公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-25 17:06 UTC

OpenIdentityPlatform / commons

Parent POM for projects. Provides default project build configuration.

Java自定义许可证★ 5 星标⑂ 14 复刻始于 2017年9月在 GitHub 上查看 ↗

OpenIdentityPlatform/commons 的健康指数为 100 分中的 49 分,处于「存在风险」区间。 其得分最高的类别是Vitality(87/100),最低的是Community & Adoption(33/100)。 最近一次更新在 1 天前。 近期的大部分工作由 4 位贡献者完成。

49
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

49
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

高风险司法辖区政策对加权总体健康应用 75% 的乘数,并对其设置“存在风险”上限 49。

所有权

288 关注者36 个公开仓库始于 2017年8月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Mavenorg.openidentityplatform.commons:build-tools3.1.2-339 天前
Mavenorg.openidentityplatform.commons:cassandra-embedded3.1.2-219 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

87优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 1 天前
15.2/36提交节奏 — 52 周中有 22 周有提交
18/18提交量 — 最近一年 153 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year153
human_commit_share1
days_since_last_push1
active_weeks_last_year22

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 41 个发布版本
36/36发布时效 — 最近一次发布版本于 9 天前
27/27发布节奏 — 约每 43.6 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count41
latest_release_tag3.1.2
releases_from_tags
days_since_latest_release9
mean_days_between_releases43.6
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

33存在风险 · 占总体的 18%
评分方式
9.8/60星标 — 5 个星标
9.3/25复刻 — 14 个复刻
3.9/15关注者 — 6 位关注者
所用输入
forks14
stars5
watchers6
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

44存在风险
评分方式
22.5/22.5README
16.9/22.5许可证 — 存在许可证文件,但不是可识别的许可证
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

86优秀 · 占总体的 24%
评分方式
43.2/54巴士系数 — 4 位贡献者贡献了半数提交
17.2/22.5提交分布 — 头号贡献者编写了 24% 的提交
13.5/13.5贡献者广度 — 65 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 13 contributing companies or organizations
所用输入
bus_factor4
contributors_sampled65
top_contributor_share0.235
评分方式
46.8/46.8议题解决 — 100% 的议题已关闭
34.1/38.3PR 接受 — 已裁定的 PR 中 254/285 已合并
13.5/15OpenSSF Scorecard:Code-Review — Found 29/30 approved changesets -- score normalized to 9
所用输入
merged_prs254
open_issues0
closed_issues19
issue_closed_ratio1
closed_unmerged_prs31
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
17.7/25所有者影响力 — OpenIdentityPlatform 有 288 位关注者
23.4/25既往记录 — 36 个公开仓库,账户约 8 年
所用输入
followers288
owner_typeOrganization
is_verified
owner_loginOpenIdentityPlatform
public_repos36
account_age_days3,272
评分方式
25/25已发布且可解析 — maven 上有 2 个软件包
35/35发布时效 — 最近一次发布于 9 天前
20/20版本历史 — 33 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesorg.openidentityplatform.commons:build-tools, org.openidentityplatform.commons:cassandra-embedded
ecosystemsmaven
any_deprecated
min_days_since_publish9

工程质量

基础的工程与文档实践是否到位?

70良好 · 占总体的 20%

工程实践

84良好
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
16/16Linter 配置 — .eslintrc
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

50中等
评分方式
30/30README
0/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

46存在风险 · 占总体的 16%

安全态势

40存在风险
评分方式
3/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
6.8/7.5Code-Review — Found 29/30 approved changesets -- score normalized to 9
2.5/2.5Contributors — project has 13 contributing companies or organizations
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.2/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
4.5/5SAST — SAST tool detected but not run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
5.2/7.5Vulnerabilities — 3 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.4
high_risk_jurisdiction_cap49
high_risk_jurisdiction_multiplier75
security_posture_after_multiplier40
security_posture_before_jurisdiction54
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。 高风险司法辖区政策应用 75% 的乘数,并对安全态势设置“存在风险”上限 49。
评分方式
13.2/35直接依赖不含已知公告 — 1 个受影响:org.testng:testng 6.14.3 (high 7.8)
25/25间接依赖不含已知公告 — 没有间接依赖携带已知公告
33.5/40没有长期未处理的公告 — 1 个携带公告的软件包超过 90 天未处理;最早一条发布于 1,343 天前
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages3
unassessed_packages0
affected_by_severityhigh 1
direct_affected_packages1
比对的是 maven:org.openidentityplatform.commons:build-tools@3.1.2 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 3 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

57中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 98 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.98
agent_instruction_files
agent_instruction_max_bytes
评分方式
12.6/18一条命令的引导启动 — bloomfilter/core/pom.xml, bloomfilter/monitoring/pom.xml, bloomfilter/pom.xml(工具链约定,无任务运行器)
22/22自动化测试
11/11Lint / 格式化配置 — .eslintrc
11/11静态类型检查 — Java(静态类型)
0/10可复现环境
2/10已体现的代理实践 — 最近 100 次提交中有 1 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
2/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.01
toolchain_manifestsbloomfilter/core/pom.xml, bloomfilter/monitoring/pom.xml, bloomfilter/pom.xml, build-tools/pom.xml, cassandra-embedded/pom.xml, commons/audit/core/pom.xml, commons/audit/handler-csv/pom.xml, commons/audit/handler-elasticsearch/pom.xml, commons/audit/handler-jdbc/pom.xml, commons/audit/handler-jms/pom.xml, commons/audit/handler-json/pom.xml, commons/audit/handler-splunk/pom.xml, commons/audit/handler-syslog/pom.xml, commons/audit/json/pom.xml, commons/audit/pom.xml, commons/audit/servlet/pom.xml, commons/auth-filters/authn-filter/jaspi-functional-tests/pom.xml, commons/auth-filters/authn-filter/jaspi-modules/iwa-module/pom.xml, commons/auth-filters/authn-filter/jaspi-modules/jwt-session-module/pom.xml, commons/auth-filters/authn-filter/jaspi-modules/openam-session-module/pom.xml, commons/auth-filters/authn-filter/jaspi-modules/openid-connect-module/pom.xml, commons/auth-filters/authn-filter/jaspi-modules/pom.xml, commons/auth-filters/authn-filter/jaspi-runtime/pom.xml, commons/auth-filters/authn-filter/pom.xml, commons/auth-filters/authz-filter/framework-api/pom.xml, commons/auth-filters/authz-filter/framework-functional-tests/pom.xml, commons/auth-filters/authz-filter/framework/pom.xml, commons/auth-filters/authz-filter/modules/oauth2-module/pom.xml, commons/auth-filters/authz-filter/modules/pom.xml, commons/auth-filters/authz-filter/pom.xml, commons/auth-filters/pom.xml, commons/doc-common-content/pom.xml, commons/doc-default-branding/pom.xml, commons/doc-maven-plugin/pom.xml, commons/doc-maven-plugin/src/test/resources/antora/pom.xml, commons/doc-maven-plugin/src/test/resources/unit/pom.xml, commons/geo/pom.xml, commons/http-framework/benchmarks/pom.xml, commons/http-framework/binding-test-utils/pom.xml, commons/http-framework/client-apache-async/pom.xml, commons/http-framework/client-apache-common/pom.xml, commons/http-framework/client-apache-sync/pom.xml, commons/http-framework/core/pom.xml, commons/http-framework/examples/descriptor-example/pom.xml, commons/http-framework/examples/pom.xml, commons/http-framework/examples/servlet-example/pom.xml, commons/http-framework/grizzly/pom.xml, commons/http-framework/oauth2/pom.xml, commons/http-framework/pom.xml, commons/http-framework/servlet/pom.xml, commons/httpdump/pom.xml, commons/json-crypto/cli/pom.xml, commons/json-crypto/core/pom.xml, commons/json-crypto/pom.xml, commons/json-fluent/pom.xml, commons/json-ref/core/pom.xml, commons/json-ref/jackson/pom.xml, commons/json-ref/pom.xml, commons/json-schema/cli/pom.xml, commons/json-schema/core/pom.xml, commons/json-schema/pom.xml, commons/json-web-token/pom.xml, commons/launcher/launcher-zip/pom.xml, commons/launcher/launcher/pom.xml, commons/launcher/pom.xml, commons/pom.xml, commons/rest/api-descriptor/pom.xml, commons/rest/json-resource-examples/pom.xml, commons/rest/json-resource-http/pom.xml, commons/rest/json-resource/pom.xml, commons/rest/pom.xml, commons/rest/rest-docbook/pom.xml, commons/security/pom.xml, commons/selfservice/core/pom.xml, commons/selfservice/custom-stage/pom.xml, commons/selfservice/example-ui/pom.xml, commons/selfservice/example/pom.xml, commons/selfservice/json/pom.xml, commons/selfservice/pom.xml, commons/selfservice/stages/pom.xml, commons/util/pom.xml, commons/util/test-utils/pom.xml, commons/util/util/pom.xml, commons/xcite-maven-plugin/pom.xml, commons/xcite-maven-plugin/src/it/xcite/pom.xml, guice/core/pom.xml, guice/pom.xml, guice/servlet/pom.xml, guice/test/pom.xml, i18n-framework/core/pom.xml, i18n-framework/jul/pom.xml, i18n-framework/maven-plugin/pom.xml, i18n-framework/pom.xml, i18n-framework/slf4j/pom.xml, maven-external-dependency-plugin/maven-external-dependency-plugin-test/pom.xml, maven-external-dependency-plugin/maven-external-dependency-plugin/pom.xml, persistit/core/pom.xml, persistit/pom.xml, persistit/ui/pom.xml, pom.xml, script/common/pom.xml, script/groovy/pom.xml, script/javascript/pom.xml, script/pom.xml, ui/commons/pom.xml, ui/mock/pom.xml, ui/pom.xml, ui/user/pom.xml
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Java(静态类型)
54.6/55可控的文件大小 — 采样的 2,019 个源文件中有 16 个超过 60KB
所用输入
primary_languageJava
largest_source_bytes275,910
source_files_sampled2,019
oversized_source_files16

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — example, examples
所用输入
example_dirsexample, examples
has_mcp_signal
api_schema_files

关键数据

5GitHub 星标
65贡献者
153最近 12 个月提交数
1距最近推送天数
41发布版本数
4巴士系数(bus factor)
0开放议题
Maven软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 14 ⇿
0Star
14Fork
32发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

03581013151422018-122022-032025-06
主版本 1次版本 2修订 29

每个点涵盖 6 天。

OpenSSF Scorecard 5.4 / 10
5.4综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-25 17:05 UTC

4Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
9Code-ReviewFound 29/30 approved changesets -- score normalized to 9
10Contributorsproject has 13 contributing companies or organizations
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
9Licenselicense file detected
10Maintained30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
9SASTSAST tool detected but not run on all commits
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
7Vulnerabilities3 existing vulnerabilities detected
直接依赖 161
注册表软件包版本约束清单文件
Mavenorg.hdrhistogram:HdrHistogram${hdrhistogram.version}bloomfilter/pom.xml
Mavenorg.testng:testngbuild-tools/pom.xml
Mavenorg.apache.cassandra:java-driver-corecassandra-embedded/pom.xml
Mavenorg.apache.cassandra:cassandra-allcassandra-embedded/pom.xml
Mavenat.yawk.lz4:lz4-java1.10.1cassandra-embedded/pom.xml
Mavenorg.xerial.snappy:snappy-java1.1.10.5cassandra-embedded/pom.xml
Mavencom.google.guava:failureaccess1.0.1cassandra-embedded/pom.xml
Mavenorg.slf4j:slf4j-apiguice/pom.xml
Mavenorg.assertj:assertj-coreguice/pom.xml
Mavenorg.slf4j:slf4j-nopguice/pom.xml
Mavenorg.openidentityplatform.commons.guice:core${project.version}guice/pom.xml
Mavenorg.openidentityplatform.commons.guice:servlet${project.version}guice/pom.xml
Mavencom.google.inject:guice${guice.version}guice/pom.xml
Mavenorg.apache.httpcomponents:httpasyncclient-osgi4.1.4pom.xml
Mavenorg.apache.httpcomponents:httpcore-osgi4.4.14pom.xml
Mavenorg.apache.httpcomponents:httpcore4.4.14pom.xml
Mavenorg.apache.httpcomponents:httpcore-nio4.4.14pom.xml
Mavenorg.apache.httpcomponents:httpclient-osgi4.5.13pom.xml
Mavenorg.apache.httpcomponents:httpclient4.5.13pom.xml
Mavenorg.slf4j:slf4j-jdk14${slf4j.version}pom.xml
Mavenorg.slf4j:slf4j-api${slf4j.version}pom.xml
Mavenorg.slf4j:slf4j-nop${slf4j.version}pom.xml
Mavenorg.slf4j:slf4j-simple${slf4j.version}pom.xml
Mavenorg.slf4j:jul-to-slf4j${slf4j.version}pom.xml
Mavenorg.slf4j:jcl-over-slf4j${slf4j.version}pom.xml
Mavenorg.slf4j:log4j-over-slf4j${slf4j.version}pom.xml
Mavencom.google.guava:guava33.4.8-jrepom.xml
Mavencom.sun.mail:jakarta.mail2.0.2pom.xml
Mavencom.fasterxml.jackson:jackson-bom${jackson.version}pom.xml
Mavenorg.bouncycastle:bc-jdk18on-bom1.84pom.xml
Mavenorg.openidentityplatform.commons.guice:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.guice:test${project.version}pom.xml
Mavenorg.openidentityplatform.commons.guice:servlet${project.version}pom.xml
Mavenorg.openidentityplatform.commons:util${project.version}pom.xml
Mavenorg.openidentityplatform.commons:test-utils${project.version}pom.xml
Mavenorg.openidentityplatform.commons.ui:user${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:client-apache-async${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:client-apache-common${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:client-apache-sync${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:servlet${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:grizzly${project.version}pom.xml
Mavenorg.openidentityplatform.commons.http-framework:oauth2${project.version}pom.xml
Mavenorg.openidentityplatform.commons.json-crypto:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.json-crypto:cli${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-patch${project.version}pom.xml
Mavenorg.openidentityplatform.commons.json-ref:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.json-ref:jackson${project.version}pom.xml
Mavenorg.openidentityplatform.commons.json-schema:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.json-schema:cli${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-web-token${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-resource-descriptor${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-resource${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-resource${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-resource-http${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-resource-examples${project.version}pom.xml
Mavenorg.openidentityplatform.commons:api-descriptor${project.version}pom.xml
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:iwa-module${project.version}pom.xml
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:jwt-session-module${project.version}pom.xml
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:openam-session-module${project.version}pom.xml
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:openid-connect-module${project.version}pom.xml
Mavenorg.openidentityplatform.commons.authn-filter:jaspi-runtime${project.version}pom.xml
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter:framework${project.version}pom.xml
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter:framework-api${project.version}pom.xml
Mavenorg.openidentityplatform.commons:oauth2-module${project.version}pom.xml
Mavenorg.openidentityplatform.commons:oauth2-restlet${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:json${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-csv${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-elasticsearch${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-jdbc${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-jms${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-syslog${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-splunk${project.version}pom.xml
Mavenorg.openidentityplatform.commons.audit:handler-json${project.version}pom.xml
Mavenorg.openidentityplatform.commons.selfservice:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.selfservice:stages${project.version}pom.xml
Mavenorg.openidentityplatform.commons.selfservice:json${project.version}pom.xml
Mavenorg.openidentityplatform.commons:security${project.version}pom.xml
Mavenorg.openidentityplatform.commons:cassandra-embedded${project.version}pom.xml
Mavenorg.openidentityplatform.commons:json-fluent${project.version}pom.xml
Mavenorg.openidentityplatform.commons.script:javascript${project.version}pom.xml
Mavenorg.openidentityplatform.commons.script:groovy${project.version}pom.xml
Mavenorg.openidentityplatform.commons.launcher:launcher${project.version}pom.xml
Mavenorg.openidentityplatform.commons.launcher:launcher-zip${project.version}pom.xml
Mavenorg.openidentityplatform.commons.script:common${project.version}pom.xml
Mavenorg.mozilla:rhino${rhino.version}pom.xml
Mavenorg.mozilla:rhino-engine${rhino.version}pom.xml
Mavenorg.asciidoctor:asciidoctorj2.5.3pom.xml
Mavenorg.openidentityplatform.commons.ui:commons${project.version}pom.xml
Mavenio.swagger:swagger-models${swagger.version}pom.xml
Mavenio.swagger:swagger-core${swagger.version}pom.xml
Mavenorg.openidentityplatform.commons:geo${project.version}pom.xml
Mavenorg.openidentityplatform.commons:httpdump${project.version}pom.xml
Mavenorg.openidentityplatform.commons.i18n-framework:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.i18n-framework:slf4j${project.version}pom.xml
Mavenorg.openidentityplatform.commons:build-tools${project.version}pom.xml
Mavenorg.openidentityplatform.commons.persistit:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.bloomfilter:core${project.version}pom.xml
Mavenorg.openidentityplatform.commons.bloomfilter:monitoring${project.version}pom.xml
Mavencom.maxmind.geoip2:geoip22.13.0pom.xml
Mavencom.sun.xml.fastinfoset:FastInfoset1.2.17pom.xml
Mavenjavax.xml.bind:jaxb-api2.3.1pom.xml
Mavencom.sun.xml.bind:jaxb-core2.3.0.1pom.xml
Mavencom.sun.xml.bind:jaxb-impl2.3.2pom.xml
Mavencom.sun.xml.bind:jaxb1-impl2.2.5.1pom.xml
Mavencom.google.code.findbugs:jsr3053.0.2pom.xml
Mavenorg.apache.commons:commons-lang33.20.0pom.xml
Mavencommons-io:commons-io2.16.1pom.xml
Mavencommons-fileupload:commons-fileupload1.6.0pom.xml
Mavenorg.apache.commons:commons-text1.15.0pom.xml
Mavenorg.json:json20231013pom.xml
Mavenorg.codehaus.groovy:groovy-all2.4.21pom.xml
Mavenorg.eclipse.jetty:jetty-servlet${jetty.version}pom.xml
Mavenorg.eclipse.jetty:jetty-server${jetty.version}pom.xml
Mavenorg.eclipse.jetty.websocket:websocket-jetty-server${jetty.version}pom.xml
Mavenorg.glassfish.grizzly:grizzly-framework${grizzly-framework.version}pom.xml
Mavenorg.glassfish.grizzly:grizzly-http-server${grizzly-framework.version}pom.xml
Mavenorg.glassfish.grizzly:grizzly-http-servlet${grizzly-framework.version}pom.xml
Mavenorg.glassfish.grizzly:grizzly-websockets${grizzly-framework.version}pom.xml
Mavenorg.apache.cassandra:java-driver-core${cassandra.version}pom.xml
Mavenorg.apache.cassandra:java-driver-query-builder${cassandra.version}pom.xml
Mavenorg.apache.cassandra:cassandra-all${cassandra-all.version}pom.xml
Mavenio.netty:netty-bom4.2.15.Finalpom.xml
Mavenorg.openidentityplatform:build-tools${forgerockBuildToolsVersion}pom.xml
Mavencom.puppycrawl.tools:checkstyle[8.29,)pom.xml
Mavenorg.apache.maven.wagon:wagon-ssh2.2pom.xml
Mavenorg.easytesting:fest-assert-core2.0M10script/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:jquery${jquery.version}ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:lodash3.10.1ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:handlebars4.7.7ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:requirejs2.3.7ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backbone1.1.2ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backbone.paginator.min2.0.2ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:i18next1.7.3ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:react15.2.1ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:react-dom15.2.1ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap3.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap3.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap-dialog1.34.4ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap-dialog1.34.4ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:font-awesome4.5.0ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:selectize0.12.1ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:selectize0.12.1ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:dragula3.6.7ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:xdate0.8ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:moment2.28.0ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:js2form2.0-769718aui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:form2js2.0-769718aui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:jquery.placeholder2.0.8ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:spin2.0.1ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:jquery.ba-dotimeout1.0ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid.min0.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid.min0.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-paginator.min0.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-paginator.min0.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-filter.min0.3.7ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-filter.min0.3.7ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backbone-relational0.9.0ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-select-all0.3.5ui/pom.xml
Mavenorg.openidentityplatform.commons.ui.libs:sinon${sinon.version}ui/pom.xml
全部依赖 530

来自 GitHub 依赖图的完整解析依赖集合:259 个直接依赖与 271 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Mavenat.yawk.lz4:lz4-java1.10.1直接
Mavencom.fasterxml.jackson:jackson-bom2.18.6直接
Mavencom.google.code.findbugs:jsr305直接
Mavencom.google.code.findbugs:jsr3053.0.0直接
Mavencom.google.code.findbugs:jsr3053.0.2直接
Mavencom.google.guava:failureaccess1.0.1直接
Mavencom.google.guava:guava直接
Mavencom.google.guava:guava33.4.8-jre直接
Mavencom.google.inject:guice直接
Mavencom.google.inject:guice7.0.0直接
Mavencom.maxmind.geoip2:geoip2直接
Mavencom.maxmind.geoip2:geoip22.13.0直接
Mavencom.puppycrawl.tools:checkstyle直接
Mavencom.sun.mail:jakarta.mail直接
Mavencom.sun.mail:jakarta.mail2.0.2直接
Mavencom.sun.xml.bind:jaxb-core直接
Mavencom.sun.xml.bind:jaxb-core2.3.0.1直接
Mavencom.sun.xml.bind:jaxb-impl直接
Mavencom.sun.xml.bind:jaxb-impl2.3.2直接
Mavencom.sun.xml.bind:jaxb1-impl2.2.5.1直接
Mavencom.sun.xml.fastinfoset:FastInfoset1.2.17直接
Mavencommons-fileupload:commons-fileupload直接
Mavencommons-fileupload:commons-fileupload1.6.0直接
Mavencommons-io:commons-io直接
Mavencommons-io:commons-io2.14.0直接
Mavencommons-io:commons-io2.16.1直接
Mavenio.netty:netty-bom4.2.15直接
Mavenio.swagger:swagger-core直接
Mavenio.swagger:swagger-core1.6.11直接
Mavenio.swagger:swagger-models直接
Mavenio.swagger:swagger-models1.6.11直接
Mavenjavax.xml.bind:jaxb-api直接
Mavenjavax.xml.bind:jaxb-api2.3.1直接
Mavenorg.apache.cassandra:cassandra-all直接
Mavenorg.apache.cassandra:cassandra-all5.0.7直接
Mavenorg.apache.cassandra:java-driver-core直接
Mavenorg.apache.cassandra:java-driver-core4.19.2直接
Mavenorg.apache.cassandra:java-driver-query-builder4.19.2直接
Mavenorg.apache.commons:commons-lang3直接
Mavenorg.apache.commons:commons-lang33.1直接
Mavenorg.apache.commons:commons-lang33.20.0直接
Mavenorg.apache.commons:commons-text直接
Mavenorg.apache.commons:commons-text1.15.0直接
Mavenorg.apache.httpcomponents:httpasyncclient-osgi直接
Mavenorg.apache.httpcomponents:httpasyncclient-osgi4.1.4直接
Mavenorg.apache.httpcomponents:httpclient直接
Mavenorg.apache.httpcomponents:httpclient4.5.13直接
Mavenorg.apache.httpcomponents:httpclient-osgi直接
Mavenorg.apache.httpcomponents:httpclient-osgi4.5.13直接
Mavenorg.apache.httpcomponents:httpcore4.4.14直接
Mavenorg.apache.httpcomponents:httpcore-nio4.4.14直接
Mavenorg.apache.httpcomponents:httpcore-osgi直接
Mavenorg.apache.httpcomponents:httpcore-osgi4.4.14直接
Mavenorg.apache.maven.wagon:wagon-ssh2.2直接
Mavenorg.asciidoctor:asciidoctorj直接
Mavenorg.asciidoctor:asciidoctorj2.5.3直接
Mavenorg.assertj:assertj-core直接
Mavenorg.assertj:assertj-core2.1.0直接
Mavenorg.assertj:assertj-core3.27.7直接
Mavenorg.bouncycastle:bc-jdk18on-bom1.84直接
Mavenorg.codehaus.groovy:groovy-all直接
Mavenorg.codehaus.groovy:groovy-all2.1.3直接
Mavenorg.codehaus.groovy:groovy-all2.4.21直接
Mavenorg.easytesting:fest-assert-core直接
Mavenorg.easytesting:fest-assert-core2.0M10直接
Mavenorg.easytesting:fest-assert-core2.0M8直接
Mavenorg.eclipse.jetty.websocket:websocket-jetty-server11.0.25直接
Mavenorg.eclipse.jetty:jetty-server直接
Mavenorg.eclipse.jetty:jetty-server11.0.25直接
Mavenorg.eclipse.jetty:jetty-servlet直接
Mavenorg.eclipse.jetty:jetty-servlet11.0.25直接
Mavenorg.glassfish.grizzly:grizzly-framework3.0.1直接
Mavenorg.glassfish.grizzly:grizzly-http-server直接
Mavenorg.glassfish.grizzly:grizzly-http-server3.0.1直接
Mavenorg.glassfish.grizzly:grizzly-http-servlet直接
Mavenorg.glassfish.grizzly:grizzly-http-servlet3.0.1直接
Mavenorg.glassfish.grizzly:grizzly-websockets3.0.1直接
Mavenorg.hdrhistogram:HdrHistogram直接
Mavenorg.hdrhistogram:HdrHistogram2.1.4直接
Mavenorg.json:json直接
Mavenorg.json:json20231013直接
Mavenorg.mozilla:rhino直接
Mavenorg.mozilla:rhino1.7.11直接
Mavenorg.mozilla:rhino1.7.15.1直接
Mavenorg.mozilla:rhino-engine直接
Mavenorg.mozilla:rhino-engine1.7.15.1直接
Mavenorg.openidentityplatform.commons.audit:core直接
Mavenorg.openidentityplatform.commons.audit:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-csv直接
Mavenorg.openidentityplatform.commons.audit:handler-csv3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-elasticsearch直接
Mavenorg.openidentityplatform.commons.audit:handler-elasticsearch3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-jdbc直接
Mavenorg.openidentityplatform.commons.audit:handler-jdbc3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-jms3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-json3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-splunk3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:handler-syslog直接
Mavenorg.openidentityplatform.commons.audit:handler-syslog3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.audit:json直接
Mavenorg.openidentityplatform.commons.audit:json3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter:framework直接
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter:framework3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter:framework-api直接
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter:framework-api3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:iwa-module3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:jwt-session-module3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:openam-session-module3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.authn-filter.jaspi-modules:openid-connect-module3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.authn-filter:jaspi-runtime直接
Mavenorg.openidentityplatform.commons.authn-filter:jaspi-runtime3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.bloomfilter:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.bloomfilter:monitoring3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.guice:core直接
Mavenorg.openidentityplatform.commons.guice:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.guice:servlet3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.guice:test直接
Mavenorg.openidentityplatform.commons.guice:test3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:client-apache-async直接
Mavenorg.openidentityplatform.commons.http-framework:client-apache-async3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:client-apache-common直接
Mavenorg.openidentityplatform.commons.http-framework:client-apache-common3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:client-apache-sync直接
Mavenorg.openidentityplatform.commons.http-framework:client-apache-sync3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:core直接
Mavenorg.openidentityplatform.commons.http-framework:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:grizzly3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:oauth23.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.http-framework:servlet直接
Mavenorg.openidentityplatform.commons.http-framework:servlet3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.i18n-framework:core直接
Mavenorg.openidentityplatform.commons.i18n-framework:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.i18n-framework:slf4j3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.json-crypto:cli3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.json-crypto:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.json-ref:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.json-ref:jackson3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.json-schema:cli3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.json-schema:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.launcher:launcher3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.launcher:launcher-zip3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.persistit:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.script:common3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.script:groovy3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.script:javascript3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.selfservice:core直接
Mavenorg.openidentityplatform.commons.selfservice:core3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.selfservice:json3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.selfservice:stages直接
Mavenorg.openidentityplatform.commons.selfservice:stages3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.ui.libs:backbone直接
Mavenorg.openidentityplatform.commons.ui.libs:backbone1.1.2直接
Mavenorg.openidentityplatform.commons.ui.libs:backbone-relational直接
Mavenorg.openidentityplatform.commons.ui.libs:backbone-relational0.9.0直接
Mavenorg.openidentityplatform.commons.ui.libs:backbone.paginator.min直接
Mavenorg.openidentityplatform.commons.ui.libs:backbone.paginator.min2.0.2直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-filter.min直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-filter.min0.3.7直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-paginator.min直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-paginator.min0.3.5直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid-select-all0.3.5直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid.min直接
Mavenorg.openidentityplatform.commons.ui.libs:backgrid.min0.3.5直接
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap直接
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap3.3.5直接
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap-dialog直接
Mavenorg.openidentityplatform.commons.ui.libs:bootstrap-dialog1.34.4直接
Mavenorg.openidentityplatform.commons.ui.libs:dragula直接
Mavenorg.openidentityplatform.commons.ui.libs:dragula3.6.7直接
Mavenorg.openidentityplatform.commons.ui.libs:font-awesome直接
Mavenorg.openidentityplatform.commons.ui.libs:font-awesome4.5.0直接
Mavenorg.openidentityplatform.commons.ui.libs:form2js直接
Mavenorg.openidentityplatform.commons.ui.libs:form2js2.0-769718a直接
Mavenorg.openidentityplatform.commons.ui.libs:handlebars直接
Mavenorg.openidentityplatform.commons.ui.libs:handlebars4.7.7直接
Mavenorg.openidentityplatform.commons.ui.libs:i18next直接
Mavenorg.openidentityplatform.commons.ui.libs:i18next1.7.3直接
Mavenorg.openidentityplatform.commons.ui.libs:jquery直接
Mavenorg.openidentityplatform.commons.ui.libs:jquery3.7.1直接
Mavenorg.openidentityplatform.commons.ui.libs:jquery.ba-dotimeout直接
Mavenorg.openidentityplatform.commons.ui.libs:jquery.ba-dotimeout1.0直接
Mavenorg.openidentityplatform.commons.ui.libs:jquery.placeholder直接
Mavenorg.openidentityplatform.commons.ui.libs:jquery.placeholder2.0.8直接
Mavenorg.openidentityplatform.commons.ui.libs:js2form直接
Mavenorg.openidentityplatform.commons.ui.libs:js2form2.0-769718a直接
Mavenorg.openidentityplatform.commons.ui.libs:lodash直接
Mavenorg.openidentityplatform.commons.ui.libs:lodash3.10.1直接
Mavenorg.openidentityplatform.commons.ui.libs:moment直接
Mavenorg.openidentityplatform.commons.ui.libs:moment2.28.0直接
Mavenorg.openidentityplatform.commons.ui.libs:react15.2.1直接
Mavenorg.openidentityplatform.commons.ui.libs:react-dom15.2.1直接
Mavenorg.openidentityplatform.commons.ui.libs:requirejs直接
Mavenorg.openidentityplatform.commons.ui.libs:requirejs2.3.7直接
Mavenorg.openidentityplatform.commons.ui.libs:selectize直接
Mavenorg.openidentityplatform.commons.ui.libs:selectize0.12.1直接
Mavenorg.openidentityplatform.commons.ui.libs:sinon直接
Mavenorg.openidentityplatform.commons.ui.libs:sinon15.2.0直接
Mavenorg.openidentityplatform.commons.ui.libs:spin直接
Mavenorg.openidentityplatform.commons.ui.libs:spin2.0.1直接
Mavenorg.openidentityplatform.commons.ui.libs:xdate直接
Mavenorg.openidentityplatform.commons.ui.libs:xdate0.8直接
Mavenorg.openidentityplatform.commons.ui:commons3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons.ui:user3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:api-descriptor直接
Mavenorg.openidentityplatform.commons:api-descriptor3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:build-tools3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:cassandra-embedded3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:geo直接
Mavenorg.openidentityplatform.commons:geo3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:httpdump3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-fluent直接
Mavenorg.openidentityplatform.commons:json-fluent3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-patch3.0.2直接
Mavenorg.openidentityplatform.commons:json-patch3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource直接
Mavenorg.openidentityplatform.commons:json-resource21.0.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource-descriptor21.0.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource-descriptor3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource-examples21.0.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource-examples3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource-http直接
Mavenorg.openidentityplatform.commons:json-resource-http21.0.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-resource-http3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:json-web-token直接
Mavenorg.openidentityplatform.commons:json-web-token3.0.2直接
Mavenorg.openidentityplatform.commons:json-web-token3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:oauth2-module3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:oauth2-restlet3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:security直接
Mavenorg.openidentityplatform.commons:security3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:test-utils直接
Mavenorg.openidentityplatform.commons:test-utils3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform.commons:util直接
Mavenorg.openidentityplatform.commons:util3.2.0-SNAPSHOT直接
Mavenorg.openidentityplatform:build-tools直接
Mavenorg.slf4j:jcl-over-slf4j直接
Mavenorg.slf4j:jcl-over-slf4j1.7.25直接
Mavenorg.slf4j:jcl-over-slf4j2.0.17直接
Mavenorg.slf4j:jul-to-slf4j1.7.25直接
Mavenorg.slf4j:jul-to-slf4j2.0.17直接
Mavenorg.slf4j:log4j-over-slf4j2.0.17直接
Mavenorg.slf4j:slf4j-api直接
Mavenorg.slf4j:slf4j-api1.7.25直接
Mavenorg.slf4j:slf4j-api2.0.17直接
Mavenorg.slf4j:slf4j-jdk141.7.25直接
Mavenorg.slf4j:slf4j-jdk142.0.17直接
Mavenorg.slf4j:slf4j-nop直接
Mavenorg.slf4j:slf4j-nop1.7.25直接
Mavenorg.slf4j:slf4j-nop2.0.17直接
Mavenorg.slf4j:slf4j-simple直接
Mavenorg.slf4j:slf4j-simple1.7.25直接
Mavenorg.slf4j:slf4j-simple2.0.17直接
Mavenorg.testng:testng直接
Mavenorg.testng:testng6.0.1直接
Mavenorg.testng:testng6.14.3直接
Mavenorg.testng:testng6.8.8直接
Mavenorg.testng:testng6.9.8直接
Mavenorg.xerial.snappy:snappy-java1.1.10.5直接
Mavenargs4j:args4j2.0.16间接
Mavencom.fasterxml.jackson.core:jackson-annotations间接
Mavencom.fasterxml.jackson.core:jackson-annotations2.9.10间接
Mavencom.fasterxml.jackson.core:jackson-core间接
Mavencom.fasterxml.jackson.core:jackson-core2.9.10间接
Mavencom.fasterxml.jackson.core:jackson-databind间接
Mavencom.fasterxml.jackson.dataformat:jackson-dataformat-csv2.9.10间接
Mavencom.fasterxml.jackson.dataformat:jackson-dataformat-xml2.9.10间接
Mavencom.fasterxml.jackson.dataformat:jackson-dataformat-yaml间接
Mavencom.fasterxml.jackson.datatype:jackson-datatype-json-org2.9.10间接
Mavencom.fasterxml.jackson.module:jackson-module-afterburner2.9.10间接
Mavencom.fasterxml.jackson.module:jackson-module-jaxb-annotations2.9.10间接
Mavencom.fasterxml.jackson.module:jackson-module-jsonSchema间接
Mavencom.fasterxml.jackson.module:jackson-module-jsonSchema2.9.10间接
Mavencom.github.eirslett:frontend-maven-plugin间接
Mavencom.github.eirslett:frontend-maven-plugin1.15.0间接
Mavencom.googlecode.json-simple:json-simple1.1间接
Mavencom.googlecode.json-simple:json-simple1.1.1间接
Mavencom.h2database:h2间接
Mavencom.h2database:h21.4.188间接
Mavencom.jayway.restassured:rest-assured间接
Mavencom.jayway.restassured:rest-assured2.3.0间接
Mavencom.mycila:license-maven-plugin间接
Mavencom.mycila:license-maven-plugin2.6间接
Mavencom.xebialabs.restito:restito间接
Mavencom.xebialabs.restito:restito0.5.1间接
Mavencom.zaxxer:HikariCP间接
Mavencom.zaxxer:HikariCP2.4.1间接
Mavencommons-cli:commons-cli间接
Mavencommons-cli:commons-cli1.2间接
Mavencommons-logging:commons-logging1.2间接
Mavende.matrixweb.osgi.wrapped:osgi-wrapped-rhino1.7R4间接
Mavenjakarta.inject:jakarta.inject-api间接
Mavenjakarta.inject:jakarta.inject-api2.0.1间接
Mavenjakarta.jms:jakarta.jms-api3.0.0间接
Mavenjakarta.servlet:jakarta.servlet-api间接
Mavenjakarta.servlet:jakarta.servlet-api5.0.0间接
Mavenjavax.jms:javax.jms-api2.0.1间接
Mavenjavax.servlet:javax.servlet-api4.0.1间接
Mavenjoda-time:joda-time间接
Mavenjoda-time:joda-time2.1间接
Mavenjunit:junit间接
Mavenjunit:junit4.13.1间接
Mavenjunit:junit4.13.2间接
Mavennet.sf.supercsv:super-csv间接
Mavennet.sf.supercsv:super-csv2.4.0间接
Mavenorg.apache.felix:maven-bundle-plugin间接
Mavenorg.apache.felix:maven-bundle-plugin5.1.9间接
Mavenorg.apache.felix:maven-scr-plugin1.7.4间接
Mavenorg.apache.felix:org.apache.felix.configadmin1.9.26间接
Mavenorg.apache.felix:org.apache.felix.fileinstall3.6.4间接
Mavenorg.apache.felix:org.apache.felix.framework间接
Mavenorg.apache.felix:org.apache.felix.framework4.0.3间接
Mavenorg.apache.felix:org.apache.felix.metatype1.1.2间接
Mavenorg.apache.felix:org.apache.felix.scr2.1.20间接
Mavenorg.apache.felix:org.apache.felix.shell1.4.3间接
Mavenorg.apache.felix:org.apache.felix.webconsole5.0.18间接
Mavenorg.apache.felix:org.apache.felix.webconsole.plugins.ds2.1.0间接
Mavenorg.apache.maven.doxia:doxia-module-markdown1.4间接
Mavenorg.apache.maven.plugin-testing:maven-plugin-testing-harness3.3.0间接
Mavenorg.apache.maven.plugin-tools:maven-plugin-annotations3.3间接
Mavenorg.apache.maven.plugin-tools:maven-plugin-annotations3.6.0间接
Mavenorg.apache.maven.plugins:maven-antrun-plugin间接
Mavenorg.apache.maven.plugins:maven-antrun-plugin1.7间接
Mavenorg.apache.maven.plugins:maven-assembly-plugin间接
Mavenorg.apache.maven.plugins:maven-assembly-plugin3.1.0间接
Mavenorg.apache.maven.plugins:maven-changelog-plugin间接
Mavenorg.apache.maven.plugins:maven-checkstyle-plugin2.5间接
Mavenorg.apache.maven.plugins:maven-checkstyle-plugin3.0.0间接
Mavenorg.apache.maven.plugins:maven-clean-plugin间接
Mavenorg.apache.maven.plugins:maven-clean-plugin3.1.0间接
Mavenorg.apache.maven.plugins:maven-compiler-plugin3.13.0间接
Mavenorg.apache.maven.plugins:maven-dependency-plugin间接
Mavenorg.apache.maven.plugins:maven-dependency-plugin1.6.0间接
Mavenorg.apache.maven.plugins:maven-dependency-plugin2.10间接
Mavenorg.apache.maven.plugins:maven-dependency-plugin3.1.0间接
Mavenorg.apache.maven.plugins:maven-dependency-plugin3.2.0-SNAPSHOT间接
Mavenorg.apache.maven.plugins:maven-deploy-plugin间接
Mavenorg.apache.maven.plugins:maven-deploy-plugin3.0.0-M1间接
Mavenorg.apache.maven.plugins:maven-docck-plugin1.0间接
Mavenorg.apache.maven.plugins:maven-eclipse-plugin2.9间接
Mavenorg.apache.maven.plugins:maven-enforcer-plugin间接
Mavenorg.apache.maven.plugins:maven-enforcer-plugin3.0.0-M2间接
Mavenorg.apache.maven.plugins:maven-failsafe-plugin间接
Mavenorg.apache.maven.plugins:maven-failsafe-plugin3.0.0-M3间接
Mavenorg.apache.maven.plugins:maven-gpg-plugin间接
Mavenorg.apache.maven.plugins:maven-gpg-plugin1.4间接
Mavenorg.apache.maven.plugins:maven-gpg-plugin1.6间接
Mavenorg.apache.maven.plugins:maven-install-plugin间接
Mavenorg.apache.maven.plugins:maven-install-plugin2.3.1间接
Mavenorg.apache.maven.plugins:maven-install-plugin2253间接
Mavenorg.apache.maven.plugins:maven-install-plugin3.0.0-M1间接
Mavenorg.apache.maven.plugins:maven-invoker-plugin间接
Mavenorg.apache.maven.plugins:maven-invoker-plugin1.7间接
Mavenorg.apache.maven.plugins:maven-jar-plugin间接
Mavenorg.apache.maven.plugins:maven-jar-plugin3.0.2间接
Mavenorg.apache.maven.plugins:maven-jarsigner-plugin1.2间接
Mavenorg.apache.maven.plugins:maven-javadoc-plugin间接
Mavenorg.apache.maven.plugins:maven-javadoc-plugin2.9间接
Mavenorg.apache.maven.plugins:maven-javadoc-plugin3.12.0间接
Mavenorg.apache.maven.plugins:maven-jxr-plugin2.2间接
Mavenorg.apache.maven.plugins:maven-jxr-plugin2.3间接
Mavenorg.apache.maven.plugins:maven-plugin-plugin2.4.3间接
Mavenorg.apache.maven.plugins:maven-plugin-plugin3.6.0间接
Mavenorg.apache.maven.plugins:maven-pmd-plugin2.4间接
Mavenorg.apache.maven.plugins:maven-pmd-plugin3.4间接
Mavenorg.apache.maven.plugins:maven-project-info-reports-plugin间接
Mavenorg.apache.maven.plugins:maven-project-info-reports-plugin2.4间接
Mavenorg.apache.maven.plugins:maven-project-info-reports-plugin2.6间接
Mavenorg.apache.maven.plugins:maven-project-info-reports-plugin2.7间接
Mavenorg.apache.maven.plugins:maven-release-plugin间接
Mavenorg.apache.maven.plugins:maven-release-plugin3.0.0-M7间接
Mavenorg.apache.maven.plugins:maven-remote-resources-plugin1.5间接
Mavenorg.apache.maven.plugins:maven-resources-plugin3.0.2间接
Mavenorg.apache.maven.plugins:maven-scm-plugin1.9.5间接
Mavenorg.apache.maven.plugins:maven-shade-plugin间接
Mavenorg.apache.maven.plugins:maven-shade-plugin1.5间接
Mavenorg.apache.maven.plugins:maven-shade-plugin2.3间接
Mavenorg.apache.maven.plugins:maven-shade-plugin3.6.0间接
Mavenorg.apache.maven.plugins:maven-site-plugin1.4间接
Mavenorg.apache.maven.plugins:maven-site-plugin3.3间接
Mavenorg.apache.maven.plugins:maven-source-plugin间接
Mavenorg.apache.maven.plugins:maven-source-plugin3.0.1间接
Mavenorg.apache.maven.plugins:maven-surefire-plugin间接
Mavenorg.apache.maven.plugins:maven-surefire-plugin3.1.2间接
Mavenorg.apache.maven.plugins:maven-war-plugin间接
Mavenorg.apache.maven.plugins:maven-war-plugin3.2.2间接
Mavenorg.apache.maven.wagon:wagon-provider-api3.4.3间接
Mavenorg.apache.maven:maven-compat3.8.1间接
Mavenorg.apache.maven:maven-core3.8.1间接
Mavenorg.apache.maven:maven-model3.8.1间接
Mavenorg.apache.maven:maven-plugin-api2.0间接
Mavenorg.apache.maven:maven-plugin-api3.0.5间接
Mavenorg.apache.maven:maven-plugin-api3.5.4间接
Mavenorg.apache.maven:maven-plugin-api3.8.1间接
Mavenorg.apache.maven:maven-project2.2.1间接
Mavenorg.apache.maven:maven-settings2.2.1间接
Mavenorg.apache.servicemix.bundles:org.apache.servicemix.bundles.javax-inject间接
Mavenorg.apache.servicemix.bundles:org.apache.servicemix.bundles.rhino1.7R4_1间接
Mavenorg.codehaus.cargo:cargo-maven3-plugin间接
Mavenorg.codehaus.cargo:cargo-maven3-plugin1.10.20间接
Mavenorg.codehaus.gmaven:gmaven-plugin1.5间接
Mavenorg.codehaus.mojo:build-helper-maven-plugin间接
Mavenorg.codehaus.mojo:build-helper-maven-plugin1.10间接
Mavenorg.codehaus.mojo:build-helper-maven-plugin1.8间接
Mavenorg.codehaus.mojo:cobertura-maven-plugin间接
Mavenorg.codehaus.mojo:cobertura-maven-plugin2.7间接
Mavenorg.codehaus.mojo:findbugs-maven-plugin2.3间接
Mavenorg.codehaus.mojo:findbugs-maven-plugin3.0.1间接
Mavenorg.codehaus.mojo:jslint-maven-plugin1.0.1间接
Mavenorg.codehaus.mojo:license-maven-plugin1.16间接
Mavenorg.codehaus.mojo:rmic-maven-plugin1.0间接
Mavenorg.codehaus.mojo:rmic-maven-plugin1.3间接
Mavenorg.codehaus.plexus:plexus-archiver4.8.0间接
Mavenorg.codehaus.plexus:plexus-digest1.0间接
Mavenorg.codehaus.plexus:plexus-maven-plugin1.3.8间接
Mavenorg.codehaus.plexus:plexus-utils4.0.3间接
Mavenorg.codehaus.plexus:plexus-xml3.0.1间接
Mavenorg.easytesting:fest-assert1.4间接
Mavenorg.eclipse.jetty:jetty-maven-plugin9.2.1.v20140609间接
Mavenorg.eclipse.jetty:jetty-maven-plugin9.2.13.v20150730间接
Mavenorg.eclipse.m2e:lifecycle-mapping1.0.0间接
Mavenorg.eclipse.wst.jsdt.debug:rhino.debugger1.0.600.v201604292217间接
Mavenorg.eclipse.wst.jsdt.debug:transport1.0.300.v201502261613间接
Mavenorg.freemarker:freemarker2.3.22间接
Mavenorg.glassfish.corba:rmic4.2.0-b007间接
Mavenorg.glassfish:javax.security.auth.message间接
Mavenorg.glassfish:javax.security.auth.message3.1间接
Mavenorg.hamcrest:hamcrest-core1.3间接
Mavenorg.mcraig:jcite1.13.0间接
Mavenorg.mockito:mockito-all1.10.19间接
Mavenorg.mockito:mockito-core间接
Mavenorg.mockito:mockito-core2.23.4间接
Mavenorg.openidentityplatform.commons.auth-filters.authz-filter.modules:oauth2-module3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons.http-framework.examples:http-descriptor-example3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons.http-framework:binding-test-utils间接
Mavenorg.openidentityplatform.commons.http-framework:binding-test-utils3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons.i18n-framework:maven-plugin3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons.selfservice:custom-stage3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons.selfservice:example-ui3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons.ui.libs:CodeMirror4.10间接
Mavenorg.openidentityplatform.commons.ui.libs:less1.5.1间接
Mavenorg.openidentityplatform.commons.ui.libs:qunit间接
Mavenorg.openidentityplatform.commons.ui.libs:qunit2.20.1间接
Mavenorg.openidentityplatform.commons.ui.libs:titatoggle1.2.6间接
Mavenorg.openidentityplatform.commons:authz-framework3.1.5间接
Mavenorg.openidentityplatform.commons:authz-framework-api3.1.5间接
Mavenorg.openidentityplatform.commons:doc-maven-plugin3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons:forgerock-audit-core间接
Mavenorg.openidentityplatform.commons:forgerock-audit-core4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-csv间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-csv4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-elasticsearch间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-elasticsearch4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-jdbc间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-jdbc4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-jms间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-jms4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-json4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-splunk4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-syslog间接
Mavenorg.openidentityplatform.commons:forgerock-audit-handler-syslog4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-audit-json间接
Mavenorg.openidentityplatform.commons:forgerock-audit-json4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-authz-oauth2-module3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-authz-oauth2-restlet3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-bloomfilter-core间接
Mavenorg.openidentityplatform.commons:forgerock-bom4.1.1间接
Mavenorg.openidentityplatform.commons:forgerock-jaspi-iwa-module3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-jaspi-jwt-session-module3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-jaspi-openam-session-module3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-jaspi-openid-connect-module3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-jaspi-runtime3.1.5间接
Mavenorg.openidentityplatform.commons:forgerock-selfservice-core1.0.3间接
Mavenorg.openidentityplatform.commons:forgerock-selfservice-json1.0.3间接
Mavenorg.openidentityplatform.commons:forgerock-selfservice-stages1.0.3间接
Mavenorg.openidentityplatform.commons:forgerock-test-utils间接
Mavenorg.openidentityplatform.commons:forgerock-test-utils21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons:forgerock-util间接
Mavenorg.openidentityplatform.commons:forgerock-util21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons:json-crypto-cli3.0.2间接
Mavenorg.openidentityplatform.commons:json-crypto-core3.0.2间接
Mavenorg.openidentityplatform.commons:json-ref-core3.0.2间接
Mavenorg.openidentityplatform.commons:json-ref-jackson3.0.2间接
Mavenorg.openidentityplatform.commons:json-schema-cli3.0.2间接
Mavenorg.openidentityplatform.commons:json-schema-core3.0.2间接
Mavenorg.openidentityplatform.commons:maven-external-dependency-plugin1.0.0间接
Mavenorg.openidentityplatform.commons:maven-external-dependency-plugin1.5.1间接
Mavenorg.openidentityplatform.commons:maven-external-dependency-plugin3.0.5-SNAPSHOT间接
Mavenorg.openidentityplatform.commons:maven-external-dependency-plugin3.2.0-SNAPSHOT间接
Mavenorg.openidentityplatform.commons:script-common间接
Mavenorg.openidentityplatform.http:chf-client-apache-async间接
Mavenorg.openidentityplatform.http:chf-client-apache-async21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.http:chf-client-apache-common21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.http:chf-client-apache-sync21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.http:chf-http-core间接
Mavenorg.openidentityplatform.http:chf-http-core21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.http:chf-http-servlet间接
Mavenorg.openidentityplatform.http:chf-http-servlet21.0.0-SNAPSHOT间接
Mavenorg.openidentityplatform.maven.plugins:javadoc-updater-maven-plugin间接
Mavenorg.openidentityplatform.maven.plugins:javadoc-updater-maven-plugin1.0.0间接
Mavenorg.ops4j.base:ops4j-base-spi1.4.0间接
Mavenorg.ops4j.pax.swissbox:pax-swissbox-extender1.6.0间接
Mavenorg.ops4j.pax.web:pax-web-jetty-bundle1.1.10间接
Mavenorg.osgi:org.osgi.core间接
Mavenorg.osgi:org.osgi.core4.3.1间接
Mavenorg.osgi:org.osgi.core6.0.0间接
Mavenorg.ow2.asm:asm7.3.1间接
Mavenorg.slf4j:osgi-over-slf4j间接
Mavenorg.slf4j:slf4j-jcl间接
Mavenorg.sonatype.central:central-publishing-maven-plugin0.8.0间接
Mavenorg.twdata.maven:mojo-executor2.2.0间接
Mavenorg.zeroturnaround:jrebel-maven-plugin1.1.3间接
npmes5-ext0.10.53间接
npmeslint4.18.2间接
npmeslint-formatter-warning-summary^1.0.1间接
npmgrunt1.5.3间接
npmgrunt1.6.2间接
npmgrunt-cli1.4.3间接
npmgrunt-contrib-less1.4.0间接
npmgrunt-contrib-qunit10.1.1间接
npmgrunt-contrib-requirejs1.0.0间接
npmgrunt-contrib-watch1.0.1间接
npmgrunt-contrib-watch1.1.0间接
npmgrunt-eslint17.3.1间接
npmgrunt-eslint19.0.0间接
npmgrunt-notify0.4.5间接
npmgrunt-sync0.8.2间接
npmjsdoc3.5.5间接
npmless-plugin-clean-css1.5.1间接
npmrimraf2.5.3间接
依赖安全公告 1

安装 maven:org.openidentityplatform.commons:build-tools@3.1.2 会引入 3 个包(直接与传递):其中 1 个存在已知公告,1 个为直接依赖。

软件包版本关系严重程度公告数修复版本
org.testng:testng6.14.3直接17.7.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 111272,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "CQL": 224,
        "CSS": 59882,
        "HTML": 82334,
        "Java": 13722338,
        "Less": 79742,
        "Roff": 9,
        "Ruby": 377,
        "XSLT": 456521,
        "Shell": 14440,
        "Groovy": 4445,
        "Python": 13624,
        "Batchfile": 3460,
        "FreeMarker": 4795,
        "JavaScript": 558017
      },
      "pushed_at": "2026-07-24T11:45:31Z",
      "created_at": "2017-09-20T09:49:12Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T11:46:09Z",
      "description": "Parent POM for projects. Provides default project build configuration.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "master",
      "license_spdx_raw": "NOASSERTION",
      "primary_language": "Java",
      "significant_languages": [
        "Java"
      ]
    },
    "owner": {
      "blog": "https://www.openidentityplatform.org/",
      "name": "Open Identity Platform",
      "type": "Organization",
      "login": "OpenIdentityPlatform",
      "company": null,
      "location": null,
      "followers": 288,
      "avatar_url": "https://avatars.githubusercontent.com/u/30845478?v=4",
      "created_at": "2017-08-08T20:50:31Z",
      "is_verified": null,
      "public_repos": 36,
      "account_age_days": 3272
    },
    "license": {
      "state": "custom",
      "spdx_id": null,
      "raw_spdx": "NOASSERTION",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "3.1.2",
          "kind": "patch",
          "published_at": "2026-07-16T15:41:26Z"
        },
        {
          "tag": "3.1.1",
          "kind": "patch",
          "published_at": "2026-06-11T10:54:29Z"
        },
        {
          "tag": "3.1.0",
          "kind": "minor",
          "published_at": "2026-04-14T09:09:49Z"
        },
        {
          "tag": "3.0.4",
          "kind": "patch",
          "published_at": "2026-03-22T17:49:12Z"
        },
        {
          "tag": "3.0.3",
          "kind": "patch",
          "published_at": "2026-03-09T11:12:22Z"
        },
        {
          "tag": "3.0.2",
          "kind": "patch",
          "published_at": "2025-12-11T08:59:57Z"
        },
        {
          "tag": "3.0.1",
          "kind": "patch",
          "published_at": "2025-11-06T14:13:00Z"
        },
        {
          "tag": "2.4.1",
          "kind": "patch",
          "published_at": "2025-09-04T08:43:32Z"
        },
        {
          "tag": "2.4.0",
          "kind": "minor",
          "published_at": "2025-07-15T10:35:02Z"
        },
        {
          "tag": "2.3.0",
          "kind": "minor",
          "published_at": "2025-06-19T12:57:44Z"
        },
        {
          "tag": "2.2.4",
          "kind": "patch",
          "published_at": "2025-03-17T11:22:32Z"
        },
        {
          "tag": "2.2.3",
          "kind": "patch",
          "published_at": "2024-11-08T10:07:54Z"
        },
        {
          "tag": "2.2.2",
          "kind": "patch",
          "published_at": "2024-10-01T14:57:31Z"
        },
        {
          "tag": "2.2.1",
          "kind": "patch",
          "published_at": "2024-09-19T08:12:25Z"
        },
        {
          "tag": "2.2.0",
          "kind": "minor",
          "published_at": "2024-09-09T08:46:17Z"
        },
        {
          "tag": "2.1.6",
          "kind": "patch",
          "published_at": "2024-08-07T12:08:36Z"
        },
        {
          "tag": "2.1.5",
          "kind": "patch",
          "published_at": "2024-07-22T13:43:39Z"
        },
        {
          "tag": "2.1.4",
          "kind": "patch",
          "published_at": "2024-06-20T09:47:31Z"
        },
        {
          "tag": "2.1.3",
          "kind": "patch",
          "published_at": "2024-05-06T07:56:41Z"
        },
        {
          "tag": "2.1.2",
          "kind": "patch",
          "published_at": "2024-01-16T13:44:48Z"
        },
        {
          "tag": "2.1.1",
          "kind": "patch",
          "published_at": "2023-10-23T15:56:38Z"
        },
        {
          "tag": "2.0.18",
          "kind": "patch",
          "published_at": "2023-07-20T07:04:50Z"
        },
        {
          "tag": "2.0.17",
          "kind": "patch",
          "published_at": "2022-11-29T08:51:50Z"
        },
        {
          "tag": "2.0.16",
          "kind": "patch",
          "published_at": "2022-08-02T08:00:04Z"
        },
        {
          "tag": "2.0.15",
          "kind": "patch",
          "published_at": "2022-05-31T21:01:05Z"
        },
        {
          "tag": "2.0.14",
          "kind": "patch",
          "published_at": "2022-04-19T12:14:38Z"
        },
        {
          "tag": "2.0.13",
          "kind": "patch",
          "published_at": "2022-04-08T10:08:10Z"
        },
        {
          "tag": "2.0.12",
          "kind": "patch",
          "published_at": "2021-10-04T13:24:16Z"
        },
        {
          "tag": "2.0.11",
          "kind": "patch",
          "published_at": "2021-10-04T13:24:50Z"
        },
        {
          "tag": "2.0.10",
          "kind": "patch",
          "published_at": "2021-10-04T13:25:04Z"
        },
        {
          "tag": "2.0.9",
          "kind": "patch",
          "published_at": "2021-10-04T13:25:15Z"
        },
        {
          "tag": "2.0.8",
          "kind": "patch",
          "published_at": "2021-10-04T13:25:52Z"
        },
        {
          "tag": "2.0.7",
          "kind": "patch",
          "published_at": "2021-10-04T13:26:07Z"
        },
        {
          "tag": "1.2.11",
          "kind": "patch",
          "published_at": "2021-02-08T15:25:10Z"
        },
        {
          "tag": "2.0.6",
          "kind": "patch",
          "published_at": "2021-10-04T13:27:01Z"
        },
        {
          "tag": "2.0.5",
          "kind": "patch",
          "published_at": "2021-10-04T13:27:24Z"
        },
        {
          "tag": "2.0.4",
          "kind": "patch",
          "published_at": "2021-10-04T13:27:34Z"
        },
        {
          "tag": "2.0.3",
          "kind": "patch",
          "published_at": "2021-10-04T13:27:44Z"
        },
        {
          "tag": "2.0.2",
          "kind": "patch",
          "published_at": "2021-10-04T13:27:55Z"
        },
        {
          "tag": "2.0.1",
          "kind": "patch",
          "published_at": "2021-10-04T13:28:07Z"
        },
        {
          "tag": "2.0.0",
          "kind": "major",
          "published_at": "2021-10-04T13:28:17Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "6e401980df01af4385e9c3ed4b68857521fdb534",
          "body": "…lose() (#305)\n\nA transaction commit racing Persistit.close() could reach\nJournalManager.waitForDurability after close() cleared the\nJOURNAL_FLUSHER reference and fail with a raw IllegalStateException,\nbypassing callers' closed-state handling (seen as a\nTransactionTest2.transactionsConcurrentWithPer\n[…]\ne that can never be confirmed.\n\nNew JournalManagerTest cases cover both windows; without the fix the\nfirst fails with the IllegalStateException and the second hangs past\nits join deadline.\n\nFixes #304",
          "is_bot": false,
          "headline": "[#304] Throw PersistitClosedException when a commit races Persistit.c…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-24T11:45:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d639f4c81b6312961c5d48240bd6319bd5070ba",
          "body": "…#303)\n\nResolve both java/chained-type-tests alerts in Converter:\n- wrap(Parameter, Request, Scriptable): dispatch via Request.accept(\n  RequestVisitor) instead of an instanceof chain over the Request subtypes\n- wrap(Parameter, Object, Scriptable, boolean): dispatch via an ordered\n  Class -> strategy registry, iterated in the same precedence as the\n  previous if/else-if chain\n\nBehaviour is unchanged; the javascript module tests pass.",
          "is_bot": false,
          "headline": "Refactor Converter type dispatch to remove chained instanceof tests (…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-24T08:19:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5186067806ea3334dd7a18c816f66e5a85317dc",
          "body": "* Clean up low-severity CodeQL code-quality alerts\n\nResolve 17 CodeQL note-level alerts across 15 files:\n- inefficient-empty-string-test: use String.isEmpty() instead of \"\"-equality (8)\n- inefficient-string-constructor: drop redundant new String(...) wrappers (2)\n- inefficient-key-set-iterator: iter\n[…]\nf the object's default toString() in CrestApiProducer\n- py/unused-import (1): drop the unused `import sys, os` in the persistit\n  doc conf.py\n\nBehaviour is unchanged; all touched Java modules compile.",
          "is_bot": false,
          "headline": "Clean up low-severity CodeQL code-quality alerts (#302)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-24T05:19:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "458c89eec56acb9da2af1b226939f0878cde09fd",
          "body": "… (#301)\n\nBufferPool.get() honored its timeout budget only when claiming a buffer\nthat already held the wanted page. On a pool miss, allocBuffer() gave up\nafter a single clock sweep of 2 x bufferCount ticks and threw a raw\nIllegalStateException(\"No available Buffers\"), so concurrent sweepers\nracing \n[…]\nfaced by TransactionTest2.transactionsWithInterrupts on a\nwindows-latest CI cell where a worker died with \"No available Buffers\"\nduring the interrupt storm against the 20-buffer test pool.\n\nFixes #300",
          "is_bot": false,
          "headline": "[#300] Make BufferPool.get honor its timeout when allocating a buffer…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-23T18:36:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a65eeefa0eea78c9688bee8805cabaf5492b74d3",
          "body": "Resolve 17 CodeQL note-level alerts across 15 files:\n- inefficient-empty-string-test: use String.isEmpty() instead of \"\"-equality (8)\n- inefficient-string-constructor: drop redundant new String(...) wrappers (2)\n- inefficient-key-set-iterator: iterate entrySet() instead of keySet()+get() (2)\n- useless-tostring-call: remove toString() on values already String (2)\n- local-variable-is-never-read: remove dead local assignments (3)\n\nBehaviour is unchanged; all touched modules compile.",
          "is_bot": false,
          "headline": "Clean up low-severity CodeQL code-quality alerts (#299)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-23T17:43:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e3ab7f3de8c26ade2cabb2f33d6f594da429833",
          "body": "* Resolve open CodeQL alerts in the persistit module\n\nClears the open code-scanning alerts (1 high, 2 warnings, 8 notes) in the\npersistit module. The high java/improper-validation-of-array-index finding\nwas a false positive - the original bounds check was already correct - so\nthis is a static-analys\n[…]\n true\n(java/constant-comparison). Restore the plain \"reserve = null;\".\n\nThe remaining array-index (Exchange) and never-read (BufferPool) findings\nare false positives, to be dismissed in code scanning.",
          "is_bot": false,
          "headline": "Resolve open CodeQL alerts in the persistit module (#295)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-23T13:30:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b19d0ab159b9b760c94532271c71aba71dc48580",
          "body": "Resolve five CodeQL js/ alerts in first-party UI code (no behavior change):\n\n- ViewManager.js: drop redundant 'cDialog !== null' next to the truthiness\n  check (js/comparison-between-incompatible-types).\n- LoginTemplate.html: remove the duplicated type=\"checkbox\" attribute on the\n  loginRemember inp\n[…]\nUrl regex character class\n  (js/regex/duplicate-in-character-class).\n- UserProfileKBATab.js: simplify the always-true inner 'isKbaQuestion' term\n  in the KBA validation guard (js/trivial-conditional).",
          "is_bot": false,
          "headline": "Clean up CodeQL js/ warnings in commons UI (#298)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-23T07:08:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "817f5edb6005cf0ae525e2bd93ce5ff56cf0267b",
          "body": "Drop the vendored Swagger UI 2.1.4 WAR overlay and its only consumer\nwiring in json-resource-examples. The stale third-party JS in the\noverlay was the source of most open CodeQL code-scanning alerts,\nincluding the sole error-level one (js/invalid-prototype-value).",
          "is_bot": false,
          "headline": "Remove the openapi-war-overlay module (#296)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-23T05:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e54dcaac642b8e252a96d1dd10656ad798199388",
          "body": "checkForInterleavedBetweenClasses wrapped a single ITestNGMethod.getInstance()\nvalue into a one-element array and then tested testInstances.length != 1, a\ncondition that is always false (dead branch flagged by CodeQL\njava/constant-comparison). Use the single test instance directly and drop the\nuseless array allocation and comparison.",
          "is_bot": false,
          "headline": "Remove always-false array-length check in ForgeRockTestListener (#297)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-23T05:23:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39ddc41758ce0641369cdc65abb0f987d0836523",
          "body": "* Report leftover MVV mark bits in IntegrityCheck\n\nA prune interrupted before the issue #286 fix could leave 0x8000 mark\nbits behind in on-disk version length fields. Since PR #288 the read\npaths strip the mark bit silently, so such versions read normally and\nicheck reported affected volumes as clea\n[…]\ned from the\nlist and the arithmetic still converges, so -P cleared the\nTransactionIndex despite real corruption. Count every fault found -\nrecorded in the list or not - and gate on the counts instead.",
          "is_bot": false,
          "headline": "[#290] Report leftover MVV mark bits in IntegrityCheck (#291)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-22T13:31:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19c9d70993846c185003bdca3a52d54cd55d469a",
          "body": "* Clear stale MVV mark bits before pruning\n\nMVV.prune uses the 0x8000 mark bit in the version length field as\ntransient private state and assumes no version is marked on entry. A\nvolume corrupted by a prune interrupted before the #288 fix violates\nthat assumption: a leftover mark on an obsolete vers\n[…]\nuld\nreject it. Hoist the verify() call that already runs on every prune\nand sweep only well-formed regions; a malformed region is left to the\nfirst pass's guard, which throws without writing anything.",
          "is_bot": false,
          "headline": "[#292] Clear stale MVV mark bits before pruning (#293)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-22T11:07:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fff316f1d0e6198985db66097e61d3d6dd6fbc07",
          "body": "MVV.prune's finally-block safety net used the wrong loop bound\n(index < length instead of index < offset + length), so a prune that\nexited via an exception - e.g. PersistitInterruptedException while\nresolving a commit status under interrupt - left mark bits set in the\nlive buffer page whenever the M\n[…]\nrupted-prune unmark safety net; make\n  transactionsWithInterrupts assert no worker died with an unexpected\n  exception, reporting the first failure, with shared counters reset\n  in @Before\n\nFixes #286",
          "is_bot": false,
          "headline": "Fix MVV marked-version corruption after interrupted prune (#288)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-22T06:19:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f4cf7b691cd3acfe4caf88e0c278470e7ede0e3f",
          "body": "* Guard query-param parsing against prototype pollution\n\noauthReturn.html and mockOAuthAuthorization.html built a queryParams\nobject by writing map[name] = value for every URL parameter, where the\nname is user-controlled. A parameter named __proto__ (or constructor /\nprototype) could therefore pollu\n[…]\nrotocol/host\nconcatenation and reads clearer. Also document that any query or\nfragment on the incoming redirect_uri is dropped deliberately - the\ncaller appends its own ?code=...&state=... parameters.",
          "is_bot": false,
          "headline": "Guard OAuth return pages against prototype pollution (#281)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-22T06:18:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27487bc6f50de13dacc3c982315359617ba0937b",
          "body": "* Use AES/GCM instead of AES/CBC for json-crypto session encryption\n\nCodeQL java/weak-cryptographic-algorithm flagged the hardcoded\nAES/CBC/PKCS5Padding session cipher in SimpleEncryptor.asymmetric() as\nvulnerable to padding-oracle attacks. Switch it to authenticated\nAES/GCM/NoPadding: a fresh sessi\n[…]\nfixtures with a fixed key so legacy\n  decryption is enforced by CI, not just same-build roundtrips\n- Document the NIST SP 800-38D 2^32-invocations bound for GCM under\n  long-lived caller-supplied keys",
          "is_bot": false,
          "headline": "Use AES/GCM instead of AES/CBC for json-crypto session encryption (#277)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T11:14:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0375f902886961bbb174f96d1b72caeff7c29a02",
          "body": "* Escape all quotes in UI helpers (CodeQL incomplete-sanitization)\n\nTwo String.replace() calls passed a plain-string first argument, so only\nthe first matching quote was escaped:\n\n- UIUtils.js staticSelect: replace(\"'\", ...) escaped only the first\n  single quote in a value spliced into a jQuery attr\n[…]\nquote\nlive. Double backslashes first, then escape quotes, in the staticSelect\nHandlebars helper and the anonymous-process filter builder.\n\n* Fix eslint max-len violation in UIUtils staticSelect helper",
          "is_bot": false,
          "headline": "Escape all quotes in UI helpers (CodeQL incomplete-sanitization) (#280)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T09:51:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "168426923918fe3587d523d869219d2f0b7937bd",
          "body": "… task in SecureCsvWriter (#289)\n\nThe signature task guarded itself with ReentrantLock.isLocked(), a\ncheck-then-act on a method documented for monitoring only. When the\nsignature timer fired while close() (or a concurrent writeEvent()) held\nsignatureLock, the task silently skipped writing, while clo\n[…]\norkaround (489875550) whose debug traces are also\nremoved. shouldGenerateHMACColumn now uses a signature interval that\ncannot fire mid-test, making its expected file content deterministic.\n\nFixes #287",
          "is_bot": false,
          "headline": "Fix lost final signature race between close() and scheduled signature…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T09:50:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9111bb7287f483f9207a49a3dda4630bdef2ddc8",
          "body": "…all) (#285)\n\n* Replace deprecated method/constructor calls (CodeQL java/deprecated-call)\n\nMigrate 77 java/deprecated-call code scanning alerts to the recommended\nnon-deprecated APIs:\n\n- Class.newInstance() -> getDeclaredConstructor().newInstance()\n- ResourceException.getException -> newResourceExce\n[…]\nnce Jackson 2.12; call the 7-arg one with strictTypeIdHandling=true,\n  matching the deprecated constructor's delegation, so behavior is\n  unchanged (resolves the remaining java/deprecated-call alert).",
          "is_bot": false,
          "headline": "Replace deprecated method/constructor calls (CodeQL java/deprecated-c…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T08:19:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f4716c240589636b346b73478d532bffb82ef97",
          "body": "- Add minimal top-level GITHUB_TOKEN permissions to fix\n  actions/missing-workflow-permissions: contents:read for build and\n  deploy, contents:write for release (needed for release:prepare git\n  push and GitHub Release creation).\n- Pin softprops/action-gh-release to commit SHA (v3.0.2) to fix\n  actions/unpinned-tag.",
          "is_bot": false,
          "headline": "Harden GitHub Actions workflows (CodeQL medium alerts) (#283)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T08:18:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "281b89dc233cad961e7b4a6ed7c05dca9ebfef82",
          "body": "namePattern is built from a string via new RegExp(\"...\"), so the string\nparser consumed the backslashes before the regex ever saw them: \"\\-\"\nbecame \"-\" and \"\\s\" became \"s\" (CodeQL js/useless-regexp-character-escape).\n\nAs a side effect the trailing \"-\" formed a reversed range with the\npreceding U+00F\n[…]\ner in character class\". Escape the whitespace class as\n\"\\\\s\" and move the literal hyphen to the end of the character class. The\nexpression now compiles and matches names containing spaces and hyphens.",
          "is_bot": false,
          "headline": "Fix useless regex escapes in ValidatorsUtils namePattern (#282)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T08:18:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16e701a6eac5d72be1abb76f8a2d2114df86f784",
          "body": "Hoist the write lock into a local variable so lock() and unlock() act\non the same Lock reference instead of two separate writeLock() calls,\nresolving CodeQL java/unreleased-lock.",
          "is_bot": false,
          "headline": "Fix potential unreleased lock in ScriptRegistryImpl.addSourceUnit (#284)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T08:17:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01d05f02b13520a392677a2e864c33f5c92b9cff",
          "body": "Fix all high-severity CodeQL findings in the docbook branding stylesheet:\n\n- js/insecure-download: three $.getScript() calls fetched executable\n  JavaScript from cdnjs.cloudflare.com over plain HTTP (man-in-the-middle\n  tampering). Switch them to HTTPS; cdnjs serves the same paths over TLS.\n- js/xss\n[…]\nlly.\n\nVerified with Node: the file parses, HTML metacharacters are escaped, the\nexample strings are still wrapped in their styled spans, and the escaped\nhost pattern no longer matches unrelated hosts.",
          "is_bot": false,
          "headline": "Harden docbook branding scripts.js (CodeQL high alerts) (#279)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T08:17:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dc5709d0e375fa9c07d16815f73a191db0979a26",
          "body": "Backport targeted security fixes into the vendored Swagger UI copy of\nmarked (openapi-war-overlay), closing three CodeQL high alerts without a\nrisky full library upgrade:\n\n- js/redos: the inline `em` grammar used [\\s\\S] alongside the __ / **\n  literals, so a run of those markers could be partitioned\n[…]\nscript payloads.\n\nVerified with Node: em/strong/link rendering is unchanged, the\npreviously catastrophic inputs finish in under 0.1 ms, and the dangerous\nschemes are blocked while http: still renders.",
          "is_bot": false,
          "headline": "Fix ReDoS and URL-scheme bypass in bundled marked.js (#278)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-21T08:16:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f5e38085bd57d301603d8288e3c7b88e3a51506",
          "body": "* Drop the stale animal-sniffer Java 1.7 API check from persistit\n\nThe persistit modules pinned animal-sniffer to the signature\norg.codehaus.mojo.signature:java17:1.0 — the Java 1.7 API surface —\ninherited from the upstream Akiban Persistit build. The project compiles\nat maven.compiler.release=11, s\n[…]\nis no upstream owner to preserve.\n\nUse the CDDL block of the root pom, which is their parent, with a\nstandalone 3A Systems copyright covering 2020 (when the files were\nadded) through the current year.",
          "is_bot": false,
          "headline": "Drop the stale animal-sniffer Java 1.7 API check from persistit (#276)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-17T10:07:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f8c98909ae8e2fd6d6faebc80a203d1632db84e",
          "body": "…class) (#249)\n\nAdd static to 12 member nested classes that never reference their\nenclosing instance, across 10 files, dropping the implicit outer-this\nreference. Behavior-preserving and self-checked by compilation: adding\nstatic to a nested class that actually used the enclosing instance would\nfail to compile. Verified by compiling every affected Maven module\n(commons audit, http-framework, util, httpdump, doc-maven-plugin, and\npersistit core/ui).",
          "is_bot": false,
          "headline": "Make non-static nested classes static (CodeQL java/non-static-nested-…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:32:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cca1422d7cd269932099a18970d60628e2f77bfa",
          "body": "…r-read) (#248)\n\nResolve 16 of the 18 alerts by removing local variables that are\nassigned but never read, across 12 files. Side effects are preserved:\nin IntegrityCheck both the shadowing _totalPages accumulator and its\nupdate are dropped (pure getter, result unused); the AdminUI and\nInspectorPanel\n[…]\nTableModel's minWidth\n(its assignment consumes a StringTokenizer token a later read depends\non). Verified by compiling every affected Maven module plus javac for\nthe persistit doc and example sources.",
          "is_bot": false,
          "headline": "Remove never-read local variables (CodeQL java/local-variable-is-neve…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:31:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "138bd7a5a1a433ec691a686eb545cb81bf17b9ab",
          "body": "…cient-boxed-constructor) (#247)\n\nReplace 17 uses of the deprecated boxed-primitive constructors\n(new Long/Integer/Short/Byte/Character/Float/Double(...)) with the\ncorresponding X.valueOf(...) factory methods across 6 files. valueOf\navoids an unnecessary allocation and may reuse cached instances; th\n[…]\nnge is behavior-preserving (equal values, same equals/hashCode).\nVerified by compiling persistit/core, persistit/ui and the jaspi\njwt-session-module, plus javac for the persistit FindFile Ant example.",
          "is_bot": false,
          "headline": "Replace boxed-primitive constructors with valueOf (CodeQL java/ineffi…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:23:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e51627447584993b5a805b2e13ac3adee4a4af6c",
          "body": "…ation) (#246)\n\nAnnotate 308 methods that override a superclass method or implement an\ninterface method but were missing @Override, across 97 files in 9 modules.\nAnnotation-only and behavior-preserving; verified by compiling every\naffected Maven module (plus javac for the two persistit Ant examples).",
          "is_bot": false,
          "headline": "Add missing @Override annotations (CodeQL java/missing-override-annot…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:23:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0c34652338c9bcc5e8a335e26abba96f3d9d18b",
          "body": "…non-short-circuit-evaluation) (#245)\n\nThe anti-value guard combined removeOnlyAntiValue with the isKeyRangeAntiValue\ncheck using the non-short-circuit & operator, so isKeyRangeAntiValue was always\nevaluated even when removeOnlyAntiValue was false. isKeyRangeAntiValue only reads\nbuffer state and has no side effects, so switching to && is behaviour-preserving\nand skips the redundant call when the flag is already false.",
          "is_bot": false,
          "headline": "Use short-circuit && in Exchange.removeKeyRangeInternal (CodeQL java/…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:11:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77e436ca8d2ac4d31f7a343f22ee49c342432e80",
          "body": "…case-in-switch) (#244)\n\nAsyncHttpClientProvider switched on the HostnameVerifier option but only had a\ncase for ALLOW_ALL, relying on a pre-initialised DefaultHostnameVerifier to cover\nSTRICT. Give the switch a default branch that assigns the strict verifier, the\nsame shape already used by SyncHttpClientProvider.\n\nBehaviour is unchanged - STRICT still maps to DefaultHostnameVerifier - but the\nswitch now covers every enum value and the two client providers are consistent.",
          "is_bot": false,
          "headline": "Handle the STRICT host name verifier explicitly (CodeQL java/missing-…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:10:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f436d06f4fbcf7bcca6b15f7f97f98bd9fb7281",
          "body": "…otify-all) (#243)\n\nkick() woke a waiter with notify(). Today there is only ever a single waiter -\nthe one background thread per IOTaskRunnable that blocks in run()'s wait() - so\nnotify() and notifyAll() are equivalent, but notify() is fragile: if another\nthread ever waited on the same monitor, noti\n[…]\n It wakes the same single waiter now (no thundering herd),\nand the wait loop already re-checks its conditions (shouldStop / _notified /\nrecomputed wait time), so any extra wake-ups are handled safely.",
          "is_bot": false,
          "headline": "Use notifyAll in IOTaskRunnable.kick (CodeQL java/notify-instead-of-n…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:10:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "868309c70b0f4d520562c7f23e50a06caa43b869",
          "body": "…va/subtle-inherited-call) (#242)\n\nThe anonymous LinkedHashMap that backs AccessTokenValidationCache overrides\nremoveEldestEntry and calls an unqualified size(). That resolves to\nLinkedHashMap.size() (correct), but the enclosing AccessTokenValidationCache\nalso declares a size() method, so the call i\n[…]\nholds the write\nlock.\n\nQualify the call as super.size() to make it explicit that it is the map's own\ninherited size. Behaviour is unchanged: the unqualified call already bound to\nLinkedHashMap.size().",
          "is_bot": false,
          "headline": "Qualify the LinkedHashMap size() call in removeEldestEntry (CodeQL ja…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:04:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "130bcc2a7a1d33dbdd4d4a56c12dd5681a0ae5ae",
          "body": "…lizable-inner-class) (#241)\n\n* Declare AdminUI inner classes non-serializable (CodeQL java/non-serializable-inner-class)\n\nAdminUI.AdminAction (extends AbstractAction) and AdminUI.SplashWindow (extends\nJWindow) are non-static inner classes that inherit Serializable from their Swing\nsuperclasses, whi\n[…]\ncts.\n\nCount and print transient CorruptVolumeExceptions for diagnostics but no\nlonger fail on them; keep failing on IntegrityCheck faults or on any\nother exception type (NPE, RebalanceException, ...).",
          "is_bot": false,
          "headline": "Declare AdminUI inner classes non-serializable (CodeQL java/non-seria…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:04:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35122276063765713101400e9c342b5ed4fa867e",
          "body": "…read-start-in-constructor) (#239)\n\nThe AdminUI() constructor started two threads - one that builds the Swing frame\n(joined before the constructor returned) and one that resolves the local host\nname - so both anonymous Thread subclasses captured `this` and could touch\nAdminUI fields before construct\n[…]\nThe main() flow is unchanged: construct (records the RMI host) -> launch (builds\nthe frame, waits for it, starts the host-name lookup) -> connect. The frame is\nstill fully built before connect() runs.",
          "is_bot": false,
          "headline": "Launch AdminUI helper threads outside the constructor (CodeQL java/th…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:04:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0c75fb65af484f03444c8788b5659b323c4749a",
          "body": "…masks-super-field) (#238)\n\n* Stop shadowing Task._stop and Task._lastException (CodeQL java/field-masks-super-field)\n\nStreamLoader and StreamSaver each redeclared _stop and _lastException, which are\nalready declared in their superclass Task. The shadowing meant the two classes\ndid not share the bas\n[…]\nas no side\neffects and the left operand is always evaluated first, so switching to &&\nis behaviour-preserving and avoids the redundant _stop.get() once the loop\ncondition's left side is already false.",
          "is_bot": false,
          "headline": "Stop shadowing Task._stop and Task._lastException (CodeQL java/field-…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:03:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fafb12acf199f3b154c215d872146ec37b54ee72",
          "body": "…l-boxed-variable) (#237)\n\nSeven local variables were declared with a boxed type (Integer/Long/Double/\nBoolean) but only ever hold a primitive value and are never null, so each\nincurred needless boxing and an implicit unbox on every use. Declare them with\nthe corresponding primitive type:\n\n  - DateU\n[…]\nMojo: cachedCreateChecksums (from a boolean field)\n    and artifactAlreadyInstalled (from File.exists()) become boolean.\n\nEach value was already unboxed at its point of use, so behaviour is unchanged.",
          "is_bot": false,
          "headline": "Declare never-null local variables as primitives (CodeQL java/non-nul…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:03:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "40b65a80a10ca8899026ba7747eed8109adba0b6",
          "body": "Seven null checks tested a value that provably cannot be null at that point, so\nthe guarded branch (or the null arm of a ternary) was dead code. Simplify each:\n\n  - Persistit.crash: _journalManager and _bufferPoolTable are final fields\n    initialised inline to new instances, so they are never null.\n[…]\n the intended IllegalArgumentException is thrown instead.\n\nBehaviour is unchanged for every existing input; the OSGi case additionally\nreports the missing-resource error cleanly rather than as an NPE.",
          "is_bot": false,
          "headline": "Remove useless null checks (CodeQL java/useless-null-check) (#236)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:02:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1b356a07674fefcd94d397bd73667b2ad83a1ee",
          "body": "…gument) (#235)\n\nTen format/log calls passed arguments that the format string never referenced,\nso the values were silently dropped from the message. Add the missing\nplaceholders so the arguments actually appear:\n\n  - SLF4JErrorReporter.warning/error: the format string was empty (\"\") while\n    five \n[…]\nnUserResponse: two LOG.error calls\n    dropped the non-2xx response body. Add a {} so the body is logged.\n\nBehaviour is otherwise unchanged; only the previously discarded values now\nreach the message.",
          "is_bot": false,
          "headline": "Reference the supplied format arguments (CodeQL java/unused-format-ar…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:02:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71c2337dd03013b3c8475bf516f471fd9158d6cd",
          "body": "…verride) (#234)\n\nFour methods overrode a synchronized method from java.io.InputStream or\njava.lang.Throwable without carrying the synchronized modifier, so a caller\nthat relies on the base-class locking contract loses it on these subtypes.\nRestore the modifier on each override:\n\n  - ByteArrayBranch\n[…]\nour the Throwable.getCause\n    contract.\n\nEach method only reads or writes its own fields, so adding synchronized cannot\nintroduce a lock-ordering deadlock, and single-threaded callers are unaffected.",
          "is_bot": false,
          "headline": "Synchronize overrides of synchronized methods (CodeQL java/non-sync-o…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:01:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9fffd3caeb1dec84eebaf2b3522dadde8508c854",
          "body": "…atus-of-call) (#233)\n\nNine call sites discarded the return value of a stream read/skip or of\nFile.renameTo, so a short read, an incomplete skip, or a failed rename passed\nsilently. Consume and act on each result:\n\n  - StreamLoader.next: read the record key/value with DataInputStream.readFully\n    i\n[…]\nr failing I/O is\nnow surfaced.\n\nAlso add the missing 3A Systems Portions header line to StreamLoader.java,\nBackupTask.java, WDSSO.java and DerValue.java (Value.java and IOMeter.java\nalready carry it).",
          "is_bot": false,
          "headline": "Check ignored error status of I/O calls (CodeQL java/ignored-error-st…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:01:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "292d210758a896aa51e66ee295725594e7ea1668",
          "body": "…istent-compareto-and-equals) (#232)\n\nThree persistit engine classes implemented Comparable/compareTo but inherited\nObject.equals, so equals and compareTo could disagree:\n\n  - BufferPool.BufferHolder        (sorted via Arrays.sort by volumeId, page)\n  - JournalManager.TransactionMapItem (held in a T\n[…]\ntity equals, this is\nbehaviour-preserving for all existing usages.\n\nAlso add the missing 3A Systems Portions header line to JournalManager.java\n(TreeBuilder.java and BufferPool.java already carry it).",
          "is_bot": false,
          "headline": "Declare equals/hashCode consistent with compareTo (CodeQL java/incons…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:00:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "52ba37feed6a33be54ee1e4371d94cb281212734",
          "body": "…larger-than-type-width) (#231)\n\nIn IOMeter.dump() the composite event key was built as\n\"(volumeHandle << 48) + pageAddress\". volumeHandle is an int, and Java uses\nonly the low 5 bits of an int shift distance, so \"<< 48\" was silently\nevaluated as \"<< 16\" in 32-bit arithmetic before being widened to \n[…]\nwith analyzePages.\n\nCast volumeHandle to long first so the shift is performed in 64 bits:\n((long) volumeHandle << 48) + pageAddress. This only affects the -a page\nanalysis of the journal dump utility.",
          "is_bot": false,
          "headline": "Widen volumeHandle to long before shifting by 48 (CodeQL java/lshift-…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T17:00:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1993f46249ddb9f44e2ef4665fc095bb572db2ad",
          "body": "…L java/reference-equality-on-strings) (#230)\n\nResourceResponseImpl.equals() delegated to a private isEqual(String, String)\nhelper that started with a \"s1 == s2\" reference check. The reference compare\nwas an intentional fast-path / both-null shortcut and the real value compare\nwas done by s1.equals(\n[…]\nthe two isEqual calls with Objects.equals (already imported) and drop\nthe helper. Behaviour is identical - Objects.equals performs the same\n\"a == b || (a != null && a.equals(b))\" null-safe comparison.",
          "is_bot": false,
          "headline": "Use Objects.equals instead of hand-rolled String == comparison (CodeQ…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:59:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1bd8fddda5b622fa3352db6b518884ab728e5d9",
          "body": "…uncaught-number-format-exception) (#229)\n\nEach site called Integer/Long/Double parsing on a value that reaches it\nwithout a surrounding catch, so malformed input escaped as a raw\nNumberFormatException. Every site is now routed to the failure mode that\nalready fits its method contract, so callers ge\n[…]\nxception naming\n  the offending spec instead of a bare NumberFormatException.\n\nBehaviour is unchanged for valid input. Compiles: mvn -o -am compile across\nall eleven affected modules -> BUILD SUCCESS.",
          "is_bot": false,
          "headline": "Handle uncaught NumberFormatException at 20 parse sites (CodeQL java/…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:59:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63bc6b8504ade54f5641af32019a7f596539f06f",
          "body": "…d-unsafe-dateformat) (#228)\n\nKey.SDF was a public static SimpleDateFormat shared across all threads.\nSimpleDateFormat is not thread-safe: concurrent format()/parse() calls\ncorrupt its internal Calendar state, producing garbled output, wrong\ndates, or ArrayIndexOutOfBoundsException. Key.SDF is reach\n[…]\nes to Key.SDF.get().\n\nThe remaining private static SimpleDateFormat fields (JournalTool,\nVolumeHeader, CheckpointManager, and the AbstractSuite test) were not\nflagged by CodeQL and are left unchanged.",
          "is_bot": false,
          "headline": "Make the shared Key.SDF date formatter thread-safe (CodeQL java/threa…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:58:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9978bd198c64c15706a340f2d5da0a3094a8596a",
          "body": "…ger-multiplication-cast-to-long) (#227)\n\nIn each case the product was computed in int arithmetic and only then widened to\nlong, so a large enough operand overflows before the conversion. Add an L suffix\nto the first factor so the multiplication is performed in long.\n\n- JournalManagerBench.runTest: \n[…]\nd of Timer.schedule; use 1000L.\n\nBehaviour is unchanged for in-range inputs; only the silent int overflow at large\ninputs is removed. These are benchmark/example/admin-UI classes, not core data\npaths.",
          "is_bot": false,
          "headline": "Widen int multiplications to long before conversion (CodeQL java/inte…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:57:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "801d03f10d4cf4ad21c1bb68e520192a1cfa86fc",
          "body": "…-comparison (#226)\n\nFix 2 real defects and remove 12 provably-constant (dead) comparisons across\ncommons and persistit. The dead-comparison removals are behaviour-identical and\nclear the alerts at the source rather than by annotation.\n\nReal bugs:\n- ManagementTableModel: the column-removal loop was \n[…]\ndefensive\nassertions/bounds (LongRecordHelper, Key.maxStorableKeySize, Buffer page checks),\na provable invariant on the hot key-search path, and the explicit HTTP status-family\nrange ladder in Status.",
          "is_bot": false,
          "headline": "Fix and clean up constant comparisons flagged by CodeQL java/constant…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:56:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79532a28585046d0d454da565088246293e1793b",
          "body": "…ue-may-be-null (#225)\n\nFix 12 genuine null-dereference defects across commons, script and persistit.\nIn each case a value that can be null - per an explicit guard elsewhere or an\nunassigned local - was dereferenced.\n\n- AsciiDocTable.columnsPerRow: the range check dereferenced the Integer field\n  th\n[…]\n is unchanged on the non-error paths; only guaranteed or latent NPEs are\navoided. The remaining alerts for this rule are dismissed as false positives\n(correlated invariants the analyzer cannot prove).",
          "is_bot": false,
          "headline": "Fix null-pointer dereferences flagged by CodeQL java/dereferenced-val…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:54:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "637877070bf30a3b3f0852486ec555848180f543",
          "body": "… java/unsafe-get-resource) (#224)\n\nThe idiom getClass().getResource() / getResourceAsStream() resolves resources\nrelative to the runtime class, so a subclass in another package (or one loaded by\na different class loader) could resolve a different resource than the author\nintended. CodeQL flags this\n[…]\nlerts.\n\nBehaviour is otherwise unchanged.\n\nVerified: commons/util/util, commons/audit/core, commons/audit/servlet,\ncommons/selfservice/example, cassandra-embedded and commons/doc-maven-plugin\ncompile.",
          "is_bot": false,
          "headline": "Use class literals instead of getClass() for resource loading (CodeQL…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:52:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07f471cc20063cdf95e454fecafb9d7d9e915f3f",
          "body": "Two code paths could leave an output file descriptor open when an exception was\nthrown before the explicit close():\n\n- script/common Utils.copyURLToFile: the input channel and the FileOutputStream\n  behind the output channel were closed in a finally block, but only after both\n  were created outside \n[…]\nrces also makes a failing close() a suppressed\n  exception rather than masking the original error from the dump.\n\nBehaviour is otherwise unchanged.\n\nVerified: script/common and persistit/core compile.",
          "is_bot": false,
          "headline": "Close leaked output streams (CodeQL java/output-resource-leak) (#223)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:52:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81020845d6528a88c9da82278e0c49d8a9d93ed4",
          "body": "…va/input-resource-leak) (#222)\n\n* Close leaked input streams/readers with try-with-resources (CodeQL java/input-resource-leak)\n\nSeven code paths opened a FileInputStream / FileReader / InputStreamReader /\nSocket and could leave the file descriptor open on method exit, either because\nthe stream was \n[…]\nommand loop, so the\nsource stack is always released regardless of how the loop ends. Also route the\nexisting \"source\" reset-to-console path through the same helper.\n\nVerified: persistit/core compiles.",
          "is_bot": false,
          "headline": "Close leaked input streams/readers with try-with-resources (CodeQL ja…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:51:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "28261ac5326d5d03b1146e3fd157af43b200d3c0",
          "body": "…g-equals-signature) (#221)\n\n* Remove dead equals overload on BundleHandlerBuilder (CodeQL java/wrong-equals-signature)\n\nBundleHandlerBuilder declared equals(BundleHandlerBuilder), which overloads\nrather than overrides Object.equals(Object), so it is never dispatched by\ncollections or Objects.equals\n[…]\nong-equals-signature code-scanning alert.\n\n* Apply suggestions from code review\n\nCo-authored-by: Maxim Thomas <maxim.thomas@gmail.com>\n\n---------\n\nCo-authored-by: Maxim Thomas <maxim.thomas@gmail.com>",
          "is_bot": false,
          "headline": "Remove dead equals overload on BundleHandlerBuilder (CodeQL java/wron…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:50:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7faa435cf2d26d98832bfbd5e62fdbbc7961dea5",
          "body": "…a/empty-container) (#220)\n\neval() allocated a local HashMap 'scope' and tested scope.containsKey(...)\nin the scopes loop, but nothing ever put into it, so the map was always\nempty and that check was always false.\n\nRemove the dead map (and its now-unused java.util.HashMap import) and reduce\nthe guar\n[…]\n is behaviour-preserving: since scope was always empty,\nscope.containsKey(...) never affected the result.\n\nVerified: script/javascript compiles.\n\nResolves the java/empty-container code-scanning alert.",
          "is_bot": false,
          "headline": "Drop the always-empty scope dedup map in RhinoScript.eval (CodeQL jav…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:50:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94dbc2160d869d36e585afa1df8d4b01591d2432",
          "body": "…x-out-of-bounds) (#219)\n\naddSchedules(int[][] pairs) steps the index by 2 and reads both pairs[index]\nand pairs[index + 1], but the loop guard was index < pairs.length. For an\nodd-length array the final iteration reads pairs[pairs.length], throwing\nArrayIndexOutOfBoundsException.\n\nGuard on index + \n[…]\npass even-length constants, so\nbehaviour is unchanged; the fix just makes the access provably in bounds.\n\nVerified: persistit/core compiles.\n\nResolves the java/index-out-of-bounds code-scanning alert.",
          "is_bot": false,
          "headline": "Iterate ThreadSequencer schedules by complete pairs (CodeQL java/inde…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:49:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "13e64de703493a6e1f5808c0ecb1ea56bc5d55d7",
          "body": "…rence-equality-of-boxed-types) (#218)\n\n* Compare bundle start levels by value, not reference (CodeQL java/reference-equality-of-boxed-types)\n\nThe duplicate-detection check in buildBundleHandlerList compared a bundle\nhandler's start level against itself:\n\n    newHandler.getStartLevel() == newHandler\n[…]\nality-of-boxed-types code-scanning alert.\n\n* Apply suggestions from code review\n\nCo-authored-by: Maxim Thomas <maxim.thomas@gmail.com>\n\n---------\n\nCo-authored-by: Maxim Thomas <maxim.thomas@gmail.com>",
          "is_bot": false,
          "headline": "Compare bundle start levels by value, not reference (CodeQL java/refe…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:39:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d3d7e745fa111b84a6aff13833b9d934be8cc19",
          "body": "…odification) (#217)\n\nsourceCache is a LinkedHashMap<ScriptName, SourceContainer>, but\nremoveSourceUnit called sourceCache.remove(unit), passing the SourceUnit\nitself. Map.remove(Object) accepts any type, so this compiled, but a\nSourceUnit never equals a ScriptName key, so the removal was a silent n\n[…]\nr).\n\nVerified: script/common compiles.\n\nResolves the java/type-mismatch-modification code-scanning alert. (The\nadjacent unreleased-lock bug in the same finally block is handled separately\nin PR #208.)",
          "is_bot": false,
          "headline": "Remove source unit by its ScriptName key (CodeQL java/type-mismatch-m…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:38:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d02a76d5cfdd45cf54c7eb5b2f7018e25f8c895e",
          "body": "Two collections were populated but never read:\n\n  - TransactionIndex.checkpointAccumulatorSnapshots: a lookupMap that mapped\n    each accumulator to itself and was never queried. Drop the map (and its\n    now-unused java.util.HashMap / java.util.Map imports); the loop keeps its\n    real work, accumu\n[…]\ness reporting is unaffected - it is maintained separately in reset()\n    and checkVolume().\n\nNo behavioural change. persistit/core compiles.\n\nResolves the 2 java/unused-container code-scanning alerts.",
          "is_bot": false,
          "headline": "Remove unused containers (CodeQL java/unused-container) (#216)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:38:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c35bbcc3166956e17a26c39be4a6d084815f3ab2",
          "body": "…) (#215)\n\nsetLogFile(String) is synchronized and writes _logFileName, but getLogFile()\nreads the field without synchronization. Because the read establishes no\nhappens-before relationship with the synchronized write, a caller of\ngetLogFile() may observe a stale value.\n\nDeclare _logFileName volatile\n[…]\nynchronized-getter code-scanning alert on IOMeter. The\nother alert of this rule (PersistitMap.ExchangeEntry.getValue) was dismissed\nas a false positive: its _value field is final and never reassigned.",
          "is_bot": false,
          "headline": "Make IOMeter._logFileName volatile (CodeQL java/unsynchronized-getter…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:37:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d60dece1bf02b50c57a7707e38010dbe7e65b238",
          "body": "…nc-on-field) (#214)\n\nBranchingStreamWrapper synchronized on its trunk field to coordinate the\nbranches that share a Trunk, but close() also reassigned that same field\n(trunk = null) to mark the branch closed. Synchronizing on a field that is\nreassigned is unsafe: the monitor object is mutated, and \n[…]\nat window because trunk had been nulled.\n\nVerified: commons/http-framework/core compiles and BranchingStreamWrapperTest\npasses (116 tests).\n\nResolves the java/unsafe-sync-on-field code-scanning alert.",
          "is_bot": false,
          "headline": "Lock on a stable trunk, flag closed separately (CodeQL java/unsafe-sy…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:37:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90289dbe55461adec93db7f01054db4af79ed921",
          "body": "…e-checked-locking) (#213)\n\n* Make double-checked-locking fields volatile (CodeQL java/unsafe-double-checked-locking)\n\nFour classes lazily initialize a field with the double-checked locking idiom\nbut the field was non-volatile:\n\n    if (field == null) {\n        synchronized (this) {\n            if (\n[…]\nble-checked-locking code-scanning alerts.\n\n* Apply suggestions from code review\n\nCo-authored-by: Maxim Thomas <maxim.thomas@gmail.com>\n\n---------\n\nCo-authored-by: Maxim Thomas <maxim.thomas@gmail.com>",
          "is_bot": false,
          "headline": "Make double-checked-locking fields volatile (CodeQL java/unsafe-doubl…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:36:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d26e5076c81cbb3e97d9e7dac5b5f154bb53fa3",
          "body": "…and-hashcode) (#212)\n\nNine classes overrode one of equals()/hashCode() but not the other, breaking\nthe Object contract that equal objects must share a hash code.\n\nAdd the missing hashCode(), derived from the same fields the existing equals()\ncompares:\n  - CheckpointManager.Checkpoint          (_tim\n[…]\no identity is the correct and\npre-existing semantics.\n\nVerified: commons/util/util, persistit/core and persistit/ui compile.\n\nResolves the 9 java/inconsistent-equals-and-hashcode code-scanning alerts.",
          "is_bot": false,
          "headline": "Make equals and hashCode consistent (CodeQL java/inconsistent-equals-…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:36:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b9ad2f8ef7a2f3748b07053e61d16979f5bd480",
          "body": "…ethod) (#211)\n\nTwenty classes across six modules are Cloneable but did not declare a\nclone() method, so cloning fell through to Object.clone()'s shallow copy\nwithout the class taking responsibility for the contract. Most inherit\nCloneable transitively from a third-party base (swagger Property, Apac\n[…]\ncontract that CodeQL flags.\n\nVerified: api-descriptor, util/util, json-fluent, http client, script/groovy\nand persistit/ui all compile.\n\nResolves the 21 java/missing-clone-method code-scanning alerts.",
          "is_bot": false,
          "headline": "Override clone() in Cloneable subclasses (CodeQL java/missing-clone-m…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:36:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "83f766c4599d05ca6c8c69db51bdf8ad97151fab",
          "body": "…ure-smtp-ssl) (#210)\n\nExampleEmailService configured the mail session with mail.smtp.starttls.enable\nbut left mail.smtp.ssl.checkserveridentity unset. STARTTLS without server\nidentity verification does not authenticate the SMTP server, so the session\n(and the SMTP credentials it carries) is exposed\n[…]\np.ssl.checkserveridentity = true  (verify the server certificate)\n\nThis is example/demo code copied by downstream users, so it should model a\nsecure SMTP configuration.\n\nFixes code-scanning alert #89.",
          "is_bot": false,
          "headline": "Verify SMTP server identity in ExampleEmailService (CodeQL java/insec…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:35:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23dd40262647d8b609e396bbf23a044f677e7252",
          "body": "…209)\n\nAbstractJwtSessionModule.initialize() read the isSecure module option and\ndefaulted it to false when unset:\n\n    this.isSecure = secure == null ? false : secure;\n\nThe JWT session cookie carries an authenticated session, so a non-Secure\ndefault lets the browser send it over plain HTTP, exposin\n[…]\n; those behind a TLS-terminating\nproxy are unaffected (the browser still speaks HTTPS). Only genuine\nend-to-end plain-HTTP setups must now set isSecure=false explicitly.\n\nFixes code-scanning alert #5.",
          "is_bot": false,
          "headline": "Default JWT session cookie to Secure (CodeQL java/insecure-cookie) (#…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:35:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0385796b65c972c67187fd2e3da620139025c1d4",
          "body": "… java/unreleased-lock) (#208)\n\nremoveSourceUnit(SourceContainer) acquired sourceCacheLock.writeLock()\nand, in the finally block, called writeLock().lock() again instead of\nunlock(). Each call therefore incremented the write hold count by two\nand released it zero times, permanently leaking the write\n[…]\nge the finally block to release the lock with writeLock().unlock().\nThe lock is now correctly balanced with the acquisition on entry, as it\nalready is in addSourceUnit.\n\nFixes code-scanning alert #38.",
          "is_bot": false,
          "headline": "Release the write lock in ScriptRegistryImpl.removeSourceUnit (CodeQL…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:34:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f36f8d394d60ae966d307dc822a86ea9a7bfca4b",
          "body": "…able-exit-in-loop) (#207)\n\nThe inner loop is `for (int j = 0; j < 2 && index >= 0; j++)`, and its body\nbegan with `if (index < 0) break;`. The for condition already guarantees\nindex >= 0 on entry, and index is only decremented at the very end of the\nbody, so `index < 0` is always false at that poin\n[…]\n. Behaviour is unchanged: the loop still\nterminates via `j < 2` and the `index >= 0` guard in the for condition, and\nbuffer[index] remains protected by that same guard.\n\nFixes code-scanning alert #97.",
          "is_bot": false,
          "headline": "Remove unreachable break in Key.appendBigInteger (CodeQL java/unreach…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:33:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8dd64fe88eb236f36a4b1d714a979a240e3b193",
          "body": "…deQL java/implicit-cast-in-compound-assignment) (#206)\n\nskip(long n) reduced n with Math.min(n, data.length - position) and then\ndid `position += n`, where position is an int. That compound assignment\nimplicitly narrows the long back to int.\n\nThere is no actual overflow: Math.min bounds the value t\n[…]\nnt\n(the (int) cast is lossless for the reasons above), doing the compound\nassignment in pure int arithmetic, and widening back to long on return.\nBehaviour is unchanged.\n\nFixes code-scanning alert #1.",
          "is_bot": false,
          "headline": "Make the narrowing cast explicit in ByteArrayBranchingStream.skip (Co…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:33:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a6b4c57c5a34a325255fb6eac5d5212a69aaa32",
          "body": "…on-with-wider-type) (#204)\n\nThe \"pviewchain\" CLI command walks the right-sibling chain of B-tree\npages and caps the number of pages it prints with a counter guard:\n\n    long count = 0;\n    while (currentPage > 0 && count++ < maxcount) { ... }\n\nmaxcount is declared as long, but count was an int. The\n[…]\nmaxcount, so the int-vs-long\ncomparison is gone and the safety cap holds.\n\nFor normal inputs (maxcount is bounded 1..1_000_000 by the @Arg spec)\nbehaviour is unchanged.\n\nFixes code-scanning alert #54.",
          "is_bot": false,
          "headline": "Use long for the page counter in CLI.pviewchain (CodeQL java/comparis…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:32:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ee95e76eadbe660918dda1aaf28ace201a751da",
          "body": "…ava/tainted-arithmetic) (#203)\n\n* Clamp overflow when computing task expiration in Task.setup (CodeQL java/tainted-arithmetic)\n\nTask.setup(...) computed _expirationTime as now() + maxTime, where\nmaxTime is an externally supplied value (passed through\nManagementImpl.startTask over the RMI/JMX manage\n[…]\nhe tainted maxTime still\nreaches the +. Bound-check the operand before the addition instead — clamp to\nLong.MAX_VALUE when now + maxTime would overflow. Behaviour is unchanged for\nevery maxTime value.",
          "is_bot": false,
          "headline": "Clamp overflow when computing task expiration in Task.setup (CodeQL j…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:31:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9d06b097411ede76f07d229ab787938900f1f31",
          "body": "…py (CodeQL java/improper-validation-of-array-index) (#202)\n\nExchange.fetchBufferCopy(int level) takes an externally supplied tree\nlevel (reachable via ManagementImpl.getBufferInfo over RMI/JMX and the\nCLI \"pview\" command) and uses it to index the fixed-size _levelCache\narray (length MAX_TREE_DEPTH \n[…]\nid inputs are unaffected\n(they always satisfy lvl < depth <= _levelCache.length); out-of-range\ninput now raises the same IllegalArgumentException instead of an AIOOBE.\n\nFixes code-scanning alert #101.",
          "is_bot": false,
          "headline": "Guard tree level against _levelCache bounds in Exchange.fetchBufferCo…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:30:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c141b8c78505524f8a34f8af3fb42ffdb540950",
          "body": "…a/insufficient-key-size) (#200)\n\nRsaJWKTest and JsonCryptoTest generated ephemeral RSA key pairs with a\n1024-bit modulus, which CodeQL flags as below the recommended 2048-bit\nminimum (CWE-326). The keys are throwaway test fixtures with no production\nimpact, but bumping them to 2048 bits removes the\n[…]\n\nThe tests assert round-trip properties (modulus/exponent, JWK encode/decode,\nencrypt/decrypt) that are independent of key size, so they pass unchanged.\n\nFixes code-scanning alerts #17, #18, #19, #20.",
          "is_bot": false,
          "headline": "Use RSA 2048-bit keys in json-crypto/json-web-token tests (CodeQL jav…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:29:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "98628ebdb1f46835df2a975d71830478a2e61a51",
          "body": "…L java/weak-cryptographic-algorithm) (#199)\n\nSimpleEncryptor.asymmetric() encrypted the payload with a freshly generated\nAES session key under AES/ECB/PKCS5Padding. ECB is deterministic and leaks\nequality of plaintext blocks within a message regardless of key freshness\n(CWE-327), so a random sessio\n[…]\nt reads the\n\"cipher\" field and the optional \"iv\" from the encrypted object -- so values\npreviously written with AES/ECB (no IV) still decrypt, while new values use CBC.\n\nFixes code-scanning alert #33.",
          "is_bot": false,
          "headline": "Use AES/CBC instead of AES/ECB for the JSON session-key cipher (CodeQ…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:29:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca212a6058dc505e03fa6094141b9304047343da",
          "body": "…sensitive-log) (#198)\n\n* Stop logging sensitive credentials in auth/HTTP modules (CodeQL java/sensitive-log)\n\nRemove secret values from debug/trace log statements flagged by CodeQL rule\njava/sensitive-log (CWE-532: Insertion of Sensitive Information into Log File):\n\n- ResourceServerFilter: no longe\n[…]\nports in WDSSO,\n  OpenAMSessionModule, ResourceServerFilter and HttpFrameworkServlet.\n- Declare a direct util dependency in iwa-module and servlet (oauth2 and\n  openam-session-module already had one).",
          "is_bot": false,
          "headline": "Stop logging sensitive credentials in auth/HTTP modules (CodeQL java/…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:11:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35c2522f7edb983897e2cca64fade6304f6082f9",
          "body": "…meric-cast) (#197)\n\nA percent-encoded octet is validated to the single unsigned-byte range\n(0x00-0xFF) and the narrowing to byte is made explicit via a low-8-bit\nmask, so the user-controlled value can no longer silently truncate.\nNo behavioral change; UrisTest (54 tests) still passes.\n\nFixes code-scanning alert #21.",
          "is_bot": false,
          "headline": "Guard tainted numeric cast in Uris.urlDecode0 (CodeQL java/tainted-nu…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-16T16:09:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b7da5ef86bfff548ba0617dfc54cb1da1330d0c",
          "body": null,
          "is_bot": false,
          "headline": "[maven-release-plugin] prepare for next development iteration",
          "author_name": "Open Identity Platform Community",
          "author_login": null,
          "committed_at": "2026-07-16T15:23:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3d1157788b3edf650f26e19d7433db6de6b1c48",
          "body": null,
          "is_bot": false,
          "headline": "[maven-release-plugin] prepare release 3.1.2",
          "author_name": "Open Identity Platform Community",
          "author_login": null,
          "committed_at": "2026-07-16T15:23:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a81ee1e4f3ad63a753b9777093cdb5df722d6f6b",
          "body": "…s dropped mid-store (#275)\n\nFixes the residual bug-1017957 race from #274. When storeInternal has\ncommitted a split, the key-pointer pair for the new right sibling is\ninserted at the next level by a later loop iteration. If that iteration\nhits a RetryException (tree height growth with a contended c\n[…]\ninto a\nsame-key replace.\n\nBoth behaviors are covered deterministically by Bug1017957ResidualTest,\ndriven by a new STORE_PENDING_SPLIT ThreadSequencer schedule; both tests\nfail with the fixes reverted.",
          "is_bot": false,
          "headline": "persistit: revalidate pending index insertions after the tree claim i…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-12T12:03:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1f81a1a6c65ce7ec1d803a5243966a1079b1e6f",
          "body": "…ndCommittedVersions (#272) (#273)\n\nThe store-time prune in Exchange consults the ActiveTransactionCache: a\nstale cache conservatively keeps the previous committed version while a\nfresh one removes it. The test hardcoded the stale-cache outcome\n(2 versions removed), which only holds while the whole \n[…]\n cache explicitly before every store so\npruning always sees fresh commit status, and update the expected count\nto the deterministic fully-pruned outcome (4 versions removed, 2\nsurviving).\n\nFixes #272.",
          "is_bot": false,
          "headline": "persistit: stabilize flaky MVCCPruneTest.testPruneAlternatingAbortedA…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-12T12:02:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50f78ed3d17a1b98bb1f997ba3ec19b446e5ca23",
          "body": "* Clean up Javadoc warnings and fail the build on new ones\n\n- Remove the deprecated <footer> config that only emitted the JDK\n  \"-footer option is no longer supported\" warning; the header already\n  carries the same title.\n- Drop the empty <p></p> in the launcher overview that produced an\n  \"empty <p\n[…]\n Fill in concise,\naccurate descriptions for all such tags across the reactor (mostly\npersistit/core) so the Javadoc build is warning-free on every JDK.\nComment-only changes; no code behavior affected.",
          "is_bot": false,
          "headline": "Clean up Javadoc warnings and fail the build on new ones (#271)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-12T10:05:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d64b4a86e6cf6451d61b5174005b194f321a549",
          "body": "The Build Maven workflow stopped at the package phase, so failsafe\nintegration tests (*IT.java) in jaspi-functional-tests and\nframework-functional-tests never ran on pull requests — they were only\nexercised by the deploy workflow on master. Switch the build to\nmvn verify so the integration-test and verify phases run in CI,\nwhich also enables the persistit animal-sniffer API compatibility check.",
          "is_bot": false,
          "headline": "Run integration tests in the default CI build (#270)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T11:05:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "04b02d1d36e31cbb762b21c18d3f9bee36dc14ad",
          "body": "…e (#269)\n\nFileChannel#write may report partial progress instead of throwing - the\noriginal authors observed this empirically on disk-full (see the\ncomment in JournalManager#flush), and the same reporting is possible\nfor transfers aborted by a concurrent interrupt-driven channel close,\nthe suspected\n[…]\nwrite injection.\n- IOFailureTest#testVolumeShortWriteMustNotTearPage: deterministic\n  reproduction; without the fix it fails with CorruptVolumeException\n  \"page=6 ... is before left edge\".\n\nFixes #268",
          "is_bot": false,
          "headline": "persistit: do not accept short writes when copying pages to the volum…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:39:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0117a1341eb87e975b0f584778d2ab67ed67981a",
          "body": "…e block end (#267)\n\nAn IOException thrown inside JournalManager.rollover() - e.g. an\nInterruptedIOException when the rolling thread is interrupted during\nflush, truncate or force - after writeJournalEnd() had already consumed\nthe JE reserve left _currentAddress closer than JE.OVERHEAD to the block\n\n[…]\n-rollover\n  geometry with an injected truncate failure.\n- TransactionTest2: catch Throwable in workers so internal Errors are\n  reported and counted instead of silently killing the thread.\n\nFixes #265",
          "is_bot": false,
          "headline": "persistit: keep JournalManager consistent when rollover fails near th…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:39:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6f0a2a8d14ef839a3a71d359cac183fa58d06249",
          "body": "Recovery completes synchronously inside initialize(), but two maintenance\ntasks were left to background timers: the TransactionIndex active-transaction\ncache update and CleanupManager's pruneTimelyResources() (first pass no\nearlier than 1s after startup). Until they ran, residual tree-version state\n\n[…]\n get correct step visibility immediately after initialize()\nreturns. Both calls are idempotent and their cost is bounded (one ATC\nrecompute plus one pass over recovered timely resources).\n\nFixes #264.",
          "is_bot": false,
          "headline": "persistit: settle MVCC state at the end of Persistit.initialize() (#266)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:38:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe7a7b9af2dfe0f0b090a16a2108fc4bbac94f7b",
          "body": "…e (bug 1017957 class race) (#263)\n\nrebalanceSplit() links a new page only through its sibling chain and defers the\nparent index entry to a background CleanupIndexHole action. By the time the\nCleanupManager runs it, the action may be arbitrarily stale: a covering\nremoveKeyRange can have unlinked the\n[…]\nt.induceCorruptionByStress with its original strict zero-exception\nassertion green across repeated runs. The race itself reproduces only on CI\nrunners, which is where this fix is ultimately validated.",
          "is_bot": false,
          "headline": "Validate the page before re-inserting an index pointer in fixIndexHol…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:38:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a0e784de050bb821d7f13fb3e06f992a5b8f79a",
          "body": "* Stabilize flaky CleanupManagerTest.testCleanupHappens\n\nThe test offered 500 cleanup actions and waited only while\ngetEnqueuedCount() > 0. That counter drops to 0 as soon as the background\nCLEANUP_MANAGER thread dequeues the batch -- before performAction runs -- so on\na slow runner the wait loop ex\n[…]\nneTimelyResources() call added to Persistit.initialize() by #266.\nWaiting for and asserting absolute values could then exit early or fail;\ntake a baseline before enqueueing and compare deltas instead.",
          "is_bot": false,
          "headline": "Stabilize flaky CleanupManagerTest.testCleanupHappens (#262)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:37:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc17385b9ff7c07dba4791de91471893e40a2a49",
          "body": "The missing-volume alert asserted after startup is posted by\nJournalManager.writeForCopy when the journal copier copies a page back to a\nnow-deleted volume. For the non-transactional pages this test writes, that copy\nruns on the background JOURNAL_COPIER thread, so the assertion immediately after\nne\n[…]\no the alert is\ngenerated deterministically. ignoreMissingVolumes is still false at that point,\nso the missing-volume pages are retained and the later\nignoreMissingVolumes-behavior check is unaffected.",
          "is_bot": false,
          "headline": "Stabilize flaky JournalManagerTest.missingVolumePageHandling (#261)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:37:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a367ef3c9abe7614f4a183bbe8703835d06b0ac9",
          "body": "The test records the buffer inventory at shutdown, restarts with a\nTrackingFileChannel injected into the volume channel, preloads, and asserts\nthe channel saw the reads. Intermittently it saw zero reads:\nrecordBufferInventory() interleaves its own _buffer_inventory_ tree stores\nwith the pool scan, s\n[…]\nugh the injected channel in\nstrictly ascending page order.\n\nAlso fix TrackingFileChannel.assertOrdered, which never advanced `previous`\nand so only checked `position > -1`; it now verifies read order.",
          "is_bot": false,
          "headline": "Make WarmupTest.readOrderIsSequential deterministic (#259)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:36:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d05ea8615d16b0c107b3df534a4db3aa89c3a4c6",
          "body": "* Stabilize flaky TransactionIndexTest.testDeadlockedWwDependency\n\nThe test builds a three-transaction deadlock cycle (ts1 <- ts3 <- ts2 <- ts1)\nand assumed a specific thread would win the deadlock-detection race: that t3\n(which closes the cycle) reports UNCOMMITTED and that t2 then clears to 0 once\n[…]\n bimodal\n  1 s/5 s) and the detection window widens to t3's own 10 s timeout.\n- Finding 2: include elapsed1/elapsed2 in the diagnostic state string.\n- Finding 4: constrain result1 to {0, UNCOMMITTED}.",
          "is_bot": false,
          "headline": "Stabilize flaky TransactionIndexTest.testDeadlockedWwDependency (#256)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:36:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14a85cd0ce636ebdd03967583b9c76757bb288ee",
          "body": "…lose (#255)\n\nThe test closed Persistit and immediately asserted that no worker threads\nwere left stranded, but worker threads unwind from the closure\nasynchronously. On a loaded CI runner a worker that had not yet caught its\nexpected exception left _strandedThreads at 1, producing a spurious\n\"expec\n[…]\n).\n\nJoin the worker threads with a bounded deadline before the assertion so\nthey can observe the closure and exit, and reset the shared\n_strandedThreads counter at the start of the test for isolation.",
          "is_bot": false,
          "headline": "Stabilize flaky TransactionTest2.transactionsConcurrentWithPersistitC…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:35:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99f54421e82fba8e504037f56fa845d49c8f40d6",
          "body": "…order) (#254)\n\n* Fix flaky WarmupTest.testWarmup: compare resident page set, not slot order\n\nWarmupTest.testWarmup asserted that after a bufferinventory+bufferpreload\nrestart every buffer slot holds the same page as before shutdown\n(getBufferCopy(i) before == getBufferCopy(i) after). That is not wh\n[…]\n: gate the under-fill assertion on validPageCount() -- the raw count\n  of occupied buffers -- instead of the filtered/deduplicated resident set,\n  which a full pool of lock-volume pages could satisfy.",
          "is_bot": false,
          "headline": "Fix flaky WarmupTest.testWarmup (compare resident page set, not slot …",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-11T08:35:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f75702da387e7ec9dbd0f3cd90965055fe0680f",
          "body": "…rameter, java/inconsistent-javadoc-throws) (#250)\n\nCorrect or remove 47 Javadoc tags that reference parameters or exceptions\nthe method does not have, across 22 files (mostly persistit/core):\n\n- 15 tags renamed to the actual parameter, or to the exception the method\n  really throws (e.g. @param val\n[…]\nduplicating an\n  already-documented exception.\n\nDocumentation-only, no code changes. Verified by compiling persistit/core\nand script/javascript and running javadoc:javadoc (doclint) on\npersistit/core.",
          "is_bot": false,
          "headline": "Fix stale Javadoc @param/@throws tags (CodeQL java/unknown-javadoc-pa…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-10T07:28:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81567b15534b721648dacee6ac6c3a58627fc31e",
          "body": "Extend the CodeQL matrix beyond java-kotlin to also analyse:\n\n- javascript-typescript: the self-service example UI and openapi\n  translators contain first-party JS worth scanning.\n- python: persistit docs/stress-test helper scripts.\n- actions: the repository's own GitHub Actions workflows.\n\nAll lang\n[…]\nths-ignore entries so the JavaScript analysis skips minified and\nvendored third-party code (SyntaxHighlighter, swagger-ui, webjars,\nnode_modules) instead of reporting noise on code we do not maintain.",
          "is_bot": false,
          "headline": "Scan JavaScript/TypeScript, Python and Actions with CodeQL (#253)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-09T19:44:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "942a02ed8e54a8c032c725d0d5d0f605f5e9e71b",
          "body": "…avadoc (#252)\n\nSet <doclint>all,-missing</doclint> so the standard-doclet documentation\ncompleteness warnings (no comment, no @param/@return, default constructor)\nstop surfacing as CI annotations across the JDK build matrix, while keeping\nthe html, reference, syntax and accessibility checks that ca\n[…]\nnon-inherited {@inheritDoc} tags in OAuth2Module with real text\n- add missing Javadoc to the maven-external-dependency-plugin mojos\n\nFull reactor javadoc now builds with zero warnings and zero errors.",
          "is_bot": false,
          "headline": "Silence doclint \"missing\" warnings and fix remaining HTML/reference j…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-09T19:43:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20724bcdf56b9a05463dbd5de73e92fc252ec52d",
          "body": "Add a `concurrency` group keyed on workflow + ref to all workflows so\nsuperseded runs on the same ref no longer pile up.\n\n- build, codeql: cancel-in-progress true to drop stale CI/analysis runs\n- deploy, release: cancel-in-progress false so in-flight publishing is\n  queued rather than aborted; deploy keys the group on the source run's\n  head branch (workflow_run has no meaningful github.ref)\n- codeql: align the pre-existing group name with the shared pattern",
          "is_bot": false,
          "headline": "Add concurrency control to GitHub Actions workflows (#251)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-09T08:00:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "701221a756165fedee864e0bc7e4c38c9cf02d4e",
          "body": "…(#240)\n\n* Enable persistit tests on JDK 26 and re-enable passing ignored tests\n\npersistit/core tests were disabled (skipTests=true, 2021) and could not\nrun on modern JDKs. Re-enable them and fix the JDK incompatibilities:\n\n- IOTaskRunnable.crash(): replace removed Thread.stop() with a cooperative\n \n[…]\n. Verify ClassIndex consistency (lookupByClass and\nlookupByHandle agree for every reachable class) single-threaded on the test\nthread after the workers join, so a genuine failure is reported reliably.",
          "is_bot": false,
          "headline": "Enable persistit tests on JDK 26 and re-enable passing ignored tests …",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-09T05:43:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ace38e02b46a2e23753bfcf2681b1f54a1bca4a9",
          "body": "- correct \"additonal-configs\" repository id to \"additional-configs\"\n- add missing space in \"settings != null &&\" condition\n- use Files.createTempDirectory instead of FileUtils.createTempFile + mkdirs,\n  which created a file and then failed to mkdirs over it",
          "is_bot": false,
          "headline": "Fix typo and temp-directory bug in ResolveExternalDependencyMojo (#195)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-08T16:38:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f7067f394bfdee4549bf2094342df594b18539d",
          "body": "* Initial plan\n\n* Fix typos in InstallExternalDependencyMojo\n\n- Correct 'see' to 'seem' in the execute() comment\n- Correct 'aritifact' to 'artifact' in the \"already exists\" log message\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: Valera V Harseko <vharseko@3a-systems.ru>",
          "is_bot": false,
          "headline": "Fix typos in InstallExternalDependencyMojo (#193)",
          "author_name": "Copilot",
          "author_login": "Copilot",
          "committed_at": "2026-07-08T16:37:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4ed6c9b0d23917b05243860b97551d3429639619",
          "body": "…(#192)\n\n- Correct 'see' to 'seem' in the execute() comment\n- Correct 'locale' to 'local' in the log and exception messages\n- Remove the always-true `if (repo == null)` check that followed\n  `ArtifactRepository repo = null;` by initializing repo directly from\n  project.getDistributionManagementArtifactRepository()",
          "is_bot": false,
          "headline": "Fix typos and remove dead null check in DeployExternalDependencyMojo …",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-08T16:36:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8d45a2f18637faf0f46a39bbc240e79ad8e661e",
          "body": "…#188)\n\nFixes the code-quality finding about the incorrect lowercase spelling of\n\"javascript\" in the class/method Javadoc. Only prose is changed; the\norg.mozilla.javascript import and the class name are left untouched.",
          "is_bot": false,
          "headline": "Capitalize \"JavaScript\" in JsonPatchJavascriptValueTransformer docs (…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-08T16:29:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc940419513a29417af10215294c027ccaa6d1f7",
          "body": "…) (#187)\n\nResolves the \"org.mockito.Matchers is deprecated\" code-quality finding by\nreplacing it with org.mockito.ArgumentMatchers everywhere, and moves the\nremaining modules off the Mockito 1.x mockito-all uber-jar onto\nmockito-core 2.23.4 (already managed in the root pom).\n\nChanges:\n- 11 modules:\n[…]\nck, so byte-buddy resolves classes against\n    the real classloader.\n\nVerified under JDK 11: all affected modules plus the binding-test-utils\nconsumers (servlet, grizzly) compile and their tests pass.",
          "is_bot": false,
          "headline": "Migrate tests from Mockito 1 (mockito-all) to Mockito 2 (mockito-core…",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-08T16:28:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7e2513a486c72400d505ea0ebbb7fed525b9150",
          "body": null,
          "is_bot": false,
          "headline": "Update commons-text version to 1.15.0 (#185)",
          "author_name": "Valery Kharseko",
          "author_login": "vharseko",
          "committed_at": "2026-07-08T16:27:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 41,
      "commits_last_year": 153,
      "latest_release_at": "2026-07-16T15:41:26Z",
      "latest_release_tag": "3.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 22,
      "days_since_latest_release": 9,
      "mean_days_between_releases": 43.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "org.openidentityplatform.commons:build-tools",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/org.openidentityplatform.commons/build-tools",
          "is_deprecated": false,
          "latest_version": "3.1.2",
          "repository_url": null,
          "versions_count": 33,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-16T15:51:51Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        },
        {
          "name": "org.openidentityplatform.commons:cassandra-embedded",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/org.openidentityplatform.commons/cassandra-embedded",
          "is_deprecated": false,
          "latest_version": "3.1.2",
          "repository_url": null,
          "versions_count": 21,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-16T15:51:52Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        }
      ]
    },
    "popularity": {
      "forks": 14,
      "stars": 5,
      "watchers": 6,
      "fork_history": {
        "days": [
          {
            "date": "2018-12-30",
            "count": 1
          },
          {
            "date": "2019-04-25",
            "count": 1
          },
          {
            "date": "2019-12-07",
            "count": 1
          },
          {
            "date": "2020-02-11",
            "count": 1
          },
          {
            "date": "2020-06-16",
            "count": 1
          },
          {
            "date": "2020-07-01",
            "count": 1
          },
          {
            "date": "2020-11-24",
            "count": 1
          },
          {
            "date": "2020-12-01",
            "count": 1
          },
          {
            "date": "2021-02-07",
            "count": 1
          },
          {
            "date": "2022-01-21",
            "count": 1
          },
          {
            "date": "2022-05-17",
            "count": 2
          },
          {
            "date": "2022-05-25",
            "count": 1
          },
          {
            "date": "2025-06-30",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 14,
        "total_forks": 14
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "example",
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "bloomfilter/core/pom.xml",
        "bloomfilter/monitoring/pom.xml",
        "bloomfilter/pom.xml",
        "build-tools/pom.xml",
        "cassandra-embedded/pom.xml",
        "commons/audit/core/pom.xml",
        "commons/audit/handler-csv/pom.xml",
        "commons/audit/handler-elasticsearch/pom.xml",
        "commons/audit/handler-jdbc/pom.xml",
        "commons/audit/handler-jms/pom.xml",
        "commons/audit/handler-json/pom.xml",
        "commons/audit/handler-splunk/pom.xml",
        "commons/audit/handler-syslog/pom.xml",
        "commons/audit/json/pom.xml",
        "commons/audit/pom.xml",
        "commons/audit/servlet/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-functional-tests/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-modules/iwa-module/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-modules/jwt-session-module/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-modules/openam-session-module/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-modules/openid-connect-module/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-modules/pom.xml",
        "commons/auth-filters/authn-filter/jaspi-runtime/pom.xml",
        "commons/auth-filters/authn-filter/pom.xml",
        "commons/auth-filters/authz-filter/framework-api/pom.xml",
        "commons/auth-filters/authz-filter/framework-functional-tests/pom.xml",
        "commons/auth-filters/authz-filter/framework/pom.xml",
        "commons/auth-filters/authz-filter/modules/oauth2-module/pom.xml",
        "commons/auth-filters/authz-filter/modules/pom.xml",
        "commons/auth-filters/authz-filter/pom.xml",
        "commons/auth-filters/pom.xml",
        "commons/doc-common-content/pom.xml",
        "commons/doc-default-branding/pom.xml",
        "commons/doc-maven-plugin/pom.xml",
        "commons/doc-maven-plugin/src/test/resources/antora/pom.xml",
        "commons/doc-maven-plugin/src/test/resources/unit/pom.xml",
        "commons/geo/pom.xml",
        "commons/http-framework/benchmarks/pom.xml",
        "commons/http-framework/binding-test-utils/pom.xml",
        "commons/http-framework/client-apache-async/pom.xml",
        "commons/http-framework/client-apache-common/pom.xml",
        "commons/http-framework/client-apache-sync/pom.xml",
        "commons/http-framework/core/pom.xml",
        "commons/http-framework/examples/descriptor-example/pom.xml",
        "commons/http-framework/examples/pom.xml",
        "commons/http-framework/examples/servlet-example/pom.xml",
        "commons/http-framework/grizzly/pom.xml",
        "commons/http-framework/oauth2/pom.xml",
        "commons/http-framework/pom.xml",
        "commons/http-framework/servlet/pom.xml",
        "commons/httpdump/pom.xml",
        "commons/json-crypto/cli/pom.xml",
        "commons/json-crypto/core/pom.xml",
        "commons/json-crypto/pom.xml",
        "commons/json-fluent/pom.xml",
        "commons/json-ref/core/pom.xml",
        "commons/json-ref/jackson/pom.xml",
        "commons/json-ref/pom.xml",
        "commons/json-schema/cli/pom.xml",
        "commons/json-schema/core/pom.xml",
        "commons/json-schema/pom.xml",
        "commons/json-web-token/pom.xml",
        "commons/launcher/launcher-zip/pom.xml",
        "commons/launcher/launcher/pom.xml",
        "commons/launcher/pom.xml",
        "commons/pom.xml",
        "commons/rest/api-descriptor/pom.xml",
        "commons/rest/json-resource-examples/pom.xml",
        "commons/rest/json-resource-http/pom.xml",
        "commons/rest/json-resource/pom.xml",
        "commons/rest/pom.xml",
        "commons/rest/rest-docbook/pom.xml",
        "commons/security/pom.xml",
        "commons/selfservice/core/pom.xml",
        "commons/selfservice/custom-stage/pom.xml",
        "commons/selfservice/example-ui/pom.xml",
        "commons/selfservice/example/pom.xml",
        "commons/selfservice/json/pom.xml",
        "commons/selfservice/pom.xml",
        "commons/selfservice/stages/pom.xml",
        "commons/util/pom.xml",
        "commons/util/test-utils/pom.xml",
        "commons/util/util/pom.xml",
        "commons/xcite-maven-plugin/pom.xml",
        "commons/xcite-maven-plugin/src/it/xcite/pom.xml",
        "guice/core/pom.xml",
        "guice/pom.xml",
        "guice/servlet/pom.xml",
        "guice/test/pom.xml",
        "i18n-framework/core/pom.xml",
        "i18n-framework/jul/pom.xml",
        "i18n-framework/maven-plugin/pom.xml",
        "i18n-framework/pom.xml",
        "i18n-framework/slf4j/pom.xml",
        "maven-external-dependency-plugin/maven-external-dependency-plugin-test/pom.xml",
        "maven-external-dependency-plugin/maven-external-dependency-plugin/pom.xml",
        "persistit/core/pom.xml",
        "persistit/pom.xml",
        "persistit/ui/pom.xml",
        "pom.xml",
        "script/common/pom.xml",
        "script/groovy/pom.xml",
        "script/javascript/pom.xml",
        "script/pom.xml",
        "ui/commons/pom.xml",
        "ui/mock/pom.xml",
        "ui/pom.xml",
        "ui/user/pom.xml"
      ],
      "largest_source_bytes": 275910,
      "source_files_sampled": 2019,
      "oversized_source_files": 16,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "bloomfilter/pom.xml",
        "build-tools/pom.xml",
        "cassandra-embedded/pom.xml",
        "commons/pom.xml",
        "guice/pom.xml",
        "i18n-framework/pom.xml",
        "persistit/pom.xml",
        "pom.xml",
        "script/pom.xml",
        "ui/pom.xml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "org.testng:testng",
            "direct": true,
            "version": "6.14.3",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 7.8,
            "advisory_ids": [
              "GHSA-rc2q-x9mf-w3vf"
            ],
            "fixed_version": "7.7.0",
            "advisory_count": 1,
            "oldest_advisory_days": 1343
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 3,
        "malicious_count": 0,
        "assessed_package": "maven:org.openidentityplatform.commons:build-tools@3.1.2",
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "maven"
      ],
      "dependencies": [
        {
          "name": "org.hdrhistogram:HdrHistogram",
          "manifest": "bloomfilter/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${hdrhistogram.version}"
        },
        {
          "name": "org.testng:testng",
          "manifest": "build-tools/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.cassandra:java-driver-core",
          "manifest": "cassandra-embedded/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.apache.cassandra:cassandra-all",
          "manifest": "cassandra-embedded/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "at.yawk.lz4:lz4-java",
          "manifest": "cassandra-embedded/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.10.1"
        },
        {
          "name": "org.xerial.snappy:snappy-java",
          "manifest": "cassandra-embedded/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.10.5"
        },
        {
          "name": "com.google.guava:failureaccess",
          "manifest": "cassandra-embedded/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0.1"
        },
        {
          "name": "org.slf4j:slf4j-api",
          "manifest": "guice/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.assertj:assertj-core",
          "manifest": "guice/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.slf4j:slf4j-nop",
          "manifest": "guice/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.openidentityplatform.commons.guice:core",
          "manifest": "guice/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.guice:servlet",
          "manifest": "guice/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "com.google.inject:guice",
          "manifest": "guice/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${guice.version}"
        },
        {
          "name": "org.apache.httpcomponents:httpasyncclient-osgi",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.1.4"
        },
        {
          "name": "org.apache.httpcomponents:httpcore-osgi",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.4.14"
        },
        {
          "name": "org.apache.httpcomponents:httpcore",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.4.14"
        },
        {
          "name": "org.apache.httpcomponents:httpcore-nio",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.4.14"
        },
        {
          "name": "org.apache.httpcomponents:httpclient-osgi",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.5.13"
        },
        {
          "name": "org.apache.httpcomponents:httpclient",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.5.13"
        },
        {
          "name": "org.slf4j:slf4j-jdk14",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.slf4j:slf4j-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.slf4j:slf4j-nop",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.slf4j:slf4j-simple",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.slf4j:jul-to-slf4j",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.slf4j:jcl-over-slf4j",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "org.slf4j:log4j-over-slf4j",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${slf4j.version}"
        },
        {
          "name": "com.google.guava:guava",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "33.4.8-jre"
        },
        {
          "name": "com.sun.mail:jakarta.mail",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.2"
        },
        {
          "name": "com.fasterxml.jackson:jackson-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jackson.version}"
        },
        {
          "name": "org.bouncycastle:bc-jdk18on-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.84"
        },
        {
          "name": "org.openidentityplatform.commons.guice:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.guice:test",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.guice:servlet",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:util",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:test-utils",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.ui:user",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:client-apache-async",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:client-apache-common",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:client-apache-sync",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:servlet",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:grizzly",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.http-framework:oauth2",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.json-crypto:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.json-crypto:cli",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-patch",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.json-ref:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.json-ref:jackson",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.json-schema:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.json-schema:cli",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-web-token",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-resource-descriptor",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-resource",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-resource",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-resource-http",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-resource-examples",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:api-descriptor",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:iwa-module",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:jwt-session-module",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:openam-session-module",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:openid-connect-module",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.authn-filter:jaspi-runtime",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.auth-filters.authz-filter:framework",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.auth-filters.authz-filter:framework-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:oauth2-module",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:oauth2-restlet",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:json",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-csv",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-elasticsearch",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-jdbc",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-jms",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-syslog",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-splunk",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.audit:handler-json",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.selfservice:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.selfservice:stages",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.selfservice:json",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:security",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:cassandra-embedded",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:json-fluent",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.script:javascript",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.script:groovy",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.launcher:launcher",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.launcher:launcher-zip",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.script:common",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.mozilla:rhino",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${rhino.version}"
        },
        {
          "name": "org.mozilla:rhino-engine",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${rhino.version}"
        },
        {
          "name": "org.asciidoctor:asciidoctorj",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.5.3"
        },
        {
          "name": "org.openidentityplatform.commons.ui:commons",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "io.swagger:swagger-models",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${swagger.version}"
        },
        {
          "name": "io.swagger:swagger-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${swagger.version}"
        },
        {
          "name": "org.openidentityplatform.commons:geo",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:httpdump",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.i18n-framework:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.i18n-framework:slf4j",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons:build-tools",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.persistit:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.bloomfilter:core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.openidentityplatform.commons.bloomfilter:monitoring",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "com.maxmind.geoip2:geoip2",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.13.0"
        },
        {
          "name": "com.sun.xml.fastinfoset:FastInfoset",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.2.17"
        },
        {
          "name": "javax.xml.bind:jaxb-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.1"
        },
        {
          "name": "com.sun.xml.bind:jaxb-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.0.1"
        },
        {
          "name": "com.sun.xml.bind:jaxb-impl",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.2"
        },
        {
          "name": "com.sun.xml.bind:jaxb1-impl",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.2.5.1"
        },
        {
          "name": "com.google.code.findbugs:jsr305",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.0.2"
        },
        {
          "name": "org.apache.commons:commons-lang3",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.20.0"
        },
        {
          "name": "commons-io:commons-io",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.16.1"
        },
        {
          "name": "commons-fileupload:commons-fileupload",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.6.0"
        },
        {
          "name": "org.apache.commons:commons-text",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.15.0"
        },
        {
          "name": "org.json:json",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "20231013"
        },
        {
          "name": "org.codehaus.groovy:groovy-all",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.4.21"
        },
        {
          "name": "org.eclipse.jetty:jetty-servlet",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jetty.version}"
        },
        {
          "name": "org.eclipse.jetty:jetty-server",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jetty.version}"
        },
        {
          "name": "org.eclipse.jetty.websocket:websocket-jetty-server",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jetty.version}"
        },
        {
          "name": "org.glassfish.grizzly:grizzly-framework",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${grizzly-framework.version}"
        },
        {
          "name": "org.glassfish.grizzly:grizzly-http-server",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${grizzly-framework.version}"
        },
        {
          "name": "org.glassfish.grizzly:grizzly-http-servlet",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${grizzly-framework.version}"
        },
        {
          "name": "org.glassfish.grizzly:grizzly-websockets",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${grizzly-framework.version}"
        },
        {
          "name": "org.apache.cassandra:java-driver-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${cassandra.version}"
        },
        {
          "name": "org.apache.cassandra:java-driver-query-builder",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${cassandra.version}"
        },
        {
          "name": "org.apache.cassandra:cassandra-all",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${cassandra-all.version}"
        },
        {
          "name": "io.netty:netty-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.2.15.Final"
        },
        {
          "name": "org.openidentityplatform:build-tools",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${forgerockBuildToolsVersion}"
        },
        {
          "name": "com.puppycrawl.tools:checkstyle",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "[8.29,)"
        },
        {
          "name": "org.apache.maven.wagon:wagon-ssh",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.2"
        },
        {
          "name": "org.easytesting:fest-assert-core",
          "manifest": "script/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0M10"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:jquery",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${jquery.version}"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:lodash",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.10.1"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:handlebars",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.7.7"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:requirejs",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.7"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backbone",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.1.2"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backbone.paginator.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.2"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:i18next",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.7.3"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:react",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "15.2.1"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:react-dom",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "15.2.1"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:bootstrap",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:bootstrap",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:bootstrap-dialog",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.34.4"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:bootstrap-dialog",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.34.4"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:font-awesome",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "4.5.0"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:selectize",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.12.1"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:selectize",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.12.1"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:dragula",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "3.6.7"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:xdate",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.8"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:moment",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.28.0"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:js2form",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0-769718a"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:form2js",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0-769718a"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:jquery.placeholder",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.8"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:spin",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.0.1"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:jquery.ba-dotimeout",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.0"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid-paginator.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid-paginator.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid-filter.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.7"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid-filter.min",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.7"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backbone-relational",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.9.0"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:backgrid-select-all",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "0.3.5"
        },
        {
          "name": "org.openidentityplatform.commons.ui.libs:sinon",
          "manifest": "ui/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${sinon.version}"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "at.yawk.lz4:lz4-java",
            "direct": true,
            "version": "1.10.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson:jackson-bom",
            "direct": true,
            "version": "2.18.6",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.code.findbugs:jsr305",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.google.code.findbugs:jsr305",
            "direct": true,
            "version": "3.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.code.findbugs:jsr305",
            "direct": true,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.guava:failureaccess",
            "direct": true,
            "version": "1.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.guava:guava",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.google.guava:guava",
            "direct": true,
            "version": "33.4.8-jre",
            "ecosystem": "maven"
          },
          {
            "name": "com.google.inject:guice",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.google.inject:guice",
            "direct": true,
            "version": "7.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.maxmind.geoip2:geoip2",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.maxmind.geoip2:geoip2",
            "direct": true,
            "version": "2.13.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.puppycrawl.tools:checkstyle",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.mail:jakarta.mail",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.mail:jakarta.mail",
            "direct": true,
            "version": "2.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-core",
            "direct": true,
            "version": "2.3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-impl",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-impl",
            "direct": true,
            "version": "2.3.2",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb1-impl",
            "direct": true,
            "version": "2.2.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.fastinfoset:FastInfoset",
            "direct": true,
            "version": "1.2.17",
            "ecosystem": "maven"
          },
          {
            "name": "commons-fileupload:commons-fileupload",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-fileupload:commons-fileupload",
            "direct": true,
            "version": "1.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": true,
            "version": "2.14.0",
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": true,
            "version": "2.16.1",
            "ecosystem": "maven"
          },
          {
            "name": "io.netty:netty-bom",
            "direct": true,
            "version": "4.2.15",
            "ecosystem": "maven"
          },
          {
            "name": "io.swagger:swagger-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.swagger:swagger-core",
            "direct": true,
            "version": "1.6.11",
            "ecosystem": "maven"
          },
          {
            "name": "io.swagger:swagger-models",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "io.swagger:swagger-models",
            "direct": true,
            "version": "1.6.11",
            "ecosystem": "maven"
          },
          {
            "name": "javax.xml.bind:jaxb-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "javax.xml.bind:jaxb-api",
            "direct": true,
            "version": "2.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.cassandra:cassandra-all",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.cassandra:cassandra-all",
            "direct": true,
            "version": "5.0.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.cassandra:java-driver-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.cassandra:java-driver-core",
            "direct": true,
            "version": "4.19.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.cassandra:java-driver-query-builder",
            "direct": true,
            "version": "4.19.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-lang3",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-lang3",
            "direct": true,
            "version": "3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-lang3",
            "direct": true,
            "version": "3.20.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-text",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.commons:commons-text",
            "direct": true,
            "version": "1.15.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpasyncclient-osgi",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpasyncclient-osgi",
            "direct": true,
            "version": "4.1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpclient",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpclient",
            "direct": true,
            "version": "4.5.13",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpclient-osgi",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpclient-osgi",
            "direct": true,
            "version": "4.5.13",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpcore",
            "direct": true,
            "version": "4.4.14",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpcore-nio",
            "direct": true,
            "version": "4.4.14",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpcore-osgi",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.httpcomponents:httpcore-osgi",
            "direct": true,
            "version": "4.4.14",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.wagon:wagon-ssh",
            "direct": true,
            "version": "2.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctorj",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.asciidoctor:asciidoctorj",
            "direct": true,
            "version": "2.5.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.assertj:assertj-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.assertj:assertj-core",
            "direct": true,
            "version": "2.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.assertj:assertj-core",
            "direct": true,
            "version": "3.27.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.bouncycastle:bc-jdk18on-bom",
            "direct": true,
            "version": "1.84",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.groovy:groovy-all",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.groovy:groovy-all",
            "direct": true,
            "version": "2.1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.groovy:groovy-all",
            "direct": true,
            "version": "2.4.21",
            "ecosystem": "maven"
          },
          {
            "name": "org.easytesting:fest-assert-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.easytesting:fest-assert-core",
            "direct": true,
            "version": "2.0M10",
            "ecosystem": "maven"
          },
          {
            "name": "org.easytesting:fest-assert-core",
            "direct": true,
            "version": "2.0M8",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty.websocket:websocket-jetty-server",
            "direct": true,
            "version": "11.0.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty:jetty-server",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty:jetty-server",
            "direct": true,
            "version": "11.0.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty:jetty-servlet",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty:jetty-servlet",
            "direct": true,
            "version": "11.0.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.grizzly:grizzly-framework",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.grizzly:grizzly-http-server",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.grizzly:grizzly-http-server",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.grizzly:grizzly-http-servlet",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.grizzly:grizzly-http-servlet",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.grizzly:grizzly-websockets",
            "direct": true,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.hdrhistogram:HdrHistogram",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.hdrhistogram:HdrHistogram",
            "direct": true,
            "version": "2.1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.json:json",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.json:json",
            "direct": true,
            "version": "20231013",
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino",
            "direct": true,
            "version": "1.7.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino",
            "direct": true,
            "version": "1.7.15.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino-engine",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino-engine",
            "direct": true,
            "version": "1.7.15.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-csv",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-csv",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-elasticsearch",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-elasticsearch",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-jdbc",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-jdbc",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-jms",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-json",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-splunk",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-syslog",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:handler-syslog",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:json",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.audit:json",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.auth-filters.authz-filter:framework",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.auth-filters.authz-filter:framework",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.auth-filters.authz-filter:framework-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.auth-filters.authz-filter:framework-api",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:iwa-module",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:jwt-session-module",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:openam-session-module",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.authn-filter.jaspi-modules:openid-connect-module",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.authn-filter:jaspi-runtime",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.authn-filter:jaspi-runtime",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.bloomfilter:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.bloomfilter:monitoring",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.guice:core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.guice:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.guice:servlet",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.guice:test",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.guice:test",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:client-apache-async",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:client-apache-async",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:client-apache-common",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:client-apache-common",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:client-apache-sync",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:client-apache-sync",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:grizzly",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:oauth2",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:servlet",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:servlet",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.i18n-framework:core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.i18n-framework:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.i18n-framework:slf4j",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.json-crypto:cli",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.json-crypto:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.json-ref:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.json-ref:jackson",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.json-schema:cli",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.json-schema:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.launcher:launcher",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.launcher:launcher-zip",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.persistit:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.script:common",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.script:groovy",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.script:javascript",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:core",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:json",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:stages",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:stages",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backbone",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backbone",
            "direct": true,
            "version": "1.1.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backbone-relational",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backbone-relational",
            "direct": true,
            "version": "0.9.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backbone.paginator.min",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backbone.paginator.min",
            "direct": true,
            "version": "2.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid-filter.min",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid-filter.min",
            "direct": true,
            "version": "0.3.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid-paginator.min",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid-paginator.min",
            "direct": true,
            "version": "0.3.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid-select-all",
            "direct": true,
            "version": "0.3.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid.min",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:backgrid.min",
            "direct": true,
            "version": "0.3.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:bootstrap",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:bootstrap",
            "direct": true,
            "version": "3.3.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:bootstrap-dialog",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:bootstrap-dialog",
            "direct": true,
            "version": "1.34.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:dragula",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:dragula",
            "direct": true,
            "version": "3.6.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:font-awesome",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:font-awesome",
            "direct": true,
            "version": "4.5.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:form2js",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:form2js",
            "direct": true,
            "version": "2.0-769718a",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:handlebars",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:handlebars",
            "direct": true,
            "version": "4.7.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:i18next",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:i18next",
            "direct": true,
            "version": "1.7.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:jquery",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:jquery",
            "direct": true,
            "version": "3.7.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:jquery.ba-dotimeout",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:jquery.ba-dotimeout",
            "direct": true,
            "version": "1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:jquery.placeholder",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:jquery.placeholder",
            "direct": true,
            "version": "2.0.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:js2form",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:js2form",
            "direct": true,
            "version": "2.0-769718a",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:lodash",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:lodash",
            "direct": true,
            "version": "3.10.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:moment",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:moment",
            "direct": true,
            "version": "2.28.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:react",
            "direct": true,
            "version": "15.2.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:react-dom",
            "direct": true,
            "version": "15.2.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:requirejs",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:requirejs",
            "direct": true,
            "version": "2.3.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:selectize",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:selectize",
            "direct": true,
            "version": "0.12.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:sinon",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:sinon",
            "direct": true,
            "version": "15.2.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:spin",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:spin",
            "direct": true,
            "version": "2.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:xdate",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:xdate",
            "direct": true,
            "version": "0.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui:commons",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui:user",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:api-descriptor",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:api-descriptor",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:build-tools",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:cassandra-embedded",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:geo",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:geo",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:httpdump",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-fluent",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-fluent",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-patch",
            "direct": true,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-patch",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource",
            "direct": true,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-descriptor",
            "direct": true,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-descriptor",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-examples",
            "direct": true,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-examples",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-http",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-http",
            "direct": true,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-resource-http",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-web-token",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-web-token",
            "direct": true,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-web-token",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:oauth2-module",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:oauth2-restlet",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:security",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:security",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:test-utils",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:test-utils",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:util",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:util",
            "direct": true,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform:build-tools",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:jcl-over-slf4j",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:jcl-over-slf4j",
            "direct": true,
            "version": "1.7.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:jcl-over-slf4j",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:jul-to-slf4j",
            "direct": true,
            "version": "1.7.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:jul-to-slf4j",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:log4j-over-slf4j",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": "1.7.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-api",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-jdk14",
            "direct": true,
            "version": "1.7.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-jdk14",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-nop",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-nop",
            "direct": true,
            "version": "1.7.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-nop",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-simple",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-simple",
            "direct": true,
            "version": "1.7.25",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-simple",
            "direct": true,
            "version": "2.0.17",
            "ecosystem": "maven"
          },
          {
            "name": "org.testng:testng",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.testng:testng",
            "direct": true,
            "version": "6.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.testng:testng",
            "direct": true,
            "version": "6.14.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.testng:testng",
            "direct": true,
            "version": "6.8.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.testng:testng",
            "direct": true,
            "version": "6.9.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.xerial.snappy:snappy-java",
            "direct": true,
            "version": "1.1.10.5",
            "ecosystem": "maven"
          },
          {
            "name": "args4j:args4j",
            "direct": false,
            "version": "2.0.16",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-annotations",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-annotations",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-core",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.dataformat:jackson-dataformat-csv",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.dataformat:jackson-dataformat-xml",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.dataformat:jackson-dataformat-yaml",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.datatype:jackson-datatype-json-org",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.module:jackson-module-afterburner",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.module:jackson-module-jaxb-annotations",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.module:jackson-module-jsonSchema",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.fasterxml.jackson.module:jackson-module-jsonSchema",
            "direct": false,
            "version": "2.9.10",
            "ecosystem": "maven"
          },
          {
            "name": "com.github.eirslett:frontend-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.github.eirslett:frontend-maven-plugin",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.googlecode.json-simple:json-simple",
            "direct": false,
            "version": "1.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.googlecode.json-simple:json-simple",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.h2database:h2",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.h2database:h2",
            "direct": false,
            "version": "1.4.188",
            "ecosystem": "maven"
          },
          {
            "name": "com.jayway.restassured:rest-assured",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.jayway.restassured:rest-assured",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "maven"
          },
          {
            "name": "com.mycila:license-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.mycila:license-maven-plugin",
            "direct": false,
            "version": "2.6",
            "ecosystem": "maven"
          },
          {
            "name": "com.xebialabs.restito:restito",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.xebialabs.restito:restito",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.zaxxer:HikariCP",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.zaxxer:HikariCP",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "maven"
          },
          {
            "name": "commons-cli:commons-cli",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "commons-cli:commons-cli",
            "direct": false,
            "version": "1.2",
            "ecosystem": "maven"
          },
          {
            "name": "commons-logging:commons-logging",
            "direct": false,
            "version": "1.2",
            "ecosystem": "maven"
          },
          {
            "name": "de.matrixweb.osgi.wrapped:osgi-wrapped-rhino",
            "direct": false,
            "version": "1.7R4",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.inject:jakarta.inject-api",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.inject:jakarta.inject-api",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.jms:jakarta.jms-api",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.servlet:jakarta.servlet-api",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "jakarta.servlet:jakarta.servlet-api",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "javax.jms:javax.jms-api",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "javax.servlet:javax.servlet-api",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "joda-time:joda-time",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "joda-time:joda-time",
            "direct": false,
            "version": "2.1",
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": "4.13.1",
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": "4.13.2",
            "ecosystem": "maven"
          },
          {
            "name": "net.sf.supercsv:super-csv",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "net.sf.supercsv:super-csv",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:maven-bundle-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:maven-bundle-plugin",
            "direct": false,
            "version": "5.1.9",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:maven-scr-plugin",
            "direct": false,
            "version": "1.7.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.configadmin",
            "direct": false,
            "version": "1.9.26",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.fileinstall",
            "direct": false,
            "version": "3.6.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.framework",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.framework",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.metatype",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.scr",
            "direct": false,
            "version": "2.1.20",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.shell",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.webconsole",
            "direct": false,
            "version": "5.0.18",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.felix:org.apache.felix.webconsole.plugins.ds",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.doxia:doxia-module-markdown",
            "direct": false,
            "version": "1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugin-testing:maven-plugin-testing-harness",
            "direct": false,
            "version": "3.3.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugin-tools:maven-plugin-annotations",
            "direct": false,
            "version": "3.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugin-tools:maven-plugin-annotations",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-antrun-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-antrun-plugin",
            "direct": false,
            "version": "1.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-assembly-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-assembly-plugin",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-changelog-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-checkstyle-plugin",
            "direct": false,
            "version": "2.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-checkstyle-plugin",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-clean-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-clean-plugin",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": "3.13.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-dependency-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-dependency-plugin",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-dependency-plugin",
            "direct": false,
            "version": "2.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-dependency-plugin",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-dependency-plugin",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-deploy-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-deploy-plugin",
            "direct": false,
            "version": "3.0.0-M1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-docck-plugin",
            "direct": false,
            "version": "1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-eclipse-plugin",
            "direct": false,
            "version": "2.9",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-enforcer-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-enforcer-plugin",
            "direct": false,
            "version": "3.0.0-M2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-failsafe-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-failsafe-plugin",
            "direct": false,
            "version": "3.0.0-M3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-gpg-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-gpg-plugin",
            "direct": false,
            "version": "1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-gpg-plugin",
            "direct": false,
            "version": "1.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-install-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-install-plugin",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-install-plugin",
            "direct": false,
            "version": "2253",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-install-plugin",
            "direct": false,
            "version": "3.0.0-M1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-invoker-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-invoker-plugin",
            "direct": false,
            "version": "1.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jar-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jar-plugin",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jarsigner-plugin",
            "direct": false,
            "version": "1.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": "2.9",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": "3.12.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jxr-plugin",
            "direct": false,
            "version": "2.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jxr-plugin",
            "direct": false,
            "version": "2.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-plugin-plugin",
            "direct": false,
            "version": "2.4.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-plugin-plugin",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-pmd-plugin",
            "direct": false,
            "version": "2.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-pmd-plugin",
            "direct": false,
            "version": "3.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-project-info-reports-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-project-info-reports-plugin",
            "direct": false,
            "version": "2.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-project-info-reports-plugin",
            "direct": false,
            "version": "2.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-project-info-reports-plugin",
            "direct": false,
            "version": "2.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-release-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-release-plugin",
            "direct": false,
            "version": "3.0.0-M7",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-remote-resources-plugin",
            "direct": false,
            "version": "1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-resources-plugin",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-scm-plugin",
            "direct": false,
            "version": "1.9.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-shade-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-shade-plugin",
            "direct": false,
            "version": "1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-shade-plugin",
            "direct": false,
            "version": "2.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-shade-plugin",
            "direct": false,
            "version": "3.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-site-plugin",
            "direct": false,
            "version": "1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-site-plugin",
            "direct": false,
            "version": "3.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-source-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-source-plugin",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-war-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-war-plugin",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.wagon:wagon-provider-api",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-compat",
            "direct": false,
            "version": "3.8.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-core",
            "direct": false,
            "version": "3.8.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-model",
            "direct": false,
            "version": "3.8.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-plugin-api",
            "direct": false,
            "version": "2.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-plugin-api",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-plugin-api",
            "direct": false,
            "version": "3.5.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-plugin-api",
            "direct": false,
            "version": "3.8.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-project",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven:maven-settings",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.servicemix.bundles:org.apache.servicemix.bundles.javax-inject",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.servicemix.bundles:org.apache.servicemix.bundles.rhino",
            "direct": false,
            "version": "1.7R4_1",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.cargo:cargo-maven3-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.cargo:cargo-maven3-plugin",
            "direct": false,
            "version": "1.10.20",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.gmaven:gmaven-plugin",
            "direct": false,
            "version": "1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:build-helper-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:build-helper-maven-plugin",
            "direct": false,
            "version": "1.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:build-helper-maven-plugin",
            "direct": false,
            "version": "1.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:cobertura-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:cobertura-maven-plugin",
            "direct": false,
            "version": "2.7",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:findbugs-maven-plugin",
            "direct": false,
            "version": "2.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:findbugs-maven-plugin",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:jslint-maven-plugin",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:license-maven-plugin",
            "direct": false,
            "version": "1.16",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:rmic-maven-plugin",
            "direct": false,
            "version": "1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:rmic-maven-plugin",
            "direct": false,
            "version": "1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.plexus:plexus-archiver",
            "direct": false,
            "version": "4.8.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.plexus:plexus-digest",
            "direct": false,
            "version": "1.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.plexus:plexus-maven-plugin",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.plexus:plexus-utils",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.plexus:plexus-xml",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.easytesting:fest-assert",
            "direct": false,
            "version": "1.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty:jetty-maven-plugin",
            "direct": false,
            "version": "9.2.1.v20140609",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.jetty:jetty-maven-plugin",
            "direct": false,
            "version": "9.2.13.v20150730",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.m2e:lifecycle-mapping",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.wst.jsdt.debug:rhino.debugger",
            "direct": false,
            "version": "1.0.600.v201604292217",
            "ecosystem": "maven"
          },
          {
            "name": "org.eclipse.wst.jsdt.debug:transport",
            "direct": false,
            "version": "1.0.300.v201502261613",
            "ecosystem": "maven"
          },
          {
            "name": "org.freemarker:freemarker",
            "direct": false,
            "version": "2.3.22",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish.corba:rmic",
            "direct": false,
            "version": "4.2.0-b007",
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish:javax.security.auth.message",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.glassfish:javax.security.auth.message",
            "direct": false,
            "version": "3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.hamcrest:hamcrest-core",
            "direct": false,
            "version": "1.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.mcraig:jcite",
            "direct": false,
            "version": "1.13.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-all",
            "direct": false,
            "version": "1.10.19",
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.mockito:mockito-core",
            "direct": false,
            "version": "2.23.4",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.auth-filters.authz-filter.modules:oauth2-module",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework.examples:http-descriptor-example",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:binding-test-utils",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.http-framework:binding-test-utils",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.i18n-framework:maven-plugin",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:custom-stage",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.selfservice:example-ui",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:CodeMirror",
            "direct": false,
            "version": "4.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:less",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:qunit",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:qunit",
            "direct": false,
            "version": "2.20.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons.ui.libs:titatoggle",
            "direct": false,
            "version": "1.2.6",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:authz-framework",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:authz-framework-api",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:doc-maven-plugin",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-core",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-csv",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-csv",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-elasticsearch",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-elasticsearch",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-jdbc",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-jdbc",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-jms",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-jms",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-json",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-splunk",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-syslog",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-handler-syslog",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-json",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-audit-json",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-authz-oauth2-module",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-authz-oauth2-restlet",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-bloomfilter-core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-bom",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-jaspi-iwa-module",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-jaspi-jwt-session-module",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-jaspi-openam-session-module",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-jaspi-openid-connect-module",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-jaspi-runtime",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-selfservice-core",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-selfservice-json",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-selfservice-stages",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-test-utils",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-test-utils",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-util",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:forgerock-util",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-crypto-cli",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-crypto-core",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-ref-core",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-ref-jackson",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-schema-cli",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:json-schema-core",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:maven-external-dependency-plugin",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:maven-external-dependency-plugin",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:maven-external-dependency-plugin",
            "direct": false,
            "version": "3.0.5-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:maven-external-dependency-plugin",
            "direct": false,
            "version": "3.2.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.commons:script-common",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-client-apache-async",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-client-apache-async",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-client-apache-common",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-client-apache-sync",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-http-core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-http-core",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-http-servlet",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.http:chf-http-servlet",
            "direct": false,
            "version": "21.0.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.maven.plugins:javadoc-updater-maven-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.openidentityplatform.maven.plugins:javadoc-updater-maven-plugin",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.ops4j.base:ops4j-base-spi",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.ops4j.pax.swissbox:pax-swissbox-extender",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.ops4j.pax.web:pax-web-jetty-bundle",
            "direct": false,
            "version": "1.1.10",
            "ecosystem": "maven"
          },
          {
            "name": "org.osgi:org.osgi.core",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.osgi:org.osgi.core",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.osgi:org.osgi.core",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.ow2.asm:asm",
            "direct": false,
            "version": "7.3.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:osgi-over-slf4j",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.slf4j:slf4j-jcl",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.sonatype.central:central-publishing-maven-plugin",
            "direct": false,
            "version": "0.8.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.twdata.maven:mojo-executor",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "maven"
          },
          {
            "name": "org.zeroturnaround:jrebel-maven-plugin",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "maven"
          },
          {
            "name": "es5-ext",
            "direct": false,
            "version": "0.10.53",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "4.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-formatter-warning-summary",
            "direct": false,
            "version": "^1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "grunt",
            "direct": false,
            "version": "1.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "grunt",
            "direct": false,
            "version": "1.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-cli",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-contrib-less",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-contrib-qunit",
            "direct": false,
            "version": "10.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-contrib-requirejs",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-contrib-watch",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-contrib-watch",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-eslint",
            "direct": false,
            "version": "17.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-eslint",
            "direct": false,
            "version": "19.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-notify",
            "direct": false,
            "version": "0.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "grunt-sync",
            "direct": false,
            "version": "0.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "jsdoc",
            "direct": false,
            "version": "3.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "less-plugin-clean-css",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "rimraf",
            "direct": false,
            "version": "2.5.3",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 530,
        "direct_count": 259,
        "indirect_count": 271
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 254,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 19,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 4,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "matthew-swift",
          "commits": 1232,
          "avatar_url": "https://avatars.githubusercontent.com/u/7744942?v=4"
        },
        {
          "type": "User",
          "login": "brmiller",
          "commits": 570,
          "avatar_url": "https://avatars.githubusercontent.com/u/2447864?v=4"
        },
        {
          "type": "User",
          "login": "vharseko",
          "commits": 542,
          "avatar_url": "https://avatars.githubusercontent.com/u/6818498?v=4"
        },
        {
          "type": "User",
          "login": "jakefeasel",
          "commits": 371,
          "avatar_url": "https://avatars.githubusercontent.com/u/1343640?v=4"
        },
        {
          "type": "User",
          "login": "nathanlws",
          "commits": 335,
          "avatar_url": "https://avatars.githubusercontent.com/u/682357?v=4"
        },
        {
          "type": "User",
          "login": "akiban-build",
          "commits": 216,
          "avatar_url": "https://avatars.githubusercontent.com/u/2034454?v=4"
        },
        {
          "type": "User",
          "login": "laurentvaills",
          "commits": 209,
          "avatar_url": "https://avatars.githubusercontent.com/u/724346?v=4"
        },
        {
          "type": "User",
          "login": "ForgeRocker",
          "commits": 135,
          "avatar_url": "https://avatars.githubusercontent.com/u/36661694?v=4"
        },
        {
          "type": "User",
          "login": "jlemay86",
          "commits": 134,
          "avatar_url": "https://avatars.githubusercontent.com/u/48571877?v=4"
        },
        {
          "type": "User",
          "login": "sauthieg",
          "commits": 129,
          "avatar_url": "https://avatars.githubusercontent.com/u/128513?v=4"
        }
      ],
      "contributors_sampled": 65,
      "top_contributor_share": 0.235
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "build.yml",
        "codeql.yml",
        "deploy.yml",
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".eslintrc"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 4,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 9,
            "reason": "Found 29/30 approved changesets -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 13 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 9,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool detected but not run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 7,
            "reason": "3 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "6e401980df01af4385e9c3ed4b68857521fdb534",
        "ran_at": "2026-07-25T17:05:55Z",
        "aggregate_score": 5.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T13:21:33Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-24T11:45:31Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/OpenIdentityPlatform/commons",
    "host": "github.com",
    "name": "commons",
    "owner": "OpenIdentityPlatform"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": "High-Risk Jurisdiction Policy applies a 75% multiplier to weighted overall health and gives it an At risk ceiling of 49.",
      "notes": [
        {
          "code": "jurisdiction_overall_adjustment",
          "params": {
            "cap": 49,
            "pct": 75
          }
        }
      ],
      "value": 49,
      "inputs": {
        "security": 46,
        "vitality": 87,
        "community": 33,
        "governance": 86,
        "engineering": 70,
        "high_risk_jurisdiction_cap": 49,
        "high_risk_jurisdiction_multiplier": 75,
        "weighted_overall_before_jurisdiction": 67,
        "overall_after_jurisdiction_multiplier": 50
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 87,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "commits_last_year": 153,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 22
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "22/52 weeks with commits",
                "points": 15.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 22
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "153 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 153
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 41,
              "latest_release_tag": "3.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 9,
              "mean_days_between_releases": 43.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "41 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 41
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 9 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~43.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 43.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 33,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "forks": 14,
              "stars": 5,
              "watchers": 6,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "14 forks",
                "points": 9.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 14
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "6 watchers",
                "points": 3.9,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 44,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file present, not a recognized license",
                "points": 16.9,
                "status": "partial",
                "details": [
                  {
                    "code": "license_custom",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "excellent",
        "name": "Sustainability & Governance",
        "value": 86,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "bus_factor": 4,
              "contributors_sampled": 65,
              "top_contributor_share": 0.235
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "4 contributor(s) cover half of all commits",
                "points": 43.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 24% of commits",
                "points": 17.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 24
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "65 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 65
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 13 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "merged_prs": 254,
              "open_issues": 0,
              "closed_issues": 19,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "254/285 decided PRs merged",
                "points": 34.1,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 254,
                      "decided": 285
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 29/30 approved changesets -- score normalized to 9",
                "points": 13.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "followers": 288,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "OpenIdentityPlatform",
              "public_repos": 36,
              "account_age_days": 3272
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "288 followers of OpenIdentityPlatform",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 288,
                      "login": "OpenIdentityPlatform"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "36 public repos, account ~8 yr old",
                "points": 23.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 36
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 8
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "org.openidentityplatform.commons:build-tools",
                "org.openidentityplatform.commons:cassandra-embedded"
              ],
              "ecosystems": "maven",
              "any_deprecated": false,
              "min_days_since_publish": 9
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on maven",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "maven"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 9 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 9
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "33 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 33
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 70,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".eslintrc",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 46,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized. High-Risk Jurisdiction Policy applies a 75% multiplier to Security posture and gives it an At risk ceiling of 49.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "jurisdiction_posture_adjustment",
                "params": {
                  "cap": 49,
                  "pct": 75
                }
              }
            ],
            "value": 40,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.4,
              "high_risk_jurisdiction_cap": 49,
              "high_risk_jurisdiction_multiplier": 75,
              "security_posture_after_multiplier": 40,
              "security_posture_before_jurisdiction": 54
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 29/30 approved changesets -- score normalized to 9",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 13 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected but not run on all commits",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "3 existing vulnerabilities detected",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "good",
            "name": "Dependency advisories",
            "note": "Matched the maven:org.openidentityplatform.commons:build-tools@3.1.2 runtime dependency closure — what installing the published package pulls in — 3 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "maven:org.openidentityplatform.commons:build-tools@3.1.2",
                  "assessed": 3
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 3,
              "unassessed_packages": 0,
              "affected_by_severity": "high 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: org.testng:testng 6.14.3 (high 7.8)",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "org.testng:testng 6.14.3 (high 7.8)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 1343 days ago",
                "points": 33.5,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 1343
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 3,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "good",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 75,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": true,
              "exposures": [
                {
                  "role": "contributor_organization",
                  "count": 1,
                  "country": "Russia"
                }
              ],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 6
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "Russia: contributor_organization (1)",
                "points": 75,
                "status": "partial",
                "details": [
                  {
                    "code": "jurisdiction_exposure",
                    "params": {
                      "role": "contributor_organization",
                      "count": 1,
                      "country": "Russia"
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.98,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [
                "bloomfilter/core/pom.xml",
                "bloomfilter/monitoring/pom.xml",
                "bloomfilter/pom.xml",
                "build-tools/pom.xml",
                "cassandra-embedded/pom.xml",
                "commons/audit/core/pom.xml",
                "commons/audit/handler-csv/pom.xml",
                "commons/audit/handler-elasticsearch/pom.xml",
                "commons/audit/handler-jdbc/pom.xml",
                "commons/audit/handler-jms/pom.xml",
                "commons/audit/handler-json/pom.xml",
                "commons/audit/handler-splunk/pom.xml",
                "commons/audit/handler-syslog/pom.xml",
                "commons/audit/json/pom.xml",
                "commons/audit/pom.xml",
                "commons/audit/servlet/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-functional-tests/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-modules/iwa-module/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-modules/jwt-session-module/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-modules/openam-session-module/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-modules/openid-connect-module/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-modules/pom.xml",
                "commons/auth-filters/authn-filter/jaspi-runtime/pom.xml",
                "commons/auth-filters/authn-filter/pom.xml",
                "commons/auth-filters/authz-filter/framework-api/pom.xml",
                "commons/auth-filters/authz-filter/framework-functional-tests/pom.xml",
                "commons/auth-filters/authz-filter/framework/pom.xml",
                "commons/auth-filters/authz-filter/modules/oauth2-module/pom.xml",
                "commons/auth-filters/authz-filter/modules/pom.xml",
                "commons/auth-filters/authz-filter/pom.xml",
                "commons/auth-filters/pom.xml",
                "commons/doc-common-content/pom.xml",
                "commons/doc-default-branding/pom.xml",
                "commons/doc-maven-plugin/pom.xml",
                "commons/doc-maven-plugin/src/test/resources/antora/pom.xml",
                "commons/doc-maven-plugin/src/test/resources/unit/pom.xml",
                "commons/geo/pom.xml",
                "commons/http-framework/benchmarks/pom.xml",
                "commons/http-framework/binding-test-utils/pom.xml",
                "commons/http-framework/client-apache-async/pom.xml",
                "commons/http-framework/client-apache-common/pom.xml",
                "commons/http-framework/client-apache-sync/pom.xml",
                "commons/http-framework/core/pom.xml",
                "commons/http-framework/examples/descriptor-example/pom.xml",
                "commons/http-framework/examples/pom.xml",
                "commons/http-framework/examples/servlet-example/pom.xml",
                "commons/http-framework/grizzly/pom.xml",
                "commons/http-framework/oauth2/pom.xml",
                "commons/http-framework/pom.xml",
                "commons/http-framework/servlet/pom.xml",
                "commons/httpdump/pom.xml",
                "commons/json-crypto/cli/pom.xml",
                "commons/json-crypto/core/pom.xml",
                "commons/json-crypto/pom.xml",
                "commons/json-fluent/pom.xml",
                "commons/json-ref/core/pom.xml",
                "commons/json-ref/jackson/pom.xml",
                "commons/json-ref/pom.xml",
                "commons/json-schema/cli/pom.xml",
                "commons/json-schema/core/pom.xml",
                "commons/json-schema/pom.xml",
                "commons/json-web-token/pom.xml",
                "commons/launcher/launcher-zip/pom.xml",
                "commons/launcher/launcher/pom.xml",
                "commons/launcher/pom.xml",
                "commons/pom.xml",
                "commons/rest/api-descriptor/pom.xml",
                "commons/rest/json-resource-examples/pom.xml",
                "commons/rest/json-resource-http/pom.xml",
                "commons/rest/json-resource/pom.xml",
                "commons/rest/pom.xml",
                "commons/rest/rest-docbook/pom.xml",
                "commons/security/pom.xml",
                "commons/selfservice/core/pom.xml",
                "commons/selfservice/custom-stage/pom.xml",
                "commons/selfservice/example-ui/pom.xml",
                "commons/selfservice/example/pom.xml",
                "commons/selfservice/json/pom.xml",
                "commons/selfservice/pom.xml",
                "commons/selfservice/stages/pom.xml",
                "commons/util/pom.xml",
                "commons/util/test-utils/pom.xml",
                "commons/util/util/pom.xml",
                "commons/xcite-maven-plugin/pom.xml",
                "commons/xcite-maven-plugin/src/it/xcite/pom.xml",
                "guice/core/pom.xml",
                "guice/pom.xml",
                "guice/servlet/pom.xml",
                "guice/test/pom.xml",
                "i18n-framework/core/pom.xml",
                "i18n-framework/jul/pom.xml",
                "i18n-framework/maven-plugin/pom.xml",
                "i18n-framework/pom.xml",
                "i18n-framework/slf4j/pom.xml",
                "maven-external-dependency-plugin/maven-external-dependency-plugin-test/pom.xml",
                "maven-external-dependency-plugin/maven-external-dependency-plugin/pom.xml",
                "persistit/core/pom.xml",
                "persistit/pom.xml",
                "persistit/ui/pom.xml",
                "pom.xml",
                "script/common/pom.xml",
                "script/groovy/pom.xml",
                "script/javascript/pom.xml",
                "script/pom.xml",
                "ui/commons/pom.xml",
                "ui/mock/pom.xml",
                "ui/pom.xml",
                "ui/user/pom.xml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "bloomfilter/core/pom.xml, bloomfilter/monitoring/pom.xml, bloomfilter/pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "bloomfilter/core/pom.xml, bloomfilter/monitoring/pom.xml, bloomfilter/pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".eslintrc",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Java (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Java",
              "largest_source_bytes": 275910,
              "source_files_sampled": 2019,
              "oversized_source_files": 16
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Java (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "16/2019 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 2019,
                      "oversized": 16
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "example",
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "example, examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "example, examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-25T17:06:30.976990Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/OpenIdentityPlatform/commons.svg",
  "full_name": "OpenIdentityPlatform/commons",
  "license_state": "custom",
  "license_spdx": null
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Maven.