公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 01:57 UTC

SwissDataScienceCenter / renku-data-services

Services that handle reading and writing data from a database

PythonApache-2.0★ 8 星标⑂ 2 复刻始于 2023年4月在 GitHub 上查看 ↗

SwissDataScienceCenter/renku-data-services 的健康指数为 100 分中的 70 分,处于「良好」区间。 其得分最高的类别是Vitality(99/100),最低的是Community & Adoption(42/100)。 最近一次更新在今天。 近期的大部分工作由 2 位贡献者完成。

70
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

70
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

132 关注者135 个公开仓库始于 2017年1月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
PyPIsecrets_storage指向其他仓库——不计分1.0.0123182 天前configurationhashicorp-vaultsecretsvault

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

99优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
35.3/36提交节奏 — 52 周中有 51 周有提交
18/18提交量 — 最近一年 209 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year209
human_commit_share0.91
days_since_last_push0
active_weeks_last_year51

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 100 个发布版本
36/36发布时效 — 最近一次发布版本于 1 天前
27/27发布节奏 — 约每 8.4 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count100
latest_release_tagv0.79.0
releases_from_tags
days_since_latest_release1
mean_days_between_releases8.4
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

42存在风险 · 占总体的 18%
评分方式
13.7/60星标 — 8 个星标
0/25复刻 — 2 个复刻
3.9/15关注者 — 6 位关注者
所用输入
forks2
stars8
watchers6
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

70良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

70良好 · 占总体的 24%
评分方式
25.2/54巴士系数 — 2 位贡献者贡献了半数提交
15.6/22.5提交分布 — 头号贡献者编写了 31% 的提交
13.5/13.5贡献者广度 — 16 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 10 contributing companies or organizations
所用输入
bus_factor2
contributors_sampled16
top_contributor_share0.308
评分方式
29.1/46.8议题解决 — 62% 的议题已关闭
32.3/38.3PR 接受 — 已裁定的 PR 中 802/950 已合并
15/15OpenSSF Scorecard:Code-Review — all changesets reviewed
所用输入
merged_prs802
open_issues147
closed_issues242
issue_closed_ratio0.622
closed_unmerged_prs148
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
15.3/25所有者影响力 — SwissDataScienceCenter 有 132 位关注者
25/25既往记录 — 135 个公开仓库,账户约 9 年
所用输入
followers132
owner_typeOrganization
is_verified
owner_loginSwissDataScienceCenter
public_repos135
account_age_days3,481

工程质量

基础的工程与文档实践是否到位?

76良好 · 占总体的 20%

工程实践

94优秀
评分方式
24/24CI 工作流 — 3 个工作流
24/24存在测试
16/16Linter 配置
9.6/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

50中等
评分方式
30/30README
0/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

56中等 · 占总体的 16%

安全态势

64中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
2.5/2.5Contributors — project has 10 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 65 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate6.4
已排除计分(无数据或不适用):branch_protection, signed_releases。 其余权重已重新归一化。
评分方式
3.4/35直接依赖不含已知公告 — 11 个受影响:authlib 1.5.2 (critical 9.1), authlib 1.6.0 (critical 9.1), cryptography 44.0.2 (high 7.5),另有 8 个
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
14/40没有长期未处理的公告 — 10 个携带公告的软件包超过 90 天未处理;最早一条发布于 431 天前
所用输入
sourceosv
advisories150
affected_packages27
assessed_packages212
unassessed_packages0
affected_by_severitycritical 4, high 14, moderate 7, low 1, unknown 1
direct_affected_packages11
已排除计分(无数据或不适用):间接依赖不含已知公告。 其余权重已重新归一化。 已将 212 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

66中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 91 次人类提交中有 91 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置
11/11静态类型检查 — bases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed
10/10可复现环境 — devcontainer, Dockerfile, Nix, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 9 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilespoetry.lock
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configsbases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.09
评分方式
27/45可类型检查的代码 — Python,已配置类型检查(bases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed)
53.9/55可控的文件大小 — 采样的 537 个源文件中有 11 个超过 60KB
所用输入
primary_languagePython
largest_source_bytes223,775
source_files_sampled537
oversized_source_files11

关键数据

8GitHub 星标
16贡献者
209最近 12 个月提交数
0距最近推送天数
100发布版本数
2巴士系数(bus factor)
147开放议题
PyPI软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch pypi package 'renku-data-services' from its registry
  • Could not fetch pypi package 'k8s_cache' from its registry
  • pypi package 'secrets_storage' points at a different repository (https://github.com/bigbag/secrets-storage); excluded from ecosystem scoring
  • Could not fetch pypi package 'renku_data_tasks' from its registry
  • Could not fetch pypi package 'renku_data_service' from its registry
  • deps.dev does not index pypi:secrets_storage@1.0.0; advisories assessed against the repository dependency graph instead
  • Advisory severity resolved for 120 of 124 advisories (lookup cap); the remainder are reported as unknown severity

更多细节

Star 与 Fork 历史 0 ★ / 2 ⇿
0Star
2Fork

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

111222212023-052023-122024-07

每个点涵盖 2 天。

OpenSSF Scorecard 6.4 / 10
6.4综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 01:57 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
10Contributorsproject has 10 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities65 existing vulnerabilities detected
直接依赖 166
注册表软件包版本约束清单文件
PyPIsanic^25.12.0pyproject.toml
PyPIpydantic^2.10.6pyproject.toml
PyPIsqlalchemy^2.0.38pyproject.toml
PyPIalembic^1.14.1pyproject.toml
PyPIasyncpg^0.30.0pyproject.toml
PyPIpyjwt^2.10.1pyproject.toml
PyPItenacity^9.0.0pyproject.toml
PyPIhttpx<0.29pyproject.toml
PyPIkubernetes^31.0.0pyproject.toml
PyPIpython-ulid^3.0.0pyproject.toml
PyPIpython-gitlab^5.6.0pyproject.toml
PyPIpsycopg^3.2.3pyproject.toml
PyPIurllib3^2.6.0pyproject.toml
PyPIdeepmerge^2.0pyproject.toml
PyPIauthlib^1.5.0pyproject.toml
PyPIundictify^0.11.3pyproject.toml
PyPIprometheus-sanic^3.0.0pyproject.toml
PyPIprometheus_client^0.7.1pyproject.toml
PyPImarshmallow^3.26.1pyproject.toml
PyPIescapism^1.0.1pyproject.toml
PyPIsentry-sdk^2.22.0pyproject.toml
PyPIauthzed^1.20.0pyproject.toml
PyPIcryptography^44.0.1pyproject.toml
PyPIsetuptools^75.8.2pyproject.toml
PyPIkr8s^0.20.7pyproject.toml
PyPIpython-box^7.0.1pyproject.toml
PyPIwerkzeug^3.1.3pyproject.toml
PyPItoml^0.10.2pyproject.toml
PyPIaiofiles^24.1.0pyproject.toml
PyPIprotobuf^5.29.3pyproject.toml
PyPIpoetry^2.1.1pyproject.toml
PyPIparsy^2.1pyproject.toml
PyPIsanic-ext^25.12.0pyproject.toml
PyPIposthog^3.21.0pyproject.toml
PyPImarkdown-code-runner^2.2.0pyproject.toml
PyPIsanic^25.12.0projects/k8s_watcher/pyproject.toml
PyPIpydantic^2.10.6projects/k8s_watcher/pyproject.toml
PyPIsqlalchemy^2.0.38projects/k8s_watcher/pyproject.toml
PyPIalembic^1.14.1projects/k8s_watcher/pyproject.toml
PyPIasyncpg^0.30.0projects/k8s_watcher/pyproject.toml
PyPIpyjwt^2.10.1projects/k8s_watcher/pyproject.toml
PyPItenacity^9.0.0projects/k8s_watcher/pyproject.toml
PyPIhttpx<0.29projects/k8s_watcher/pyproject.toml
PyPIkubernetes^31.0.0projects/k8s_watcher/pyproject.toml
PyPIpython-ulid^3.0.0projects/k8s_watcher/pyproject.toml
PyPIpython-gitlab^5.6.0projects/k8s_watcher/pyproject.toml
PyPIpsycopg^3.2.3projects/k8s_watcher/pyproject.toml
PyPIurllib3^2.6.0projects/k8s_watcher/pyproject.toml
PyPIdeepmerge^2.0projects/k8s_watcher/pyproject.toml
PyPIauthlib^1.5.0projects/k8s_watcher/pyproject.toml
PyPIundictify^0.11.3projects/k8s_watcher/pyproject.toml
PyPIprometheus-sanic^3.0.0projects/k8s_watcher/pyproject.toml
PyPIsentry-sdk^2.22.0projects/k8s_watcher/pyproject.toml
PyPIauthzed^1.20.0projects/k8s_watcher/pyproject.toml
PyPIsetuptools^75.8.2projects/k8s_watcher/pyproject.toml
PyPIaiofiles^24.1.0projects/k8s_watcher/pyproject.toml
PyPIprotobuf^5.29.3projects/k8s_watcher/pyproject.toml
PyPIcryptography^44.0.1projects/k8s_watcher/pyproject.toml
PyPImarshmallow^3.26.1projects/k8s_watcher/pyproject.toml
PyPIescapism^1.0.1projects/k8s_watcher/pyproject.toml
PyPIkr8s^0.20.7projects/k8s_watcher/pyproject.toml
PyPIpython-box^7.0.1projects/k8s_watcher/pyproject.toml
PyPIwerkzeug^3.1.3projects/k8s_watcher/pyproject.toml
PyPItoml^0.10.2projects/k8s_watcher/pyproject.toml
PyPIparsy^2.1projects/k8s_watcher/pyproject.toml
PyPIsanic-ext^25.12.0projects/k8s_watcher/pyproject.toml
PyPImarkdown-code-runner^2.2.0projects/k8s_watcher/pyproject.toml
PyPIsanic^25.12.0projects/renku_data_service/pyproject.toml
PyPIpydantic^2.10.6projects/renku_data_service/pyproject.toml
PyPIsqlalchemy^2.0.38projects/renku_data_service/pyproject.toml
PyPIalembic^1.14.1projects/renku_data_service/pyproject.toml
PyPIasyncpg^0.30.0projects/renku_data_service/pyproject.toml
PyPIpyjwt^2.10.1projects/renku_data_service/pyproject.toml
PyPItenacity^9.0.0projects/renku_data_service/pyproject.toml
PyPIhttpx<0.29projects/renku_data_service/pyproject.toml
PyPIkubernetes^31.0.0projects/renku_data_service/pyproject.toml
PyPIpython-ulid^3.0.0projects/renku_data_service/pyproject.toml
PyPIpython-gitlab^5.6.0projects/renku_data_service/pyproject.toml
PyPIpsycopg^3.2.3projects/renku_data_service/pyproject.toml
PyPIurllib3^2.6.0projects/renku_data_service/pyproject.toml
PyPIdeepmerge^2.0projects/renku_data_service/pyproject.toml
PyPIauthlib^1.5.0projects/renku_data_service/pyproject.toml
PyPIundictify^0.11.3projects/renku_data_service/pyproject.toml
PyPIprometheus-sanic^3.0.0projects/renku_data_service/pyproject.toml
PyPIsentry-sdk^2.22.0projects/renku_data_service/pyproject.toml
PyPIauthzed^1.20.0projects/renku_data_service/pyproject.toml
PyPIsetuptools^75.8.2projects/renku_data_service/pyproject.toml
PyPIaiofiles^24.1.0projects/renku_data_service/pyproject.toml
PyPIprotobuf^5.29.3projects/renku_data_service/pyproject.toml
PyPIcryptography^44.0.1projects/renku_data_service/pyproject.toml
PyPImarshmallow^3.26.1projects/renku_data_service/pyproject.toml
PyPIescapism^1.0.1projects/renku_data_service/pyproject.toml
PyPIkr8s^0.20.7projects/renku_data_service/pyproject.toml
PyPIpython-box^7.0.1projects/renku_data_service/pyproject.toml
PyPIwerkzeug^3.1.3projects/renku_data_service/pyproject.toml
PyPItoml^0.10.2projects/renku_data_service/pyproject.toml
PyPIparsy^2.1projects/renku_data_service/pyproject.toml
PyPIsanic-ext^25.12.0projects/renku_data_service/pyproject.toml
PyPIposthog^3.21.0projects/renku_data_service/pyproject.toml
PyPImarkdown-code-runner^2.2.0projects/renku_data_service/pyproject.toml
PyPIsanic^25.12.0projects/renku_data_tasks/pyproject.toml
PyPIpydantic^2.10.6projects/renku_data_tasks/pyproject.toml
PyPIsqlalchemy^2.0.38projects/renku_data_tasks/pyproject.toml
PyPIalembic^1.14.1projects/renku_data_tasks/pyproject.toml
PyPIasyncpg^0.30.0projects/renku_data_tasks/pyproject.toml
PyPIpyjwt^2.10.1projects/renku_data_tasks/pyproject.toml
PyPItenacity^9.0.0projects/renku_data_tasks/pyproject.toml
PyPIhttpx<0.29projects/renku_data_tasks/pyproject.toml
PyPIkubernetes^31.0.0projects/renku_data_tasks/pyproject.toml
PyPIpython-ulid^3.0.0projects/renku_data_tasks/pyproject.toml
PyPIpython-gitlab^5.6.0projects/renku_data_tasks/pyproject.toml
PyPIpsycopg^3.2.3projects/renku_data_tasks/pyproject.toml
PyPIurllib3^2.6.0projects/renku_data_tasks/pyproject.toml
PyPIdeepmerge^2.0projects/renku_data_tasks/pyproject.toml
PyPIauthlib^1.5.0projects/renku_data_tasks/pyproject.toml
PyPIundictify^0.11.3projects/renku_data_tasks/pyproject.toml
PyPIprometheus-sanic^3.0.0projects/renku_data_tasks/pyproject.toml
PyPIsentry-sdk^2.22.0projects/renku_data_tasks/pyproject.toml
PyPIauthzed^1.20.0projects/renku_data_tasks/pyproject.toml
PyPIsetuptools^75.8.2projects/renku_data_tasks/pyproject.toml
PyPIaiofiles^24.1.0projects/renku_data_tasks/pyproject.toml
PyPIprotobuf^5.29.3projects/renku_data_tasks/pyproject.toml
PyPIcryptography^44.0.1projects/renku_data_tasks/pyproject.toml
PyPImarshmallow^3.26.1projects/renku_data_tasks/pyproject.toml
PyPIescapism^1.0.1projects/renku_data_tasks/pyproject.toml
PyPIkr8s^0.20.7projects/renku_data_tasks/pyproject.toml
PyPIpython-box^7.0.1projects/renku_data_tasks/pyproject.toml
PyPIwerkzeug^3.1.3projects/renku_data_tasks/pyproject.toml
PyPItoml^0.10.2projects/renku_data_tasks/pyproject.toml
PyPIparsy^2.1projects/renku_data_tasks/pyproject.toml
PyPIsanic-ext^23.12.0projects/renku_data_tasks/pyproject.toml
PyPIposthog^3.21.0projects/renku_data_tasks/pyproject.toml
PyPImarkdown-code-runner^2.2.0projects/renku_data_tasks/pyproject.toml
PyPIsanic^25.12.0projects/secrets_storage/pyproject.toml
PyPIpydantic^2.10.6projects/secrets_storage/pyproject.toml
PyPIsqlalchemy^2.0.38projects/secrets_storage/pyproject.toml
PyPIalembic^1.14.1projects/secrets_storage/pyproject.toml
PyPIasyncpg^0.30.0projects/secrets_storage/pyproject.toml
PyPIpyjwt^2.10.1projects/secrets_storage/pyproject.toml
PyPItenacity^9.0.0projects/secrets_storage/pyproject.toml
PyPIhttpx<0.29projects/secrets_storage/pyproject.toml
PyPIkubernetes^31.0.0projects/secrets_storage/pyproject.toml
PyPIpython-ulid^3.0.0projects/secrets_storage/pyproject.toml
PyPIpython-gitlab^5.6.0projects/secrets_storage/pyproject.toml
PyPIpsycopg^3.2.3projects/secrets_storage/pyproject.toml
PyPIurllib3^2.6.0projects/secrets_storage/pyproject.toml
PyPIdeepmerge^2.0projects/secrets_storage/pyproject.toml
PyPIauthlib^1.5.0projects/secrets_storage/pyproject.toml
PyPIundictify^0.11.3projects/secrets_storage/pyproject.toml
PyPIprometheus-sanic^3.0.0projects/secrets_storage/pyproject.toml
PyPIsentry-sdk^2.22.0projects/secrets_storage/pyproject.toml
PyPIcryptography^44.0.1projects/secrets_storage/pyproject.toml
PyPIauthzed^1.20.0projects/secrets_storage/pyproject.toml
PyPIsetuptools^75.8.2projects/secrets_storage/pyproject.toml
PyPIaiofiles^24.1.0projects/secrets_storage/pyproject.toml
PyPIprotobuf^5.29.3projects/secrets_storage/pyproject.toml
PyPIescapism^1.0.1projects/secrets_storage/pyproject.toml
PyPIkr8s^0.20.7projects/secrets_storage/pyproject.toml
PyPIpython-box^7.0.1projects/secrets_storage/pyproject.toml
PyPImarshmallow^3.26.1projects/secrets_storage/pyproject.toml
PyPItoml^0.10.2projects/secrets_storage/pyproject.toml
PyPIwerkzeug^3.1.3projects/secrets_storage/pyproject.toml
PyPIparsy^2.1projects/secrets_storage/pyproject.toml
PyPIsanic-ext^25.12.0projects/secrets_storage/pyproject.toml
PyPIposthog^3.21.0projects/secrets_storage/pyproject.toml
PyPImarkdown-code-runner^2.2.0projects/secrets_storage/pyproject.toml
全部依赖 212

来自 GitHub 依赖图的完整解析依赖集合:40 个直接依赖与 172 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
PyPIaiofiles24.1.0直接
PyPIalembic1.15.2直接
PyPIasyncpg0.30.0直接
PyPIauthlib1.5.2直接
PyPIauthlib1.6.0直接
PyPIauthzed1.21.1直接
PyPIcryptography44.0.2直接
PyPIdeepmerge2.0直接
PyPIescapism1.0.1直接
PyPIhttpx0.28.1直接
PyPIkr8s0.20.7直接
PyPIkubernetes31.0.0直接
PyPImarkdown-code-runner2.2.0直接
PyPImarshmallow3.26.1直接
PyPImarshmallow3.26.2直接
PyPIparsy2.1直接
PyPIpoetry2.1.2直接
PyPIposthog3.25.0直接
PyPIprometheus-client0.7.1直接
PyPIprometheus-sanic3.0.0直接
PyPIprotobuf5.29.4直接
PyPIpsycopg3.2.6直接
PyPIpydantic2.11.3直接
PyPIpydantic2.13.4直接
PyPIpyjwt2.12.1直接
PyPIpython-box7.3.2直接
PyPIpython-gitlab5.6.0直接
PyPIpython-ulid3.0.0直接
PyPIsanic25.12.0直接
PyPIsanic-ext23.12.0直接
PyPIsanic-ext25.12.0直接
PyPIsentry-sdk2.26.1直接
PyPIsetuptools75.9.1直接
PyPIsqlalchemy2.0.40直接
PyPItenacity9.1.2直接
PyPItoml0.10.2直接
PyPIundictify0.11.3直接
PyPIurllib32.6.0直接
PyPIurllib32.6.2直接
PyPIwerkzeug3.1.3直接
PyPIaiosqlite0.20.0间接
PyPIannotated-types0.7.0间接
PyPIanyio4.9.0间接
PyPIargcomplete3.6.2间接
PyPIarrow1.3.0间接
PyPIasyncache0.3.1间接
PyPIattrs25.3.0间接
PyPIbackoff2.2.1间接
PyPIbandit1.8.3间接
PyPIblack25.1.0间接
PyPIbuild1.2.2.post1间接
PyPIcachecontrol0.14.2间接
PyPIcachetools5.5.2间接
PyPIcel-python0.2.0间接
PyPIcertifi2025.1.31间接
PyPIcffi1.17.1间接
PyPIcfgv3.4.0间接
PyPIcharset-normalizer3.4.1间接
PyPIcleo2.1.0间接
PyPIclick8.1.8间接
PyPIcolorama0.4.6间接
PyPIcoverage7.8.0间接
PyPIcrashtest0.4.1间接
PyPIdatamodel-code-generator0.57.0间接
PyPIdebugpy1.8.14间接
PyPIdistlib0.3.9间接
PyPIdistro1.9.0间接
PyPIdnspython2.7.0间接
PyPIdulwich0.22.8间接
PyPIdurationpy0.9间接
PyPIemail-validator2.2.0间接
PyPIexecnet2.1.1间接
PyPIfastjsonschema2.21.1间接
PyPIfilelock3.18.0间接
PyPIfindpython0.6.3间接
PyPIfqdn1.5.1间接
PyPIgenson1.3.0间接
PyPIgoogle-auth2.39.0间接
PyPIgoogleapis-common-protos1.70.0间接
PyPIgraphql-core3.2.6间接
PyPIgreenlet3.2.0间接
PyPIgreenlet3.2.1间接
PyPIgrpc-interceptor0.15.4间接
PyPIgrpcio1.71.0间接
PyPIh110.14.0间接
PyPIharfile0.3.0间接
PyPIhtml5tagger1.3.0间接
PyPIhttpcore1.0.8间接
PyPIhttptools0.6.4间接
PyPIhttpx-ws0.7.2间接
PyPIhypothesis6.131.8间接
PyPIhypothesis-graphql0.11.1间接
PyPIhypothesis-jsonschema0.23.1间接
PyPIidentify2.6.10间接
PyPIidna3.10间接
PyPIinflect5.6.2间接
PyPIiniconfig2.1.0间接
PyPIinstaller0.7.0间接
PyPIisoduration20.11.0间接
PyPIisort6.0.1间接
PyPIjaraco-classes3.4.0间接
PyPIjaraco-context6.0.1间接
PyPIjaraco-functools4.1.0间接
PyPIjeepney0.9.0间接
PyPIjinja23.1.6间接
PyPIjmespath1.0.1间接
PyPIjsonpointer3.0.0间接
PyPIjsonschema4.23.0间接
PyPIjsonschema-specifications2025.4.1间接
PyPIjunit-xml1.9间接
PyPIkeyring25.6.0间接
PyPIlark0.12.0间接
PyPImako1.3.10间接
PyPImarkdown-it-py3.0.0间接
PyPImarkupsafe3.0.2间接
PyPImdurl0.1.2间接
PyPImirakuru2.6.0间接
PyPImonotonic1.6间接
PyPImore-itertools10.7.0间接
PyPImsgpack1.1.0间接
PyPImultidict6.4.3间接
PyPImypy1.15.0间接
PyPImypy-extensions1.1.0间接
PyPInodeenv1.9.1间接
PyPIoauthlib3.2.2间接
PyPIpackaging25.0间接
PyPIpackaging26.0间接
PyPIpathspec0.12.1间接
PyPIpbr6.1.1间接
PyPIpbs-installer2025.4.9间接
PyPIpkginfo1.12.1.2间接
PyPIplatformdirs4.3.7间接
PyPIpluggy1.5.0间接
PyPIpoetry-core2.1.2间接
PyPIport-for0.7.4间接
PyPIpre-commit4.2.0间接
PyPIpropcache0.3.1间接
PyPIprotovalidate0.7.1间接
PyPIpsutil7.0.0间接
PyPIpsycopg-binary3.2.6间接
PyPIpyasn10.6.1间接
PyPIpyasn1-modules0.4.2间接
PyPIpycparser2.22间接
PyPIpydantic-core2.33.1间接
PyPIpydantic-core2.46.4间接
PyPIpygments2.19.1间接
PyPIpyproject-hooks1.2.0间接
PyPIpyrate-limiter3.7.0间接
PyPIpytest8.3.5间接
PyPIpytest-asyncio0.21.2间接
PyPIpytest-cov6.1.1间接
PyPIpytest-mock3.14.0间接
PyPIpytest-postgresql6.1.1间接
PyPIpytest-subtests0.14.1间接
PyPIpytest-testmon2.2.0间接
PyPIpytest-xdist3.6.1间接
PyPIpython-dateutil2.9.0.post0间接
PyPIpython-jsonpath1.3.0间接
PyPIpywin32-ctypes0.2.3间接
PyPIpyyaml6.0.2间接
PyPIrapidfuzz3.13.0间接
PyPIreferencing0.36.2间接
PyPIrequests2.32.3间接
PyPIrequests-oauthlib2.0.0间接
PyPIrequests-toolbelt1.0.0间接
PyPIrfc3339-validator0.1.4间接
PyPIrfc39871.3.8间接
PyPIrich14.0.0间接
PyPIrpds-py0.24.0间接
PyPIrsa4.9.1间接
PyPIruamel-yaml0.18.14间接
PyPIruamel-yaml-clib0.2.12间接
PyPIruff0.8.6间接
PyPIsanic-routing23.12.0间接
PyPIsanic-testing24.6.0间接
PyPIschemathesis3.39.7间接
PyPIsecretstorage3.3.3间接
PyPIshellingham1.5.4间接
PyPIsix1.17.0间接
PyPIsniffio1.3.1间接
PyPIsortedcontainers2.4.0间接
PyPIstarlette0.46.2间接
PyPIstarlette-testclient0.4.1间接
PyPIstevedore5.4.1间接
PyPIsyrupy4.9.1间接
PyPItomli2.2.1间接
PyPItomli-w1.2.0间接
PyPItomlkit0.13.2间接
PyPItracerite2.3.1间接
PyPItrove-classifiers2025.4.11.15间接
PyPItypes-aiofiles24.1.0.20250326间接
PyPItypes-python-dateutil2.9.0.20241206间接
PyPItypes-pyyaml6.0.12.20250402间接
PyPItypes-requests2.32.0.20250328间接
PyPItypes-toml0.10.8.20240310间接
PyPItypes-urllib31.26.25.14间接
PyPItyping-extensions4.13.2间接
PyPItyping-extensions4.15.0间接
PyPItyping-inspection0.4.0间接
PyPItyping-inspection0.4.2间接
PyPItzdata2025.2间接
PyPIujson5.10.0间接
PyPIuri-template1.3.0间接
PyPIuvloop0.21.0间接
PyPIvirtualenv20.30.0间接
PyPIwebcolors24.11.1间接
PyPIwebsocket-client1.8.0间接
PyPIwebsockets15.0.1间接
PyPIwsproto1.2.0间接
PyPIxattr1.1.4间接
PyPIyarl1.20.0间接
PyPIzstandard0.23.0间接
依赖安全公告 27

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 212 个包,其中也包含从不交付的开发与测试版本固定:27 个存在已知公告,11 个为直接依赖。

软件包版本关系严重程度公告数修复版本
authlib1.5.2直接严重201.7.1
authlib1.6.0直接严重201.7.1
black25.1.0间接严重326.3.1
h110.14.0间接严重20.16.0
cryptography44.0.2直接548.0.1
protobuf5.29.4直接46.33.5
pyjwt2.12.1直接92.13.0
setuptools75.9.1直接483.0.0
urllib32.6.0直接62.7.0
urllib32.6.2直接62.7.0
click8.1.8间接18.3.3
dulwich0.22.8间接41.2.5
jaraco-context6.0.1间接26.1.0
mako1.3.10间接41.3.12
msgpack1.1.0间接11.2.1
pyasn10.6.1间接90.6.4
starlette0.46.2间接141.3.1
ujson5.10.0间接85.13.0
marshmallow3.26.1直接24.1.2
poetry2.1.2直接42.3.4
werkzeug3.1.3直接63.1.6
filelock3.18.0间接43.20.3
idna3.10间接23.15
pytest8.3.5间接29.0.3
requests2.32.3间接42.33.0
pygments2.19.1间接22.20.0
virtualenv20.30.0间接未知2

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 10360,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Nix": 11054,
        "Mako": 510,
        "Shell": 5796,
        "Python": 4313564,
        "PLpgSQL": 4615,
        "Makefile": 9052,
        "Dockerfile": 7733,
        "JavaScript": 3447
      },
      "pushed_at": "2026-07-22T18:48:52Z",
      "created_at": "2023-04-11T19:47:52Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T18:49:27Z",
      "description": "Services that handle reading and writing data from a database",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://www.datascience.ch/",
      "name": "Swiss Data Science Center",
      "type": "Organization",
      "login": "SwissDataScienceCenter",
      "company": null,
      "location": "Switzerland",
      "followers": 132,
      "avatar_url": "https://avatars.githubusercontent.com/u/25008760?v=4",
      "created_at": "2017-01-09T13:39:16Z",
      "is_verified": null,
      "public_repos": 135,
      "account_age_days": 3481
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.79.0",
          "kind": "minor",
          "published_at": "2026-07-21T13:53:18Z"
        },
        {
          "tag": "v0.78.2",
          "kind": "patch",
          "published_at": "2026-07-10T17:13:34Z"
        },
        {
          "tag": "v0.78.1",
          "kind": "patch",
          "published_at": "2026-07-09T07:15:16Z"
        },
        {
          "tag": "v0.77.1",
          "kind": "patch",
          "published_at": "2026-06-26T14:33:54Z"
        },
        {
          "tag": "v0.78.0",
          "kind": "minor",
          "published_at": "2026-06-26T13:43:59Z"
        },
        {
          "tag": "v0.77.0",
          "kind": "minor",
          "published_at": "2026-06-17T09:55:56Z"
        },
        {
          "tag": "v0.76.1",
          "kind": "patch",
          "published_at": "2026-06-15T09:12:25Z"
        },
        {
          "tag": "v0.76.0",
          "kind": "minor",
          "published_at": "2026-06-01T12:57:03Z"
        },
        {
          "tag": "v0.75.0",
          "kind": "minor",
          "published_at": "2026-05-28T07:56:57Z"
        },
        {
          "tag": "v0.72.3",
          "kind": "patch",
          "published_at": "2026-05-07T09:33:02Z"
        },
        {
          "tag": "v0.74.1",
          "kind": "patch",
          "published_at": "2026-05-08T08:12:51Z"
        },
        {
          "tag": "v0.74.0",
          "kind": "minor",
          "published_at": "2026-05-07T07:36:24Z"
        },
        {
          "tag": "v0.73.1",
          "kind": "patch",
          "published_at": "2026-05-05T12:34:15Z"
        },
        {
          "tag": "v0.73.0",
          "kind": "minor",
          "published_at": "2026-04-29T12:41:00Z"
        },
        {
          "tag": "v0.72.2",
          "kind": "patch",
          "published_at": "2026-04-24T09:44:06Z"
        },
        {
          "tag": "v0.72.1",
          "kind": "patch",
          "published_at": "2026-04-10T07:52:30Z"
        },
        {
          "tag": "v0.72.0",
          "kind": "minor",
          "published_at": "2026-04-08T14:39:50Z"
        },
        {
          "tag": "v0.71.2",
          "kind": "patch",
          "published_at": "2026-03-17T16:18:23Z"
        },
        {
          "tag": "v0.71.1",
          "kind": "patch",
          "published_at": "2026-03-12T09:12:40Z"
        },
        {
          "tag": "v0.71.0",
          "kind": "minor",
          "published_at": "2026-03-04T13:50:32Z"
        },
        {
          "tag": "v0.70.0",
          "kind": "minor",
          "published_at": "2026-03-03T19:34:11Z"
        },
        {
          "tag": "v0.69.0",
          "kind": "minor",
          "published_at": "2026-02-18T13:28:02Z"
        },
        {
          "tag": "v0.68.1",
          "kind": "patch",
          "published_at": "2026-01-27T16:23:38Z"
        },
        {
          "tag": "v0.68.0",
          "kind": "minor",
          "published_at": "2026-01-27T08:15:14Z"
        },
        {
          "tag": "v0.67.2",
          "kind": "patch",
          "published_at": "2026-01-20T10:18:48Z"
        },
        {
          "tag": "v0.67.1",
          "kind": "patch",
          "published_at": "2026-01-19T13:29:54Z"
        },
        {
          "tag": "v0.67.0",
          "kind": "minor",
          "published_at": "2026-01-15T08:15:11Z"
        },
        {
          "tag": "v0.65.1",
          "kind": "patch",
          "published_at": "2026-01-14T13:54:27Z"
        },
        {
          "tag": "v0.66.0",
          "kind": "minor",
          "published_at": "2026-01-09T16:27:34Z"
        },
        {
          "tag": "v0.65.0",
          "kind": "minor",
          "published_at": "2025-12-19T15:55:49Z"
        },
        {
          "tag": "v0.64.0",
          "kind": "minor",
          "published_at": "2025-12-17T08:15:11Z"
        },
        {
          "tag": "v0.63.0",
          "kind": "minor",
          "published_at": "2025-12-10T14:56:59Z"
        },
        {
          "tag": "v0.62.0",
          "kind": "minor",
          "published_at": "2025-12-08T08:53:41Z"
        },
        {
          "tag": "v0.61.0",
          "kind": "minor",
          "published_at": "2025-12-04T08:39:09Z"
        },
        {
          "tag": "v0.60.5",
          "kind": "patch",
          "published_at": "2025-11-17T10:53:32Z"
        },
        {
          "tag": "v0.60.4",
          "kind": "patch",
          "published_at": "2025-11-14T09:46:21Z"
        },
        {
          "tag": "v0.60.3",
          "kind": "patch",
          "published_at": "2025-11-13T08:15:46Z"
        },
        {
          "tag": "v0.60.2",
          "kind": "patch",
          "published_at": "2025-11-12T14:25:40Z"
        },
        {
          "tag": "v0.60.1",
          "kind": "patch",
          "published_at": "2025-11-10T09:17:09Z"
        },
        {
          "tag": "v0.60.0",
          "kind": "minor",
          "published_at": "2025-10-27T11:56:17Z"
        },
        {
          "tag": "v0.59.0",
          "kind": "minor",
          "published_at": "2025-10-09T07:37:21Z"
        },
        {
          "tag": "v0.58.0",
          "kind": "minor",
          "published_at": "2025-10-08T11:01:45Z"
        },
        {
          "tag": "v0.57.0",
          "kind": "minor",
          "published_at": "2025-09-25T15:36:19Z"
        },
        {
          "tag": "v0.56.0",
          "kind": "minor",
          "published_at": "2025-09-08T12:15:50Z"
        },
        {
          "tag": "v0.55.0",
          "kind": "minor",
          "published_at": "2025-08-22T09:40:10Z"
        },
        {
          "tag": "v0.54.0",
          "kind": "minor",
          "published_at": "2025-08-18T08:22:18Z"
        },
        {
          "tag": "v0.53.2",
          "kind": "patch",
          "published_at": "2025-08-15T09:29:31Z"
        },
        {
          "tag": "v0.53.1",
          "kind": "patch",
          "published_at": "2025-08-14T11:33:36Z"
        },
        {
          "tag": "v0.53.0",
          "kind": "minor",
          "published_at": "2025-08-11T09:54:01Z"
        },
        {
          "tag": "v0.52.0",
          "kind": "minor",
          "published_at": "2025-07-30T11:29:18Z"
        },
        {
          "tag": "v0.51.0",
          "kind": "minor",
          "published_at": "2025-07-24T11:02:52Z"
        },
        {
          "tag": "v0.50.0",
          "kind": "minor",
          "published_at": "2025-07-14T07:18:18Z"
        },
        {
          "tag": "v0.49.0",
          "kind": "minor",
          "published_at": "2025-06-19T07:19:38Z"
        },
        {
          "tag": "v0.48.1",
          "kind": "patch",
          "published_at": "2025-06-13T16:04:08Z"
        },
        {
          "tag": "v0.48.0",
          "kind": "minor",
          "published_at": "2025-06-10T09:11:52Z"
        },
        {
          "tag": "v0.47.1",
          "kind": "patch",
          "published_at": "2025-05-27T11:43:42Z"
        },
        {
          "tag": "v0.47.0",
          "kind": "minor",
          "published_at": "2025-05-22T14:50:39Z"
        },
        {
          "tag": "v0.46.0",
          "kind": "minor",
          "published_at": "2025-05-21T11:45:36Z"
        },
        {
          "tag": "v0.45.0",
          "kind": "minor",
          "published_at": "2025-05-19T09:46:30Z"
        },
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2025-05-15T14:45:24Z"
        },
        {
          "tag": "v0.43.3",
          "kind": "patch",
          "published_at": "2025-05-14T13:52:20Z"
        },
        {
          "tag": "v0.43.2",
          "kind": "patch",
          "published_at": "2025-05-14T07:08:46Z"
        },
        {
          "tag": "v0.43.1",
          "kind": "patch",
          "published_at": "2025-05-13T11:26:13Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2025-05-12T07:06:25Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2025-05-08T15:55:44Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2025-05-07T14:39:19Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2025-05-07T10:50:05Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2025-04-14T11:06:14Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2025-04-14T07:02:47Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2025-04-04T09:30:46Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2025-03-24T12:56:47Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2025-03-17T15:09:26Z"
        },
        {
          "tag": "v0.35.2",
          "kind": "patch",
          "published_at": "2025-03-17T13:16:05Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2025-03-12T09:00:33Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2025-03-06T16:00:29Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2025-03-03T11:08:40Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2025-02-20T16:01:36Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2025-02-07T09:10:05Z"
        },
        {
          "tag": "v0.31.1",
          "kind": "patch",
          "published_at": "2025-01-15T08:43:14Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2025-01-14T13:48:09Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2024-12-23T14:34:37Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2024-12-19T15:12:02Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2024-12-17T12:52:48Z"
        },
        {
          "tag": "v0.27.1",
          "kind": "patch",
          "published_at": "2024-12-02T14:35:45Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2024-11-26T07:43:06Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2024-11-13T12:18:31Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2024-10-28T14:29:46Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2024-10-25T09:32:26Z"
        },
        {
          "tag": "v0.24.1",
          "kind": "patch",
          "published_at": "2024-10-25T08:03:13Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2024-10-21T11:33:11Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2024-10-17T08:35:09Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2024-10-07T13:38:45Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2024-10-04T08:25:15Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2024-09-10T12:11:24Z"
        },
        {
          "tag": "v0.19.1",
          "kind": "patch",
          "published_at": "2024-08-23T12:55:42Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2024-08-21T12:21:00Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2024-07-30T09:37:25Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2024-07-24T07:46:06Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2024-07-10T07:29:54Z"
        },
        {
          "tag": "v0.16.1",
          "kind": "patch",
          "published_at": "2024-07-09T15:48:26Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e81895b495079eef2dfd00ff6569f6e3b2f31815",
          "body": "Co-authored-by: Tasko Olevski <16360283+olevski@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: export to envidat (#1329)",
          "author_name": "Mohammad Alisafaee",
          "author_login": "mohammad-alisafaee",
          "committed_at": "2026-07-22T18:48:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65190e2285fcceba53ee0c641315374acbfddcf6",
          "body": null,
          "is_bot": false,
          "headline": "feat: add option to set cpu limits (#1384)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-21T14:06:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad8d07f3e0c48bbfef1d140b3922289fa9813fc6",
          "body": null,
          "is_bot": false,
          "headline": "fix: distinguish union for patching launchers envs (#1389)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-21T13:26:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85e87a7d31ab41d01dc10f0d5fcb21d2628d64d4",
          "body": "Co-authored-by: Samuel Gaist <samuel.gaist@idiap.ch>",
          "is_bot": false,
          "headline": "fix: flaky test failing with 403 (#1386)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-21T07:00:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "685bcd9ee5c774064e0a185b8db8a8b1539af9a8",
          "body": "Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/cache from 5 to 6 (#1364)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-16T14:09:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6ab3474dba4844f08ab4038296886cad05ded2d",
          "body": "Co-authored-by: Mohammad Alisafaee <mohammad.alisafaee@epfl.ch>",
          "is_bot": false,
          "headline": "feat: get data connector links by doi (#1381)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-13T16:03:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fac6e97f0056ad0690ec6dde1f47aafcac98e2a9",
          "body": null,
          "is_bot": false,
          "headline": "chore: make sure tests can run in parallel (#1382)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-13T14:57:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b1aca9e5bc920aab7f790aac4d6beb5609ac721a",
          "body": null,
          "is_bot": false,
          "headline": "fix: check workdir for private images (#1380)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-10T17:12:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0240f2e67ffb7dd06094164e06cdb8de9ec0d4d6",
          "body": "Co-authored-by: Flora Thiebaut <flora.thiebaut@sdsc.ethz.ch>",
          "is_bot": false,
          "headline": "fix: set work and mount dir correctly (#1379)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-07-09T14:02:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8853b75d74e7255f6094b23a62608f705965810c",
          "body": null,
          "is_bot": false,
          "headline": "fix: generate one service account per build run (#1376)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-07-08T11:49:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cf122a865710c80163ab68e76c66b14ebd53fc8",
          "body": "Update session metrics to include a new `session_type` field used to differentiate interactive sessions and offline jobs.\n\nAlso, fixes a bug introduced in #1368 where session events were not sent because of case-sensitive matching with the `GVK` dataclass.",
          "is_bot": false,
          "headline": "feat: add session type to some metrics (#1372)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-07-07T12:50:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff28f85831f5bdbeadb45415d86124766d445bdf",
          "body": "…n-pool deadlock (#1374)\n\n* test: test number of pool connection for `get_resource_pool_users`\n\n* fix: accept session for `get_user`\n\n* feat: allow getting multiple users\n\n* fix: batch get users and reuse sessions",
          "is_bot": false,
          "headline": "Fix: reuse DB session in `get_resource_pool_users` to avoid connectio…",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-07-07T06:47:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edb6ea628dfcfa7b1ce434c7fb8a1d2605c1c5ff",
          "body": null,
          "is_bot": false,
          "headline": "feat: add support for inferred-frontend and no-implicit-frontend (#1371)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-07-06T08:27:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29590e7eecbb49f7589224e252b515c8f924581b",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6 to 7 (#1358)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-01T08:38:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e36c7d79784e49e06c05a1aff4b7a01f79330392",
          "body": "Closes #1365.",
          "is_bot": false,
          "headline": "fix: allow unsetting quota (#1367)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-06-30T13:55:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "167bcebc36985a512c977d582e8e2c9dc0dc3369",
          "body": "Closes #915.",
          "is_bot": false,
          "headline": "fix: dispatch metrics by k8s kind (#1368)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-06-30T07:50:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d978816e63509bd14bab924f75bb3eb77b3ffcd3",
          "body": "…1351)\n\nCloses #1347.",
          "is_bot": false,
          "headline": "fix: update some build permissions when the source repo is private (#…",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-06-29T14:32:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88b2173f6862ee8243afd658a940575b1f85d037",
          "body": null,
          "is_bot": false,
          "headline": "fix: solr splitting project name (#1362)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-06-26T13:38:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40b17da11396dada8ac7e558a07dc770b295deec",
          "body": "Relates and depend upon https://github.com/SwissDataScienceCenter/renku/pull/4486/",
          "is_bot": false,
          "headline": "chore: Update CI values file name. (#1360)",
          "author_name": "Alessandro Degano",
          "author_login": "aledegano",
          "committed_at": "2026-06-24T13:28:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f5b75480bbf75c00ac1afab3fb452f2ace6b4330",
          "body": "* Require submission_id for starting jobs: it is necessary for a client to allow idempotent requests on failure\n* Return session-type and submission_id in session list\n* Remove default listing of interactive sessions when no filter is applied\n* Use non-interactive as api value consistently\n* Add job\n[…]\nb command and arguments when submitting a job\n* Return command and args with session details\n\n* Return completed job date using idleSince\n\nAmalthea sets it whenever the job goes to Failed or Succeeded",
          "is_bot": false,
          "headline": "feat: Allow multiple jobs per job launcher (#1328)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-06-24T11:25:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b35001c8490207a83a49df639ec1b721a1844c27",
          "body": "* feat: add remote-tunnel label for network policy selection\n\n* fix: label name",
          "is_bot": false,
          "headline": "feat: add remote-tunnel label for network policy selection (#1357)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-06-22T14:04:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7ba895f7cf3703daec3cdb0f595df09c52851583",
          "body": "* refactor: add feature flag for private repo builds\n\nIn order to make the code simpler as well, start moving\ndefault value handling in the configuration class.",
          "is_bot": false,
          "headline": "feat: add feature flag for private repo builds (#1355)",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-06-17T15:22:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b50de661ce9803aa3b3efffe4054dd69a4cf3ca",
          "body": "…350)\n\n* feat: add `_get_readiness_probe` to allow http probes on remote sessions\n\n* feat: wire in `_get_readiness_probe` in `start_session`\n\n* feat: add integration test for remote session readiness probe\n\n* squashme: formatting",
          "is_bot": false,
          "headline": "feat: Use an HTTP readiness probe for remote interactive sessions (#1…",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-06-17T14:02:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f4afa44719039442e8491155038efb63ccbd0f3",
          "body": null,
          "is_bot": false,
          "headline": "fix: slow resource usage query (#1337)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-06-17T09:53:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f4832ce52cf10e0e500fab1bf4ad965b07b0bca",
          "body": "…p (#1349)\n\n* feat: add testmon to dev dependencies for faster testing loop\n\n* chore: add testmon artefacts to `.gitignore`\n\n* chore: update license name to match SPDX version\n\nCo-authored-by: Samuel Gaist <samuel.gaist@idiap.ch>\n\n---------\n\nCo-authored-by: Samuel Gaist <samuel.gaist@idiap.ch>",
          "is_bot": false,
          "headline": "feat: add `pytest-testmon` as a dev dependency for faster testing loo…",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-06-16T13:37:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8aac47e37c59b8950a6e8fc981ac57f8f3406c25",
          "body": "…ge (#1315)\n\n* feat: sync resource pool viewer access on OAuth2 connect and disconnect (#1317)\n\n* feat: sync RP access on OAuth connect/disconnect\n\nAdd _on_oauth2_connected and _on_oauth2_disconnected helpers\nthat auto-grant/revoke viewer access to resource pools linked\nto the provider. Wire member_\n[…]\nse in AUTHZ\n\n* test: end-to-end RP+OAuth integration tests (#1327)\n\n* test: add RP remote provider end-to-end tests\n\n* test: add OAuth callback RP access end-to-end tests\n\n* chore: remove useless test",
          "is_bot": false,
          "headline": "feat: automatic resource pool viewer access via OAuth2 provider linka…",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-06-11T08:54:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84d1d91c03a584c369537f4fab5e649f674b2709",
          "body": "* fix(tests: add missing fixture for anonymous session tests\n\nAmalthea is required and it would not work if test is run\nin isolation or from the file.\n\n* fix: do not return private image pull secret if user is anonymous\n\n* refactor: use forbidden error when repository is not accessible\n\n* refactor: \n[…]\nheck endpoint\"\n\nThis reverts commit f1b3b6adf9394de633f796a3fe7a0a4d988d767b.\n\n* chore: improved error message on missing successful build\n\n---------\n\nCo-authored-by: Flora Thiebaut <flora@leafty.dev>",
          "is_bot": false,
          "headline": "Refactor: improve image accessibility checks (#1333)",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-06-10T15:41:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aba6234e425df4c4f1691968c4827c48b898eea1",
          "body": "Closes #1338.",
          "is_bot": false,
          "headline": "fix: do not fail builds when refreshing them from another user (#1343)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-06-10T13:33:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb0c2c1d40355c8b0200108c6d7e06b49c7f091e",
          "body": "Make it so that (if configured) admins are the only one allowed to\ncreate projects and groups. By default we have the old behavior so that\neveryone who is logged in can create a group or project. The limits are\napplied in addition to all other authorization schemes and regardless of\nwhere the project will be created (username or group).",
          "is_bot": false,
          "headline": "feat: limit project group creation to admins (#1331)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-06-01T09:46:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c50f11c25d2648c6d7afddc86b4589cb6c9825d",
          "body": "* feat: add group and projects to resource pool authz (#1267)\n\n* Feat: move resource pools check to authz (#1248)\n\n* feat: update schema for authzed\n\n* feat(authz): add ResourcePool as a supported authorization resource\n\n* feat(authz): add member and prohibited relationship types\n\n* feat(db): add Re\n[…]\nsers response\n\n* chore: more precise type checking\n\n* refactor: authzed as source of truth\n\n* feat: add generic model validator\n\n---------\n\nCo-authored-by: Flora Thiebaut <flora.thiebaut@sdsc.ethz.ch>",
          "is_bot": false,
          "headline": "feat: resource-pool authz for groups and projects (#1311)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-05-29T13:59:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "656eb38032eae959cd718cdfd5f0bf9d312cb121",
          "body": null,
          "is_bot": false,
          "headline": "fix: properly filter data connectors (#1326)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-05-26T13:08:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64032dd750f7d55d98df4a93ff7b269c449d760d",
          "body": "This had a really long complicated regex. This regex did not include\nimages on a repository that has a custom port. Like\n`repo.com:5000/prj/img`. Instead of changing the already involved regex\nI removed it fully. Now we do a lot of checks for image existence on the\nfrontend and backend so users would know quickly the image is not\naccessible.",
          "is_bot": false,
          "headline": "fix: simplify validation for valid container image (#1324)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-05-26T08:37:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7574fe09562ec2b9b27849fb5e9c25f71b0b196",
          "body": null,
          "is_bot": false,
          "headline": "feat: enforce quota (#1307)",
          "author_name": "Mohammad Alisafaee",
          "author_login": "mohammad-alisafaee",
          "committed_at": "2026-05-22T12:36:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ede0073a403e5d71ffb6826e7d8af537584a520",
          "body": "* Add new column launcher_type to launchers. It is by default 'interactive' which is the name of all current launchers.\n* Remove session_type from post request",
          "is_bot": false,
          "headline": "feat: Add launcher_type to launcher definition (#1303)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-05-21T11:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48b2b721d88073955a13d018bac498cc94696c87",
          "body": "This fix makes sure that the correct renku labels are applied to sessions when they are patched. Notably, the session type label is added with the value `\"interactive\"` if it not present (assuming old sessions are interactive).",
          "is_bot": false,
          "headline": "fix: update session labels upon patch (#1320)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-05-21T10:06:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42c90405aceb58b7d98fd21996ffb9c10c3d58df",
          "body": "This fixes an issue where sessions started before the label was applied are invisible and unusable from the API.",
          "is_bot": false,
          "headline": "fix: assume no label is interactive in list_sessions() (#1318)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-05-21T08:54:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "851c6d78507405b31b9b5bc25126ca058a74ea49",
          "body": null,
          "is_bot": false,
          "headline": "feat: Add resource usage endpoint to get usage for a given user (#1238)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-05-20T13:36:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98be3dbfbbc90f9f5ea2c488e5cf340e2460a02a",
          "body": null,
          "is_bot": false,
          "headline": "Changes to support major solr upgrade to 10 (#1275)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-05-20T12:58:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39484bad3058085e7cce226b6fee1b63db193d5d",
          "body": null,
          "is_bot": false,
          "headline": "fix: slow resource requests usage query (#1306)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-05-20T09:46:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "262d3d2b1b2a75c2064f5989d691443b99320dbc",
          "body": "Co-authored-by: Flora Thiebaut <flora.thiebaut@sdsc.ethz.ch>",
          "is_bot": false,
          "headline": "fix: remove some information when listing users (#1302)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-05-19T12:28:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63ba8b21430f9b3dd0f6a1665e0f5c1b8343f74f",
          "body": null,
          "is_bot": false,
          "headline": "fix: finding data connectors by slug (#1310)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-05-19T08:51:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f1ef4654ffb68749b760442616e66a494a1e996",
          "body": null,
          "is_bot": false,
          "headline": "fix: avoid inheritance in openapi (#1304)",
          "author_name": "Mohammad Alisafaee",
          "author_login": "mohammad-alisafaee",
          "committed_at": "2026-05-11T22:54:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75e96ae86c5f2341889a7dbb2331b2b1ca35445f",
          "body": null,
          "is_bot": false,
          "headline": "feat: task to check session quota and send alerts (#1252)",
          "author_name": "Mohammad Alisafaee",
          "author_login": "mohammad-alisafaee",
          "committed_at": "2026-05-11T16:55:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d0e2bde6000f1e5c67af5a99782bb4ecd983d60",
          "body": "Co-authored-by: Chandrasekhar Ramakrishnan <ciyer@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: return used credits and remaining resource hours in pools (#1244)",
          "author_name": "Mohammad Alisafaee",
          "author_login": "mohammad-alisafaee",
          "committed_at": "2026-05-07T13:10:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d313ca4db3ec6ec18897603e786408baeea95714",
          "body": "Bumps [azure/login](https://github.com/azure/login) from 2 to 3.\n- [Release notes](https://github.com/azure/login/releases)\n- [Commits](https://github.com/azure/login/compare/v2...v3)\n\n---\nupdated-dependencies:\n- dependency-name: azure/login\n  dependency-version: '3'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump azure/login from 2 to 3 (#1286)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T12:44:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d7e6cd2d8106174b38e9e541edcdea98e842945",
          "body": "Bumps [azure/aks-set-context](https://github.com/azure/aks-set-context) from 4 to 5.\n- [Release notes](https://github.com/azure/aks-set-context/releases)\n- [Changelog](https://github.com/Azure/aks-set-context/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/azure/aks-set-context/compare/v4...v\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump azure/aks-set-context from 4 to 5 (#1285)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T12:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6eb1ebc2a9945358f2e6ccb19f5ae28759eca646",
          "body": "Sometimes the buildrun status is considered failed when in reality it is\nnot failed. This should address that. It is because of some transient\nstate in the buildrun conditions.",
          "is_bot": false,
          "headline": "fix: buildrun status false failed (#1300)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-05-07T09:29:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b74955a7941166650dd3b0c29575c25cd4d5cf5d",
          "body": "* Add non-interactive flag to session start request\n* Updated CRD from amalthea changes\n* List only interactive sessions by default, allow options via query parameter\n* Move extra containers to init containrs for jobs and remove readiness probe for jobs\n* Fix declaration of enum in session spec\n\nThe\n[…]\n now fixed in the\nalready existing subclass by redefining the field.\n\n* Report correct status after renku job is done\n\nThe new state \"succeeded\" needs to be propagated into the api response\nstructure.",
          "is_bot": false,
          "headline": "feat: Add support to start non-interactive sessions (#1246)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-05-07T05:56:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5de30c478b43dff085880b964e6f6fa78d78194b",
          "body": "* feat: decouple queries from resource pool repository\n\n* refactor: use ResourcePoolQueryRepo without authz\n\n* fix: Monkey patch non caching authz in tests\n\n* Fix: Apply typo fixes from code review\n\nCo-authored-by: Flora Thiebaut <flora@leafty.dev>\n\n* sqashme: formatting\n\n---------\n\nCo-authored-by: Flora Thiebaut <flora@leafty.dev>",
          "is_bot": false,
          "headline": "fix: decouple authz from k8s watcher (#1282)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-05-05T19:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a31913faca502d7e826ec05e4f231b6a1b42f36",
          "body": "Closes #1287.\n\nAlso, ensure the annotations are updated when resuming.",
          "is_bot": false,
          "headline": "fix: set priority class name when resuming a session (#1288)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-05-05T13:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a8955e21da11f0bf235e5156e97758536e37ebf",
          "body": "Closes #1289.\n\nAlso, commit db session in the authz_change decorator.",
          "is_bot": false,
          "headline": "fix: initialize the default resource pool in the worker thread (#1290)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-05-05T11:58:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cdf55c3a27db9b20f274a1c6af4ef6b0025a06f",
          "body": "…ions (#1280)\n\nCloses #1278.",
          "is_bot": false,
          "headline": "fix: validate project_template_id in POST /api/data/capacity-reservat…",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-04-29T15:17:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "234b23af47c5245c45011a06750077e07046c648",
          "body": "Use internal tokens for sessions. The internal tokens are used by the following services supporting sessions:\n* git-proxy\n* csi-rclone\n* remote-session-controller",
          "is_bot": false,
          "headline": "feat: use self-minted tokens for sessions (#1258)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-04-29T12:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7234584cc9f126d5ff6ca9d4bdea388816158cca",
          "body": "…ectly (#1274)\n\n* fix: don-t recreate private image pull secret\n\nWhen retrieving the image pull secret to be used by a session, if\nit's an existing secret, do not add it to the extra resources to\nbe created.\n\nThis is the case for the registry used to store the images built\nout of private repositories.",
          "is_bot": false,
          "headline": "fix(sessions): use image pull secret from private build registry corr…",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-04-29T08:14:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "814d1e65e39dae159aeb5d49d920c1fa15da2507",
          "body": "* Feat: move resource pools check to authz (#1248)\n\n* feat: update schema for authzed\n\n* feat(authz): add ResourcePool as a supported authorization resource\n\n* feat(authz): add member and prohibited relationship types\n\n* feat(db): add ResourcePool authz schema migration, copy membership\n\n* chore(aut\n[…]\no represent non-group resources\n\n* refactor: unify resource pool membership under single ResourceType\n\n* refactor: rename default resource pool create function\n\n* refactor: use TypeVar for resource_id",
          "is_bot": false,
          "headline": "Feat: ResourcePool Authorization via Authzed/SpiceDB (#1266)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-04-27T15:56:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad7bb15d06b0ad06dec111eac41f8a8845df5b6f",
          "body": "Bumps [docker/metadata-action](https://github.com/docker/metadata-action) from 5 to 6.\n- [Release notes](https://github.com/docker/metadata-action/releases)\n- [Commits](https://github.com/docker/metadata-action/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependency-name: docker/metadata-action\n  d\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/metadata-action from 5 to 6 (#1230)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-27T14:06:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f998f9a8caba0c440850060cb3fdd214d115acb4",
          "body": "Bumps [docker/login-action](https://github.com/docker/login-action) from 3 to 4.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: docker/login-action\n  dependency-versi\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/login-action from 3 to 4 (#1229)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-27T13:13:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90c81487e07ada61f3d5aa61b66a6cb03105ba78",
          "body": "Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3 to 4.\n- [Release notes](https://github.com/docker/setup-qemu-action/releases)\n- [Commits](https://github.com/docker/setup-qemu-action/compare/v3...v4)\n\n---\nupdated-dependencies:\n- dependency-name: docker/setup-qemu-\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump docker/setup-qemu-action from 3 to 4 (#1228)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-27T12:18:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad0332fabdefbd73ad5c31e39839ccc5f829624b",
          "body": null,
          "is_bot": false,
          "headline": "fix: strip prefix for rstudio built from code (#1269)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-04-24T09:39:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "069d523588c1d6c1a0d4bde61983001a31377b9b",
          "body": "…#1265)\n\n* feat(notebook): add secret handling for private registry image pull\n\nThis secret is created by the admin deploying the platform and is\nnot user accessible.\n\n* chore: update patch_sesssion for new image pull secret implementation\n\n* fix: add missing None check for private registry secret h\n[…]\nrepositories to the same registry used for\npublic repositories.\n\n* feat: add tests for image prefix validation\n\n* chore: fix format issues\n\n---------\n\nCo-authored-by: Flora Thiebaut <flora@leafty.dev>",
          "is_bot": false,
          "headline": "feat(notebook): add secret handling for private registry image pull (…",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-04-22T12:08:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac935e7d534a8b9c84ecc1d4076819fdb2395371",
          "body": "… (#1254)",
          "is_bot": false,
          "headline": "fix: redirect to frontend with error params on oauth callback failure…",
          "author_name": "Andrea Cordoba",
          "author_login": "andre-code",
          "committed_at": "2026-04-21T09:02:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8eeedd17e7206e1bbeb592a72ba511a140c01898",
          "body": "…1264)\n\n* feat: add insecure registries configuration option\n\nDifferent BuildStrategy support different ways of doing it.\nIn the case of the buildpacks based strategy that is used here,\none can use the CNB_INSECURE_REGISTRIES environment variable\nwith a comma separated list of insecure registries. Insecure\nin this context means http registries or registries behind a\nself-signed certificate.\n\n* chore: add warning when configuring insecure registries",
          "is_bot": false,
          "headline": "feat(builds): add the possibility to configure insecure registries (#…",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-04-20T15:51:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd0bf2ec082c5cf89fd48d8cf73abc917e8ff159",
          "body": null,
          "is_bot": false,
          "headline": "fix: users API response (#1261)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-04-17T12:06:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e9a9ce763c65fc601ecaacedf049bc72779721b",
          "body": "* feat: add private image prefix to config\n\n* feat(repositories/db): add token getter\n\nThis will be used to create the secret allowing\nShipwright to create images out of private repositories.\n\n* feat(session/models): add authentication secret\n\nThis will allow to pass authentication information to\nth\n[…]\ne\n\nWhile containing yaml, k8s config files do not end with\n.yaml by default so if testing with a local cluster, the\ntests will fail.\n\n* fix(tests): fix authorisation headers for resource pool creation",
          "is_bot": false,
          "headline": "feat: build from private repositories (#1250)",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-04-15T11:55:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe542a9234a0cc73bb6f8db261752afc0dd53c13",
          "body": null,
          "is_bot": false,
          "headline": "fix: cloning repos token urls (#1253)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-04-10T07:34:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62c200e4c2816a20f99075767aa9f5eb7ab3deff",
          "body": "* feat: add deposit api spec (#1221)\n\n* feat: add k8s client for deposits (#1222)\n\n* feat: endpoints for data deposits (#1196)\n\n* feat: add deposit job (#1233)\n\n* fix: return the etag of data deposits",
          "is_bot": false,
          "headline": "feat: publish zenodo datasets (#1236)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-04-08T14:38:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f78e402a845dedee71ef246d41a183a658f9ddc",
          "body": "This will allow, for example, to create dedicated\nnetwork policies that applies specifically to these\nsessions.\n\nThe safe username label cannot be used in this context\nas the label filter does not support regexp expressions.",
          "is_bot": false,
          "headline": "feat: add label to session for anonymous sessions (#1240)",
          "author_name": "Samuel Gaist",
          "author_login": "sgaist",
          "committed_at": "2026-04-07T10:28:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6d149c232f7d44d9b12ae84a7a4858699094f3d",
          "body": "Closes #1209.",
          "is_bot": false,
          "headline": "fix: send 404 when a sessions is not found (#1234)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-03-26T14:15:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "516b84f644224e11f5f295593e7fb2376e79372e",
          "body": null,
          "is_bot": false,
          "headline": "feat: support runai as an amalthea remote backend (#1235)",
          "author_name": "Chandrasekhar Ramakrishnan",
          "author_login": "ciyer",
          "committed_at": "2026-03-20T17:52:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17f5a1e1404596fdf614125b14ac02c50c7c9f22",
          "body": null,
          "is_bot": false,
          "headline": "fix: handle missing jwk (#1243)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-03-17T16:17:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf89619774eac79f2e9cb3d28de2239b95270194",
          "body": null,
          "is_bot": false,
          "headline": "fix: use correct CPU quantity (#1239)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-03-11T16:16:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20e13ad82ec4f225d07ea53910793060458d3d8b",
          "body": null,
          "is_bot": false,
          "headline": "fix: error message on bad builder/frontend variant pair (#1227)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-03-06T13:25:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a343fa693208b8f4ab68d061fe41ee9c5bdbf25",
          "body": "* Record certain data in a `resource_request_log table`\n* Snapshots are stored periodically from data_tasks\n* Resource request tracking is disabled by default, requires `ENABLE_RESOURCE_REQUEST_TRACKING=true` to be in the env",
          "is_bot": false,
          "headline": "feat: Enable resource requests tracking (#1207)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-03-04T13:37:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4336619ba89145530b854a0be0665498058bb488",
          "body": "Bumps [SwissDataScienceCenter/renku-actions](https://github.com/swissdatasciencecenter/renku-actions) from 1.22.1 to 1.23.1.\n- [Release notes](https://github.com/swissdatasciencecenter/renku-actions/releases)\n- [Commits](https://github.com/swissdatasciencecenter/renku-actions/compare/v1.22.1...v1.23\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump SwissDataScienceCenter/renku-actions (#1216)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-03T20:14:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "145c38061c770e4784e3b9a64887b99b1c460fe2",
          "body": null,
          "is_bot": false,
          "headline": "feat: add R related variants for custom sessions (#1219)",
          "author_name": "Salim Kayal",
          "author_login": "SalimKayal",
          "committed_at": "2026-03-03T19:32:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82b72b9004cb6a2c81c152df572ff8731538e692",
          "body": null,
          "is_bot": false,
          "headline": "feat: add capacity reservation (#1205)",
          "author_name": "Wes Johnson",
          "author_login": "wesjdj",
          "committed_at": "2026-03-03T17:13:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28f99970dc06e01b279e3956a709820b27f7b302",
          "body": "Co-authored-by: Flora Thiebaut <flora.thiebaut@sdsc.ethz.ch>",
          "is_bot": false,
          "headline": "chore: fix failing tests (#1224)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-03-03T15:55:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "363203aceb8fae83c41d27ea7bf5a28178c6dd51",
          "body": null,
          "is_bot": false,
          "headline": "feat: add sentry trace id to logs and errors (#1187)",
          "author_name": "Mohammad Alisafaee",
          "author_login": "mohammad-alisafaee",
          "committed_at": "2026-02-25T15:22:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eff3c2df8f325f14741f4e14f073abc296a3d7ad",
          "body": "…(#1193)\n\n* Introduce K8s Subclasses for K8sResourceQuota & K8sPriorityClass\n  * Properly handle quota.id\n  * Move QuotaRepo to crc.db, and conversion methods to models.Quota\n\n* K8sClients\n  * Always use the namespace from the ClusterConnection\n  * Stabilise some tests by ensuring generated values do not overlap\n\n* K8sWatcher: prevent spurious logs in case of failing connection to remote clusters\n\n* Set AmaltheaSession.spec.url correctly",
          "is_bot": false,
          "headline": "feat: Allow remote cluster sessions to function on lock down cluster …",
          "author_name": "Lionel Sambuc",
          "author_login": "sambuc",
          "committed_at": "2026-02-25T07:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "136df8c3b2c74d7f24327dbf1cb118f5fc5ac077",
          "body": null,
          "is_bot": false,
          "headline": "feat: add project, data connector counts in Search result (#1198)",
          "author_name": "Andrea Cordoba",
          "author_login": "andre-code",
          "committed_at": "2026-02-20T10:25:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "193c270d9c6601bc959d68c9eccf2abdbdf3a750",
          "body": "This change allows the configuration of the `args` used for the `git-proxy` container in sessions.\n\nThe git proxy is being moved to the amalthea repository and now needs to be started with `[ \"gitproxy\", \"proxy\" ]` from the `renku/sidecars` container.",
          "is_bot": false,
          "headline": "feat: move git-https-server to amalthea (#1212)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-02-18T12:44:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c51cccc90cd80315dfd0be140140dbc9eb42052a",
          "body": "…rs (#1201)\n\nAdd support for using OAuth2.0 integrations to mount data connectors in sessions. Google Drive and Dropbox storage types can now be accessed from Renku sessions.\n\nContents:\n* #1190\n* #1195\n* #1200",
          "is_bot": false,
          "headline": "feat: add support for using OAuth 2.0 integrations with data connecto…",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-02-18T10:44:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3c9e42d838a65b63e51576c19e5bc4c846898e2",
          "body": "* Generate code for new amalthea version\n* Pass annotations and labels to amalthea spec template",
          "is_bot": false,
          "headline": "chore: Pass renku annotations to amalthea session spec (#1206)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-02-18T10:22:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75b4116d6ab605ba32b7201a46347d48389177d2",
          "body": "Closes #1213.",
          "is_bot": false,
          "headline": "feat: add visibility field to GET /repository response (#1214)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-02-17T14:17:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36e8a0007b05f9e220846f4f28b27fd5f07bc69b",
          "body": null,
          "is_bot": false,
          "headline": "chore: upgrade renku actions to 1.22.1 (#1211)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-02-16T14:17:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "308f0a040e334944f9f3241662213272cd2d5fe9",
          "body": "Update rclone validation to use an allow list system:\n* All storage types are listed and are explicitly allowed or blocked\n* For all allowed storage types, all options are marked as allowed or blocked\n\nThis update also blocks potentially unsafe options (referring to a local file or a potential arbitrary command).\n\nTests in `test/components/renku_data_services/storage/test_rclone.py` are designed to help maintain the configuration of allowed storage types and storage options.",
          "is_bot": false,
          "headline": "feat: use allow list for rclone (#1202)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-02-11T10:05:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7738d1145f9c2b7506dfdc58ae5118463f4a232",
          "body": "Bumps [SwissDataScienceCenter/renku-actions](https://github.com/swissdatasciencecenter/renku-actions) from 1.20.0 to 1.21.0.\n- [Release notes](https://github.com/swissdatasciencecenter/renku-actions/releases)\n- [Commits](https://github.com/swissdatasciencecenter/renku-actions/compare/v1.20.0...v1.21\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump SwissDataScienceCenter/renku-actions (#1199)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-02-03T08:41:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc433f04f8a8672e31b5089ca20081527e85d5c4",
          "body": null,
          "is_bot": false,
          "headline": "build: update devcontainer (#1197)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-01-29T12:30:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb893a7883ff6c913b314a3708f8b5472d0667e9",
          "body": null,
          "is_bot": false,
          "headline": "fix: url path for sessions (#1192)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-27T15:28:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49eb81aa2b70a4eff924bd47a2c6d00a3201f657",
          "body": null,
          "is_bot": false,
          "headline": "feat: cluster default tls cert in sessions (#1183)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-27T08:11:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c2cbb4486bf768fd86b4d2b25fde8c05e047e56",
          "body": null,
          "is_bot": false,
          "headline": "refactor: remove v1 legacy code (#1185)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-23T07:54:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30d87c96449979ced29fdfff72953b13470584b5",
          "body": "Closes #1159.",
          "is_bot": false,
          "headline": "build: bump sanic to v25.12.0 (#1184)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-01-22T12:43:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a5f7675846f1d43861dfc0d74bec528fb915498a",
          "body": null,
          "is_bot": false,
          "headline": "fix: use ingress class name for local cluster (#1169)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-19T13:56:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe344ccd9e6f90382a6795cd0a9813aa981466d5",
          "body": null,
          "is_bot": false,
          "headline": "fix: handle missing status in k8s watcher metrics (#1180)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-16T15:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef764fe87241d8e7188ddeaef64f320da4d52e26",
          "body": null,
          "is_bot": false,
          "headline": "fix: handle httpx.ReadError in k8s watcher (#1179)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-16T15:36:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f124188cc0aa93869912f1e84b9be09c8602ad0",
          "body": "Closes #1163.\n\nThis should improve type safety with the SessionTasks Python class.",
          "is_bot": false,
          "headline": "fix: use protocol for SessionTasks (#1165)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-01-15T09:15:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c9e7a1ab3cdfd7efcba63e91ee47abdcaef29f7",
          "body": null,
          "is_bot": false,
          "headline": "fix: do not fail on cluster name conflicts with 500 (#1171)",
          "author_name": "Tasko Olevski",
          "author_login": "olevski",
          "committed_at": "2026-01-15T08:08:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a359bf53af65d7cb4c1d2eebb561c55c721d0a1",
          "body": "Closes #1167.\n\nRemove unsafe option `bearer_token_command` from the WebDAV provider.\n\nSee also #964.",
          "is_bot": false,
          "headline": "fix: remove unsafe webdav option (#1168)",
          "author_name": "Flora Thiebaut",
          "author_login": "leafty",
          "committed_at": "2026-01-14T13:30:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "357962b38cf86af0174df65be81c564c6e429ce5",
          "body": null,
          "is_bot": false,
          "headline": "fix: b64 encode secret values on patch (#1150)",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-01-13T14:27:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5af14c9c8d28da9d9390441583e1d16997a0461",
          "body": "…nateAt (#1128)",
          "is_bot": false,
          "headline": "feat: set lastInteraction time via session patch and return willHiber…",
          "author_name": "eikek",
          "author_login": "eikek",
          "committed_at": "2026-01-13T12:44:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 209,
      "latest_release_at": "2026-07-21T13:53:18Z",
      "latest_release_tag": "v0.79.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 51,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 8.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 62,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "secrets_storage",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "configuration",
            "hashicorp-vault",
            "secrets",
            "vault",
            "Development Status :: 5 - Production/Stable",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: Apache Software License",
            "Programming Language :: Python :: 3 :: Only",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.14",
            "Topic :: Security",
            "Topic :: Software Development :: Libraries"
          ],
          "ecosystem": "pypi",
          "matches_repo": false,
          "registry_url": "https://pypi.org/project/secrets_storage/",
          "is_deprecated": false,
          "latest_version": "1.0.0",
          "repository_url": "https://github.com/bigbag/secrets-storage",
          "versions_count": 18,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 123,
          "first_published_at": "2021-01-31T20:01:57.089526Z",
          "latest_published_at": "2026-07-20T12:33:27.764615Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 2
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 8,
      "watchers": 6,
      "fork_history": {
        "days": [
          {
            "date": "2023-05-22",
            "count": 1
          },
          {
            "date": "2024-07-10",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 194
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [
        "bases/renku_data_services/data_api/py.typed",
        "bases/renku_data_services/data_tasks/py.typed",
        "bases/renku_data_services/k8s_cache/py.typed",
        "bases/renku_data_services/secrets_storage_api/py.typed",
        "components/renku_data_services/app_config/py.typed",
        "components/renku_data_services/authn/py.typed",
        "components/renku_data_services/crc/py.typed",
        "components/renku_data_services/db_config/py.typed",
        "components/renku_data_services/k8s/py.typed",
        "components/renku_data_services/metrics/py.typed",
        "components/renku_data_services/migrations/py.typed",
        "components/renku_data_services/project/py.typed",
        "components/renku_data_services/session/py.typed",
        "components/renku_data_services/storage/py.typed",
        "components/renku_data_services/utils/py.typed"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 223775,
      "source_files_sampled": 537,
      "oversized_source_files": 11,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "authlib",
            "direct": true,
            "version": "1.5.2",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-7432-952r-cw78",
              "GHSA-9ggr-2464-2j32",
              "GHSA-fg6f-75jq-6523",
              "GHSA-g7f3-828f-7h7m",
              "GHSA-jj8c-mmj3-mmgv",
              "GHSA-m344-f55w-2m6j",
              "GHSA-pq5p-34cr-23v9",
              "GHSA-r95x-qfjj-fjj2",
              "GHSA-w8p2-r796-3vmq",
              "GHSA-wvwj-cvrp-7pv5"
            ],
            "fixed_version": "1.7.1",
            "advisory_count": 20,
            "oldest_advisory_days": 303
          },
          {
            "name": "authlib",
            "direct": true,
            "version": "1.6.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-7432-952r-cw78",
              "GHSA-9ggr-2464-2j32",
              "GHSA-fg6f-75jq-6523",
              "GHSA-g7f3-828f-7h7m",
              "GHSA-jj8c-mmj3-mmgv",
              "GHSA-m344-f55w-2m6j",
              "GHSA-pq5p-34cr-23v9",
              "GHSA-r95x-qfjj-fjj2",
              "GHSA-w8p2-r796-3vmq",
              "GHSA-wvwj-cvrp-7pv5"
            ],
            "fixed_version": "1.7.1",
            "advisory_count": 20,
            "oldest_advisory_days": 303
          },
          {
            "name": "black",
            "direct": false,
            "version": "25.1.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.8,
            "advisory_ids": [
              "GHSA-3936-cmfr-pm3m",
              "PYSEC-2026-2120",
              "PYSEC-2026-2121"
            ],
            "fixed_version": "26.3.1",
            "advisory_count": 3,
            "oldest_advisory_days": 133
          },
          {
            "name": "h11",
            "direct": false,
            "version": "0.14.0",
            "severity": "critical",
            "ecosystem": "pypi",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-vqfr-h8mv-ghfj",
              "PYSEC-2026-348"
            ],
            "fixed_version": "0.16.0",
            "advisory_count": 2,
            "oldest_advisory_days": 454
          },
          {
            "name": "cryptography",
            "direct": true,
            "version": "44.0.2",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-537c-gmf6-5ccf",
              "GHSA-m959-cc7f-wv43",
              "GHSA-r6ph-v2qm-q3c2",
              "PYSEC-2026-2141",
              "PYSEC-2026-35"
            ],
            "fixed_version": "48.0.1",
            "advisory_count": 5,
            "oldest_advisory_days": 162
          },
          {
            "name": "protobuf",
            "direct": true,
            "version": "5.29.4",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-7gcm-g887-7qv7",
              "GHSA-8qvm-5x2c-j2w7",
              "PYSEC-2026-1805",
              "PYSEC-2026-1806"
            ],
            "fixed_version": "6.33.5",
            "advisory_count": 4,
            "oldest_advisory_days": 401
          },
          {
            "name": "pyjwt",
            "direct": true,
            "version": "2.12.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.4,
            "advisory_ids": [
              "GHSA-993g-76c3-p5m4",
              "GHSA-fhv5-28vv-h8m8",
              "GHSA-jq35-7prp-9v3f",
              "GHSA-w7vc-732c-9m39",
              "GHSA-xgmm-8j9v-c9wx",
              "PYSEC-2026-175",
              "PYSEC-2026-177",
              "PYSEC-2026-178",
              "PYSEC-2026-179"
            ],
            "fixed_version": "2.13.0",
            "advisory_count": 9,
            "oldest_advisory_days": 55
          },
          {
            "name": "setuptools",
            "direct": true,
            "version": "75.9.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-5rjg-fvgr-3xxf",
              "GHSA-h35f-9h28-mq5c",
              "PYSEC-2025-49",
              "PYSEC-2026-3447"
            ],
            "fixed_version": "83.0.0",
            "advisory_count": 4,
            "oldest_advisory_days": 431
          },
          {
            "name": "urllib3",
            "direct": true,
            "version": "2.6.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-38jv-5279-wg99",
              "GHSA-mf9v-mfxr-j63j",
              "GHSA-qccp-gfcp-xxvc",
              "PYSEC-2026-141",
              "PYSEC-2026-142",
              "PYSEC-2026-1996"
            ],
            "fixed_version": "2.7.0",
            "advisory_count": 6,
            "oldest_advisory_days": 196
          },
          {
            "name": "urllib3",
            "direct": true,
            "version": "2.6.2",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-38jv-5279-wg99",
              "GHSA-mf9v-mfxr-j63j",
              "GHSA-qccp-gfcp-xxvc",
              "PYSEC-2026-141",
              "PYSEC-2026-142",
              "PYSEC-2026-1996"
            ],
            "fixed_version": "2.7.0",
            "advisory_count": 6,
            "oldest_advisory_days": 196
          },
          {
            "name": "click",
            "direct": false,
            "version": "8.1.8",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.2,
            "advisory_ids": [
              "PYSEC-2026-2132"
            ],
            "fixed_version": "8.3.3",
            "advisory_count": 1,
            "oldest_advisory_days": 83
          },
          {
            "name": "dulwich",
            "direct": false,
            "version": "0.22.8",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-897w-fcg9-f6xj",
              "GHSA-xrvj-v92f-53gj",
              "PYSEC-2026-2463",
              "PYSEC-2026-2466"
            ],
            "fixed_version": "1.2.5",
            "advisory_count": 4,
            "oldest_advisory_days": 55
          },
          {
            "name": "jaraco-context",
            "direct": false,
            "version": "6.0.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 8.6,
            "advisory_ids": [
              "GHSA-58pv-8j8x-9vj2",
              "PYSEC-2026-1469"
            ],
            "fixed_version": "6.1.0",
            "advisory_count": 2,
            "oldest_advisory_days": 190
          },
          {
            "name": "mako",
            "direct": false,
            "version": "1.3.10",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-2h4p-vjrc-8xpq",
              "GHSA-v92g-xgxw-vvmm",
              "PYSEC-2026-2617",
              "PYSEC-2026-88"
            ],
            "fixed_version": "1.3.12",
            "advisory_count": 4,
            "oldest_advisory_days": 97
          },
          {
            "name": "msgpack",
            "direct": false,
            "version": "1.1.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-6v7p-g79w-8964"
            ],
            "fixed_version": "1.2.1",
            "advisory_count": 1,
            "oldest_advisory_days": 33
          },
          {
            "name": "pyasn1",
            "direct": false,
            "version": "0.6.1",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-63vm-454h-vhhq",
              "GHSA-8ppf-4f7h-5ppj",
              "GHSA-hm4w-wwcw-mr6r",
              "GHSA-jr27-m4p2-rc6r",
              "PYSEC-2026-1810",
              "PYSEC-2026-2263",
              "PYSEC-2026-3455",
              "PYSEC-2026-3456",
              "PYSEC-2026-3457"
            ],
            "fixed_version": "0.6.4",
            "advisory_count": 9,
            "oldest_advisory_days": 187
          },
          {
            "name": "starlette",
            "direct": false,
            "version": "0.46.2",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-2c2j-9gv5-cj73",
              "GHSA-7f5h-v6xp-fcq8",
              "GHSA-82w8-qh3p-5jfq",
              "GHSA-86qp-5c8j-p5mr",
              "GHSA-jp82-jpqv-5vv3",
              "GHSA-wqp7-x3pw-xc5r",
              "GHSA-x746-7m8f-x49c",
              "PYSEC-2026-161",
              "PYSEC-2026-1941",
              "PYSEC-2026-1942"
            ],
            "fixed_version": "1.3.1",
            "advisory_count": 14,
            "oldest_advisory_days": 366
          },
          {
            "name": "ujson",
            "direct": false,
            "version": "5.10.0",
            "severity": "high",
            "ecosystem": "pypi",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3j69-69wj-xqx2",
              "GHSA-c38f-wx89-p2xg",
              "GHSA-c8rr-9gxc-jprv",
              "GHSA-wgvc-ghv9-3pmm",
              "PYSEC-2026-2291",
              "PYSEC-2026-2292",
              "PYSEC-2026-2293",
              "PYSEC-2026-2294"
            ],
            "fixed_version": "5.13.0",
            "advisory_count": 8,
            "oldest_advisory_days": 126
          },
          {
            "name": "marshmallow",
            "direct": true,
            "version": "3.26.1",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-428g-f7cq-pgp5",
              "PYSEC-2026-1605"
            ],
            "fixed_version": "4.1.2",
            "advisory_count": 2,
            "oldest_advisory_days": 212
          },
          {
            "name": "poetry",
            "direct": true,
            "version": "2.1.2",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.5,
            "advisory_ids": [
              "GHSA-2599-h6xx-hpxp",
              "GHSA-73h3-mf4w-8647",
              "PYSEC-2026-2260",
              "PYSEC-2026-2890"
            ],
            "fixed_version": "2.3.4",
            "advisory_count": 4,
            "oldest_advisory_days": 112
          },
          {
            "name": "werkzeug",
            "direct": true,
            "version": "3.1.3",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-29vq-49wr-vm6x",
              "GHSA-87hc-h4r5-73f7",
              "GHSA-hgf8-39gv-g3f2",
              "PYSEC-2026-2044",
              "PYSEC-2026-2046",
              "PYSEC-2026-2320"
            ],
            "fixed_version": "3.1.6",
            "advisory_count": 6,
            "oldest_advisory_days": 233
          },
          {
            "name": "filelock",
            "direct": false,
            "version": "3.18.0",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.3,
            "advisory_ids": [
              "GHSA-qmgc-5h2g-mvrw",
              "GHSA-w853-jp5j-5j7f",
              "PYSEC-2026-1374",
              "PYSEC-2026-1375"
            ],
            "fixed_version": "3.20.3",
            "advisory_count": 4,
            "oldest_advisory_days": 218
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.10",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-65pc-fj4g-8rjx",
              "PYSEC-2026-215"
            ],
            "fixed_version": "3.15",
            "advisory_count": 2,
            "oldest_advisory_days": 64
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "8.3.5",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 6.8,
            "advisory_ids": [
              "GHSA-6w46-j5rx-g56g",
              "PYSEC-2026-1845"
            ],
            "fixed_version": "9.0.3",
            "advisory_count": 2,
            "oldest_advisory_days": 181
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.32.3",
            "severity": "moderate",
            "ecosystem": "pypi",
            "cvss_score": 5.5,
            "advisory_ids": [
              "GHSA-9hjg-9r4m-mvj7",
              "GHSA-gc5v-m9x4-r6x2",
              "PYSEC-2026-1872",
              "PYSEC-2026-2275"
            ],
            "fixed_version": "2.33.0",
            "advisory_count": 4,
            "oldest_advisory_days": 408
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.19.1",
            "severity": "low",
            "ecosystem": "pypi",
            "cvss_score": 3.3,
            "advisory_ids": [
              "GHSA-5239-wwwm-4pmq",
              "PYSEC-2026-2987"
            ],
            "fixed_version": "2.20.0",
            "advisory_count": 2,
            "oldest_advisory_days": 122
          },
          {
            "name": "virtualenv",
            "direct": false,
            "version": "20.30.0",
            "severity": "unknown",
            "ecosystem": "pypi",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-597g-3phw-6986",
              "PYSEC-2026-2009"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": null
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 1,
          "high": 14,
          "unknown": 1,
          "critical": 4,
          "moderate": 7
        },
        "advisory_count": 150,
        "affected_count": 27,
        "assessed_count": 212,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 11
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "sanic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "pydantic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0.38"
        },
        {
          "name": "alembic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.14.1"
        },
        {
          "name": "asyncpg",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.30.0"
        },
        {
          "name": "pyjwt",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.1"
        },
        {
          "name": "tenacity",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "<0.29"
        },
        {
          "name": "kubernetes",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^31.0.0"
        },
        {
          "name": "python-ulid",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "python-gitlab",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "psycopg",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.2.3"
        },
        {
          "name": "urllib3",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.6.0"
        },
        {
          "name": "deepmerge",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0"
        },
        {
          "name": "authlib",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "undictify",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.11.3"
        },
        {
          "name": "prometheus-sanic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "prometheus_client",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "marshmallow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.26.1"
        },
        {
          "name": "escapism",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "sentry-sdk",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.22.0"
        },
        {
          "name": "authzed",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "cryptography",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^44.0.1"
        },
        {
          "name": "setuptools",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^75.8.2"
        },
        {
          "name": "kr8s",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.20.7"
        },
        {
          "name": "python-box",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^7.0.1"
        },
        {
          "name": "werkzeug",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.1.3"
        },
        {
          "name": "toml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.10.2"
        },
        {
          "name": "aiofiles",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^24.1.0"
        },
        {
          "name": "protobuf",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.29.3"
        },
        {
          "name": "poetry",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "parsy",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.1"
        },
        {
          "name": "sanic-ext",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "posthog",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.21.0"
        },
        {
          "name": "markdown-code-runner",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "sanic",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "pydantic",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0.38"
        },
        {
          "name": "alembic",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.14.1"
        },
        {
          "name": "asyncpg",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.30.0"
        },
        {
          "name": "pyjwt",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.1"
        },
        {
          "name": "tenacity",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "httpx",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "<0.29"
        },
        {
          "name": "kubernetes",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^31.0.0"
        },
        {
          "name": "python-ulid",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "python-gitlab",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "psycopg",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.2.3"
        },
        {
          "name": "urllib3",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.6.0"
        },
        {
          "name": "deepmerge",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0"
        },
        {
          "name": "authlib",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "undictify",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.11.3"
        },
        {
          "name": "prometheus-sanic",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "sentry-sdk",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.22.0"
        },
        {
          "name": "authzed",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "setuptools",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^75.8.2"
        },
        {
          "name": "aiofiles",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^24.1.0"
        },
        {
          "name": "protobuf",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.29.3"
        },
        {
          "name": "cryptography",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^44.0.1"
        },
        {
          "name": "marshmallow",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.26.1"
        },
        {
          "name": "escapism",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "kr8s",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.20.7"
        },
        {
          "name": "python-box",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^7.0.1"
        },
        {
          "name": "werkzeug",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.1.3"
        },
        {
          "name": "toml",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.10.2"
        },
        {
          "name": "parsy",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.1"
        },
        {
          "name": "sanic-ext",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "markdown-code-runner",
          "manifest": "projects/k8s_watcher/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "sanic",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "pydantic",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0.38"
        },
        {
          "name": "alembic",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.14.1"
        },
        {
          "name": "asyncpg",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.30.0"
        },
        {
          "name": "pyjwt",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.1"
        },
        {
          "name": "tenacity",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "httpx",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "<0.29"
        },
        {
          "name": "kubernetes",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^31.0.0"
        },
        {
          "name": "python-ulid",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "python-gitlab",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "psycopg",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.2.3"
        },
        {
          "name": "urllib3",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.6.0"
        },
        {
          "name": "deepmerge",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0"
        },
        {
          "name": "authlib",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "undictify",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.11.3"
        },
        {
          "name": "prometheus-sanic",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "sentry-sdk",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.22.0"
        },
        {
          "name": "authzed",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "setuptools",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^75.8.2"
        },
        {
          "name": "aiofiles",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^24.1.0"
        },
        {
          "name": "protobuf",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.29.3"
        },
        {
          "name": "cryptography",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^44.0.1"
        },
        {
          "name": "marshmallow",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.26.1"
        },
        {
          "name": "escapism",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "kr8s",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.20.7"
        },
        {
          "name": "python-box",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^7.0.1"
        },
        {
          "name": "werkzeug",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.1.3"
        },
        {
          "name": "toml",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.10.2"
        },
        {
          "name": "parsy",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.1"
        },
        {
          "name": "sanic-ext",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "posthog",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.21.0"
        },
        {
          "name": "markdown-code-runner",
          "manifest": "projects/renku_data_service/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "sanic",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "pydantic",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0.38"
        },
        {
          "name": "alembic",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.14.1"
        },
        {
          "name": "asyncpg",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.30.0"
        },
        {
          "name": "pyjwt",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.1"
        },
        {
          "name": "tenacity",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "httpx",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "<0.29"
        },
        {
          "name": "kubernetes",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^31.0.0"
        },
        {
          "name": "python-ulid",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "python-gitlab",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "psycopg",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.2.3"
        },
        {
          "name": "urllib3",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.6.0"
        },
        {
          "name": "deepmerge",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0"
        },
        {
          "name": "authlib",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "undictify",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.11.3"
        },
        {
          "name": "prometheus-sanic",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "sentry-sdk",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.22.0"
        },
        {
          "name": "authzed",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "setuptools",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^75.8.2"
        },
        {
          "name": "aiofiles",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^24.1.0"
        },
        {
          "name": "protobuf",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.29.3"
        },
        {
          "name": "cryptography",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^44.0.1"
        },
        {
          "name": "marshmallow",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.26.1"
        },
        {
          "name": "escapism",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "kr8s",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.20.7"
        },
        {
          "name": "python-box",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^7.0.1"
        },
        {
          "name": "werkzeug",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.1.3"
        },
        {
          "name": "toml",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.10.2"
        },
        {
          "name": "parsy",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.1"
        },
        {
          "name": "sanic-ext",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^23.12.0"
        },
        {
          "name": "posthog",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.21.0"
        },
        {
          "name": "markdown-code-runner",
          "manifest": "projects/renku_data_tasks/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "sanic",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "pydantic",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.6"
        },
        {
          "name": "sqlalchemy",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0.38"
        },
        {
          "name": "alembic",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.14.1"
        },
        {
          "name": "asyncpg",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.30.0"
        },
        {
          "name": "pyjwt",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.10.1"
        },
        {
          "name": "tenacity",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^9.0.0"
        },
        {
          "name": "httpx",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "<0.29"
        },
        {
          "name": "kubernetes",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^31.0.0"
        },
        {
          "name": "python-ulid",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "python-gitlab",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.6.0"
        },
        {
          "name": "psycopg",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.2.3"
        },
        {
          "name": "urllib3",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.6.0"
        },
        {
          "name": "deepmerge",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.0"
        },
        {
          "name": "authlib",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "undictify",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.11.3"
        },
        {
          "name": "prometheus-sanic",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "sentry-sdk",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.22.0"
        },
        {
          "name": "cryptography",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^44.0.1"
        },
        {
          "name": "authzed",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.20.0"
        },
        {
          "name": "setuptools",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^75.8.2"
        },
        {
          "name": "aiofiles",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^24.1.0"
        },
        {
          "name": "protobuf",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^5.29.3"
        },
        {
          "name": "escapism",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "kr8s",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.20.7"
        },
        {
          "name": "python-box",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^7.0.1"
        },
        {
          "name": "marshmallow",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.26.1"
        },
        {
          "name": "toml",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^0.10.2"
        },
        {
          "name": "werkzeug",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.1.3"
        },
        {
          "name": "parsy",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.1"
        },
        {
          "name": "sanic-ext",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^25.12.0"
        },
        {
          "name": "posthog",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^3.21.0"
        },
        {
          "name": "markdown-code-runner",
          "manifest": "projects/secrets_storage/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "^2.2.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "aiofiles",
            "direct": true,
            "version": "24.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "alembic",
            "direct": true,
            "version": "1.15.2",
            "ecosystem": "pypi"
          },
          {
            "name": "asyncpg",
            "direct": true,
            "version": "0.30.0",
            "ecosystem": "pypi"
          },
          {
            "name": "authlib",
            "direct": true,
            "version": "1.5.2",
            "ecosystem": "pypi"
          },
          {
            "name": "authlib",
            "direct": true,
            "version": "1.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "authzed",
            "direct": true,
            "version": "1.21.1",
            "ecosystem": "pypi"
          },
          {
            "name": "cryptography",
            "direct": true,
            "version": "44.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "deepmerge",
            "direct": true,
            "version": "2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "escapism",
            "direct": true,
            "version": "1.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "httpx",
            "direct": true,
            "version": "0.28.1",
            "ecosystem": "pypi"
          },
          {
            "name": "kr8s",
            "direct": true,
            "version": "0.20.7",
            "ecosystem": "pypi"
          },
          {
            "name": "kubernetes",
            "direct": true,
            "version": "31.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown-code-runner",
            "direct": true,
            "version": "2.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "marshmallow",
            "direct": true,
            "version": "3.26.1",
            "ecosystem": "pypi"
          },
          {
            "name": "marshmallow",
            "direct": true,
            "version": "3.26.2",
            "ecosystem": "pypi"
          },
          {
            "name": "parsy",
            "direct": true,
            "version": "2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "poetry",
            "direct": true,
            "version": "2.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "posthog",
            "direct": true,
            "version": "3.25.0",
            "ecosystem": "pypi"
          },
          {
            "name": "prometheus-client",
            "direct": true,
            "version": "0.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "prometheus-sanic",
            "direct": true,
            "version": "3.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "protobuf",
            "direct": true,
            "version": "5.29.4",
            "ecosystem": "pypi"
          },
          {
            "name": "psycopg",
            "direct": true,
            "version": "3.2.6",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic",
            "direct": true,
            "version": "2.11.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic",
            "direct": true,
            "version": "2.13.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pyjwt",
            "direct": true,
            "version": "2.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "python-box",
            "direct": true,
            "version": "7.3.2",
            "ecosystem": "pypi"
          },
          {
            "name": "python-gitlab",
            "direct": true,
            "version": "5.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-ulid",
            "direct": true,
            "version": "3.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sanic",
            "direct": true,
            "version": "25.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sanic-ext",
            "direct": true,
            "version": "23.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sanic-ext",
            "direct": true,
            "version": "25.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sentry-sdk",
            "direct": true,
            "version": "2.26.1",
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": true,
            "version": "75.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "sqlalchemy",
            "direct": true,
            "version": "2.0.40",
            "ecosystem": "pypi"
          },
          {
            "name": "tenacity",
            "direct": true,
            "version": "9.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "toml",
            "direct": true,
            "version": "0.10.2",
            "ecosystem": "pypi"
          },
          {
            "name": "undictify",
            "direct": true,
            "version": "0.11.3",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": true,
            "version": "2.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "urllib3",
            "direct": true,
            "version": "2.6.2",
            "ecosystem": "pypi"
          },
          {
            "name": "werkzeug",
            "direct": true,
            "version": "3.1.3",
            "ecosystem": "pypi"
          },
          {
            "name": "aiosqlite",
            "direct": false,
            "version": "0.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "annotated-types",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "anyio",
            "direct": false,
            "version": "4.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "argcomplete",
            "direct": false,
            "version": "3.6.2",
            "ecosystem": "pypi"
          },
          {
            "name": "arrow",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "asyncache",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "attrs",
            "direct": false,
            "version": "25.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "backoff",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "bandit",
            "direct": false,
            "version": "1.8.3",
            "ecosystem": "pypi"
          },
          {
            "name": "black",
            "direct": false,
            "version": "25.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "build",
            "direct": false,
            "version": "1.2.2.post1",
            "ecosystem": "pypi"
          },
          {
            "name": "cachecontrol",
            "direct": false,
            "version": "0.14.2",
            "ecosystem": "pypi"
          },
          {
            "name": "cachetools",
            "direct": false,
            "version": "5.5.2",
            "ecosystem": "pypi"
          },
          {
            "name": "cel-python",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "certifi",
            "direct": false,
            "version": "2025.1.31",
            "ecosystem": "pypi"
          },
          {
            "name": "cffi",
            "direct": false,
            "version": "1.17.1",
            "ecosystem": "pypi"
          },
          {
            "name": "cfgv",
            "direct": false,
            "version": "3.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "charset-normalizer",
            "direct": false,
            "version": "3.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "cleo",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "click",
            "direct": false,
            "version": "8.1.8",
            "ecosystem": "pypi"
          },
          {
            "name": "colorama",
            "direct": false,
            "version": "0.4.6",
            "ecosystem": "pypi"
          },
          {
            "name": "coverage",
            "direct": false,
            "version": "7.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "crashtest",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "datamodel-code-generator",
            "direct": false,
            "version": "0.57.0",
            "ecosystem": "pypi"
          },
          {
            "name": "debugpy",
            "direct": false,
            "version": "1.8.14",
            "ecosystem": "pypi"
          },
          {
            "name": "distlib",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "pypi"
          },
          {
            "name": "distro",
            "direct": false,
            "version": "1.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "dnspython",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "dulwich",
            "direct": false,
            "version": "0.22.8",
            "ecosystem": "pypi"
          },
          {
            "name": "durationpy",
            "direct": false,
            "version": "0.9",
            "ecosystem": "pypi"
          },
          {
            "name": "email-validator",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "execnet",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "fastjsonschema",
            "direct": false,
            "version": "2.21.1",
            "ecosystem": "pypi"
          },
          {
            "name": "filelock",
            "direct": false,
            "version": "3.18.0",
            "ecosystem": "pypi"
          },
          {
            "name": "findpython",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "pypi"
          },
          {
            "name": "fqdn",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "pypi"
          },
          {
            "name": "genson",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "google-auth",
            "direct": false,
            "version": "2.39.0",
            "ecosystem": "pypi"
          },
          {
            "name": "googleapis-common-protos",
            "direct": false,
            "version": "1.70.0",
            "ecosystem": "pypi"
          },
          {
            "name": "graphql-core",
            "direct": false,
            "version": "3.2.6",
            "ecosystem": "pypi"
          },
          {
            "name": "greenlet",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "greenlet",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "grpc-interceptor",
            "direct": false,
            "version": "0.15.4",
            "ecosystem": "pypi"
          },
          {
            "name": "grpcio",
            "direct": false,
            "version": "1.71.0",
            "ecosystem": "pypi"
          },
          {
            "name": "h11",
            "direct": false,
            "version": "0.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "harfile",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "html5tagger",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "httpcore",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "pypi"
          },
          {
            "name": "httptools",
            "direct": false,
            "version": "0.6.4",
            "ecosystem": "pypi"
          },
          {
            "name": "httpx-ws",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis",
            "direct": false,
            "version": "6.131.8",
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis-graphql",
            "direct": false,
            "version": "0.11.1",
            "ecosystem": "pypi"
          },
          {
            "name": "hypothesis-jsonschema",
            "direct": false,
            "version": "0.23.1",
            "ecosystem": "pypi"
          },
          {
            "name": "identify",
            "direct": false,
            "version": "2.6.10",
            "ecosystem": "pypi"
          },
          {
            "name": "idna",
            "direct": false,
            "version": "3.10",
            "ecosystem": "pypi"
          },
          {
            "name": "inflect",
            "direct": false,
            "version": "5.6.2",
            "ecosystem": "pypi"
          },
          {
            "name": "iniconfig",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "installer",
            "direct": false,
            "version": "0.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "isoduration",
            "direct": false,
            "version": "20.11.0",
            "ecosystem": "pypi"
          },
          {
            "name": "isort",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jaraco-classes",
            "direct": false,
            "version": "3.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jaraco-context",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jaraco-functools",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jeepney",
            "direct": false,
            "version": "0.9.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jinja2",
            "direct": false,
            "version": "3.1.6",
            "ecosystem": "pypi"
          },
          {
            "name": "jmespath",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonpointer",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": false,
            "version": "4.23.0",
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema-specifications",
            "direct": false,
            "version": "2025.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "junit-xml",
            "direct": false,
            "version": "1.9",
            "ecosystem": "pypi"
          },
          {
            "name": "keyring",
            "direct": false,
            "version": "25.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "lark",
            "direct": false,
            "version": "0.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mako",
            "direct": false,
            "version": "1.3.10",
            "ecosystem": "pypi"
          },
          {
            "name": "markdown-it-py",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "markupsafe",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mdurl",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "mirakuru",
            "direct": false,
            "version": "2.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "monotonic",
            "direct": false,
            "version": "1.6",
            "ecosystem": "pypi"
          },
          {
            "name": "more-itertools",
            "direct": false,
            "version": "10.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "msgpack",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "multidict",
            "direct": false,
            "version": "6.4.3",
            "ecosystem": "pypi"
          },
          {
            "name": "mypy",
            "direct": false,
            "version": "1.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "mypy-extensions",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "pypi"
          },
          {
            "name": "nodeenv",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "oauthlib",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "25.0",
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": false,
            "version": "26.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pathspec",
            "direct": false,
            "version": "0.12.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pbr",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pbs-installer",
            "direct": false,
            "version": "2025.4.9",
            "ecosystem": "pypi"
          },
          {
            "name": "pkginfo",
            "direct": false,
            "version": "1.12.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "platformdirs",
            "direct": false,
            "version": "4.3.7",
            "ecosystem": "pypi"
          },
          {
            "name": "pluggy",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "pypi"
          },
          {
            "name": "poetry-core",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "pypi"
          },
          {
            "name": "port-for",
            "direct": false,
            "version": "0.7.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pre-commit",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "propcache",
            "direct": false,
            "version": "0.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "protovalidate",
            "direct": false,
            "version": "0.7.1",
            "ecosystem": "pypi"
          },
          {
            "name": "psutil",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "psycopg-binary",
            "direct": false,
            "version": "3.2.6",
            "ecosystem": "pypi"
          },
          {
            "name": "pyasn1",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyasn1-modules",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pycparser",
            "direct": false,
            "version": "2.22",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-core",
            "direct": false,
            "version": "2.33.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic-core",
            "direct": false,
            "version": "2.46.4",
            "ecosystem": "pypi"
          },
          {
            "name": "pygments",
            "direct": false,
            "version": "2.19.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pyproject-hooks",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pyrate-limiter",
            "direct": false,
            "version": "3.7.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": "8.3.5",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-asyncio",
            "direct": false,
            "version": "0.21.2",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-cov",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-mock",
            "direct": false,
            "version": "3.14.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-postgresql",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-subtests",
            "direct": false,
            "version": "0.14.1",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-testmon",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-xdist",
            "direct": false,
            "version": "3.6.1",
            "ecosystem": "pypi"
          },
          {
            "name": "python-dateutil",
            "direct": false,
            "version": "2.9.0.post0",
            "ecosystem": "pypi"
          },
          {
            "name": "python-jsonpath",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "pywin32-ctypes",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "pypi"
          },
          {
            "name": "rapidfuzz",
            "direct": false,
            "version": "3.13.0",
            "ecosystem": "pypi"
          },
          {
            "name": "referencing",
            "direct": false,
            "version": "0.36.2",
            "ecosystem": "pypi"
          },
          {
            "name": "requests",
            "direct": false,
            "version": "2.32.3",
            "ecosystem": "pypi"
          },
          {
            "name": "requests-oauthlib",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "requests-toolbelt",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3339-validator",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "pypi"
          },
          {
            "name": "rfc3987",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "pypi"
          },
          {
            "name": "rich",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rpds-py",
            "direct": false,
            "version": "0.24.0",
            "ecosystem": "pypi"
          },
          {
            "name": "rsa",
            "direct": false,
            "version": "4.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "ruamel-yaml",
            "direct": false,
            "version": "0.18.14",
            "ecosystem": "pypi"
          },
          {
            "name": "ruamel-yaml-clib",
            "direct": false,
            "version": "0.2.12",
            "ecosystem": "pypi"
          },
          {
            "name": "ruff",
            "direct": false,
            "version": "0.8.6",
            "ecosystem": "pypi"
          },
          {
            "name": "sanic-routing",
            "direct": false,
            "version": "23.12.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sanic-testing",
            "direct": false,
            "version": "24.6.0",
            "ecosystem": "pypi"
          },
          {
            "name": "schemathesis",
            "direct": false,
            "version": "3.39.7",
            "ecosystem": "pypi"
          },
          {
            "name": "secretstorage",
            "direct": false,
            "version": "3.3.3",
            "ecosystem": "pypi"
          },
          {
            "name": "shellingham",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "pypi"
          },
          {
            "name": "six",
            "direct": false,
            "version": "1.17.0",
            "ecosystem": "pypi"
          },
          {
            "name": "sniffio",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "sortedcontainers",
            "direct": false,
            "version": "2.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "starlette",
            "direct": false,
            "version": "0.46.2",
            "ecosystem": "pypi"
          },
          {
            "name": "starlette-testclient",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "stevedore",
            "direct": false,
            "version": "5.4.1",
            "ecosystem": "pypi"
          },
          {
            "name": "syrupy",
            "direct": false,
            "version": "4.9.1",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli",
            "direct": false,
            "version": "2.2.1",
            "ecosystem": "pypi"
          },
          {
            "name": "tomli-w",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "tomlkit",
            "direct": false,
            "version": "0.13.2",
            "ecosystem": "pypi"
          },
          {
            "name": "tracerite",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "pypi"
          },
          {
            "name": "trove-classifiers",
            "direct": false,
            "version": "2025.4.11.15",
            "ecosystem": "pypi"
          },
          {
            "name": "types-aiofiles",
            "direct": false,
            "version": "24.1.0.20250326",
            "ecosystem": "pypi"
          },
          {
            "name": "types-python-dateutil",
            "direct": false,
            "version": "2.9.0.20241206",
            "ecosystem": "pypi"
          },
          {
            "name": "types-pyyaml",
            "direct": false,
            "version": "6.0.12.20250402",
            "ecosystem": "pypi"
          },
          {
            "name": "types-requests",
            "direct": false,
            "version": "2.32.0.20250328",
            "ecosystem": "pypi"
          },
          {
            "name": "types-toml",
            "direct": false,
            "version": "0.10.8.20240310",
            "ecosystem": "pypi"
          },
          {
            "name": "types-urllib3",
            "direct": false,
            "version": "1.26.25.14",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.13.2",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-extensions",
            "direct": false,
            "version": "4.15.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-inspection",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "pypi"
          },
          {
            "name": "typing-inspection",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "pypi"
          },
          {
            "name": "tzdata",
            "direct": false,
            "version": "2025.2",
            "ecosystem": "pypi"
          },
          {
            "name": "ujson",
            "direct": false,
            "version": "5.10.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uri-template",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "pypi"
          },
          {
            "name": "uvloop",
            "direct": false,
            "version": "0.21.0",
            "ecosystem": "pypi"
          },
          {
            "name": "virtualenv",
            "direct": false,
            "version": "20.30.0",
            "ecosystem": "pypi"
          },
          {
            "name": "webcolors",
            "direct": false,
            "version": "24.11.1",
            "ecosystem": "pypi"
          },
          {
            "name": "websocket-client",
            "direct": false,
            "version": "1.8.0",
            "ecosystem": "pypi"
          },
          {
            "name": "websockets",
            "direct": false,
            "version": "15.0.1",
            "ecosystem": "pypi"
          },
          {
            "name": "wsproto",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "pypi"
          },
          {
            "name": "xattr",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "pypi"
          },
          {
            "name": "yarl",
            "direct": false,
            "version": "1.20.0",
            "ecosystem": "pypi"
          },
          {
            "name": "zstandard",
            "direct": false,
            "version": "0.23.0",
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 212,
        "direct_count": 40,
        "indirect_count": 172
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 47,
        "merged_prs": 802,
        "open_issues": 147,
        "closed_ratio": 0.622,
        "closed_issues": 242,
        "closed_unmerged_prs": 148
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "olevski",
          "commits": 198,
          "avatar_url": "https://avatars.githubusercontent.com/u/16360283?v=4"
        },
        {
          "type": "User",
          "login": "leafty",
          "commits": 149,
          "avatar_url": "https://avatars.githubusercontent.com/u/951086?v=4"
        },
        {
          "type": "User",
          "login": "Panaetius",
          "commits": 131,
          "avatar_url": "https://avatars.githubusercontent.com/u/664486?v=4"
        },
        {
          "type": "User",
          "login": "eikek",
          "commits": 50,
          "avatar_url": "https://avatars.githubusercontent.com/u/701128?v=4"
        },
        {
          "type": "User",
          "login": "mohammad-alisafaee",
          "commits": 25,
          "avatar_url": "https://avatars.githubusercontent.com/u/50210674?v=4"
        },
        {
          "type": "User",
          "login": "sambuc",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/2292559?v=4"
        },
        {
          "type": "User",
          "login": "sgaist",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/898010?v=4"
        },
        {
          "type": "User",
          "login": "SalimKayal",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/1343871?v=4"
        },
        {
          "type": "User",
          "login": "andre-code",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/43388408?v=4"
        },
        {
          "type": "User",
          "login": "ciyer",
          "commits": 11,
          "avatar_url": "https://avatars.githubusercontent.com/u/1196411?v=4"
        }
      ],
      "contributors_sampled": 16,
      "top_contributor_share": 0.308
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "acceptance-tests.yml",
        "save_cache.yml",
        "test_publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "poetry.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 10 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "65 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e81895b495079eef2dfd00ff6569f6e3b2f31815",
        "ran_at": "2026-07-23T01:57:21Z",
        "aggregate_score": 6.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-22T19:17:51Z",
      "oldest_open_prs": [
        {
          "number": 128,
          "created_at": "2024-02-26T12:27:55Z",
          "last_comment_at": "2024-03-26T11:04:40Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 248,
          "created_at": "2024-06-10T08:59:18Z",
          "last_comment_at": "2024-06-10T10:13:40Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 425,
          "created_at": "2024-09-25T09:21:15Z",
          "last_comment_at": "2024-09-25T14:32:13Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 727,
          "created_at": "2025-03-12T14:04:08Z",
          "last_comment_at": "2025-03-20T21:37:46Z",
          "last_comment_author": "RenkuBot"
        },
        {
          "number": 750,
          "created_at": "2025-03-26T07:02:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 785,
          "created_at": "2025-04-09T22:39:38Z",
          "last_comment_at": "2025-04-09T23:13:22Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 790,
          "created_at": "2025-04-10T21:53:35Z",
          "last_comment_at": "2025-04-10T22:13:03Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 840,
          "created_at": "2025-05-13T11:45:57Z",
          "last_comment_at": "2025-05-13T11:47:02Z",
          "last_comment_author": "RenkuBot"
        },
        {
          "number": 848,
          "created_at": "2025-05-14T12:26:21Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 867,
          "created_at": "2025-05-19T07:48:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 929,
          "created_at": "2025-07-16T08:34:30Z",
          "last_comment_at": "2025-07-16T08:54:08Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 995,
          "created_at": "2025-08-26T14:00:49Z",
          "last_comment_at": "2025-08-26T14:31:38Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 1019,
          "created_at": "2025-09-25T11:50:56Z",
          "last_comment_at": "2025-09-25T15:35:05Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 1053,
          "created_at": "2025-10-08T12:01:40Z",
          "last_comment_at": "2025-10-08T13:05:53Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 1068,
          "created_at": "2025-10-17T07:36:46Z",
          "last_comment_at": "2025-10-17T08:09:35Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 1090,
          "created_at": "2025-10-30T14:40:55Z",
          "last_comment_at": "2025-10-31T10:50:17Z",
          "last_comment_author": "RenkuBot"
        },
        {
          "number": 1103,
          "created_at": "2025-11-10T10:12:02Z",
          "last_comment_at": "2025-11-10T17:40:38Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 1124,
          "created_at": "2025-11-28T10:52:50Z",
          "last_comment_at": "2025-11-28T11:20:46Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 1134,
          "created_at": "2025-12-12T09:11:41Z",
          "last_comment_at": "2025-12-12T09:33:07Z",
          "last_comment_author": "coveralls"
        },
        {
          "number": 1135,
          "created_at": "2025-12-12T13:19:17Z",
          "last_comment_at": "2025-12-12T13:49:44Z",
          "last_comment_author": "coveralls"
        }
      ],
      "last_merged_pr_at": "2026-07-22T18:48:50Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 24,
          "created_at": "2023-08-25T09:44:15Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 123,
          "created_at": "2024-02-16T08:58:27Z",
          "last_comment_at": "2024-03-21T14:42:09Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 146,
          "created_at": "2024-03-13T09:51:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 151,
          "created_at": "2024-03-18T14:58:39Z",
          "last_comment_at": "2024-10-29T09:36:55Z",
          "last_comment_author": "Panaetius"
        },
        {
          "number": 181,
          "created_at": "2024-04-24T12:59:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 191,
          "created_at": "2024-05-08T09:37:57Z",
          "last_comment_at": "2024-10-29T07:55:38Z",
          "last_comment_author": "Panaetius"
        },
        {
          "number": 199,
          "created_at": "2024-05-13T13:08:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 200,
          "created_at": "2024-05-13T14:12:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 233,
          "created_at": "2024-05-29T09:30:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 266,
          "created_at": "2024-06-19T06:57:57Z",
          "last_comment_at": "2024-07-08T07:27:45Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 278,
          "created_at": "2024-06-21T07:33:12Z",
          "last_comment_at": "2024-06-21T07:40:23Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 280,
          "created_at": "2024-06-21T13:34:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 286,
          "created_at": "2024-06-25T12:05:47Z",
          "last_comment_at": "2024-07-08T07:26:22Z",
          "last_comment_author": "leafty"
        },
        {
          "number": 294,
          "created_at": "2024-07-03T10:00:07Z",
          "last_comment_at": "2024-07-03T10:01:12Z",
          "last_comment_author": "olevski"
        },
        {
          "number": 303,
          "created_at": "2024-07-15T14:23:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 309,
          "created_at": "2024-07-16T14:26:28Z",
          "last_comment_at": "2024-10-29T14:41:26Z",
          "last_comment_author": "Panaetius"
        },
        {
          "number": 344,
          "created_at": "2024-08-06T14:35:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 367,
          "created_at": "2024-08-23T11:18:34Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 396,
          "created_at": "2024-09-11T08:23:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 400,
          "created_at": "2024-09-11T09:01:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/SwissDataScienceCenter/renku-data-services",
    "host": "github.com",
    "name": "renku-data-services",
    "owner": "SwissDataScienceCenter"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 70,
      "inputs": {
        "security": 56,
        "vitality": 99,
        "community": 42,
        "governance": 70,
        "engineering": 76
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 99,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "commits_last_year": 209,
              "human_commit_share": 0.91,
              "days_since_last_push": 0,
              "active_weeks_last_year": 51
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "51/52 weeks with commits",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 51
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "209 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 209
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.79.0",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 8.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~8.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 8.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 42,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "forks": 2,
              "stars": 8,
              "watchers": 6,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "8 stars",
                "points": 13.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "6 watchers",
                "points": 3.9,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 70,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 16,
              "top_contributor_share": 0.308
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 31% of commits",
                "points": 15.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 31
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "16 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 10 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "merged_prs": 802,
              "open_issues": 147,
              "closed_issues": 242,
              "issue_closed_ratio": 0.622,
              "closed_unmerged_prs": 148
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "62% of issues closed",
                "points": 29.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 62
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "802/950 decided PRs merged",
                "points": 32.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 802,
                      "decided": 950
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "followers": 132,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "SwissDataScienceCenter",
              "public_repos": 135,
              "account_age_days": 3481
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "132 followers of SwissDataScienceCenter",
                "points": 15.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 132,
                      "login": "SwissDataScienceCenter"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "135 public repos, account ~9 yr old",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 135
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 9
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 76,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 16,
                "status": "met",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 56,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 6.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 10 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "65 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "critical",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 212 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 212
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 23,
            "inputs": {
              "source": "osv",
              "advisories": 150,
              "affected_packages": 27,
              "assessed_packages": 212,
              "unassessed_packages": 0,
              "affected_by_severity": "critical 4, high 14, moderate 7, low 1, unknown 1",
              "direct_affected_packages": 11
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "11 affected: authlib 1.5.2 (critical 9.1), authlib 1.6.0 (critical 9.1), cryptography 44.0.2 (high 7.5), +8 more",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 11,
                      "packages": "authlib 1.5.2 (critical 9.1), authlib 1.6.0 (critical 9.1), cryptography 44.0.2 (high 7.5)"
                    }
                  },
                  {
                    "code": "advisories_affected_more",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "10 advisory-carrying package(s) unaddressed past 90 days; oldest published 431 days ago",
                "points": 14,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 10,
                      "oldest": 431
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 212,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 11
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 66,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "91 of 91 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 91,
                      "sampled": 91
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "poetry.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "bases/renku_data_services/data_api/py.typed",
                "bases/renku_data_services/data_tasks/py.typed",
                "bases/renku_data_services/k8s_cache/py.typed",
                "bases/renku_data_services/secrets_storage_api/py.typed",
                "components/renku_data_services/app_config/py.typed",
                "components/renku_data_services/authn/py.typed",
                "components/renku_data_services/crc/py.typed",
                "components/renku_data_services/db_config/py.typed",
                "components/renku_data_services/k8s/py.typed",
                "components/renku_data_services/metrics/py.typed",
                "components/renku_data_services/migrations/py.typed",
                "components/renku_data_services/project/py.typed",
                "components/renku_data_services/session/py.typed",
                "components/renku_data_services/storage/py.typed",
                "components/renku_data_services/utils/py.typed"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.09
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 11,
                "status": "met",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "bases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "bases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "9 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 9,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 223775,
              "source_files_sampled": 537,
              "oversized_source_files": 11
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (bases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "bases/renku_data_services/data_api/py.typed, bases/renku_data_services/data_tasks/py.typed, bases/renku_data_services/k8s_cache/py.typed, bases/renku_data_services/secrets_storage_api/py.typed, components/renku_data_services/app_config/py.typed, components/renku_data_services/authn/py.typed, components/renku_data_services/crc/py.typed, components/renku_data_services/db_config/py.typed, components/renku_data_services/k8s/py.typed, components/renku_data_services/metrics/py.typed, components/renku_data_services/migrations/py.typed, components/renku_data_services/project/py.typed, components/renku_data_services/session/py.typed, components/renku_data_services/storage/py.typed, components/renku_data_services/utils/py.typed",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "11/537 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 537,
                      "oversized": 11
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch pypi package 'renku-data-services' from its registry",
    "Could not fetch pypi package 'k8s_cache' from its registry",
    "pypi package 'secrets_storage' points at a different repository (https://github.com/bigbag/secrets-storage); excluded from ecosystem scoring",
    "Could not fetch pypi package 'renku_data_tasks' from its registry",
    "Could not fetch pypi package 'renku_data_service' from its registry",
    "deps.dev does not index pypi:secrets_storage@1.0.0; advisories assessed against the repository dependency graph instead",
    "Advisory severity resolved for 120 of 124 advisories (lookup cap); the remainder are reported as unknown severity"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T01:57:46.938565Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/SwissDataScienceCenter/renku-data-services.svg",
  "full_name": "SwissDataScienceCenter/renku-data-services",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计PyPI.