公开记录
软件健康报告模式 0.23.0 · 指标 1.13.0 · 2026-07-21 20:45 UTC

archlinux / devtools

Tools for Arch Linux package maintainers (read-only mirror)

ShellGPL-3.0★ 108 星标⑂ 56 复刻始于 2019年1月在 GitHub 上查看 ↗

archlinux/devtools 的健康指数为 100 分中的 53 分,处于「中等」区间。 其得分最高的类别是Sustainability & Governance(60/100),最低的是AI Readiness(36/100)。 最近一次更新在 19 天前。 近期的大部分工作由 4 位贡献者完成。

53
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

53
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

6,268 关注者50 个公开仓库始于 2013年6月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

57中等 · 占总体的 22%
评分方式
28.8/36推送新近度 — 最近一次推送于 19 天前
10.4/36提交节奏 — 52 周中有 15 周有提交
13.4/18提交量 — 最近一年 30 次提交
7/10OpenSSF Scorecard:Maintained — 9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
所用输入
commits_last_year30
human_commit_share1
days_since_last_push19
active_weeks_last_year15

发布纪律

52中等
评分方式
27/27有发布版本 — 已发布 10 个发布版本
0/36发布时效 — 最近一次发布版本于 1,695 天前
19.8/27发布节奏 — 约每 88.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count10
latest_release_tag20211129
releases_from_tags
days_since_latest_release1,695
mean_days_between_releases88.2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

52中等 · 占总体的 18%
评分方式
32.9/60星标 — 108 个星标
14.5/25复刻 — 56 个复刻
6.5/15关注者 — 16 位关注者
所用输入
forks56
stars108
watchers16
growth_stateorganic
growth_factor_pct100

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(GPL-3.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

60中等 · 占总体的 24%
评分方式
43.2/54巴士系数 — 4 位贡献者贡献了半数提交
17.6/22.5提交分布 — 头号贡献者编写了 22% 的提交
13.5/13.5贡献者广度 — 82 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 59 contributing companies or organizations
所用输入
bus_factor4
contributors_sampled82
top_contributor_share0.216
评分方式
0/46.8议题解决 — 没有议题或无数据
6.5/38.3PR 接受 — 已裁定的 PR 中 10/59 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs10
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs49
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
25/25所有者影响力 — archlinux 有 6,268 位关注者
24.4/25既往记录 — 50 个公开仓库,账户约 13 年
所用输入
followers6,268
owner_typeOrganization
is_verified
owner_loginarchlinux
public_repos50
account_age_days4,788

工程质量

基础的工程与文档实践是否到位?

55中等 · 占总体的 20%

工程实践

38存在风险
评分方式
0/24CI 工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
6.4/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

80良好
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://gitlab.archlinux.org/archlinux/devtools
10/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepagehttps://gitlab.archlinux.org/archlinux/devtools
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

37存在风险 · 占总体的 16%

安全态势

37存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 59 contributing companies or organizations
0/10Dangerous-Workflow — 无数据
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
5.2/7.5Maintained — 9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
0/5Packaging — 无数据
0/5Pinned-Dependencies — 无数据
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — 无数据
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated12
scorecard_versionv5.5.0
checks_inconclusive6
scorecard_aggregate3.7
已排除计分(无数据或不适用):ci_tests, dangerous_workflow, packaging, pinned_dependencies, signed_releases, token_permissions。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

36存在风险 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 98 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.98
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
0/11Lint / 格式化配置
0/11静态类型检查
0/10可复现环境
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — 无数据
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
已排除计分(无数据或不适用):OpenSSF Scorecard:Pinned-Dependencies。 其余权重已重新归一化。
评分方式
0/45可类型检查的代码 — Shell,未配置类型检查
0/55可控的文件大小 — 未检测到源文件
所用输入
primary_languageShell
largest_source_bytes
source_files_sampled0
oversized_source_files0
已排除计分(无数据或不适用):可控的文件大小。 其余权重已重新归一化。

机器可读接口

40存在风险
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — contrib/makepkg/PKGBUILD.proto
0/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_filescontrib/makepkg/PKGBUILD.proto

关键数据

108GitHub 星标
82贡献者
30最近 12 个月提交数
19距最近推送天数
10发布版本数
4巴士系数(bus factor)
0开放议题
软件包生态系统数

更多细节

Star 与 Fork 历史 108 ★ / 56 ⇿
108Star
56Fork
10发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

0204060801001201085342019-012022-102026-07
主版本 0次版本 0修订 0

每个点涵盖 7 天。

OpenSSF Scorecard 3.7 / 10
3.7综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-21 20:45 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 59 contributing companies or organizations
不适用Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
7Maintained9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
不适用Packagingpackaging workflow not detected
不适用Pinned-Dependenciesno dependencies found
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
不适用Token-PermissionsNo tokens found
10Vulnerabilities0 existing vulnerabilities detected
全部依赖 0

来自 GitHub 依赖图的完整解析依赖集合:0 个直接依赖与 0 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
依赖安全公告 未评估

本报告未能完成公告比对:No resolved dependencies to assess

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1793,
      "has_wiki": false,
      "homepage": "https://gitlab.archlinux.org/archlinux/devtools",
      "languages": {
        "Shell": 369200,
        "Makefile": 7762
      },
      "pushed_at": "2026-07-02T09:34:59Z",
      "created_at": "2019-01-21T23:19:41Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-13T02:06:48Z",
      "description": "Tools for Arch Linux package maintainers (read-only mirror)",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "GPL-3.0",
      "default_branch": "master",
      "license_spdx_raw": "GPL-3.0",
      "primary_language": "Shell",
      "significant_languages": [
        "Shell"
      ]
    },
    "owner": {
      "blog": "https://www.archlinux.org/",
      "name": "Arch Linux",
      "type": "Organization",
      "login": "archlinux",
      "company": null,
      "location": null,
      "followers": 6268,
      "avatar_url": "https://avatars.githubusercontent.com/u/4673648?v=4",
      "created_at": "2013-06-11T20:13:04Z",
      "is_verified": null,
      "public_repos": 50,
      "account_age_days": 4788
    },
    "license": {
      "state": "standard",
      "spdx_id": "GPL-3.0",
      "raw_spdx": "GPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "20211129",
          "kind": "other",
          "published_at": "2021-11-29T19:48:36Z"
        },
        {
          "tag": "20210202",
          "kind": "other",
          "published_at": "2021-11-29T19:48:00Z"
        },
        {
          "tag": "20200407",
          "kind": "other",
          "published_at": "2020-04-07T20:43:58Z"
        },
        {
          "tag": "20200213",
          "kind": "other",
          "published_at": "2020-04-07T20:43:32Z"
        },
        {
          "tag": "20191227",
          "kind": "other",
          "published_at": "2019-12-27T15:08:35Z"
        },
        {
          "tag": "20191212",
          "kind": "other",
          "published_at": "2019-12-12T00:03:45Z"
        },
        {
          "tag": "20191130",
          "kind": "other",
          "published_at": "2019-11-30T12:32:26Z"
        },
        {
          "tag": "20191016",
          "kind": "other",
          "published_at": "2019-10-15T22:54:00Z"
        },
        {
          "tag": "20190912",
          "kind": "other",
          "published_at": "2019-09-27T22:33:37Z"
        },
        {
          "tag": "20190821",
          "kind": "other",
          "published_at": "2019-09-27T22:33:18Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "8f0d146f8aaeba77a52fbe5db48f1e21b28d8551",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.5.1",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-06-21T22:15:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "269d6ac027d5f75bf5aed8003870ea9231e75ffc",
          "body": "Signed-off-by: Morten Linderud <foxboron@archlinux.org>",
          "is_bot": false,
          "headline": "feat(config): don't strip rust binaries",
          "author_name": "Morten Linderud",
          "author_login": "Foxboron",
          "committed_at": "2026-06-21T21:59:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bb933e408ef9254b66abf98bdb9757cc91c786db",
          "body": "Enable ICF (Identical Code Folding) to reduce binary size by merging\nread-only sections based on content. ICF is enabled via RUSTFLAGS\ninstead of LDFLAGS, because Rust uses LLD as the default linker\nsince version 1.90.0 and GNU ld does not support ICF.\n\nInspired by: https://github.com/denoland/deno/pull/34478",
          "is_bot": false,
          "headline": "feat(config): enable safe ICF for Rust",
          "author_name": "George Hu",
          "author_login": "Integral-Tech",
          "committed_at": "2026-06-21T21:46:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11428c1d1dc3e175c5fb71d64c78dfed33bacdc5",
          "body": "While running a longer makechrootpkg session that involves many\npackages, looking at the terminal output is not always sufficient to\ntell which package makechrootpkg is currently processing.\n\nIn systemd version 256, a feature was introduced in `systemd-nspawn`,\nwhich sets the window title from the c\n[…]\n\nname for its window title, so use a machine name of `inspecting` here,\nfollowed by a hyphen and the shell PID.\n\n[1]: https://github.com/systemd/systemd/commit/ab03434aa7b1cc174bfc75a21923165d394e47b3",
          "is_bot": false,
          "headline": "feat(makechrootpkg): use meaningful machine name",
          "author_name": "Claudia Pellegrino",
          "author_login": "claui",
          "committed_at": "2026-06-05T12:59:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "59f49cb86af36d1b70d24d544dd022fe564833ed",
          "body": "The option was referenced in the help text as well as the man page and\ncompletion, hence it is safe to assume that the intent was for it to be\nimplemented.\n\nComponent: pkgctl issue close\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "chore: Add missing short-hand option",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-05-20T18:50:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a84b3fbcdb3611d8c685a31bb54b84f0b76d520",
          "body": "Component: pkgctl repo clone\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "chore: Drop non-existing option from completion",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-05-20T18:47:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c890d495a6d1fe4d3f6a918d570d00c5746373ce",
          "body": "Component: pkgctl build\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "chore: Add missing completion for `--nocheck`",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-05-20T18:46:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "554d5b726c5d99655580f8861e30e6083d11a383",
          "body": "Component: pkgctl diff\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "chore: Align option casing in completion",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-05-20T18:46:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f80b33cc8e6851d65bc3618ac47e2a5368eeac15",
          "body": "Component: pkgctl issue list\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "chore: Add missing completion to filter by label",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-05-20T18:43:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "091bbf92f06c8ad9bd77f5bd4a06e4e26e28d862",
          "body": "This allows people to offload their package builds to machines other\nthan `build.archlinux.org`, which comes in handy if the load on that\nmachine is high due to other ongoing builds.\n\nComponent: pkgctl build\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "feat(build): Add `--offload-host` option to select remote machine",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2026-04-11T13:56:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8fe0ae2bc3872f1d17c45b8ea7891062c5b792f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.5.0",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2026-01-27T19:01:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81a616ae2d8a6a9a1484a80a0276274fbb27396d",
          "body": "…ion is absent\n\nWe originally had this as a warning to allow packagers some time for transitioning.\nHowever, now the gloves come off and we will require all packages to have proper licensing\ninformation.",
          "is_bot": false,
          "headline": "feat(commitpkg): Change warning to hard error when licensing informat…",
          "author_name": "Sven-Hendrik Haase",
          "author_login": "svenstaro",
          "committed_at": "2026-01-19T16:43:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d712dd3a9f611ebddf5cff20afb18ce83d23ebb",
          "body": "The hard check here has been prevented us (the RISC-V port) from utilizing `pkgctl build` for a while. As long as the list (DEVTOOLS_VALID_ARCHES) isn't easily extendable, I think it's a better idea to allow building with a warning when specifying `--arch` manually.",
          "is_bot": false,
          "headline": "feat: allow building for unsupported architecture",
          "author_name": "Felix Yan",
          "author_login": "felixonmars",
          "committed_at": "2026-01-18T15:28:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29f93c1f33220c83366fb1da6baca8b01a1baf45",
          "body": "This is a bit of a convenience developer experience commit, so callers\nonly need to do whatever to just set `SRCPKGDEST` and the `makepkg_source_package`\nfunction will make sure the variable is properly exported so `makepkg`\nwill see it.",
          "is_bot": false,
          "headline": "feat(util): make sure SRCPKGDEST is exported before shelling out",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2026-01-18T12:54:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d69286438ccfaa25e95446828f2d2e94be1fc302",
          "body": "Pacman introduces declaring some variables as readonly after loading,\nwhich leads to warnings on stderr when the function is called multiple\ntimes. Avoid this situation by using our own helper utility and ensure\nwe are only actually calling load once per process.",
          "is_bot": false,
          "headline": "fix(util): only load makepkg.conf once to avoid warnings in pacman 7.1",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2026-01-18T12:52:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76a82952664403fce0cbbfe9d3546454e13c6594",
          "body": "This makes sure the exported variables will only matter for the\nexecution of makepkg creating a source tarball, and not leak outside\nof the `makepkg_source_package` function call.\n\nThis bug has been uncovered, when offload build became an internal\nsubcommand rather than an external binary spawning a\n[…]\n this by wrapping the fakeroot invocation in an own sub-shell where\nwe can export variables, but it will be reset once the sub-shell scope\nends.\n\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "fix(util): ensure exported vars are not crossing process boundaries",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2026-01-17T18:09:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fa016d6eeb60b345e5a67d17ea1e97948f28108",
          "body": "Fixes: #287\n\nComponent: pkgctl build\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "fix(build): create artifact target directories if they dont exist",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2026-01-16T22:36:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10bd21df22c930b960e58cdd355f16a22b5d0871",
          "body": "Use a client-server script invocation instead of piping complex shell\ncommands as pure strings to the remote. Now we call a server use only\ncomponent on the remote server to execute the desired build.\n\nThis change allows for properly developing the remote command without\ngolfing around shell strings\n[…]\nffect we are now not\ndepending on a POSIX compliant login shell anymore, as we simply invoke\na pkgctl subcommand schema.\n\nComponent: pkgctl build\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(build): Invoke pkgctl offload server subcommand over ssh",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2026-01-16T22:36:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bdb9fa92f853d26ecd2040ab9b5d1da9bb478275",
          "body": "Makepkg 7.1 (as of [`f07d547c`][1]) stopped reading /etc/gitconfig for all\nGit operations. Before, it only ignored the system config for the\narchive command (as part of checksumming).\n\nWe need to set `safe.directory = *` for all our Git operations on the\nbuild server, otherwise mismatching ownership\n[…]\nttps://gitlab.archlinux.org/pacman/pacman/-/commit/f07d547cf1f879d263904fd792d2c4ebc3ba312f\n[2]: https://gitlab.archlinux.org/archlinux/infrastructure/-/commit/95791da9d8d6f1225fee5d6f1938154dec866864",
          "is_bot": false,
          "headline": "makechrootpkg: Install /etc/makepkg.d/gitconfig in chroots",
          "author_name": "Jan Alexander Steffens (heftig)",
          "author_login": "heftig",
          "committed_at": "2025-12-20T18:56:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c9d37ea739013b264023f5841c12c3091d1a063",
          "body": "Fixes: #272\nComponent: pkgctl build",
          "is_bot": false,
          "headline": "fix(archbuild): check if chroot version file exists before reading",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-12-05T22:19:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93a0362759d209e4d3e46278988d53ddb7c45450",
          "body": null,
          "is_bot": false,
          "headline": "chore(config): sync makepkg.conf and pacman.conf with pacman v7.1",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-12-05T21:23:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "075a59dce47b9ad59980eb9490c87ceccd872d31",
          "body": "Introduced in Pacman 7.1, this is required to parallelize stripping.",
          "is_bot": false,
          "headline": "feat(makechrootpkg): Support NPROC from makepkg.conf",
          "author_name": "Jan Alexander Steffens (heftig)",
          "author_login": "heftig",
          "committed_at": "2025-12-05T17:06:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5835e201362a544fd93f688f615cf427fd1bd539",
          "body": "The [cmd](https://nvchecker.readthedocs.io/en/latest/usage.html#find-with-a-command)\nsource allows nvchecker to use a shell command line to get versions.\nUsing this source within `.nvchecker.toml` would result in `pkgctl\nversion {check,upgrade}` to run arbitrary commands which isn't\ndesirable, as it\n[…]\ns /\ndependencies to run said commands or even executing malicious commands\nin hypothetical worst case scenarios)\n\nComponent: pkgctl version check\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(version): Disallow using the \"cmd\" source for nvchecker",
          "author_name": "Robin Candau",
          "author_login": "Antiz96",
          "committed_at": "2025-10-05T18:06:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7c3fcf9c1631dd8eb21c8fd24c67dd8604f91213",
          "body": "This allows more flexibility and chaining by being able to define\nmultiple sources per pkgbase and chain them together to achieve the\nfinal result. This may also be helpful to combine multiple from/to\npatterns into a chain to achieve the final pkgver to compare against.\n\nTo utilize the combiner sour\n[…]\nhe `pkgbase` followed by\nthe stage name, separated by double colons.\nFor example: `[\"sudo:stage1\"]`.\n\nFixes #216\n\nComponent: pkgctl version check\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(version): support combiner source for version check commands",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-10-05T17:48:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82ddc7b3bdce557428d19f8dc397dddf644d64bf",
          "body": "`pkgbuild_set_pkgver()` used the value of `$pkgver` directly in regular\nexpressions, which breaks if said value happens to contain e.g. a `+`.\nFix this by escaping all possible regex metacharacters in `$pkgver`.\n\nComponent: pkgctl build\nComponent: pkgctl version upgrade",
          "is_bot": false,
          "headline": "fix(pkgctl): handle pkgver values containing regex metacharacters",
          "author_name": "Ivan Shapovalov",
          "author_login": "intelfx",
          "committed_at": "2025-10-05T17:26:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bcbdde3fab2f27c61d59a12dbda9402962a0b32",
          "body": "We don't actually need any data from the package, except the pkgbase\nwhich is exclusively used during logging. Simply grep the pkgbase name\nand use the path during early code path issues.\n\nComponent: pkgctl license check",
          "is_bot": false,
          "headline": "chore(license): avoid sourcing PKGBUILD in check subcommand",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-10-05T16:47:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "062c678119819f671df96a7e499f2392ce69cf04",
          "body": "Avoid multiple concurrent invocations of rsync clashing when creating\nthe partial dir.\n\nFixes: https://gitlab.archlinux.org/archlinux/devtools/-/issues/266",
          "is_bot": false,
          "headline": "fix(release): Use unique partial dirs",
          "author_name": "Jan Alexander Steffens (heftig)",
          "author_login": "heftig",
          "committed_at": "2025-10-04T19:14:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd4dc54fbbb3d026c40b9c80ecc3ce29948e7cf7",
          "body": "Component: pkgctl",
          "is_bot": false,
          "headline": "doc: Add pkgctl-license entry to see also",
          "author_name": "Rafael Fontenelle",
          "author_login": "rffontenelle",
          "committed_at": "2025-10-04T19:04:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a46cb8150cf3acf57705765ef4cb845cf6a8265e",
          "body": "Component: pkgctl",
          "is_bot": false,
          "headline": "doc: Add license sub-command to pkgctl.1",
          "author_name": "Rafael Fontenelle",
          "author_login": "rffontenelle",
          "committed_at": "2025-10-04T19:03:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "447f7b411776ea2ad36a27e19239e6d65ffa6dee",
          "body": null,
          "is_bot": false,
          "headline": "Fix typo",
          "author_name": "Rafael Fontenelle",
          "author_login": "rffontenelle",
          "committed_at": "2025-09-29T23:00:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f0ebbc6d27f4bf0dfa20dbc649c802ee4e1139b",
          "body": "36 packages use this while 26 use *.pam and 21 use *.logrotate. Seems\nanecdotally common enough to add this here.",
          "is_bot": false,
          "headline": "fix(license): add .gitignore to REUSE defaults",
          "author_name": "Aaron Liu",
          "author_login": "aaronliu0130",
          "committed_at": "2025-08-08T12:13:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc56ebedf3cf06d711240745232285ac27213842",
          "body": "Signed-off-by: Jakub Klinkovský <lahwaacz@archlinux.org>",
          "is_bot": false,
          "headline": "fix(completion): fix bash completion for the license subcommand",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2025-08-05T15:48:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01757e690458ef69708e6261a901bf5b303b6a3c",
          "body": "So far all files in `needsversioning=(...)` have been printed to the\ncommand line if they were found, which is not useful, especially now\nthat we have more files present there.\n\nIt makes sense however to keep the standard error output, as this gives\na actionable suggestion what one should to to fix the issue:\n\n    > error: pathspec 'PKGBUILD' did not match any file(s) known to git\n    > Did you forget to 'git add'?\n\nFixes #281\n\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix(commitpkg): Quiet git ls-files output",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2025-08-01T09:26:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5fe8ff3e6455ce94fd3e57f625f5304c9b7b319",
          "body": "Eg. to match:\n- sysusers.conf\n- $pkgname.sysusers\n- $pkgname.sysusers.conf",
          "is_bot": false,
          "headline": "feat(license): Extend matches for sysusers/tmpfiles configs",
          "author_name": "Daniel M. Capella",
          "author_login": "polyzen",
          "committed_at": "2025-07-29T03:38:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad7dd50bf301ca77a798a130e92284bf12ae46ed",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.4.0",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2025-07-25T07:04:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a381835e8feecef9a017c989c8ca3273e2fe0c3",
          "body": "This implements RFC 54: https://rfc.archlinux.page/0054-fortran-flags/",
          "is_bot": false,
          "headline": "feat(config): set default build flags for Fortran",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2025-07-25T06:54:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8c475b3f402809fc65b7f43ffe82d2e6a9c7c16",
          "body": "This will check for license compliance before committing.",
          "is_bot": false,
          "headline": "feat(commitpkg): Integrate with pkgctl license",
          "author_name": "Sven-Hendrik Haase",
          "author_login": "svenstaro",
          "committed_at": "2025-07-22T18:27:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74cd46f0923241d072af4cf909022eb1f38c46e6",
          "body": "This implements a part of RFC52. The new pkgctl license check subcommand calls reuse lint on\nthe provided directories while pkgctl license setup tries to make packages compliant with RFC40\nby adding a LICENSE file and by generating a REUSE.toml.\n\nComponent: pkgctl license",
          "is_bot": false,
          "headline": "feat(license): Add subcommand to check and setup licenses",
          "author_name": "Sven-Hendrik Haase",
          "author_login": "svenstaro",
          "committed_at": "2025-07-22T18:27:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40f31f98a364989b54385942c86a9d9e537b055b",
          "body": null,
          "is_bot": false,
          "headline": "fix(autocomplete): don't add extra = for message",
          "author_name": "Bert Peters",
          "author_login": "bertptrs",
          "committed_at": "2025-05-12T20:49:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6f5d72708f895b82bba28ac9f500b01a922ea9d",
          "body": "readelf will pull in remote debug info if allowed to. This is not really\nwhat we expect for diffoscope diffs, especially when our server only has\ndebug info for one side of the diff.",
          "is_bot": false,
          "headline": "fix(common): Fix diffoscope looking at remote debug info",
          "author_name": "Jan Alexander Steffens (heftig)",
          "author_login": "heftig",
          "committed_at": "2025-04-22T23:13:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4a5e5dbd98dd84313fa8786d29263e9b91014b5",
          "body": "The original wording sounded like `pkgctl build` by default updates the\nchecksums whenever `pkgver` is changed in PKGBUILD.",
          "is_bot": false,
          "headline": "fix(build): sync command description with the man page",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2025-04-18T13:56:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4926d9d8c5d353123cb7df853dd8b3aa87fc99fd",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.3.2",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-25T21:05:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7165e0d73eadf0086e87cf64846731015af27d0d",
          "body": null,
          "is_bot": false,
          "headline": "chore(conf): add whitespace to RUSTFLAGS option for unified style",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-25T20:51:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8776dd39e8aff66c549d54cddcb2bdedc0c98485",
          "body": null,
          "is_bot": false,
          "headline": "chore(makerepropkg): unify indention style of the file",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-25T20:32:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb4bf96d245b145e766c22547e67ff94f0297961",
          "body": "Previously we have only copied the passed makepkg.conf file into the\nchroot, which misses build flags for additional language specific files\nthat makepkg supports. Fix this by extracting all conf.d makepkg config\nfiles from the detected devtools archive.\n\nComponent: makerepropkg\nCo-authored-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "feat(makerepropkg): support conf.d makepkg config files from buildtool",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-25T20:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96eff0280136e62a22095694255543cbfab01586",
          "body": "Previously we have only copied the passed makepkg.conf file into the\nchroot, which misses build flags for additional language specific files\nthat makepkg supports. Fix this by also copying all config files that\nmatch the `<file>.d/*.conf` glob.\n\nFixes #244\n\nComponent: arch-nspawn\nSuggested-by: Rein Fernhout (Levitating) <me@levitati.ng>\nCo-authored-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "feat(arch-nspawn): support conf.d makepkg config files",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-25T20:20:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79c3162112524f1c0bac88c55544ab582201ed21",
          "body": "Vendor all language related makepkg.conf files which are also shipped by\nmakepkg itself. This makes sure we always have full control over the\nbuild flags inside devtools and overlay any by the vendored config we\nmaintain in devtools.\n\nComponent: archbuild\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(config): provide vendored language specific makepkg.conf files",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-15T10:43:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43cd68d73e01d02ccb137acd61fab013afc8937b",
          "body": "For our own archbuild script which is used for package building from a\ntemplate chroot, automatically handle the case where the template root\nis out of date. Check the version and enable the clean flag by default\nin case a mismatch is detected.\n\nComponent: archbuild\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(archbuild): automatically recreate chroot on version mismatch",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-15T10:43:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c1948a357265c6dc9dacf447a16be6b9fadd899",
          "body": "We are currently facing reproducible builds issues as the\nmakepkg.conf.d/rust.conf file in the root chroot was leading to pacnew\nfiles, which means the chroot did not use configs as expected from a\nclean state. Work around this problem by bumping the chroot version and\nensure we get fresh chroots with expected configs\n\nComponent: archroot\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "chore(archroot): bump version to ensure fresh roots after config changes",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-02-15T10:24:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "acd6bda3eda09ea476df105ffc43d7d2e506efd0",
          "body": null,
          "is_bot": false,
          "headline": "Don't add extra \"=\" to repo completion",
          "author_name": "Bert Peters",
          "author_login": "bertptrs",
          "committed_at": "2025-02-01T14:45:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8af7a50c0373a2116413f0b1c8331dc6f49fb458",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.3.1",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2025-01-06T09:11:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bed2b5db28a61393ab9afde5babd6447e455ce2c",
          "body": "As it turns out the Gitlab api is not guaranteed to return the\nx-total-pages header for larger query result which previously resulted\nin a division by zero for pkgctl search as the utlity function assumed\nthat this value would always be set to a positive integer.\n\nFixes #255\n\nLink: https://gitlab.com/gitlab-org/gitlab/-/issues/436373\nComponent: gitlab.sh\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix(gitlab): prevent division by 0 for missing total pages",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2025-01-05T19:19:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47d5ea1e89294b7ce57be6d190a3da4061e60137",
          "body": "The nvchecker upstream version checks are expected to work as is on any\nmachines without the need of manual Git user configuration. However,\ncertain user configuration may have a side-effect on version checks.\nSubsequently we try to avoid this situation by always disabling Git\nconfig locations.\n\nComponent: pkgctl version check\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "fix(version): Disable Git user configs to avoid side-effects",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2025-01-03T22:35:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8df81ecd7c0c50116e5e63b11de2a54f179cc164",
          "body": null,
          "is_bot": false,
          "headline": "fix: declare local arrays before using mapfile",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2025-01-03T18:04:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1101de9fb93dc9ce556681666fc4d24856e91804",
          "body": "Fixes #260",
          "is_bot": false,
          "headline": "fix(offload-build): download logs even when the build fails",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-12-14T06:34:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5e1c5fae3bb79687fe1de649d17298ccce12f31",
          "body": "Fixes #259\n\nFixes: 0df36df (\"feat(issue): add subcommand to list group and project issues\")\nComponent: pkgctl issue view\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix: Display issue comments in chronological order",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-12-13T20:33:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8ab01d66230bc7375ee8ecb0a34c65d4ef466f7",
          "body": "* Ensures availability when $COLUMNS is not present\n\nSigned-off-by: Zhou Qiankang <wszqkzqk@qq.com>",
          "is_bot": false,
          "headline": "fix(checkpkg): add a default value for terminal width",
          "author_name": "Zhou Qiankang",
          "author_login": "wszqkzqk",
          "committed_at": "2024-12-08T15:51:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d9c2e06483bbf86a04409089e565bdb92b8f401",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.3.0",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-12-04T21:37:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bcbca830e94e357b756fc9cddc885213c73dd00",
          "body": "Signed-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix(util): disable landlocking in fakeroot",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-12-04T17:15:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68eb4983473ef4cb84a1a8ff228baa454770d880",
          "body": null,
          "is_bot": false,
          "headline": "chore: sync pacman configs with package defaults",
          "author_name": "T.J. Townsend",
          "author_login": null,
          "committed_at": "2024-12-04T17:15:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23f1314733ac742ba843a06ee2eadc265dcb7f78",
          "body": "Hints to run `pkgctl version setup --help` to see how to set it up if needed.\n\nCloses https://gitlab.archlinux.org/archlinux/devtools/-/issues/236",
          "is_bot": false,
          "headline": "feat(release): Add a warning if nvchecker integration is not set",
          "author_name": "Robin Candau",
          "author_login": "Antiz96",
          "committed_at": "2024-12-03T21:32:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98b079f0472c250fa794b47d3ee8eaa38273c516",
          "body": null,
          "is_bot": false,
          "headline": "chore(doc): remove superfluous trailing whitespaces from pkgctl man",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:19:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a319b0b852df133656081f02c9ace11288f220aa",
          "body": "The pkgctl issue edit command is used to modify an existing issue in Arch Linux\npackaging projects. This command allows users to update the issue's title,\ndescription, and various attributes, ensuring that the issue information\nremains accurate and up-to-date. It also provides a streamlined facility\n[…]\nrun, the command can automatically recover to ensure that\nthe editing process is completed without losing any data.\n\nComponent: pkgctl issue edit\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to edit an issue",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:19:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1e443856d6ea9fdd276e572371e1942ba3cc059",
          "body": "The create command is used to create a new issue for an Arch Linux package.\nThis command is suitable for reporting bugs, regressions, feature requests, or\nany other issues related to a package. It provides a flexible way to document\nand track new issues within the project's issue tracking system.\n\nB\n[…]\ncommand can automatically recover to ensure that\nthe issue creation process is completed without losing any data.\n\nComponent: pkgctl issue create\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to create a new issue",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:19:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dfb65e95e30a42d0a77a7968d0973e8c2fb647a7",
          "body": "The move command allows users to transfer an issue from one project to another\nwithin the Arch Linux packaging group. This is useful when an issue is\nidentified to be more relevant or better handled in a different project.\n\nBy default, the command operates within the current directory, but users can\n[…]\nd be moved. A comment message explaining the reason for the move can\nbe provided directly through the command line.\n\nComponent: pkgctl issue move\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to move issues between projects",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:19:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e7ec8b37fcc91a777c47f79087abfec0dab320c",
          "body": "The reopen command is used to reopen a previously closed issue in Arch Linux\npackaging projects. This command is useful when an issue needs to be revisited\nor additional work is required after it was initially closed.\n\nBy default, the command operates within the current directory, but users can\nspec\n[…]\ned.\n\nUsers can provide a message directly through the command line to explain the\nreason for reopening the issue.\n\nComponent: pkgctl issue reopen\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to reopen issues",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:19:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "292920ac7eacf6348370bb7034836a1e9c0d9a8b",
          "body": "This command is used to close an issue in Arch Linux packaging projects. It\nfinalizes the issue by marking it as resolved and optionally providing a reason\nfor its closure.\n\nBy default, the command operates within the current directory, but users have\nthe option to specify a different package base.\n\n[…]\na specific resolution label can be\nset to categorize the closure reason, with the default label being \"completed.\"\n\nComponent: pkgctl issue close\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to close issues",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:18:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dde65399715aaa1496551e5f7b5467d24aa305d9",
          "body": "This command allows users to add comments to an issue in Arch Linux packaging\nprojects. This command is useful for providing feedback, updates, or any\nadditional information related to an issue directly within the project's issue\ntracking system.\n\nBy default, the command interacts with the current directory, but users can\nspecify a different package base if needed.\n\nComponent: pkgctl issue comment\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to comment on issues",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:18:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8803e5a57a64a11636074e04cd5b1669ee31cff6",
          "body": "This command is designed to display detailed information about a specific issue\nin Arch Linux packaging projects. It gathers and pretty prints all relevant\ndata about the issue, providing a comprehensive view that includes the issue's\ndescription, status as well as labels and creation date.\n\nBy defa\n[…]\n package base. Additionally, users can choose\nto view the issue in a web browser for a more interactive experience.\n\nComponent: pkgctl issue view\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to view issue details and comments",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:18:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0df36dfa521119e676b669580a489dd7f381d1a3",
          "body": "The pkgctl issue list command is used to list issues associated with a specific\npackaging project or the entire packaging subgroup in Arch Linux. This command\nfacilitates efficient issue management by allowing users to list and filter\nissues based on various criteria.\n\nResults can also be displayed directly in a web browser for easier navigation\nand review.\n\nComponent: pkgctl issue list\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(issue): add subcommand to list group and project issues",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:17:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9fe8ee947f12d3f89b4a61d097522bcf0eb138c",
          "body": "Signed-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "chore(gitlab): move project name lookup to gitlab library functions",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-12-03T21:13:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af56897f7678083cb4a1b53eb55dc39e7ffd18ba",
          "body": "…Master=auto",
          "is_bot": false,
          "headline": "feat(offload-build): create or reuse a shared SSH socket with Control…",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-11-28T14:06:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99c6c26a1cf1f80f5d3227ea6790352896dd894b",
          "body": "…ync commands",
          "is_bot": false,
          "headline": "fix(offload-build): add end-of-options token (`--`) to all ssh and rs…",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-11-28T14:06:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00f97fcd3dd426f586424f5837ccc3e6532cbacd",
          "body": null,
          "is_bot": false,
          "headline": "fix(offload-build): setup TEMPDIR in WORKDIR and fix trap override",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-11-28T14:06:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "effe511952502471277b64007fab290ae50458e9",
          "body": null,
          "is_bot": false,
          "headline": "fix(offload-build): fix quoting in sshopts and rsyncopts",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-11-28T14:06:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cd213b2f5a9cdb2eab94a91240c71a9b9d720b0",
          "body": "Instead of passing the command as one complex string to ssh, we create\nan SSH master connection and use its control socket in multiple simpler\ncommands. The same socket is passed also to rsync to transfer the srcpkg\nto the remote and to download the build artifacts.\n\nPreviously, the srcpkg was passe\n[…]\n.\n\nHowever, it seems that ssh commands with and without the `-t` flag\ncannot be multiplexed on a single connection, so there are technically\ntwo SSH connections active for the offload-build execution.",
          "is_bot": false,
          "headline": "fix(offload-build): ungolfing remote command execution",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-11-28T14:06:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b88dec322c7988a34ef289260a2874b682b04b34",
          "body": "Setup a blank config for packages without remote sources. This is\nhelpful so other commands like `pkgctl version check` operate gracefully\nas well as we have easy way to find packages that miss nvchecker\nconfig.\n\nThis must only be used for cases without an upstream, please reach out\nto the developer team for guidance regarding upstream sources that are\nhard to configure.\n\nComponent: pkgctl version setup\nSigned-off-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(version): graceful config for packages without remote sources",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-11-26T18:01:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2ab07caff8cae1d7541465ede882036b8a4be24",
          "body": "This allows for tools and data visualization to interface against pkgctl\nwith a machine readable output.\n\nFixes #237\n\nComponent: pkgctl version check\nSigned-off-by: Andreas Schleifer <segaja@archlinux.org>\nCo-authored-by: Levente Polyak <anthraxx@archlinux.org>",
          "is_bot": false,
          "headline": "feat(version): add json output option to version check command",
          "author_name": "Andreas Schleifer",
          "author_login": null,
          "committed_at": "2024-11-23T16:53:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c0f8d37d5b1f3c380b49c60f3d2e5e8ab586f62",
          "body": "From systemd-nspawn(1),\n\n\t--timezone=\n\t\tConfigures how /etc/localtime inside of the container (i.e. local timezone synchronization from host to container) shall be handled. Takes one of \"off\", \"copy\", \"bind\", \"symlink\", \"delete\" or \"auto\". If set to \"off\" the /etc/localtime file in the container\n\t\ti\n[…]\nto\".\n\n\t\tAdded in version 239.\n\nAfter this commit, we need to recreate all build environment to clean up\npollution already existed.\n\nresolve #250\n\nSigned-off-by: Celeste Liu <CoelacanthusHex@gmail.com>",
          "is_bot": false,
          "headline": "fix(arch-nspawn): add --timezone=off to avoid pollute build environment",
          "author_name": "Celeste Liu",
          "author_login": "CoelacanthusHex",
          "committed_at": "2024-11-09T12:26:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1401ce41c6ba9bd3007f4cce8a2dfcbd5864b52",
          "body": "Since commit 1d433f6 (\"feat(db): confirm list of all packages that will be removed\") packages need confirmation by default when being dropped from the db. If we make it to the DB drop phase the package already is pushed to the AUR, so it is safe to remove from the database and not removing it would create a somewhat broken state, so we assume that the package should unconditionally be removed from the db.\n\nComponent: pkgctl aur drop-from-repo\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix: disable confirmation when dropping packages",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-09-29T10:40:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8612b41a2061059a34a938355913d0fd95ce0fe9",
          "body": "PAT settings are now under `user_settings` instead of `profile`\n\nComponent: pkgctl auth login",
          "is_bot": false,
          "headline": "fix: update the personal access token URL",
          "author_name": "Orhun Parmaksız",
          "author_login": "orhun",
          "committed_at": "2024-09-25T11:20:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbb661645b49bd6bff7a4cf15fefd12c679b66c3",
          "body": "Without the \"--release\" flag the example command fails with\n==> ERROR: cannot use --message without --release.\n\nComponent: pkgctl build",
          "is_bot": false,
          "headline": "doc: fix the example in the help text",
          "author_name": "Jaroslav Lichtblau",
          "author_login": "svetlemodry",
          "committed_at": "2024-09-10T08:59:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1dc2e18f740e2c9de9ce0a95148c05005dffbb9",
          "body": "It seems like nvchecker emits two log entries for errors:\n\n    $ nvchecker --logger json -c .nvchecker.toml\n    {\"logger_name\": \"nvchecker.core\", \"name\": \"curl\", \"event\": \"token not given but it is required\", \"level\": \"error\"}\n    {\"logger_name\": \"nvchecker.core\", \"name\": \"curl\", \"error\": \"token not\n[…]\ndescribed in the related issue,\nwhich we fix by narrowing the selector to filter for the error entry.\n\nFixes #235\n\nComponent: pkgctl version check\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix: remove duplicate error message",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-09-08T20:38:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9d821448b4415f04b69f5637e20874d7396e46d",
          "body": "If the chroot was created in a way where it resides on a BTRFS file\nsystem but \"$copydir/root\" is not a snapshot an error like the following\nwould be emitted:\n\n  $ makechrootpkg -r ~/chroot\n  ==> Synchronizing chroot copy [/home/chris/chroot/root] -> [chris]...ERROR: Not a Btrfs subvolume: Invalid a\n[…]\nally the root of a BTRFS snapshot before attempting to clone it.\n\nRelated to https://gitlab.archlinux.org/archlinux/devtools/-/merge_requests/259\n\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix(makechrootpkg): improve btrfs sanity checks",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-09-08T20:33:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a620250535d59ea107e4d595a963275b2d9f2ba0",
          "body": null,
          "is_bot": false,
          "headline": "doc: specify default chroot folder for pkgctl-build",
          "author_name": "Fox2Code",
          "author_login": "Fox2Code",
          "committed_at": "2024-08-21T09:26:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27eebe383d0b571c08cba991e4824768d7623602",
          "body": "the '--pkgver' argument is not space-separated but instead specified\nwith an equals sign.\n\nComponent: pkgctl build",
          "is_bot": false,
          "headline": "doc: fix the example command in the help text",
          "author_name": "Jaroslav Lichtblau",
          "author_login": "svetlemodry",
          "committed_at": "2024-06-26T19:00:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6d416b653c339043ac3ee429b526af481521564",
          "body": "Replace `sdiff` with `diff` (also from `diffutils`) with the following\nparameters:\n\n- `--side-by-side` for the `sdiff`-like output\n- `--suppress-common-lines` for the `sdiff -s` behavior\n- `--width=\"$COLUMNS\"` to use the full terminal width (long lines are\n  still truncated but it is definitely better than the default width of\n  130 chars)\n- `--color=auto` just because 😉",
          "is_bot": false,
          "headline": "feat(checkpkg): enhance diff command for comparing file lists",
          "author_name": "Jakub Klinkovský",
          "author_login": "lahwaacz",
          "committed_at": "2024-06-26T05:40:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ff63503b94e7f523cba1a5f9e5dfdc9c8855471",
          "body": "Component: pkgctl repo configure",
          "is_bot": false,
          "headline": "fix(pkgctl): make sure git signing uses PGP",
          "author_name": "Chih-Hsuan Yen",
          "author_login": "yan12125",
          "committed_at": "2024-06-19T09:37:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f02a1a24c725fefd9046643f6be102814f35abc",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.2.1",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-06-18T12:14:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1df0979da6bbe5de8549693d12cb3e547bc6d94a",
          "body": "This avoids the unwanted removal of the folder if someone has already\npre-defined the variable.\n\nFixes #219\n\nSuggested-by: Levente Polyak <anthraxx@archlinux.org>\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix(common): guard the WORKDIR environment var",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-06-15T12:55:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1a3ed224b8d735fec0456233b68c5a583299d79",
          "body": "Signed-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "misc: add a editorconfig to devtools",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-06-11T20:04:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "144f9a871ee554b44e1d9733a56d6b4dc99803fe",
          "body": "Since version 2.15.1 nvchecker emits a warning for version strings that\nit consideres invalid (e.g. in the case of PyPI).\nThese warning messages get in the way (the first version emitted via a\nwarning is used as version to compare against) of retrieving the latest\nversion of an upstream and therefore we ignore them.\n\nComponent: pkgctl version check\nSigned-off-by: David Runge <dvzrv@archlinux.org>",
          "is_bot": false,
          "headline": "fix(version): Ignore warnings when nvchecker ignores invalid versions",
          "author_name": "David Runge",
          "author_login": "dvzrv",
          "committed_at": "2024-06-09T12:36:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44328cd9a3ced0a5736e904f80f20d1749cfcf53",
          "body": "The expected output for these tests has now changed since git smash\n(which we test against) has changed their version scheme.\n\nComponent: pkgctl version setup\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "test: fix the testcases so they pass again",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-06-08T15:35:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e2b16b0ac63e33e32a6cb889bc4b047e0d451e9",
          "body": "Systemd 256 introduces functionality which colors the terminal\nbackground on systemd-nspawn invocations which makes the pkgctl output\nlook weird.\n\nDisable this bevaviour for pkgctl, so it stays active for arch-nspawn\n(for now).\n\nComponent: pkgctl\nSigned-off-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "fix: disable systemd-nspawn terminal coloring",
          "author_name": "Christian Heusel",
          "author_login": "christian-heusel",
          "committed_at": "2024-05-22T10:33:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f0a8c345d1cd6737f709b9f7fffd18895e682ed",
          "body": "Changes made:\n- add description in doc/man/pkgctl.1.asciidoc\n- add description in doc/man/pkgctl-db(1).asciidoc\n- add manpage for pkgctl-db(1) in doc/man/pkgctl-db(1).asciidoc\n\nFixes #231\n\nSigned-off-by: Maharshi Basu <basumaharshi10@gmail.com>",
          "is_bot": false,
          "headline": "doc: add manpage info for pkgctl, pkgctl-db(1) & pkgctl-build",
          "author_name": "Maharshi Basu",
          "author_login": "MashyBasker",
          "committed_at": "2024-05-18T18:36:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f198534144f09d09f9e4c0541d8da15f8c1aed3",
          "body": "A .cache can be bind mounted into the container to save the caches for\nreuse, but sometimes we want to exclude specific caches (because they\ndon't work well, e.g. bazel's).\n\nComponent: makechrootpkg",
          "is_bot": false,
          "headline": "feat: support bind mounting a tmpfs",
          "author_name": "依云",
          "author_login": "lilydjwg",
          "committed_at": "2024-05-18T17:39:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b62ac660d258858f7a7795a113a7056d0d2c79d",
          "body": "Co-authored-by: Christian Heusel <christian@heusel.eu>",
          "is_bot": false,
          "headline": "feat(mkarchroot): allow to specify file destination inside chroot",
          "author_name": "Frédéric Pierret (fepitre)",
          "author_login": "fepitre",
          "committed_at": "2024-05-18T11:53:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cb72699f651a9e7ac8996070b974e1dda0a9733",
          "body": "Git 2.45.1 expanded its security checks to deny cloning even local repos\nthat are owned by another user. Previously, this just affected network\nfilesystems.\n\nOn our buildserver, this prevents makepkg from cloning repos from our\nshared srcdest into the srcdir, if these repos were created by another\np\n[…]\nsafe.directory` to `*`. This looks like a\nglob, but is really just a special value. The only other option would be\nto add each Git repository in srcdest to the configuration.\n\nComponent: makechrootpkg",
          "is_bot": false,
          "headline": "fix: consider all git repos inside the chroot safe",
          "author_name": "Jan Alexander Steffens (heftig)",
          "author_login": "heftig",
          "committed_at": "2024-05-17T22:15:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1790c295a054982734aa9b1b3eb4f7d4de234f6",
          "body": "This fixes issues with packages containing plus signs, that need to be\nescaped in toml as well as the extended grep regex.\n\nComponent: pkgctl version check",
          "is_bot": false,
          "headline": "fix(version): escape pkgbase in nvchecker toml",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-05-10T19:22:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12a0d0c7b58dbae32083b74760669a6edc8b7d06",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): version v1.2.0",
          "author_name": "Levente Polyak",
          "author_login": "anthraxx",
          "committed_at": "2024-05-01T14:38:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 10,
      "commits_last_year": 30,
      "latest_release_at": "2021-11-29T19:48:36Z",
      "latest_release_tag": "20211129",
      "releases_from_tags": false,
      "days_since_last_push": 19,
      "active_weeks_last_year": 15,
      "days_since_latest_release": 1695,
      "mean_days_between_releases": 88.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 56,
      "stars": 108,
      "watchers": 16,
      "fork_history": {
        "days": [
          {
            "date": "2019-01-22",
            "count": 1
          },
          {
            "date": "2019-02-02",
            "count": 1
          },
          {
            "date": "2019-03-08",
            "count": 1
          },
          {
            "date": "2019-03-11",
            "count": 1
          },
          {
            "date": "2019-03-13",
            "count": 1
          },
          {
            "date": "2019-03-26",
            "count": 1
          },
          {
            "date": "2019-04-22",
            "count": 1
          },
          {
            "date": "2019-08-09",
            "count": 1
          },
          {
            "date": "2019-10-22",
            "count": 1
          },
          {
            "date": "2019-10-29",
            "count": 1
          },
          {
            "date": "2019-11-22",
            "count": 1
          },
          {
            "date": "2019-12-21",
            "count": 1
          },
          {
            "date": "2020-04-03",
            "count": 1
          },
          {
            "date": "2020-04-09",
            "count": 1
          },
          {
            "date": "2020-05-02",
            "count": 1
          },
          {
            "date": "2020-05-13",
            "count": 1
          },
          {
            "date": "2020-05-20",
            "count": 1
          },
          {
            "date": "2020-06-24",
            "count": 2
          },
          {
            "date": "2020-07-26",
            "count": 1
          },
          {
            "date": "2020-10-31",
            "count": 1
          },
          {
            "date": "2020-11-22",
            "count": 1
          },
          {
            "date": "2020-12-07",
            "count": 1
          },
          {
            "date": "2021-05-25",
            "count": 1
          },
          {
            "date": "2021-07-13",
            "count": 1
          },
          {
            "date": "2021-07-20",
            "count": 1
          },
          {
            "date": "2021-07-29",
            "count": 1
          },
          {
            "date": "2021-08-01",
            "count": 1
          },
          {
            "date": "2021-08-08",
            "count": 2
          },
          {
            "date": "2021-09-04",
            "count": 1
          },
          {
            "date": "2021-09-15",
            "count": 1
          },
          {
            "date": "2021-09-20",
            "count": 1
          },
          {
            "date": "2021-09-21",
            "count": 1
          },
          {
            "date": "2022-01-11",
            "count": 1
          },
          {
            "date": "2022-01-13",
            "count": 1
          },
          {
            "date": "2022-01-22",
            "count": 1
          },
          {
            "date": "2022-06-04",
            "count": 1
          },
          {
            "date": "2022-06-18",
            "count": 1
          },
          {
            "date": "2022-11-21",
            "count": 1
          },
          {
            "date": "2023-04-10",
            "count": 1
          },
          {
            "date": "2023-10-09",
            "count": 1
          },
          {
            "date": "2023-10-14",
            "count": 1
          },
          {
            "date": "2023-12-30",
            "count": 1
          },
          {
            "date": "2024-01-21",
            "count": 1
          },
          {
            "date": "2024-01-24",
            "count": 1
          },
          {
            "date": "2024-03-18",
            "count": 1
          },
          {
            "date": "2024-04-07",
            "count": 1
          },
          {
            "date": "2024-05-28",
            "count": 1
          },
          {
            "date": "2024-10-21",
            "count": 1
          },
          {
            "date": "2025-03-02",
            "count": 1
          },
          {
            "date": "2026-03-07",
            "count": 1
          },
          {
            "date": "2026-03-26",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 53,
        "total_forks": 56
      },
      "star_history": {
        "days": [
          {
            "date": "2019-01-22",
            "count": 2
          },
          {
            "date": "2019-01-23",
            "count": 1
          },
          {
            "date": "2019-02-26",
            "count": 1
          },
          {
            "date": "2019-03-08",
            "count": 3
          },
          {
            "date": "2019-04-20",
            "count": 1
          },
          {
            "date": "2019-05-02",
            "count": 1
          },
          {
            "date": "2019-07-01",
            "count": 1
          },
          {
            "date": "2019-07-05",
            "count": 1
          },
          {
            "date": "2019-08-15",
            "count": 1
          },
          {
            "date": "2019-08-22",
            "count": 1
          },
          {
            "date": "2019-08-28",
            "count": 1
          },
          {
            "date": "2019-11-01",
            "count": 1
          },
          {
            "date": "2019-11-02",
            "count": 1
          },
          {
            "date": "2019-11-03",
            "count": 2
          },
          {
            "date": "2019-11-08",
            "count": 1
          },
          {
            "date": "2019-11-15",
            "count": 2
          },
          {
            "date": "2019-12-06",
            "count": 2
          },
          {
            "date": "2020-02-02",
            "count": 1
          },
          {
            "date": "2020-03-18",
            "count": 1
          },
          {
            "date": "2020-03-29",
            "count": 1
          },
          {
            "date": "2020-04-05",
            "count": 1
          },
          {
            "date": "2020-05-08",
            "count": 1
          },
          {
            "date": "2020-05-13",
            "count": 1
          },
          {
            "date": "2020-09-26",
            "count": 1
          },
          {
            "date": "2020-10-05",
            "count": 1
          },
          {
            "date": "2021-01-04",
            "count": 2
          },
          {
            "date": "2021-01-18",
            "count": 1
          },
          {
            "date": "2021-03-03",
            "count": 1
          },
          {
            "date": "2021-04-30",
            "count": 1
          },
          {
            "date": "2021-05-27",
            "count": 3
          },
          {
            "date": "2021-05-30",
            "count": 1
          },
          {
            "date": "2021-07-18",
            "count": 1
          },
          {
            "date": "2021-07-29",
            "count": 2
          },
          {
            "date": "2021-07-30",
            "count": 1
          },
          {
            "date": "2021-08-08",
            "count": 2
          },
          {
            "date": "2021-08-09",
            "count": 1
          },
          {
            "date": "2021-09-20",
            "count": 1
          },
          {
            "date": "2021-09-23",
            "count": 1
          },
          {
            "date": "2021-09-28",
            "count": 1
          },
          {
            "date": "2021-11-01",
            "count": 1
          },
          {
            "date": "2021-11-19",
            "count": 2
          },
          {
            "date": "2022-01-16",
            "count": 1
          },
          {
            "date": "2022-01-23",
            "count": 1
          },
          {
            "date": "2022-01-24",
            "count": 1
          },
          {
            "date": "2022-02-05",
            "count": 1
          },
          {
            "date": "2022-03-08",
            "count": 1
          },
          {
            "date": "2022-03-12",
            "count": 1
          },
          {
            "date": "2022-04-07",
            "count": 1
          },
          {
            "date": "2022-04-08",
            "count": 1
          },
          {
            "date": "2022-05-18",
            "count": 1
          },
          {
            "date": "2022-07-19",
            "count": 1
          },
          {
            "date": "2022-08-08",
            "count": 1
          },
          {
            "date": "2022-08-28",
            "count": 1
          },
          {
            "date": "2022-09-10",
            "count": 1
          },
          {
            "date": "2022-10-06",
            "count": 1
          },
          {
            "date": "2022-12-15",
            "count": 1
          },
          {
            "date": "2023-01-01",
            "count": 1
          },
          {
            "date": "2023-01-04",
            "count": 1
          },
          {
            "date": "2023-02-05",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 1
          },
          {
            "date": "2023-03-28",
            "count": 1
          },
          {
            "date": "2023-04-26",
            "count": 1
          },
          {
            "date": "2023-05-28",
            "count": 1
          },
          {
            "date": "2023-08-20",
            "count": 1
          },
          {
            "date": "2023-10-09",
            "count": 1
          },
          {
            "date": "2024-01-09",
            "count": 1
          },
          {
            "date": "2024-01-18",
            "count": 1
          },
          {
            "date": "2024-01-24",
            "count": 1
          },
          {
            "date": "2024-01-31",
            "count": 1
          },
          {
            "date": "2024-03-13",
            "count": 1
          },
          {
            "date": "2024-04-29",
            "count": 1
          },
          {
            "date": "2024-05-01",
            "count": 2
          },
          {
            "date": "2024-05-06",
            "count": 1
          },
          {
            "date": "2024-06-16",
            "count": 1
          },
          {
            "date": "2024-06-28",
            "count": 1
          },
          {
            "date": "2024-09-10",
            "count": 1
          },
          {
            "date": "2024-09-11",
            "count": 1
          },
          {
            "date": "2024-09-22",
            "count": 1
          },
          {
            "date": "2024-09-27",
            "count": 1
          },
          {
            "date": "2024-10-11",
            "count": 1
          },
          {
            "date": "2024-10-21",
            "count": 1
          },
          {
            "date": "2024-11-11",
            "count": 1
          },
          {
            "date": "2024-11-17",
            "count": 1
          },
          {
            "date": "2024-12-02",
            "count": 1
          },
          {
            "date": "2025-02-18",
            "count": 2
          },
          {
            "date": "2025-02-25",
            "count": 1
          },
          {
            "date": "2025-05-15",
            "count": 1
          },
          {
            "date": "2025-08-26",
            "count": 1
          },
          {
            "date": "2025-10-02",
            "count": 1
          },
          {
            "date": "2025-11-23",
            "count": 1
          },
          {
            "date": "2026-03-17",
            "count": 1
          },
          {
            "date": "2026-04-06",
            "count": 1
          },
          {
            "date": "2026-07-06",
            "count": 1
          },
          {
            "date": "2026-07-13",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 108,
        "total_stars": 108
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "contrib/makepkg/PKGBUILD.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": null,
      "source_files_sampled": 0,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": "No resolved dependencies to assess",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [],
        "collected": true,
        "truncated": false,
        "total_count": 0,
        "direct_count": 0,
        "indirect_count": 0
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 10,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 49
      },
      "bus_factor": 4,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "anthraxx",
          "commits": 231,
          "avatar_url": "https://avatars.githubusercontent.com/u/203012?v=4"
        },
        {
          "type": "User",
          "login": "pierres",
          "commits": 209,
          "avatar_url": "https://avatars.githubusercontent.com/u/977535?v=4"
        },
        {
          "type": "User",
          "login": "heftig",
          "commits": 77,
          "avatar_url": "https://avatars.githubusercontent.com/u/204006?v=4"
        },
        {
          "type": "User",
          "login": "aaronmgriffin",
          "commits": 62,
          "avatar_url": "https://avatars.githubusercontent.com/u/2569?v=4"
        },
        {
          "type": "User",
          "login": "eli-schwartz",
          "commits": 56,
          "avatar_url": "https://avatars.githubusercontent.com/u/6551424?v=4"
        },
        {
          "type": "User",
          "login": "christian-heusel",
          "commits": 55,
          "avatar_url": "https://avatars.githubusercontent.com/u/26827864?v=4"
        },
        {
          "type": "User",
          "login": "LukeShu",
          "commits": 43,
          "avatar_url": "https://avatars.githubusercontent.com/u/90273?v=4"
        },
        {
          "type": "User",
          "login": "falconindy",
          "commits": 38,
          "avatar_url": "https://avatars.githubusercontent.com/u/99302?v=4"
        },
        {
          "type": "User",
          "login": "toofishes",
          "commits": 28,
          "avatar_url": "https://avatars.githubusercontent.com/u/265817?v=4"
        },
        {
          "type": "User",
          "login": "allanmcrae",
          "commits": 25,
          "avatar_url": "https://avatars.githubusercontent.com/u/897032?v=4"
        }
      ],
      "contributors_sampled": 82,
      "top_contributor_share": 0.216
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 59 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 7,
            "reason": "9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": null,
            "reason": "no dependencies found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "8f0d146f8aaeba77a52fbe5db48f1e21b28d8551",
        "ran_at": "2026-07-21T20:45:35Z",
        "aggregate_score": 3.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/archlinux/devtools",
    "host": "github.com",
    "name": "devtools",
    "owner": "archlinux"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 37,
        "vitality": 57,
        "community": 52,
        "governance": 60,
        "engineering": 55
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 57,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "commits_last_year": 30,
              "human_commit_share": 1,
              "days_since_last_push": 19,
              "active_weeks_last_year": 15
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 19 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 19
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "15/52 weeks with commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 15
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "30 commits in the last year",
                "points": 13.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 30
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "moderate",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "releases_count": 10,
              "latest_release_tag": "20211129",
              "releases_from_tags": false,
              "days_since_latest_release": 1695,
              "mean_days_between_releases": 88.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "10 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1695 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1695
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~88.2 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 88.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 30,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 30 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 52,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "forks": 56,
              "stars": 108,
              "watchers": 16,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "108 stars",
                "points": 32.9,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 108
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "56 forks",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 56
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "16 watchers",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (GPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "GPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "good",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "bus_factor": 4,
              "contributors_sampled": 82,
              "top_contributor_share": 0.216
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "4 contributor(s) cover half of all commits",
                "points": 43.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 22% of commits",
                "points": 17.6,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 22
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "82 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 82
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 59 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 12,
            "inputs": {
              "merged_prs": 10,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 49
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "10/59 decided PRs merged",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 10,
                      "decided": 59
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "followers": 6268,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "archlinux",
              "public_repos": 50,
              "account_age_days": 4788
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "6,268 followers of archlinux",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 6268,
                      "login": "archlinux"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "50 public repos, account ~13 yr old",
                "points": 24.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 50
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 55,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://gitlab.archlinux.org/archlinux/devtools",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://gitlab.archlinux.org/archlinux/devtools",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 37,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Pinned-Dependencies, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "pinned_dependencies",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 37,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 12,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 6,
              "scorecard_aggregate": 3.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 59 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "9 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7",
                "points": 5.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 10
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 36,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.98,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Pinned-Dependencies. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_pinned_dependencies"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": false,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "no dependencies found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "critical",
            "name": "Code legibility for models",
            "note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "manageable_file_sizes"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "primary_language": "Shell",
              "largest_source_bytes": null,
              "source_files_sampled": 0,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Shell without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Shell"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "no source files detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_source_files",
                    "params": {}
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": false,
              "api_schema_files": [
                "contrib/makepkg/PKGBUILD.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "contrib/makepkg/PKGBUILD.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "contrib/makepkg/PKGBUILD.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [],
  "report_type": "repository",
  "generated_at": "2026-07-21T20:45:51.473415Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/archlinux/devtools.svg",
  "full_name": "archlinux/devtools",
  "license_state": "standard",
  "license_spdx": "GPL-3.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.23.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计.