/toml-patch",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^2.1.0"
},
{
"name": "@iarna/toml",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.0.0"
},
{
"name": "cheerio",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^1.2.0"
},
{
"name": "detect-indent",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "7.0.2"
},
{
"name": "fast-glob",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^3.3.3"
},
{
"name": "ini",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^6.0.0"
},
{
"name": "js-yaml",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^5.2.2"
},
{
"name": "lodash-es",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^4.18.1"
},
{
"name": "semver",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^7.8.5"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@decimalturn/toml-patch",
"direct": true,
"version": "^2.1.0",
"ecosystem": "npm"
},
{
"name": "@iarna/toml",
"direct": true,
"version": "^3.0.0",
"ecosystem": "npm"
},
{
"name": "cheerio",
"direct": true,
"version": "^1.2.0",
"ecosystem": "npm"
},
{
"name": "detect-indent",
"direct": true,
"version": "7.0.2",
"ecosystem": "npm"
},
{
"name": "fast-glob",
"direct": true,
"version": "^3.3.3",
"ecosystem": "npm"
},
{
"name": "ini",
"direct": true,
"version": "^6.0.0",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": true,
"version": "^5.2.2",
"ecosystem": "npm"
},
{
"name": "lodash-es",
"direct": true,
"version": "^4.18.1",
"ecosystem": "npm"
},
{
"name": "semver",
"direct": true,
"version": "^7.8.5",
"ecosystem": "npm"
},
{
"name": "installed-check",
"direct": false,
"version": "^10.0.1",
"ecosystem": "npm"
},
{
"name": "mock-fs",
"direct": false,
"version": "5.5.0",
"ecosystem": "npm"
},
{
"name": "release-it",
"direct": false,
"version": "^21.0.0",
"ecosystem": "npm"
},
{
"name": "sinon",
"direct": false,
"version": "^22.1.0",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 13,
"direct_count": 9,
"indirect_count": 4
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 17,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 31,
"closed_unmerged_prs": 5
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "webpro",
"commits": 105,
"avatar_url": "https://avatars.githubusercontent.com/u/456426?v=4"
},
{
"type": "User",
"login": "jairhenrique",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/81854?v=4"
},
{
"type": "User",
"login": "ath0mas",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/217720?v=4"
},
{
"type": "User",
"login": "PaulBartonADVR",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/87998722?v=4"
},
{
"type": "User",
"login": "imgrant",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/5815412?v=4"
},
{
"type": "User",
"login": "JamesMBarr",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/20668395?v=4"
},
{
"type": "User",
"login": "juancarlosjr97",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/36451129?v=4"
},
{
"type": "User",
"login": "rkcreation",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/5804138?v=4"
},
{
"type": "User",
"login": "gameroman",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/121314722?v=4"
},
{
"type": "User",
"login": "vergilfromadyen",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/85731267?v=4"
}
],
"contributors_sampled": 13,
"top_contributor_share": 0.868
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"test.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 3,
"reason": "2 out of 6 merged PRs checked by a CI test -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 2,
"reason": "Found 6/30 approved changesets -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 9,
"reason": "11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "2f8ae9d711132f914ed91c640f8bb02b4a524cad",
"ran_at": "2026-08-06T01:22:05Z",
"aggregate_score": 4.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"recent_prs": {
"merged_7d": 0,
"decided_7d": 0,
"merged_30d": 0,
"authors_30d": 0,
"decided_30d": 0,
"sample_size": 22,
"window_days": 30,
"sample_exhausted": false,
"authors_probed_30d": 0,
"newcomer_merged_30d": 0,
"bot_prs_excluded_30d": 0,
"newcomer_authors_30d": 0,
"newcomer_decided_30d": 0
},
"ci_last_run_at": "2026-07-25T18:57:41Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-05-29T13:56:55Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/release-it/bumper",
"host": "github.com",
"name": "bumper",
"owner": "release-it"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": "The weighted overall 58 is calibrated to 62 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 58,
"calibrated": 62,
"calibration": "2026-08-02"
}
}
],
"value": 62,
"inputs": {
"security": 53,
"vitality": 67,
"community": 56,
"governance": 64,
"calibration": "2026-08-02",
"engineering": 52,
"ai_readiness": 24,
"weighted_overall_raw": 58
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 67,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"commits_last_year": 11,
"human_commit_share": 1,
"days_since_last_push": 11,
"active_weeks_last_year": 3
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 11 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 11
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "3/52 weeks with commits",
"points": 2.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 3
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "11 commits in the last year",
"points": 9.7,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 11
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9",
"points": 9,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 92,
"inputs": {
"releases_count": 11,
"latest_release_tag": "8.0.0",
"releases_from_tags": false,
"days_since_latest_release": 11,
"mean_days_between_releases": 109.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "11 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 11
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 11 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 11
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~109.7 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 109.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 11,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 11 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 11
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 56,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "weak",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 39,
"inputs": {
"forks": 22,
"stars": 52,
"watchers": 1,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "52 stars",
"points": 27.7,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 52
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "22 forks",
"points": 11,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 22
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "1 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 1
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": 0,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "excellent",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 91,
"inputs": {
"packages": [
"@release-it/bumper"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 285492
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "285,492 downloads/month across npm",
"points": 72.7,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 285492,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 64,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 32,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 13,
"top_contributor_share": 0.868
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 87% of commits",
"points": 3,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 87
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "13 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 13
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 78,
"inputs": {
"merged_prs": 17,
"open_issues": 0,
"closed_issues": 31,
"prs_merged_7d": 0,
"prs_decided_7d": 0,
"prs_merged_30d": 0,
"prs_decided_30d": 0,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 5,
"first_time_authors_30d": 0,
"first_time_prs_merged_30d": 0,
"first_time_prs_decided_30d": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 42,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "17/22 decided PRs merged",
"points": 23.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 17,
"decided": 22
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 6/30 approved changesets -- score normalized to 2",
"points": 3,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 61,
"inputs": {
"followers": 53,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "release-it",
"public_repos": 7,
"account_age_days": 2753
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "53 followers of release-it",
"points": 12.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 53,
"login": "release-it"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "7 public repos, account ~7 yr old",
"points": 18.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 7
}
},
{
"code": "account_age_years",
"params": {
"years": 7
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"@release-it/bumper"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 11
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 11 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 11
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "33 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 33
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 52,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "2 out of 6 merged PRs checked by a CI test -- score normalized to 3",
"points": 6,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 53,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 41,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 4.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "2 out of 6 merged PRs checked by a CI test -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 6/30 approved changesets -- score normalized to 2",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@release-it/bumper@8.0.0 runtime dependency closure — what installing the published package pulls in — 49 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:@release-it/bumper@8.0.0",
"assessed": 49
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 49,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 49,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 12
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 24,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 12,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.23,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "23 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 12.3,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 23,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 22,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "JavaScript",
"largest_source_bytes": 7340,
"source_files_sampled": 11,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "JavaScript without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "JavaScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/11 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 11,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"library"
],
"labels": [
"library"
],
"scores": {
"plugin": 2,
"library": 17
},
"primary": "library",
"evidence": [
{
"tier": "declared",
"label": "library",
"source": "npm.entry",
"weight": 8
},
{
"tier": "distribution",
"label": "library",
"source": "registry:npm",
"weight": 6
},
{
"tier": "declared",
"label": "library",
"source": "npm.peer_dependencies",
"weight": 3
},
{
"tier": "description",
"label": "plugin",
"source": "description:plugin",
"weight": 2
}
],
"artifacts": [
{
"path": "package.json",
"labels": [
"library"
],
"ecosystem": "npm"
}
],
"confidence": "high",
"host_extension": false,
"runs_as_process": false,
"consumed_by_code": true
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-08-06T01:22:17.937950Z",
"schema_version": "0.31.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/release-it/bumper.svg",
"full_name": "release-it/bumper",
"license_state": "standard",
"license_spdx": "MIT"
}