Публічний реєстр
Звіт про здоров'я програмного забезпеченнясхема 0.27.0 · метрики 2.5.0 · 2026-07-30 22:50 UTC

web-auth / webauthn-lib

[READ ONLY] Webauthn library

PHPMIT★ 125 зірок⑂ 25 форківз лист. 2018 р.Переглянути на GitHub ↗
ТипБібліотекаяк це визначено

web-auth/webauthn-lib має індекс здоров’я 50 зі 100, що відповідає смузі «Помірний». Найвищий показник — Community & Adoption (71/100), найнижчий — AI Readiness (29/100). Останнє оновлення було 60 днів тому. Більшість нещодавньої роботи виконує один учасник.

50
загалом / 100
Помірний

Індекс здоров'я програмного забезпечення

Метрики згруповано у зважені категорії на шкалі 1–100. Загальна оцінка починається як їхнє зважене середнє, відкаліброване за розподілом публічного реєстру, тож діапазони мають перцентильний зміст; коли публічні дані активують Політику юрисдикцій високого ризику, рейтинг коригується й отримує верхню межу 34 («У зоні ризику»).

50
Винятковий93-100Верхній щабель реєстру (≈ топ-5%); відповідає практично всім перевіреним критеріям
Відмінний80-92Сильний за всіма напрямами; незначні прогалини
Добрий65-79Здоровий; прогалини обмежені та керовані
Помірний50-64Прийнятний, але з помітними прогалинами; рекомендовано перевірку
Слабкий35-49Суттєві недоліки в кількох сферах
У зоні ризику20-34Суттєві слабкі місця; впровадження потребує обережності
Критичний1-19Серйозні проблеми (покинутий, єдиний мейнтейнер, без базової гігієни)
ЖиттєздатністьСпільнота тавпровадженняСталість таврядуванняІнженернаякістьБезпекаГотовність доШІ

Профіль оцінок

Кожна вісь — окрема категорія. Форма важить більше, ніж середнє: здоровий об'єкт заповнює всю фігуру, тоді як профіль із піками та провалами означає, що сила в одному вимірі маскує ризик в іншому.

Зважений загальний бал 50 калібровано до 50 за шкалою опублікованого індексу (калібрування реєстру 2026-08-02).

Власність

Web-AuthenticationОрганізація
28 підписників13 публічних репозиторіївз лист. 2018 р.

За цим репозиторієм стоїть організація — спільна, підзвітна опіка, здатна пережити будь-якого окремого мейнтейнера.

Пакетні екосистеми

РеєстрПакетВерсіяЗавантажень / місВерсіїОстання публікаціяТеги
Packagistweb-auth/webauthn-lib5.3.53 443 66312260 днів томуfidofido2webauthn

Метрики за категоріями

Життєздатність

Чи живий проєкт — чи пишеться код і чи виходять релізи?

60Помірний · 21% загального індексу
Як обчислюється оцінка
18/36Свіжість push — останній push 60 дн. тому
8.3/36Ритм комітів — 12/52 тижнів із комітами
14.7/18Обсяг комітів — 42 комітів за останній рік
0/10OpenSSF Scorecard: Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Використані вхідні дані
commits_last_year42
human_commit_share1
days_since_last_push60
active_weeks_last_year12
Як обчислюється оцінка
16.2/27Випускає релізи — 100 тегів версій (без релізів GitHub)
36/36Свіжість релізів — останній реліз 60 дн. тому
27/27Ритм релізів — реліз кожні ~18 дн.
0/10OpenSSF Scorecard: Signed-Releases — немає даних
Використані вхідні дані
releases_count100
latest_release_tag5.3.5
releases_from_tagsтак
days_since_latest_release60
mean_days_between_releases18
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Signed-Releases. Залишкові ваги перенормовано.

Спільнота та впровадження

Чи має проєкт користувачів, завантаження, увагу та влаштовані умови для контриб’юторів?

71Добрий · 17% загального індексу
Як обчислюється оцінка
34/60Зірки — 125 зірок
11.5/25Форки — 25 форків
5.6/15Спостерігачі — 11 спостерігачів
Використані вхідні дані
forks25
stars125
watchers11
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history
Як обчислюється оцінка
22.5/22.5README
22.5/22.5Ліцензія — визнана ліцензія (MIT)
18/18Настанови CONTRIBUTING
0/13.5Кодекс поведінки
0/7.2Шаблон issue
6.3/6.3Шаблон PR
Використані вхідні дані
has_readmeтак
has_licenseтак
readme_badges
has_contributingтак
has_issue_templateні
has_code_of_conductні
readme_badge_services
has_pull_request_templateтак
Як обчислюється оцінка
80/80Щомісячні завантаження — 3 443 663 завантажень/місяць у packagist
13.1/20Залежні пакети в реєстрі — залежних пакетів: 92
Використані вхідні дані
packagesweb-auth/webauthn-lib
dependents92
ecosystemspackagist
total_downloads13 916 438
monthly_downloads3 443 663

Сталість та врядування

Чи переживе проєкт своїх людей — бас-фактор, реактивність, хто за ним стоїть і як супроводжуються пакети?

46Слабкий · 23% загального індексу
Як обчислюється оцінка
9/54Бас-фактор — на 1 контриб’ютор(ів) припадає половина всіх комітів
1.3/22.5Розподіл комітів — головний контриб’ютор — автор 94% комітів
13.5/13.5Широта контриб’юторів — 17 контриб’юторів
10/10OpenSSF Scorecard: Contributors — project has 6 contributing companies or organizations
Використані вхідні дані
bus_factor1
contributors_sampled17
top_contributor_share0,942
Як обчислюється оцінка
0/42Вирішення issue — немає issue або даних
0/30Прийняття PR — злито 0/1 вирішених PR
0/13Newcomer PR acceptance — за 30 дн. не вирішено жодного PR від новачка
0/15OpenSSF Scorecard: Code-Review — Found 0/30 approved changesets -- score normalized to 0
Використані вхідні дані
merged_prs0
open_issues0
closed_issues0
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio
closed_unmerged_prs1
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
Виключено з оцінювання (немає даних або не застосовно): Вирішення issue, newcomer_pr_acceptance. Залишкові ваги перенормовано.
Як обчислюється оцінка
30/30Підтримка власника — у власності організації
0/20Верифікований домен
10.5/25Охоплення власника — 28 підписників у web-auth
20.3/25Послужний список — 13 публічних репозиторіїв, вік облікового запису ~7 р.
Використані вхідні дані
followers28
owner_typeOrganization
is_verified
owner_loginweb-auth
public_repos13
account_age_days2 807

Супровід пакетів

100Винятковий
Як обчислюється оцінка
25/25Опубліковано й доступно — 1 пакет(ів) у packagist
35/35Свіжість публікацій — остання публікація 60 дн. тому
20/20Історія версій — 122 опублікованих версій
20/20Не застарілий — активний, не deprecated і не yanked
Використані вхідні дані
packagesweb-auth/webauthn-lib
ecosystemspackagist
any_deprecatedні
min_days_since_publish60

Інженерна якість

Чи наявні базові інженерні практики та документація?

38Слабкий · 19% загального індексу

Інженерні практики

30У зоні ризику
Як обчислюється оцінка
24/24Процеси CI — 1 процес(ів) CI
0/24Наявні тести
0/16Конфігурація лінтера
0/9.6Pre-commit-хуки
0/6.4.editorconfig
0/20OpenSSF Scorecard: CI-Tests — немає даних
Використані вхідні дані
has_ciтак
has_testsні
has_editorconfigні
has_linter_configні
has_precommit_configні
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: CI-Tests. Залишкові ваги перенормовано.

Документація

50Помірний
Як обчислюється оцінка
30/30README
0/25Каталог документації
0/15Сайт документації / домашня сторінка
10/10Опис репозиторію
10/10Теми — 8 тем
0/10Wiki
Використані вхідні дані
topicsfido, webauthn-support, webauthn, fido-u2f, fido2, u2f, u2f-protocol, safetynet
has_wikiні
homepage
has_readmeтак
has_docs_dirні
has_descriptionтак

Безпека

Чи міцні видимі практики безпеки й ланцюга постачання, без непослабленої пов’язаності з юрисдикціями високого ризику?

41Слабкий · 16% загального індексу

Стан безпеки

41Слабкий
Як обчислюється оцінка
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — немає даних
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 6 contributing companies or organizations
0/10Dangerous-Workflow — немає даних
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5Ліцензія — license file detected
0/7.5Maintained — 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
0/5Packaging — немає даних
0/5Pinned-Dependencies — немає даних
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — немає даних
0/7.5Token-Permissions — немає даних
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
Використані вхідні дані
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate4,1
Виключено з оцінювання (немає даних або не застосовно): ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions. Залишкові ваги перенормовано.

Готовність до ШІ

Наскільки репозиторій оснащений для розробки та супроводу за участі ШІ-агентів? Має свідомо малу вагу (4%): агентний інструментарій — реальний сигнал супроводу, але репозиторій без нього все одно може отримати 100/100.

29У зоні ризику · 4% загального індексу
Як обчислюється оцінка
0/45Інструкції для агентів — немає CLAUDE.md / AGENTS.md / правил редактора
0/15Машиночитана документація (llms.txt)
40/40Читабельна історія комітів — намір зазначено у 82 з 100 людських комітів (структурований заголовок або пояснювальний текст)
Використані вхідні дані
has_llms_txtні
legible_history_share0,82
agent_instruction_files
agent_instruction_max_bytes
Як обчислюється оцінка
0/18Розгортання однією командою
0/22Автоматизовані тести
0/11Конфігурація лінтера / форматера
0/11Статична перевірка типів
0/10Відтворюване середовище
10/10Підтверджена практика роботи з агентами — 11 з останніх 100 комітів створено агентом або з його зазначенням
0/8Автоматизоване супроводження — автоматичних оновлень залежностей не виявлено
0/10OpenSSF Scorecard: Pinned-Dependencies — немає даних
Використані вхідні дані
has_nixні
has_testsні
lockfiles
has_dockerfileні
typed_languageні
bootstrap_files
has_devcontainerні
has_linter_configні
typecheck_configs
agent_commit_share0,11
toolchain_manifests
dependency_bot_commit_share0
Виключено з оцінювання (немає даних або не застосовно): OpenSSF Scorecard: Pinned-Dependencies. Залишкові ваги перенормовано.
Як обчислюється оцінка
0/45Типізований код — PHP без конфігурації перевірки типів
55/55Керовані розміри файлів — 0/191 файлів вихідного коду понад 60 КБ
Використані вхідні дані
primary_languagePHP
largest_source_bytes18 153
source_files_sampled191
oversized_source_files0

Ключові факти

125зірок GitHub
17контриб'юторів
42комітів за останні 12 місяців
60днів від останнього пушу
100релізів
1бас-фактор
0відкритих issue
Packagistпакетних екосистем

Попередження щодо збору даних

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • No resolved dependencies carried a version and a supported ecosystem

Докладніше

Історія зірок і форків 0 ★ / 25 ⇿
0Зірки
25Форки
94Релізи

Коли додано кожну зірку й форк — зібрано з GitHub і згруповано за днями. Кумулятивне зростання розміщено просто над денними додаваннями, з яких воно складається, тож їх видно одне проти одного: рівномірне органічне накопичення виглядає зовсім інакше, ніж різкий короткочасний сплеск. Там, де цю різницю можна виміряти, її подано як автентичність росту.

05101520252522019-022022-092026-04
Мажорні 2Мінорні 14Патчі 78

Кожна точка охоплює 7 днів.

OpenSSF Scorecard 4.1 / 10
4.1сукупно

Незалежна, не прив'язана до інструментів оцінка безпеки від відкритого проєкту OpenSSF Scorecard. Кожна перевірка винагороджує практику безпеки, а не інструмент конкретного постачальника. Перевірки, які Scorecard не зміг визначити, позначено н/д і виключено з оцінки безпеки (вони ніколи не зараховуються як нуль).Scorecard v5.5.0 · 2026-07-30 22:49 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
н/дCI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 6 contributing companies or organizations
н/дDangerous-Workflowno workflows found
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintained0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
н/дPackagingpackaging workflow not detected
н/дPinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
н/дSigned-Releasesno releases found
н/дToken-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
Прямі залежності 13
РеєстрПакетОбмеження версіїМаніфест
Packagistparagonie/constant_time_encoding^2.6|^3.0composer.json
Packagistpsr/clock^1.0composer.json
Packagistpsr/event-dispatcher^1.0composer.json
Packagistpsr/log^1.0|^2.0|^3.0composer.json
Packagistspomky-labs/cbor-php^3.0composer.json
Packagistsymfony/clock^6.4|^7.0|^8.0composer.json
Packagistsymfony/uid^6.4|^7.0|^8.0composer.json
Packagistspomky-labs/pki-framework^1.0composer.json
Packagistsymfony/property-info^6.4|^7.0|^8.0composer.json
Packagistsymfony/property-access^6.4|^7.0|^8.0composer.json
Packagistsymfony/serializer^6.4|^7.0|^8.0composer.json
Packagistsymfony/deprecation-contracts^3.2composer.json
Packagistweb-auth/cose-lib^4.2.3composer.json
Усі залежності 17

Повний розв'язаний набір залежностей із графа залежностей GitHub: 13 прямих і 4 непрямих (транзитивних) пакетів. Транзитивне замикання є повним, коли в репозиторії закомічено lockfile.

РеєстрПакетВерсіяЗв'язок
Packagistparagonie/constant_time_encodingпряма
Packagistpsr/clockпряма
Packagistpsr/event-dispatcherпряма
Packagistpsr/logпряма
Packagistspomky-labs/cbor-phpпряма
Packagistspomky-labs/pki-frameworkпряма
Packagistsymfony/clockпряма
Packagistsymfony/deprecation-contractsпряма
Packagistsymfony/property-accessпряма
Packagistsymfony/property-infoпряма
Packagistsymfony/serializerпряма
Packagistsymfony/uidпряма
Packagistweb-auth/cose-libпряма
Packagistext-jsonнепряма
Packagistext-opensslнепряма
Packagistphpнепряма
Packagistphpdocumentor/reflection-docblockнепряма
Сповіщення про залежності не оцінено

Звірка сповіщень не відбулася для цього звіту: No resolved dependencies carried a version and a supported ecosystem

Звіт у форматі JSON машиночитний
{
  "data": {
    "repo": {
      "topics": [
        "fido",
        "webauthn-support",
        "webauthn",
        "fido-u2f",
        "fido2",
        "u2f",
        "u2f-protocol",
        "safetynet"
      ],
      "is_fork": false,
      "size_kb": 1276,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "PHP": 388358
      },
      "pushed_at": "2026-05-31T15:07:51Z",
      "created_at": "2018-11-22T19:42:22Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T08:22:49Z",
      "description": "[READ ONLY] Webauthn library",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "5.3.x",
      "license_spdx_raw": "MIT",
      "primary_language": "PHP",
      "significant_languages": [
        "PHP"
      ]
    },
    "owner": {
      "blog": "https://www.spomky-labs.com/",
      "name": "Web-Authentication",
      "type": "Organization",
      "login": "web-auth",
      "company": null,
      "location": "France",
      "followers": 28,
      "avatar_url": "https://avatars.githubusercontent.com/u/45272065?v=4",
      "created_at": "2018-11-22T19:38:29Z",
      "is_verified": null,
      "public_repos": 13,
      "account_age_days": 2807
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "5.3.5",
          "kind": "patch",
          "published_at": "2026-05-31T15:00:08Z"
        },
        {
          "tag": "5.3.4",
          "kind": "patch",
          "published_at": "2026-05-18T11:59:46Z"
        },
        {
          "tag": "5.3.3",
          "kind": "patch",
          "published_at": "2026-05-17T19:04:30Z"
        },
        {
          "tag": "5.3.2",
          "kind": "patch",
          "published_at": "2026-05-01T12:14:37Z"
        },
        {
          "tag": "5.3.1",
          "kind": "patch",
          "published_at": "2026-05-01T12:14:37Z"
        },
        {
          "tag": "5.3.0",
          "kind": "minor",
          "published_at": "2026-05-01T12:14:37Z"
        },
        {
          "tag": "5.2.6",
          "kind": "patch",
          "published_at": "2026-03-23T22:13:50Z"
        },
        {
          "tag": "5.2.5",
          "kind": "patch",
          "published_at": "2026-03-23T21:43:02Z"
        },
        {
          "tag": "5.2.4",
          "kind": "patch",
          "published_at": "2026-03-08T17:01:15Z"
        },
        {
          "tag": "5.2.3",
          "kind": "patch",
          "published_at": "2025-12-20T10:54:02Z"
        },
        {
          "tag": "5.2.2",
          "kind": "patch",
          "published_at": "2025-03-16T14:38:43Z"
        },
        {
          "tag": "5.2.1",
          "kind": "patch",
          "published_at": "2025-03-16T14:38:43Z"
        },
        {
          "tag": "5.2.0",
          "kind": "minor",
          "published_at": "2025-03-16T14:38:43Z"
        },
        {
          "tag": "5.1.3",
          "kind": "patch",
          "published_at": "2025-02-16T10:15:04Z"
        },
        {
          "tag": "5.1.2",
          "kind": "patch",
          "published_at": "2025-02-16T10:15:04Z"
        },
        {
          "tag": "5.1.1",
          "kind": "patch",
          "published_at": "2025-01-03T23:01:20Z"
        },
        {
          "tag": "5.1.0",
          "kind": "minor",
          "published_at": "2025-01-03T23:01:20Z"
        },
        {
          "tag": "5.0.1",
          "kind": "patch",
          "published_at": "2024-07-20T05:24:59Z"
        },
        {
          "tag": "5.0.0",
          "kind": "major",
          "published_at": "2024-07-12T14:35:35Z"
        },
        {
          "tag": "4.9.3",
          "kind": "patch",
          "published_at": "2026-02-05T12:48:16Z"
        },
        {
          "tag": "4.9.2",
          "kind": "patch",
          "published_at": "2025-01-04T09:47:58Z"
        },
        {
          "tag": "4.9.1",
          "kind": "patch",
          "published_at": "2024-07-16T18:36:36Z"
        },
        {
          "tag": "4.9.0",
          "kind": "minor",
          "published_at": "2024-07-11T09:06:25Z"
        },
        {
          "tag": "4.8.7",
          "kind": "patch",
          "published_at": "2024-04-08T10:04:23Z"
        },
        {
          "tag": "4.8.6",
          "kind": "patch",
          "published_at": "2024-04-08T10:04:23Z"
        },
        {
          "tag": "4.8.5",
          "kind": "patch",
          "published_at": "2024-04-08T10:04:23Z"
        },
        {
          "tag": "4.8.4",
          "kind": "patch",
          "published_at": "2024-03-22T20:51:36Z"
        },
        {
          "tag": "4.8.3",
          "kind": "patch",
          "published_at": "2024-03-22T20:51:36Z"
        },
        {
          "tag": "4.8.2",
          "kind": "patch",
          "published_at": "2024-02-26T19:17:26Z"
        },
        {
          "tag": "4.8.1",
          "kind": "patch",
          "published_at": "2024-02-25T20:08:25Z"
        },
        {
          "tag": "4.8.0",
          "kind": "minor",
          "published_at": "2024-02-23T11:09:26Z"
        },
        {
          "tag": "4.7.9",
          "kind": "patch",
          "published_at": "2024-02-05T17:20:58Z"
        },
        {
          "tag": "4.7.8",
          "kind": "patch",
          "published_at": "2023-12-08T13:02:43Z"
        },
        {
          "tag": "4.7.7",
          "kind": "patch",
          "published_at": "2023-11-17T11:42:57Z"
        },
        {
          "tag": "4.7.6",
          "kind": "patch",
          "published_at": "2023-11-17T11:42:57Z"
        },
        {
          "tag": "4.7.5",
          "kind": "patch",
          "published_at": "2023-11-17T11:42:57Z"
        },
        {
          "tag": "4.7.4",
          "kind": "patch",
          "published_at": "2023-11-12T07:41:19Z"
        },
        {
          "tag": "4.7.3",
          "kind": "patch",
          "published_at": "2023-10-15T11:54:31Z"
        },
        {
          "tag": "4.7.2",
          "kind": "patch",
          "published_at": "2023-09-29T14:10:15Z"
        },
        {
          "tag": "4.7.1",
          "kind": "patch",
          "published_at": "2023-09-08T10:14:34Z"
        },
        {
          "tag": "4.7.0",
          "kind": "minor",
          "published_at": "2023-07-30T17:14:57Z"
        },
        {
          "tag": "4.6.4",
          "kind": "patch",
          "published_at": "2023-07-15T14:53:06Z"
        },
        {
          "tag": "4.6.3",
          "kind": "patch",
          "published_at": "2023-06-12T14:32:32Z"
        },
        {
          "tag": "4.6.2",
          "kind": "patch",
          "published_at": "2023-06-12T14:32:32Z"
        },
        {
          "tag": "4.6.1",
          "kind": "patch",
          "published_at": "2023-06-01T19:06:30Z"
        },
        {
          "tag": "4.6.0",
          "kind": "minor",
          "published_at": "2023-06-01T19:06:30Z"
        },
        {
          "tag": "4.5.2",
          "kind": "patch",
          "published_at": "2023-05-12T18:26:01Z"
        },
        {
          "tag": "4.5.1",
          "kind": "patch",
          "published_at": "2023-01-31T17:31:30Z"
        },
        {
          "tag": "4.5.0",
          "kind": "minor",
          "published_at": "2023-01-22T17:53:31Z"
        },
        {
          "tag": "4.4.3",
          "kind": "patch",
          "published_at": "2022-11-24T20:15:14Z"
        },
        {
          "tag": "4.4.2",
          "kind": "patch",
          "published_at": "2022-11-24T20:15:14Z"
        },
        {
          "tag": "4.4.1",
          "kind": "patch",
          "published_at": "2022-11-07T21:45:07Z"
        },
        {
          "tag": "4.4.0",
          "kind": "minor",
          "published_at": "2022-11-07T21:45:07Z"
        },
        {
          "tag": "4.3.1",
          "kind": "patch",
          "published_at": "2022-11-07T20:25:44Z"
        },
        {
          "tag": "4.3.0",
          "kind": "minor",
          "published_at": "2022-10-06T11:15:37Z"
        },
        {
          "tag": "4.2.3",
          "kind": "patch",
          "published_at": "2022-11-07T20:19:30Z"
        },
        {
          "tag": "4.2.2",
          "kind": "patch",
          "published_at": "2022-09-27T10:44:51Z"
        },
        {
          "tag": "4.2.1",
          "kind": "patch",
          "published_at": "2022-09-18T15:06:01Z"
        },
        {
          "tag": "4.2.0",
          "kind": "minor",
          "published_at": "2022-09-10T16:04:39Z"
        },
        {
          "tag": "4.1.5",
          "kind": "patch",
          "published_at": "2022-09-27T10:39:16Z"
        },
        {
          "tag": "4.1.4",
          "kind": "patch",
          "published_at": "2022-08-29T20:33:38Z"
        },
        {
          "tag": "4.1.3",
          "kind": "patch",
          "published_at": "2022-08-29T20:33:38Z"
        },
        {
          "tag": "4.1.2",
          "kind": "patch",
          "published_at": "2022-08-29T20:33:38Z"
        },
        {
          "tag": "4.1.1",
          "kind": "patch",
          "published_at": "2022-08-29T20:33:38Z"
        },
        {
          "tag": "4.1.0",
          "kind": "minor",
          "published_at": "2022-08-29T17:23:55Z"
        },
        {
          "tag": "v4.0.5",
          "kind": "patch",
          "published_at": "2022-06-23T16:25:36Z"
        },
        {
          "tag": "v4.0.4",
          "kind": "patch",
          "published_at": "2022-05-09T16:34:13Z"
        },
        {
          "tag": "v4.0.3",
          "kind": "patch",
          "published_at": "2022-04-02T12:48:22Z"
        },
        {
          "tag": "v4.0.2",
          "kind": "patch",
          "published_at": "2022-04-02T12:48:22Z"
        },
        {
          "tag": "v4.0.1",
          "kind": "patch",
          "published_at": "2022-04-02T12:48:22Z"
        },
        {
          "tag": "v4.0.0",
          "kind": "major",
          "published_at": "2022-04-02T12:48:22Z"
        },
        {
          "tag": "v3.3.12",
          "kind": "patch",
          "published_at": "2022-02-18T07:13:44Z"
        },
        {
          "tag": "v3.3.11",
          "kind": "patch",
          "published_at": "2021-11-21T11:14:31Z"
        },
        {
          "tag": "v3.3.10",
          "kind": "patch",
          "published_at": "2021-11-21T11:14:31Z"
        },
        {
          "tag": "v3.3.9",
          "kind": "patch",
          "published_at": "2021-04-19T20:22:20Z"
        },
        {
          "tag": "v3.3.8",
          "kind": "patch",
          "published_at": "2021-04-19T20:22:20Z"
        },
        {
          "tag": "v3.3.7",
          "kind": "patch",
          "published_at": "2021-04-19T19:52:41Z"
        },
        {
          "tag": "v3.3.6",
          "kind": "patch",
          "published_at": "2021-04-18T07:21:22Z"
        },
        {
          "tag": "v3.3.5",
          "kind": "patch",
          "published_at": "2021-04-17T19:37:04Z"
        },
        {
          "tag": "v3.3.4",
          "kind": "patch",
          "published_at": "2021-04-16T11:31:10Z"
        },
        {
          "tag": "v3.3.3",
          "kind": "patch",
          "published_at": "2021-04-15T13:40:07Z"
        },
        {
          "tag": "v3.3.2",
          "kind": "patch",
          "published_at": "2021-02-01T07:44:44Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2021-01-09T13:31:01Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2020-12-06T14:41:49Z"
        },
        {
          "tag": "v3.2.12",
          "kind": "patch",
          "published_at": "2020-08-31T19:42:44Z"
        },
        {
          "tag": "v3.2.11",
          "kind": "patch",
          "published_at": "2020-08-31T19:42:44Z"
        },
        {
          "tag": "v3.2.10",
          "kind": "patch",
          "published_at": "2020-08-31T19:42:44Z"
        },
        {
          "tag": "v3.2.9",
          "kind": "patch",
          "published_at": "2020-08-31T19:42:44Z"
        },
        {
          "tag": "v3.2.8",
          "kind": "patch",
          "published_at": "2020-08-01T16:33:25Z"
        },
        {
          "tag": "v3.2.7",
          "kind": "patch",
          "published_at": "2020-07-21T21:49:00Z"
        },
        {
          "tag": "v3.2.6",
          "kind": "patch",
          "published_at": "2020-05-16T11:47:15Z"
        },
        {
          "tag": "v3.2.5",
          "kind": "patch",
          "published_at": "2020-05-13T16:48:54Z"
        },
        {
          "tag": "v3.2.4",
          "kind": "patch",
          "published_at": "2020-05-05T21:48:34Z"
        },
        {
          "tag": "v3.2.3",
          "kind": "patch",
          "published_at": "2020-05-05T19:30:44Z"
        },
        {
          "tag": "v3.2.2",
          "kind": "patch",
          "published_at": "2020-05-02T21:12:39Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2020-05-02T20:10:21Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2020-05-02T11:38:46Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2020-02-03T21:25:10Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2020-02-03T21:25:10Z"
        },
        {
          "tag": "v3.0.2",
          "kind": "patch",
          "published_at": "2020-02-03T21:25:10Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a272f254c056fb3d6c80a4801d3c7c5fedc6a08d",
          "body": "…(#831) (#839)\n\nAdd a per-request `mediation` hint on `PublicKeyCredentialCreationOptions` so the\nrelying party can opt out of the strict User Presence check when the credential\nis created through a Conditional Create flow (e.g. SimpleWebAuthn\n`useAutoRegister: true`, where the UP bit is legitimatel\n[…]\nemantics of `CheckUserWasPresent` and\nthe option property (validation, storage round-trip, JSON output absence)\nplus an `Issue831RegressionTest` covering the bundle integration (factory,\npolicy, DTO).",
          "is_bot": false,
          "headline": "feat: support Conditional Create (mediation) for auto-register flows …",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-05-01T12:14:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e718677555cc4f70e83f2be0aca3e6231c5bfa9",
          "body": "…#832, #833) (#838)\n\n* fix: complete CredentialRecord migration and restore 5.2.x BC (#827, #832, #833)\n\n- Rename CanSaveCredentialRecord::saveCredentialSource to saveCredentialRecord\n  and restore CanSaveCredentialSource as a standalone deprecated interface with\n  the legacy saveCredentialSource(Pu\n[…]\n\n  Claude Code skills (e.g. .claude/commands/merge-up.md) stay versioned\n  in the repo for collaboration but are excluded from the distributed\n  git archive (matching the existing /CLAUDE.md pattern).",
          "is_bot": false,
          "headline": "fix: complete CredentialRecord migration and restore 5.2.x BC (#827, …",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-05-01T11:34:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2eea7e8783b810a78d4bd033891c55ce8fcea7b4",
          "body": "…on style in tests",
          "is_bot": false,
          "headline": "refactor: remove unused AuthenticatorData imports and improve asserti…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-05-01T09:33:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26182ae87c00af98cbae813336f76023201ddcc9",
          "body": "* CheckUserHandle: Use hash_equals for comparing user handles\n\n* CheckUserHandle: Add further $responseUserHandle !== null check",
          "is_bot": false,
          "headline": "CheckUserHandle: Use hash_equals for comparing user handles (#829)",
          "author_name": "Sam Reed",
          "author_login": "reedy",
          "committed_at": "2026-04-29T15:43:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b10c38f54db49b9622ff208ccf70d0d94b41ac73",
          "body": "* 5.2.x:\n  fix: normalize host-only allowed origins to https:// scheme (#822)\n  fix: pass topOriginValidator to CheckTopOrigin in requestCeremony() (#821)\n  fix: enforce HTTPS scheme check in CheckAllowedOrigins fallback path (#820)\n  fix: regenerate PHPStan baseline to fix CI on 5.2.x\n  fix: add PH\n[…]\nsupport intermediate CA certificates (#793)\n\n# Conflicts:\n#\tphpstan-baseline.neon\n#\tsrc/webauthn/src/CeremonyStep/CeremonyStepManagerFactory.php\n#\tsrc/webauthn/src/CeremonyStep/CheckAllowedOrigins.php",
          "is_bot": false,
          "headline": "Merge branch '5.2.x' into 5.3.x",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-29T07:34:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7705e32a4148a72664eb755f53e44e3af6b2ceb3",
          "body": "…keCredentialGenerator (#823)\n\n* fix: use all transport types and deterministic generation in SimpleFakeCredentialGenerator\n\nInclude hybrid, internal and smart-card transports in the fake\ncredential pool so generated credentials are indistinguishable from\nreal ones. Replace random generation with a \n[…]\nMetadataService, FidoAllianceCompliantMetadataService, and others for better clarity and maintainability.\n- Cleaned up unused imports in test files and ensured proper organization of function imports.",
          "is_bot": false,
          "headline": "fix: complete transport pool and deterministic generation in SimpleFa…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-29T07:26:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0785f55f242c1cc026ec24a9c8653eac59fe3493",
          "body": "* fix: normalize host-only allowed origins to https:// scheme\n\nHost-only entries in allowed_origins (e.g. \"example.com\") were matched\nagainst the incoming origin's host without checking the scheme or port,\nallowing origins like https://example.com:8443 to bypass validation.\n\nSince WebAuthn requires \n[…]\n <noreply@anthropic.com>\n\n* fix: coding standards\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: normalize host-only allowed origins to https:// scheme (#822)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-23T22:13:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3c3405a0f7deb335b8611f385e4dd14587ba345b",
          "body": "…#821)\n\n* fix: pass topOriginValidator to CheckTopOrigin in requestCeremony()\n\nThe custom TopOriginValidator set via enableTopOriginValidator() was only\npassed to CheckTopOrigin in creationCeremony() but not in\nrequestCeremony(), causing the fallback HostTopOriginValidator to always\nbe used during a\n[…]\natching the method's name and intent.\n\nFixes #816\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: pass topOriginValidator to CheckTopOrigin in requestCeremony() (…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-23T21:59:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c28f27cb8f968d2b84db48587563f03bb451b60a",
          "body": "…(#820)\n\n* fix: enforce HTTPS scheme check before host matching in CheckAllowedOrigins fallback path\n\nThe HTTPS scheme check was unreachable in the fallback path (no allowed\norigins configured) because the method returned early on host match.\nMove the check before host comparison so it is always enf\n[…]\ntions that\nno longer match reported errors in CI.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: enforce HTTPS scheme check in CheckAllowedOrigins fallback path …",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-23T21:43:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1ea7e2cae320f04c75212bf019e845d8d7faf950",
          "body": "…#819)\n\nInstead of hardcoding TYPE_BASIC, the compound attestation type is now\nderived from the nested attestation types by selecting the weakest\n(least trusted) type. This prevents misrepresenting the trust level\nwhen sub-attestations have lower trust than basic.\n\nTrust order (strongest to weakest): attca > anonca > basic > self > none\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: derive compound attestation type from nested attestation types (…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-22T17:54:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4271d7556bec22dc9ff5a3cbd5233bfba04483a6",
          "body": "fix: reduce PHPStan baseline from 82 to 67 errors",
          "is_bot": false,
          "headline": "Merge pull request #818 from web-auth/fix/reduce-phpstan-baseline-v3",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-22T16:36:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b756edae0847b28635d374c945f05a3bbca78c6",
          "body": "…Stan errors",
          "is_bot": false,
          "headline": "fix: cast 'alg' to int in AttestationStatement classes to resolve PHP…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-08T21:25:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8244eb071bad73101c78b6be5c24d15070c03e22",
          "body": "- Removed unnecessary PHPStan annotations in WebauthnCollector.\n- Updated type hints in WebauthnFactory to provide more specific array structures.\n- Simplified configuration processing in WebauthnExtension.\n- Enhanced type safety in PublicKeyCredentialCreationOptionsFactory and PublicKeyCredentialRe\n[…]\nAttestationStatementSupport and PackedAttestationStatementSupport for better readability.\n- Ensured proper handling of optional parameters and improved overall code quality across the Webauthn bundle.",
          "is_bot": false,
          "headline": "Refactor Webauthn components for improved type safety and clarity",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-08T21:21:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "88c72ecd70914715f75f9c0922cdafa997fa21a3",
          "body": "…owedOrigins\n\nPort the robust origin validation fix from 5.2.4 (GHSA-f7pm-6hr8-7ggm)\nto 5.3.x. Replaces the simpler fix with the full implementation that\nincludes default port normalization and backward-compatible host-only\nmatching.\n\nCo-Authored-By: dorakemon <51844896+dorakemon@users.noreply.github.com>\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: merge up CVE fix from 5.2.x - full origin validation in CheckAll…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-08T17:56:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c346c9812d4d4a641f5ff26cd5fa4d0bf2035eeb",
          "body": "…eckAllowedOrigins\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: add PHPStan type annotations for parse_url() return values in Ch…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-08T17:01:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b39197276f2596700d0a368bca248c7d5c5c2673",
          "body": null,
          "is_bot": false,
          "headline": "Merge commit from fork",
          "author_name": "Ken Watanabe",
          "author_login": "dorakemon",
          "committed_at": "2026-03-08T16:49:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9d891cd3444bc280cce3ce5e9b47df786a727268",
          "body": "Previously, CheckAllowedOrigins reduced URL-like allowed origins to\ntheir host component only, losing scheme and port information. This\nmeant that origins like https://example.com:8443 and\nhttps://example.com:9443 were treated as identical, bypassing the\nexact origin validation required by WebAuthn \n[…]\n full origins also verifies scheme and port.\n\nFixes GHSA-f7pm-6hr8-7ggm\n\nCo-authored-by: dorakemon <51844896+dorakemon@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Merge commit from fork",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-03-08T16:49:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "586198d87293dade9dda225b29d0ec6d77bae188",
          "body": "…vements (#809)\n\nAdd precise array shapes, @var annotations, and type hints across denormalizers,\nattestation statement supports, options factories, and Symfony bundle classes.\nAll fixes preserve strict backward compatibility — no runtime behavior changes.\n\nRemaining 256 errors are structural (deprecated refs, Liskov violations,\nDI container typing, property.uninitialized, intentional casts).\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: reduce PHPStan baseline from 1638 to 256 errors via PHPDoc impro…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-02-22T23:49:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6e94e3e777ccb287b6bb8e185466f99e329ef65d",
          "body": "Document the exceptions that can be thrown by each denormalize() method,\nso consumers know which exceptions to catch when handling invalid input.\n\nAlso update ECS config to preserve @throws annotations (previously\nstripped by GeneralPhpdocAnnotationRemoveFixer from the symplify set).\n\nCloses #779\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add @throws phpdoc annotations to denormalizers (#808)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-02-22T22:15:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e9ca6d195fe1bb39dec7f77c177c2fe3ecab0d97",
          "body": "… (#805)\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add granular client override policy system for WebAuthn options…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-02-22T21:47:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fbcdda23ec8a1cce14b888ac2a6c3ad4e55a8864",
          "body": "This change improves backward compatibility by using inheritance instead\nof union types. PublicKeyCredentialSource now extends CredentialRecord,\nallowing code that type-hints CredentialRecord to automatically accept\nboth types.\n\nKey changes:\n- PublicKeyCredentialSource is now an empty class extendin\n[…]\n only\n- CredentialRecordConverter utility updated to handle inheritance\n\nThis resolves the concern raised in discussion #803 where downstream\npackages needed union types to support both v5.2 and v5.3.",
          "is_bot": false,
          "headline": "refactor: make PublicKeyCredentialSource extend CredentialRecord (#804)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2026-02-03T12:56:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84bcf41a51df9f3a43c6a6ecd758220f8045987b",
          "body": "* chore: simplify metadata statement check\n* refactor: enhance metadata statement verification logic and improve logging\n\n---------\n\nCo-authored-by: Florent Morselli <florent.morselli@spomky-labs.com>",
          "is_bot": false,
          "headline": "chore: simplify metadata statement check (#777)",
          "author_name": "zll600",
          "author_login": "zll600",
          "committed_at": "2025-12-20T21:14:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61d875e1886cbe8c7d8124de32b9537d1e653c0d",
          "body": null,
          "is_bot": false,
          "headline": "refactor: remove unused methods and clean up phpstan baseline",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-12-20T13:58:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3e6af655fb7a46e9760a764d699357364b5591b",
          "body": "# Conflicts:\n#\tcomposer.json\n#\tphpstan-baseline.neon\n#\tsrc/webauthn/src/AttestationStatement/TPMAttestationStatementSupport.php\n#\tsrc/webauthn/src/CeremonyStep/CeremonyStepManagerFactory.php\n#\ttests/library/Unit/AuthenticatorDataTest.php",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/5.3.x' into temp-ebe254",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-12-20T13:46:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8782f575032fedc36e2eb27c39c736054e2b6867",
          "body": "…ermediate CA certificates (#793)\n\n* Set the trust anchor with the trusted certificates when validating the certificate path\n\n* test: add unit tests for PhpCertificateChainValidator with intermediate CA trust anchor\n\nAdd comprehensive tests for certificate chain validation including:\n- Validation wi\n[…]\nmediate CA certificates can be used as trust anchors.\n\n* test: refactor PhpCertificateChainValidatorTest for improved readability and consistency\n\n---------\n\nCo-authored-by: zll600 <3400692417@qq.com>",
          "is_bot": false,
          "headline": "fix: set trust anchor when validating certificate path to support int…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-12-20T10:54:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49efc4a97f305d64825b1276ae5ff8b312bd0319",
          "body": "…tions for attestation statements (backport to 5.2.x) (#790)\n\n* refactor: use spomky-labs/pki-framework to replace native php openssl functions for attestation statements\n* chore: apply code style fixes and update PHPStan baseline\n- Fix code style (ECS) in AndroidKey and Apple attestation statement supports\n- Regenerate PHPStan baseline to account for removed openssl_* function calls\n\n---------\n\nCo-authored-by: zll600 <3400692417@qq.com>",
          "is_bot": false,
          "headline": "fix: use spomky-labs/pki-framework to replace native php openssl func…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-12-20T10:31:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac89d35fe7ece94e32cad253a106712b1288da35",
          "body": "Refactor constructor signatures and assertions in various classes for improved clarity",
          "is_bot": false,
          "headline": "Rector/ECS (#792)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-12-20T10:20:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88d969b1cec56f28d16b3cb02e7f24e0a9e2f987",
          "body": "* feat: introduce CredentialRecord and update references from PublicKeyCredentialSource\n\n* feat: update .gitattributes to ignore additional files and directories\n\n* feat: update .gitattributes to ignore additional files and directories",
          "is_bot": false,
          "headline": "PKCS => Credential Record (#751)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-28T07:28:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "297e7755d2300d3f5e37da7c13bf8ea81baf8830",
          "body": "…#767)",
          "is_bot": false,
          "headline": "feat: implement passkey endpoints with controller and configuration (…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-17T21:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd8f85655d5ee10b5a8b5d0d955819d2ef209653",
          "body": null,
          "is_bot": false,
          "headline": "feat: add workflow to auto-switch default branch on new tags (#769)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-17T21:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "778e90b5560af93b65c47c72681488cddab8beca",
          "body": "…(#765)\n\nrefactor: improve test method names and update PHPUnit configuration",
          "is_bot": false,
          "headline": "refactor: improve test method names and update PHPUnit configuration …",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-16T20:14:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5320619596d145ccf6daa0c4386e43a7aaa8d65f",
          "body": "* feat: update Symfony dependencies to support version 8.0\n* feat: update minimum stability to beta in composer.json",
          "is_bot": false,
          "headline": "feat: update Symfony dependencies to support version 8.0 (#763)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-14T11:31:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b960ab114ecde3e8a46bae591c3ad117a611a7fe",
          "body": "…nse validation (#762)\n\n* feat: add backup eligibility and status events to authenticator response validation\n* feat: remove deprecated BackupEligibilityChangedEvent and BackupStatusChangedEvent from PHPStan baseline",
          "is_bot": false,
          "headline": "feat: add backup eligibility and status events to authenticator respo…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-13T22:44:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "761768b05ede0ae12eedae4ed07388b98d612346",
          "body": "… WebAuthn Level 3 spec (#761)\n\nfeat: add requireResidentKey property for backward compatibility with WebAuthn Level 3 spec",
          "is_bot": false,
          "headline": "feat: add requireResidentKey property for backward compatibility with…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-11-13T21:26:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18b4636db2cd5a11608b97021ef4b41047039934",
          "body": "…y logic (#748)",
          "is_bot": false,
          "headline": "feat: add conditional create configuration and update ceremony factor…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-27T08:56:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e52191eb54129dd58121be4b92798d9cdcc7e0fa",
          "body": "…terfaces (#749)",
          "is_bot": false,
          "headline": "feat: implement Compound Attestation Statement support and related in…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-26T20:52:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a88e2eaf54ab7d6d973a7225040b17c8ad5fd93",
          "body": "…ated tests (#750)",
          "is_bot": false,
          "headline": "feat: add hints support to PublicKeyCredential options and update rel…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-26T20:43:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60b13d872c0d80b27057f5a1efe13f8bed4bd49e",
          "body": null,
          "is_bot": false,
          "headline": "feat: deprecate createFormJson method with no replacement (#746)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-26T11:57:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fe03bd50ae45ea9db42e84b000bc15af9c4453b",
          "body": "…related tests (#745)",
          "is_bot": false,
          "headline": "feat: deprecate PublicKeyCredentialRpEntity name property and update …",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-26T11:45:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5dbc37f97feec46187453de1925649f04391b33",
          "body": "…ICATOR_TRANSPORT_CABLE (#744)\n\nfeat: add new authenticator transport constants and deprecate AUTHENTICATOR_TRANSPORT_CABLE",
          "is_bot": false,
          "headline": "feat: add new authenticator transport constants and deprecate AUTHENT…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-26T10:07:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3069e12dab053a83e51907da6e92e0258345aabf",
          "body": "* chore: update CI/CD configuration and improve code quality",
          "is_bot": false,
          "headline": "chore: update CI/CD configuration and improve code quality (#736)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-10-22T15:49:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e42d3b6bb52aeac62740419609858316b2b955d",
          "body": "* Add signal classes and denormalizers for WebAuthn events\n\nIntroduced `Signal` interface along with three implementations: `AllAcceptedCredentials`, `CurrentUserDetails`, and `UnknownCredential`. Added corresponding denormalizers to handle serialization and deserialization of these events, updating\n[…]\nrDetailsDenormalizer`, and `SignalUnknownCredentialDenormalizer`), ensuring accurate tracking of static analysis issues.\n\n---------\n\nCo-authored-by: Florent Morselli <florent.morselli@spomky-labs.com>",
          "is_bot": false,
          "headline": "feat: add webauthn signal api serializers (#720)",
          "author_name": "Joost de Bruijn",
          "author_login": "joostdebruijn",
          "committed_at": "2025-10-22T08:28:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e796ab75491e2e9caa4ee249b01833c4eb334fe",
          "body": "* Update dependencies and GitHub Actions configuration\n\nUpgraded PHPUnit to support version 12.0, updated Deptrac package to version 3.0, and adjusted the GitHub Actions workflow to use `ubuntu-latest` for consistency with the latest CI environment.\n\n* Refactor constructors and improve type declarat\n[…]\nnd return types in preparation for web-auth/webauthn-lib 6.0. Included updates for child return type covariance, internal class usage, and static method calls to align with the latest library changes.",
          "is_bot": false,
          "headline": "Update dependencies and GitHub Actions configuration (#723)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-06-13T09:27:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8937c397c8ae91b5af422ca8aa915c756062da74",
          "body": "Implemented multiple WebAuthn extensions, including AppId, Uvm, CredentialProperties, LargeBlob, and PseudoRandomFunction, to enhance authentication capabilities. Updated Stimulus controller to handle input/output processing of these extensions, enabling seamless integration with WebAuthn flows. These changes improve flexibility and support for advanced use cases.",
          "is_bot": false,
          "headline": "Add WebAuthn authentication extensions support",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-03-16T14:38:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b02a2e617bad271ab23093814dcbbbf84eefc71f",
          "body": "Reorganized test configurations by splitting `config.yml` into `common.yml` and added Twig template support. Introduced Webauthn authentication mechanism with related classes, functional tests, and templates to enhance security. This commit also includes tests for authenticated access and successful login handling.",
          "is_bot": false,
          "headline": "Refactor Symfony test configurations and add badge support",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-03-16T11:12:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64508506b20e0c0d38b96d2f58cd8ab0779a2dfe",
          "body": "Introduced `allowed_origins` and `allow_subdomains` as replacements for `secured_rp_ids`, which is now deprecated and planned for removal in 6.0. Updated dependency injection, configuration definitions, and test cases accordingly. Deprecated relevant methods and classes while ensuring backward compatibility.",
          "is_bot": false,
          "headline": "Replace secured_rp_ids with allowed_origins and allow_subdomains",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-02-16T10:40:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7aa58ea290c421066d068b031f3f653dab20430c",
          "body": "Corrected the typo in the docblock annotation from `@@deprecated` to `@deprecated`. This ensures consistency with standard annotation formatting and improves code readability for developers.",
          "is_bot": false,
          "headline": "Fix typo in docblock annotation for @deprecated property (#696)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-02-16T10:15:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3630e05569271a57802736c9366efbe987bab33f",
          "body": "Ensure the 'x5c' key contains an array before creating a CertificateTrustPath. This prevents potential errors caused by invalid 'x5c' data structures during denormalization.",
          "is_bot": false,
          "headline": "Fix trust path denormalization for x5c data validation (#694)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-02-16T10:01:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d26985a5c6d69e947ca2594fbadc6116669dea8",
          "body": "Ensure the service throws a clear exception if the required \"web-token/jwt-library\" package is not installed. This prevents potential runtime issues by guiding users to install the necessary dependency upfront.",
          "is_bot": false,
          "headline": "Add validation for missing \"web-token/jwt-library\" dependency (#688)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-02-02T16:24:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b95b2b3902d943796c3c2bac2dd14af9d031fc2",
          "body": "* Add `sprintf` imports and update dependencies and baselines\r\n\r\nThis commit introduces `sprintf` imports across various files for consistency and resolves potential missing imports. Additionally, it updates dependency versions in `composer.json`, allowing support for newer releases, and updates the\n[…]\nnvironment settings to adjust deprecations handling and removed outdated entries in phpstan-baseline. Additionally, added a Symfony error handler in the test bootstrap for better exception management.",
          "is_bot": false,
          "headline": "Add `sprintf` imports and update dependencies and baselines (#668)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2025-01-03T23:01:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b5d278d2269dc41b9684ce1591daea21982cd7d1",
          "body": null,
          "is_bot": false,
          "headline": "fix php 8.4 deprecations",
          "author_name": "Patrick Kenny",
          "author_login": "ptmkenny",
          "committed_at": "2024-12-03T06:39:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc06b75c56effb97b997f22810fd8c2baeb9440a",
          "body": "The 'icon' parameter has been removed from the creation of PublicKeyCredentialEntity objects and their related tests. This is done due to it being deprecated in version 5.1 and has no effect currently. Relevant changes in the normalized results have also been made accordingly in the test cases.",
          "is_bot": false,
          "headline": "Remove 'icon' parameter from PublicKeyCredentialEntity creation",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-20T05:33:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cc8262b885cf01eee3c4c10ca3985bdd2614c97",
          "body": "A new castor.php file is introduced, replacing the existing Makefile which has been removed. This update modifies the GitHub workflows to call the appropriate Castor tasks. Minor changes are also made to existing source files and static analysis configurations to include the new castor.php file.",
          "is_bot": false,
          "headline": "Replace Makefile with castor.php and update workflow",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-20T05:24:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aff3ff0f4225e570b0ed188eeba98d9501607d11",
          "body": "The variable name \"data\" has been renamed to \"object\" in the normalize function of PublicKeyCredentialOptionsDenormalizer. The replacement aligns better to represent the instances of PublicKeyCredentialCreationOptions or PublicKeyCredentialRequestOptions that are passed into the function.",
          "is_bot": false,
          "headline": "Refactor variable name in PublicKeyCredentialOptionsDenormalizer",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-12T14:35:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9201cd6e142f148aa2a65ad26069cb37a1ed053",
          "body": "This commit changes the array filter callbacks used in PublicKeyCredentialOptionsDenormalizer and PublicKeyCredentialUserEntityDenormalizer. The old and new conditions ensure that only values that aren't null pass through, whereas previous conditions also checked against empty arrays. The callbacks have also been updated to include return type declarations for better type safety.",
          "is_bot": false,
          "headline": "Refactor array filter callbacks in Denormalizers",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-12T14:34:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be62e51bdfc6de302952f0b88cecd9bcfb3c888e",
          "body": "This commit refines the Symfony Serializer in the ExtensionDescriptor class and upgrades several packages in the composer.json file. It also cleans up the phpstan-baseline.neon file by removing noise from a slew of PHPStan errors, which indicates an improvement in the code quality and robustness. This makes the PHPStan static analysis tool more effective and useful for future developments.",
          "is_bot": false,
          "headline": "Update serializers and remove PHPStan errors",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-12T05:45:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "773626275506a2436bfe10ad337c610b7680aba8",
          "body": "Dependencies in the composer.json files have been updated for better structuring and optimization. The phpdocumentor/reflection-docblock and symfony/property-info dependencies have been moved to more appropriate sections. Also, some new suggestions have been added for better user guidance.",
          "is_bot": false,
          "headline": "Update dependencies in composer.json files",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-12T05:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c5da4e03004f15235cc4422270b861a042dbc89",
          "body": "THis PR removes all deprecated features",
          "is_bot": false,
          "headline": "Major upgrade",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-11T12:55:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c29df71fee5c2ff8bb7f68095acab9c2f3d3e63",
          "body": "Merge up 4.9.x to 5.0.x",
          "is_bot": false,
          "headline": "Merge pull request #628 from web-auth/temp-ac12ed",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-11T09:33:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0198351b6e823d2e12e2c60732b6dc6e1c39a3fc",
          "body": "All classes moved to the main package web-auth/webauthn-lib. Event, Normalizers and exception are now common.",
          "is_bot": false,
          "headline": "Deprecates web-auth/metadata-service",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-11T09:06:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cba87f7113a311e58d062d45a5780e050c91280",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch '5.0.x' into temp-489135",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-10T15:49:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27c0cfa1c751a150852df1751d256afdd7d0af47",
          "body": "Introduce the `SerializerTrait` to handle serialization and deserialization for Doctrine Types. This refactoring deprecated and replaced the previous ways in these types: `PublicKeyCredentialDescriptorType`, `AttestedCredentialDataType`, `TrustPathDataType`. Meanwhile, test entities were removed, some deprecated methods related to serialization were marked, and the database configuration was updated in the test environment.",
          "is_bot": false,
          "headline": "Implement serialization/deserialization in Doctrine Types",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-10T15:38:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b591f088cf6ced88e61002e0a61782bff20d4287",
          "body": "…re common.",
          "is_bot": false,
          "headline": "Changed ble to internal transport, because internal (Passkeys) are mo…",
          "author_name": "Marc Riemer",
          "author_login": "marcriemer",
          "committed_at": "2024-07-07T19:32:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10f5ed338b3288dd859eac65355b6d3aa7c04b9f",
          "body": "…tion messages (#620)\n\nAdded `VerificationMethodANDCombinationsDenormalizer` and included in serializer configuration. Also, implemented trigger_deprecation in jsonSerialize methods marking them as deprecated and suggesting the use of the serializer instead. Further method and class modifications are reflected in the phpstan-baseline.neon file.",
          "is_bot": false,
          "headline": "Add VerificationMethodANDCombinationsDenormalizer and trigger depreca…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-07T06:51:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0ad952249b91a25f11f01996508eee896f4446d",
          "body": "…tion messages (#620)\n\nAdded `VerificationMethodANDCombinationsDenormalizer` and included in serializer configuration. Also, implemented trigger_deprecation in jsonSerialize methods marking them as deprecated and suggesting the use of the serializer instead. Further method and class modifications are reflected in the phpstan-baseline.neon file.",
          "is_bot": false,
          "headline": "Add VerificationMethodANDCombinationsDenormalizer and trigger depreca…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-07T06:49:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12c1fcd984b386a6f0d03d597c6f2239f6844565",
          "body": "* Remove debug dump in ProfileBasedRequestOptionsBuilder\r\n\r\nThe update removes a debug dump in the ProfileBasedRequestOptionsBuilder. This dump was outputting the results of the fake credential generator if it's defined in cases when a\r\n\r\n* Add feature to hide existing credentials\r\n\r\nThe code change\n[…]\nhods in several classes, scheduled to be removed in version 5.0. Now serialization relies fully on the Symfony Serializer component. Various minor amendments in other classes to support these changes.",
          "is_bot": false,
          "headline": "Merge up 4.9.x to 5.0.x (#619)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-06T19:30:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cab57004bc4738dab86567d2dd707fa91231cb6f",
          "body": "* Add new denormalizers and deprecate old JSON methods\r\n\r\nAdded new Denormalizer classes for AttestedCredentialData, AuthenticationExtensions, and others. Deprecated JSON serialization methods in several classes, scheduled to be removed in version 5.0. Now serialization relies fully on the Symfony Serializer component. Various minor amendments in other classes to support these changes.",
          "is_bot": false,
          "headline": "Add new denormalizers and deprecate old JSON methods (#618)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-07-06T19:20:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14301665889fc8db80a784551d999aebbd35b689",
          "body": "This update enhances several denormalizer classes in the WebAuthn package (AuthenticationExtensionsDenormalizer, PublicKeyCredentialOptionsDenormalizer, PublicKeyCredentialUserEntityDenormalizer, TrustPathDenormalizer) to also support normalization. This allows backward conversion from entities back to arrays. A new Serializer unit test has been introduced for validation.",
          "is_bot": false,
          "headline": "Add normalization support to denormalizers (#604)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-06-30T06:42:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "614d5a6354ca3da6902f4df131b91671c2d12bdd",
          "body": "\"id\" has been deprecated in the Credential class and it was replaced by the new property \"$rawId\". This change was also included in several functional tests where Base64UrlSafe was being used previously. Now, 'rawId' is used throughout the system to maintain consistency. A validation to ensure the presence of a 'rawId' in the constructor of the Credential class has also been added.",
          "is_bot": false,
          "headline": "Replace deprecated id with rawId (#589)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-06-29T13:00:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6798de27cdedd8681fe4c9b13ace0ff2456d18b",
          "body": "* Add FakeCredentialGenerator for fake credentials generation\r\n\r\nThe update introduces a new FakeCredentialGenerator and its simple implementation, SimpleFakeCredentialGenerator, for generating fake credentials. This addition helps prevent username enumeration by providing fake credentials for nonexistent users. Changes have been made across multiple files, including service configuration updates and logic changes in the ProfileBasedRequestOptionsBuilder.",
          "is_bot": false,
          "headline": "Add FakeCredentialGenerator for preventing username enumeration (#603)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-06-29T12:22:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ef7e2e2c1ee3e3f4d08e55c2956bba5cb820dab",
          "body": null,
          "is_bot": false,
          "headline": "fix:  the final newline is missing",
          "author_name": "Joost de Bruijn",
          "author_login": "joostdebruijn",
          "committed_at": "2024-05-26T18:52:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04b0ff397692daf00c478ceb0a016e56f0264176",
          "body": null,
          "is_bot": false,
          "headline": "chore: allow paragonie/constant_time_encoding v3",
          "author_name": "Joost de Bruijn",
          "author_login": "joostdebruijn",
          "committed_at": "2024-05-26T18:42:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65dc91b9ec64bf672c8a0528c2888bbe20a3e7a6",
          "body": "* Deprecate Android SafetyNet support\r\n\r\nThe Android SafetyNet support is marked as deprecated starting from version 4.9.0 and will be completely removed in version 5.0.0. This includes key verification classes, configuration options, and dependencies. This decision arises from updates in the latest symfony and webauthn environments.",
          "is_bot": false,
          "headline": "Deprecate Android SafetyNet support (#585)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-04-09T09:44:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "925873eb504a1db8a77dc2b4d2b578334736fa16",
          "body": "The logic for identifying the type of Authenticator Response has been simplified. Instead of checking for multiple array keys in a data object, we now simply check for the presence of either 'attestationObject' or 'signature'. This refactoring leads to cleaner and more maintainable code.",
          "is_bot": false,
          "headline": "Refactor authenticator response identification logic",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-04-08T10:04:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d296fde8450ce6972c54315a70e32159cad7e35b",
          "body": "…… (#577)\n\n* Remove unnecessary denormalizer exception checks and deprecated functions\r\n\r\nThis commit removes unnecessary checks for denormalizer nullity and throws subsequent exceptions. The checks were removed in various Denormalizer files, resulting in a cleaner codebase.\r\n\r\n* Update phpstan-base\n[…]\neen made to the AuthenticationExtensions class, updating type hints arrays. These improvements in type validation have led to the removal of certain error messages from the phpstan-baseline.neon file.",
          "is_bot": false,
          "headline": "Remove unnecessary denormalizer exception checks and deprecated funct…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-03-22T20:51:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7714d4f21d5b48e247b2b8f74bedef52d680ad0",
          "body": null,
          "is_bot": false,
          "headline": "Fix dependency package name to symfony/property-info",
          "author_name": "abcang",
          "author_login": "abcang",
          "committed_at": "2024-03-13T07:16:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abac08104bbbbdef01ace704c90ff8290696e47f",
          "body": null,
          "is_bot": false,
          "headline": "chore: add suggests and move reflection-docblock",
          "author_name": "Joost de Bruijn",
          "author_login": "joostdebruijn",
          "committed_at": "2024-02-26T19:17:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "655a86929a93c6abb267f6a5a689b66214519526",
          "body": null,
          "is_bot": false,
          "headline": "Fix CS",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-02-26T17:08:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfbdec5a893be7f93c4a7819ad9eeda064c74c5e",
          "body": "…eFromArray (#564)\n\nWith #513 `backupEligible`, `backupStatus` and `uvInitialized` became\r\nmandatatory public key attributes, while webauthn-lib versions prior to\r\n4.8.0 did not generated this public key attributes, which means a public\r\nkey generated with 4.7.x must not be reported as invalid.\r\n\r\nFixes #563",
          "is_bot": false,
          "headline": "fix: Support 4.7.x publickey data in PublicKeyCredentialSource::creat…",
          "author_name": "Benjamin Franzke",
          "author_login": "bnf",
          "committed_at": "2024-02-26T16:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac1be6bba06f78f1d58ac75eefcedd32ef8093c7",
          "body": null,
          "is_bot": false,
          "headline": "fix: detect realType AuthenticatorAttestationResponse",
          "author_name": "Joost de Bruijn",
          "author_login": "joostdebruijn",
          "committed_at": "2024-02-25T20:08:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dee648c4a0971633c9434391c710bd3f244d6aed",
          "body": "Doctrine DBAL 4.0 and ORM 3.0 for tests",
          "is_bot": false,
          "headline": "Doctrine DBAL 4.0 and ORM 3.0 for tests (#553)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-02-23T11:09:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "283b9361c93b7f2ed3cf45227897bc6e9b669b32",
          "body": "Symfony 7 and web-token/jwt-library 3.3",
          "is_bot": false,
          "headline": "Ssupport JWT Library and SF 7.0 (#551)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2024-02-23T09:04:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfec02e5c02270879e63d176849012446fdbe003",
          "body": "Fix property access for rpId",
          "is_bot": false,
          "headline": "Fix property access for rpId (#546)",
          "author_name": "abcang",
          "author_login": "abcang",
          "committed_at": "2024-02-02T06:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdba2044c74f3a7e345fb5ca81566f85e47c372e",
          "body": "Comments addressed",
          "is_bot": false,
          "headline": "Comments addressed (#531)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-19T20:17:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4895b940a954afa80615393704b7c03584a5d375",
          "body": "Merge up 4.7.x to 4.8.x",
          "is_bot": false,
          "headline": "Merge pull request #525 from web-auth/temp-gergji",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-17T11:50:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e1b877733e4cbd43101cf0ba07f0854e4cb23de",
          "body": "…icatorSelectionCriteria",
          "is_bot": false,
          "headline": "Parameter residentKey should not be ignored when initializing Authent…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-17T11:42:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e465b8f69f8288f2a886200ccec04b4bf7fa9ca5",
          "body": "…icatorSelectionCriteria",
          "is_bot": false,
          "headline": "Parameter residentKey should not be ignored when initializing Authent…",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-17T11:39:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8867fa972f735577e712a67fed3b8c6fece1e5e6",
          "body": "Deprecate PK Loader in favor of the symfony/serializer",
          "is_bot": false,
          "headline": "Deprecate PKLoader in favor of Symfony Serializer (#515)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-15T20:20:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8753399228b15f5793b75f21e3e7153515b5b7b6",
          "body": "Ceremony steps",
          "is_bot": false,
          "headline": "Ceremony steps (#513)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-13T12:41:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4839972fc789ffbd86a864a62ef60d77d24d9d2",
          "body": null,
          "is_bot": false,
          "headline": "Merge branch '4.8.x' into merge-up-hekxnze",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-12T08:03:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "944f70e4c578d44d496f8a12299a4d89bf58e3bb",
          "body": null,
          "is_bot": false,
          "headline": "Missing Optional PublicKeyCredentialParameters for creation options",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-11-12T07:41:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad536e90faa7e19cb55f12176c355433d2e81f04",
          "body": null,
          "is_bot": false,
          "headline": "Fix missing pieces for moving to 5.0.0",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-10-27T11:59:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de4183f5f1f4475182ab2115b5e89c7383d87124",
          "body": "Fix missing pieces for moving to 5.0.0",
          "is_bot": false,
          "headline": "Fix missing pieces for moving to 5.0.0 (#499)",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-10-23T06:38:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46e5fc953212aeae07f708ae3b9105af03d01f7",
          "body": null,
          "is_bot": false,
          "headline": "Fix uncovered scenario with PublicKeyCredentialSourceRepository",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-10-15T12:50:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35945fb7155fee072c2f5186e29ab370f682dc90",
          "body": null,
          "is_bot": false,
          "headline": "@private statement removed",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-10-15T12:50:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9b0d0563c561eaec5c24c46a551bf8ff23a030b",
          "body": null,
          "is_bot": false,
          "headline": "Fix uncovered scenario with PublicKeyCredentialSourceRepository",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-10-15T11:54:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c48f7049c96c1ed96672bcbbef13be5eb90a9163",
          "body": null,
          "is_bot": false,
          "headline": "@private statement removed",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-09-29T14:10:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2df969ad54fa35af4f41097062ccf415eb3e708",
          "body": null,
          "is_bot": false,
          "headline": "The list of PKC Params is empty by default and not required anymore",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-09-29T14:05:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1ed63d95d3235f277b042983c10aa92768c0b7c",
          "body": null,
          "is_bot": false,
          "headline": "Denormalizers",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-09-17T07:40:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14190af662c436aa74024451ed0747e7d1c6a5dd",
          "body": "4.7.x to 4.8.x",
          "is_bot": false,
          "headline": "Merge pull request #475 from web-auth/4.7.x-to-4.8.x",
          "author_name": "Florent Morselli",
          "author_login": "Spomky",
          "committed_at": "2023-09-08T12:36:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 42,
      "latest_release_at": "2026-05-31T15:00:08Z",
      "latest_release_tag": "5.3.5",
      "releases_from_tags": true,
      "days_since_last_push": 60,
      "active_weeks_last_year": 12,
      "days_since_latest_release": 60,
      "mean_days_between_releases": 18
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "web-auth/webauthn-lib",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "fido",
            "FIDO2",
            "webauthn"
          ],
          "ecosystem": "packagist",
          "matches_repo": true,
          "registry_url": "https://packagist.org/packages/web-auth/webauthn-lib",
          "is_deprecated": false,
          "latest_version": "5.3.5",
          "repository_url": "https://github.com/web-auth/webauthn-lib",
          "versions_count": 122,
          "total_downloads": 13916438,
          "dependents_count": 92,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 3443663,
          "first_published_at": null,
          "latest_published_at": "2026-05-31T15:00:08Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 60
        }
      ]
    },
    "popularity": {
      "forks": 25,
      "stars": 125,
      "watchers": 11,
      "fork_history": {
        "days": [
          {
            "date": "2019-02-21",
            "count": 2
          },
          {
            "date": "2020-03-06",
            "count": 1
          },
          {
            "date": "2020-03-28",
            "count": 1
          },
          {
            "date": "2020-12-17",
            "count": 1
          },
          {
            "date": "2021-12-13",
            "count": 1
          },
          {
            "date": "2022-02-09",
            "count": 1
          },
          {
            "date": "2022-02-11",
            "count": 1
          },
          {
            "date": "2022-02-17",
            "count": 1
          },
          {
            "date": "2022-02-28",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-04-03",
            "count": 1
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-06-14",
            "count": 1
          },
          {
            "date": "2023-07-19",
            "count": 1
          },
          {
            "date": "2023-12-21",
            "count": 1
          },
          {
            "date": "2024-03-11",
            "count": 1
          },
          {
            "date": "2024-03-19",
            "count": 1
          },
          {
            "date": "2024-04-23",
            "count": 1
          },
          {
            "date": "2024-06-17",
            "count": 1
          },
          {
            "date": "2025-01-15",
            "count": 1
          },
          {
            "date": "2025-04-18",
            "count": 1
          },
          {
            "date": "2025-05-13",
            "count": 1
          },
          {
            "date": "2025-06-06",
            "count": 1
          },
          {
            "date": "2026-04-28",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 25,
        "total_forks": 25
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 18153,
      "source_files_sampled": 191,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "composer.json"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 17,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "packagist"
      ],
      "dependencies": [
        {
          "name": "paragonie/constant_time_encoding",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^2.6|^3.0"
        },
        {
          "name": "psr/clock",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0"
        },
        {
          "name": "psr/event-dispatcher",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0"
        },
        {
          "name": "psr/log",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0|^2.0|^3.0"
        },
        {
          "name": "spomky-labs/cbor-php",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^3.0"
        },
        {
          "name": "symfony/clock",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^6.4|^7.0|^8.0"
        },
        {
          "name": "symfony/uid",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^6.4|^7.0|^8.0"
        },
        {
          "name": "spomky-labs/pki-framework",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^1.0"
        },
        {
          "name": "symfony/property-info",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^6.4|^7.0|^8.0"
        },
        {
          "name": "symfony/property-access",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^6.4|^7.0|^8.0"
        },
        {
          "name": "symfony/serializer",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^6.4|^7.0|^8.0"
        },
        {
          "name": "symfony/deprecation-contracts",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^3.2"
        },
        {
          "name": "web-auth/cose-lib",
          "manifest": "composer.json",
          "ecosystem": "packagist",
          "version_constraint": "^4.2.3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "paragonie/constant_time_encoding",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "psr/clock",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "psr/event-dispatcher",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "psr/log",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "spomky-labs/cbor-php",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "spomky-labs/pki-framework",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/clock",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/deprecation-contracts",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/property-access",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/property-info",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/serializer",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "symfony/uid",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "web-auth/cose-lib",
            "direct": true,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "ext-json",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "ext-openssl",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "php",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          },
          {
            "name": "phpdocumentor/reflection-docblock",
            "direct": false,
            "version": null,
            "ecosystem": "packagist"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 17,
        "direct_count": 13,
        "indirect_count": 4
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "Spomky",
          "commits": 371,
          "avatar_url": "https://avatars.githubusercontent.com/u/1091072?v=4"
        },
        {
          "type": "User",
          "login": "joostdebruijn",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/1844089?v=4"
        },
        {
          "type": "User",
          "login": "amenophis",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/2158235?v=4"
        },
        {
          "type": "User",
          "login": "tweis",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/63323?v=4"
        },
        {
          "type": "User",
          "login": "abcang",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/4199439?v=4"
        },
        {
          "type": "User",
          "login": "bnf",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/473155?v=4"
        },
        {
          "type": "User",
          "login": "emmanuel-deloget",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/9452911?v=4"
        },
        {
          "type": "User",
          "login": "dorakemon",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/51844896?v=4"
        },
        {
          "type": "User",
          "login": "Gashmob",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/54273056?v=4"
        },
        {
          "type": "User",
          "login": "lukewarlow",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/32498324?v=4"
        }
      ],
      "contributors_sampled": 17,
      "top_contributor_share": 0.942
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": false,
      "ci_workflows": [
        "auto-switch-default-branch.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 6 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a272f254c056fb3d6c80a4801d3c7c5fedc6a08d",
        "ran_at": "2026-07-30T22:49:59Z",
        "aggregate_score": 4.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-05-04T08:09:13Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/web-auth/webauthn-lib",
    "host": "github.com",
    "name": "webauthn-lib",
    "owner": "web-auth"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 50 is calibrated to 50 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 50,
            "calibrated": 50,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 50,
      "inputs": {
        "security": 41,
        "vitality": 60,
        "community": 71,
        "governance": 46,
        "calibration": "2026-08-02",
        "engineering": 38,
        "ai_readiness": 29,
        "weighted_overall_raw": 50
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 60,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "weak",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "commits_last_year": 42,
              "human_commit_share": 1,
              "days_since_last_push": 60,
              "active_weeks_last_year": 12
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 60 days ago",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 60
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "12/52 weeks with commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "42 commits in the last year",
                "points": 14.7,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 42
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "5.3.5",
              "releases_from_tags": true,
              "days_since_latest_release": 60,
              "mean_days_between_releases": 18
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 60 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 60
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~18 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 18
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 95,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 95 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 95
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 71,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "forks": 25,
              "stars": 125,
              "watchers": 11,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "125 stars",
                "points": 34,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 125
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "25 forks",
                "points": 11.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "11 watchers",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "exceptional",
            "name": "Ecosystem adoption (downloads)",
            "note": null,
            "notes": [],
            "value": 93,
            "inputs": {
              "packages": [
                "web-auth/webauthn-lib"
              ],
              "dependents": 92,
              "ecosystems": "packagist",
              "total_downloads": 13916438,
              "monthly_downloads": 3443663
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "3,443,663 downloads/month across packagist",
                "points": 80,
                "status": "met",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 3443663,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "92 packages depend on it",
                "points": 13.1,
                "status": "partial",
                "details": [
                  {
                    "code": "registry_dependents",
                    "params": {
                      "count": 92
                    }
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "weak",
        "name": "Sustainability & Governance",
        "value": 46,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 34,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 17,
              "top_contributor_share": 0.942
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 94% of commits",
                "points": 1.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "17 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 1,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/1 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 1
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "followers": 28,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "web-auth",
              "public_repos": 13,
              "account_age_days": 2807
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "28 followers of web-auth",
                "points": 10.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 28,
                      "login": "web-auth"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "13 public repos, account ~7 yr old",
                "points": 20.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 13
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "web-auth/webauthn-lib"
              ],
              "ecosystems": "packagist",
              "any_deprecated": false,
              "min_days_since_publish": 60
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on packagist",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "packagist"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 60 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 60
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "122 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 122
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "weak",
        "name": "Engineering Quality",
        "value": 38,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": true,
              "has_tests": false,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [
                "fido",
                "webauthn-support",
                "webauthn",
                "fido-u2f",
                "fido2",
                "u2f",
                "u2f-protocol",
                "safetynet"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "weak",
        "name": "Security",
        "value": 41,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "weak",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 4.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 6 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 19
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 29,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.82,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "82 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 82,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "critical",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 11,
            "inputs": {
              "has_nix": false,
              "has_tests": false,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.11,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "11 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 11,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "primary_language": "PHP",
              "largest_source_bytes": 18153,
              "source_files_sampled": 191,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "PHP without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "PHP"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/191 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 191,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "library"
      ],
      "labels": [
        "library"
      ],
      "scores": {
        "library": 8
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:packagist",
          "weight": 6
        },
        {
          "tier": "description",
          "label": "library",
          "source": "description:library",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": false,
      "consumed_by_code": true
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T22:50:12.079763Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/w/web-auth/webauthn-lib.svg",
  "full_name": "web-auth/webauthn-lib",
  "license_state": "standard",
  "license_spdx": "MIT"
}

Оцінки — це сигнали, а не гарантії. Вони відображають публічно видимі практики на GitHub — це не аудит коду й не гарантія безпеки.

Відсутні дані виключаються, а ваги перенормовуються — нуль за відсутність ніколи не ставиться. Методологія версіонована й відкрита: метрики v2.5.0, схема v0.27.0 — повна методологія · вікі метрик.

Як окремий результат виглядає на тлі всього реєстру: сукупна статистикаPackagist.