公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-28 03:31 UTC

chainguard-dev / omnibump

Universal declarative dependency bump tool

GoApache-2.0★ 13 星标⑂ 10 复刻始于 2026年2月在 GitHub 上查看 ↗

chainguard-dev/omnibump 的健康指数为 100 分中的 73 分,处于「良好」区间。 其得分最高的类别是Vitality(88/100),最低的是Community & Adoption(38/100)。 最近一次更新在 1 天前。 近期的大部分工作由 2 位贡献者完成。

73
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

73
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

844 关注者116 个公开仓库始于 2021年7月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/chainguard-dev/omnibumpv0.23.1-513 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

88优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 1 天前
16.6/36提交节奏 — 52 周中有 24 周有提交
18/18提交量 — 最近一年 133 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year133
human_commit_share0.67
days_since_last_push1
active_weeks_last_year24

发布纪律

98优秀
评分方式
27/27有发布版本 — 已发布 42 个发布版本
36/36发布时效 — 最近一次发布版本于 1 天前
27/27发布节奏 — 约每 3.8 天发布一次
8/10OpenSSF Scorecard:Signed-Releases — 3 out of the last 3 releases have a total of 3 signed artifacts.
所用输入
releases_count42
latest_release_tagv0.23.1
releases_from_tags
days_since_latest_release1
mean_days_between_releases3.8

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

38存在风险 · 占总体的 18%
评分方式
17.5/60星标 — 13 个星标
8/25复刻 — 10 个复刻
1.7/15关注者 — 3 位关注者
所用输入
forks10
stars13
watchers3
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

71良好 · 占总体的 24%
评分方式
25.2/54巴士系数 — 2 位贡献者贡献了半数提交
15.5/22.5提交分布 — 头号贡献者编写了 31% 的提交
9.5/13.5贡献者广度 — 7 位贡献者
6/10OpenSSF Scorecard:Contributors — project has 2 contributing companies or organizations -- score normalized to 6
所用输入
bus_factor2
contributors_sampled7
top_contributor_share0.31
评分方式
18.7/46.8议题解决 — 40% 的议题已关闭
30.8/38.3PR 接受 — 已裁定的 PR 中 129/160 已合并
15/15OpenSSF Scorecard:Code-Review — all changesets reviewed
所用输入
merged_prs129
open_issues3
closed_issues2
issue_closed_ratio0.4
closed_unmerged_prs31
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
21/25所有者影响力 — chainguard-dev 有 844 位关注者
23.1/25既往记录 — 116 个公开仓库,账户约 5 年
所用输入
followers844
owner_typeOrganization
is_verified
owner_loginchainguard-dev
public_repos116
account_age_days1,839
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 3 天前
20/20版本历史 — 51 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/chainguard-dev/omnibump
ecosystemsgo
any_deprecated
min_days_since_publish3

工程质量

基础的工程与文档实践是否到位?

80良好 · 占总体的 20%

工程实践

84良好
评分方式
24/24CI 工作流 — 7 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yaml
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

75良好
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
10/10主题标签 — 4 个主题标签
0/10Wiki
所用输入
topicscargo, go, gradle, maven
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

84良好 · 占总体的 16%

安全态势

80良好
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 3 out of the last 3 releases have a total of 3 signed artifacts.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0/7.5Vulnerabilities — 152 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate8
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages50
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 50 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

79良好 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 67 次人类提交中有 67 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yaml
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 19 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 33 次为自动依赖更新
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilescomposer.lock, go.sum, uv.lock
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.19
toolchain_manifestsgo.mod, pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod, pkg/languages/golang/testdata/bye/go.mod, pkg/languages/golang/testdata/confd/go.mod, pkg/languages/golang/testdata/hello/go.mod, pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod, pkg/languages/golang/testdata/tidy-compat/go.mod, pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle, pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle, pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle, pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle, pkg/languages/java/gradle/testdata/kafka-style/build.gradle, pkg/languages/java/gradle/testdata/kayenta-style/build.gradle, pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts, pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts, pkg/languages/java/gradle/testdata/opensearch-style/build.gradle, pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle, pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts, pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle, pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle, pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts, pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts, testdata/maven-simple/pom.xml
dependency_bot_commit_share0.33
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.6/55可控的文件大小 — 采样的 157 个源文件中有 1 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes88,710
source_files_sampled157
oversized_source_files1

关键数据

13GitHub 星标
7贡献者
133最近 12 个月提交数
1距最近推送天数
42发布版本数
2巴士系数(bus factor)
3开放议题
Go软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 10 ⇿
0Star
10Fork
33发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

02468101012026-022026-042026-07
主版本 0次版本 8修订 25
OpenSSF Scorecard 8.0 / 10
8.0综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-28 03:30 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
8Signed-Releases3 out of the last 3 releases have a total of 3 signed artifacts.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
0Vulnerabilities152 existing vulnerabilities detected
直接依赖 18
注册表软件包版本约束清单文件
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1go.mod
Gogithub.com/chainguard-dev/clogv1.8.1go.mod
Gogithub.com/chainguard-dev/gopomv0.0.0-20250828200639-b1a78ac4b263go.mod
Gogithub.com/charmbracelet/logv1.0.0go.mod
Gogithub.com/ghodss/yamlv1.0.0go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-github/v75v75.0.0go.mod
Gogithub.com/samber/lov1.53.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tidwall/gjsonv1.19.0go.mod
Gogithub.com/tidwall/sjsonv1.2.5go.mod
Gogolang.org/x/expv0.0.0-20231006140011-7918f672742dgo.mod
Gogolang.org/x/modv0.38.0go.mod
Gogolang.org/x/toolsv0.48.0go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gosigs.k8s.io/release-utilsv0.12.4go.mod
全部依赖 50

来自 GitHub 依赖图的完整解析依赖集合:18 个直接依赖与 32 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1直接
Gogithub.com/burntsushi/tomlv1.6.0直接
Gogithub.com/chainguard-dev/clogv1.8.1直接
Gogithub.com/chainguard-dev/gopomv0.0.0-20250828200639-b1a78ac4b263直接
Gogithub.com/charmbracelet/logv1.0.0直接
Gogithub.com/ghodss/yamlv1.0.0直接
Gogithub.com/google/go-cmpv0.7.0直接
Gogithub.com/google/go-github/v75v75.0.0直接
Gogithub.com/samber/lov1.53.0直接
Gogithub.com/spf13/cobrav1.10.2直接
Gogithub.com/stretchr/testifyv1.11.1直接
Gogithub.com/tidwall/gjsonv1.19.0直接
Gogithub.com/tidwall/sjsonv1.2.5直接
Gogolang.org/x/expv0.0.0-20231006140011-7918f672742d直接
Gogolang.org/x/modv0.38.0直接
Gogolang.org/x/toolsv0.48.0直接
Gok8s.io/apimachineryv0.36.2直接
Gosigs.k8s.io/release-utilsv0.12.4直接
Gogithub.com/aquasecurity/go-versionv0.0.1间接
Gogithub.com/aymanbagabas/go-osc52/v2v2.0.1间接
Gogithub.com/charmbracelet/colorprofilev0.2.3-0.20250311203215-f60798e515dc间接
Gogithub.com/charmbracelet/lipglossv1.1.0间接
Gogithub.com/charmbracelet/x/ansiv0.8.0间接
Gogithub.com/charmbracelet/x/cellbufv0.0.13-0.20250311204145-2c3ea96c31dd间接
Gogithub.com/charmbracelet/x/termv0.2.1间接
Gogithub.com/clipperhouse/uax29/v2v2.6.0间接
Gogithub.com/common-nighthawk/go-figurev0.0.0-20210622060536-734e95fb86be间接
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33cc间接
Gogithub.com/go-logfmt/logfmtv0.6.1间接
Gogithub.com/google/go-querystringv1.1.0间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/kr/textv0.2.0间接
Gogithub.com/lucasb-eyer/go-colorfulv1.2.0间接
Gogithub.com/mattn/go-isattyv0.0.20间接
Gogithub.com/mattn/go-runewidthv0.0.19间接
Gogithub.com/muesli/termenvv0.16.0间接
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2间接
Gogithub.com/rivo/unisegv0.4.7间接
Gogithub.com/spf13/pflagv1.0.9间接
Gogithub.com/tidwall/matchv1.1.1间接
Gogithub.com/tidwall/prettyv1.2.0间接
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41e间接
Gogolang.org/x/syncv0.22.0间接
Gogolang.org/x/sysv0.47.0间接
Gogolang.org/x/textv0.33.0间接
Gogolang.org/x/tools/go/packages/packagestestv0.1.1-deprecated间接
Gogolang.org/x/xerrorsv0.0.0-20231012003039-104605ab7028间接
Gogopkg.in/check.v1v1.0.0-20180628173108-788fd7840127间接
Gogopkg.in/yaml.v2v2.4.0间接
Gogopkg.in/yaml.v3v3.0.1间接
依赖安全公告 1

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 50 个包,其中也包含从不交付的开发与测试版本固定:1 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
golang.org/x/textv0.33.0间接未知10.39.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "cargo",
        "go",
        "gradle",
        "maven"
      ],
      "is_fork": false,
      "size_kb": 3343,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 1439590,
        "Makefile": 3870
      },
      "pushed_at": "2026-07-27T00:19:13Z",
      "created_at": "2026-02-12T17:41:55Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T08:14:18Z",
      "description": "Universal declarative dependency bump tool",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://chainguard.dev",
      "name": "Chainguard",
      "type": "Organization",
      "login": "chainguard-dev",
      "company": null,
      "location": "United States of America",
      "followers": 844,
      "avatar_url": "https://avatars.githubusercontent.com/u/87436699?v=4",
      "created_at": "2021-07-14T15:25:28Z",
      "is_verified": null,
      "public_repos": 116,
      "account_age_days": 1839
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.23.1",
          "kind": "patch",
          "published_at": "2026-07-27T00:21:30Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-07-22T15:56:58Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-20T16:35:30Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:12:23Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-07-07T16:05:43Z"
        },
        {
          "tag": "v0.18.6",
          "kind": "patch",
          "published_at": "2026-07-01T14:26:24Z"
        },
        {
          "tag": "v0.18.2",
          "kind": "patch",
          "published_at": "2026-06-26T15:47:53Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2026-06-23T15:11:02Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:30:05Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-22T15:29:35Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-16T07:27:50Z"
        },
        {
          "tag": "v0.15.1",
          "kind": "patch",
          "published_at": "2026-06-12T07:44:35Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-11T16:11:31Z"
        },
        {
          "tag": "v0.14.4",
          "kind": "patch",
          "published_at": "2026-06-10T07:43:39Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2026-06-09T14:28:16Z"
        },
        {
          "tag": "v0.13.1",
          "kind": "patch",
          "published_at": "2026-06-05T12:59:00Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-06-04T14:54:04Z"
        },
        {
          "tag": "v0.12.5",
          "kind": "patch",
          "published_at": "2026-06-01T07:45:34Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2026-05-27T07:58:36Z"
        },
        {
          "tag": "v0.12.3",
          "kind": "patch",
          "published_at": "2026-05-27T07:58:03Z"
        },
        {
          "tag": "v0.12.2",
          "kind": "patch",
          "published_at": "2026-05-20T12:17:12Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-05-18T14:01:54Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-05-14T14:37:04Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-05-07T18:31:14Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-05-05T22:06:48Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-05-04T21:49:18Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-04-22T18:31:16Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2026-04-15T16:58:56Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-04-15T16:32:06Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-04-03T14:08:09Z"
        },
        {
          "tag": "v0.7.5",
          "kind": "patch",
          "published_at": "2026-03-20T16:26:33Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-03-16T00:08:21Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-03-10T18:32:45Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-03-09T14:21:15Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-06T23:11:06Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-03-02T00:05:29Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-02-25T20:42:33Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-02-24T14:16:47Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-02-23T18:00:17Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-02-19T19:03:43Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-02-19T17:57:03Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-02-18T21:34:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "e74d9117492fe4b08630f52c03398a8f5bdf690c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#168)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T08:13:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a00441b1767210c423f86077bb4de041d82e32f4",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.7 to 0.6.0.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/192e21d79ab29983730a13d1382995c2307fbcaa...6599ee8b7a49aef6a770f6\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.7 to 0.6.0 (#166)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-24T08:13:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5f183a1149e4df649a6930b5c2c250b4ce6f1d4",
          "body": "…(#142)\n\nBumps [github.com/chainguard-dev/clog](https://github.com/chainguard-dev/clog) from 1.8.0 to 1.8.1.\n- [Release notes](https://github.com/chainguard-dev/clog/releases)\n- [Commits](https://github.com/chainguard-dev/clog/compare/v1.8.0...v1.8.1)\n\n---\nupdated-dependencies:\n- dependency-name: gi\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github.com/chainguard-dev/clog from 1.8.0 to 1.8.1 …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:41:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2abbfd95893391f21a1141c017066208f6b30aea",
          "body": "…#144)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.1 to 9.3.0.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/82606bf257cbaff209d206a39f5134f0cfbfd\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:40:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e73c3feedd05e36d937731fc43676ad95fcbfe4a",
          "body": "…145)\n\nBumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89..\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:39:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18a97210520f6ae8449c30a852ce75a48829fccd",
          "body": "…#154)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.4 to 2.20.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/9af89fc71515a100421586dfdb3dc9c984fbf411...\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:39:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5604124d31877b827a250df09164bdd3b0d342e8",
          "body": "…ersions (#164)\n\nOn a cold Go module cache, `omnibump --replaces` could write\n`<module>@downloading` into go.mod and then fail to re-parse the file.\n`resolveVersionQuery` runs `go list -m <module>@<query>` with\nCombinedOutput(), which merges stderr into stdout. On a cold cache go\nemits progress to s\n[…]\neach go.mod. Concrete requested\nversions keep flowing through resolvePackageVersion's existing verbatim\nfallback.\n\nCloses AUTO-953\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(go): reject download-progress output when resolving replace-pin v…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-22T15:38:13Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f4aed8419ea7846eda02846b0b7b98897d7e7321",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.46.0 to 0.48.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.46.0...v0.48.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version:\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/tools from 0.46.0 to 0.48.0 (#159)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-22T15:37:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6dd36b76db0563042635b30d577079e20c203087",
          "body": "…e (#163)\n\nIn Go workspace mode omnibump only applied replace pins for modules\nalready declared in a sub-module's go.mod. A purely transitive module —\npresent in no go.mod, only in the module graph — was filtered out of\nevery module and silently dropped, so an explicitly-requested pin never\ntook eff\n[…]\nmodules already\nbeing updated, mirroring the add-if-missing behaviour omnibump already\nhas in single-module mode.\n\nCloses AUTO-954\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(go): apply replace pins for transitive-only deps in workspace mod…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-22T13:56:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "04819df76159dead4d278eff0dbd1c7fac7267e3",
          "body": "…lution edge cases (AUTO-525) (#162)\n\n* fix(rust): correct reverse-dependency resolution for real-world edge cases\n\nHarden the revdep resolver so coordinated upgrades stop aborting on phantom\nconflicts:\n\n- Group a parent's requirements by dependency rename key: a crate that renames a\n  second copy o\n[…]\nhe boundary loop and landedVersion read Cargo.lock (GetCurrentPackages) instead\n   of exec'ing `cargo metadata` per call.\nF10 ParseVersion and parseTerm share splitPre for the pre-release/build split.",
          "is_bot": false,
          "headline": "feat(rust): coordinate crate families and fix reverse-dependency reso…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-20T14:43:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f0722ce5bc8e796d7cfbb65dc62f5dab246dbf3b",
          "body": "… bumps (#157)\n\n* feat(gradle): scan typed String vars and `<<` map appends for version bumps (AUTO-761)\n\nThe Gradle scanner only recognized a fixed set of version-definition\nsyntaxes. Two constructs in real Elasticsearch build scripts fell outside\nit, so omnibump could not rewrite the source litera\n[…]\n the\n  coordinate-literal scan still records the dependency\n\nAdds a multi-module cross-aliasing regression test plus parser edge-case\ntests for the DSL gating, annotation, and coordinate-value guards.",
          "is_bot": false,
          "headline": "feat(gradle): scan typed String vars and `<<` map appends for version…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-15T15:22:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "014583d6d081ff74c7bb72729dbbf7a118350939",
          "body": "…(#156)\n\n* fix(rust): validate and land dependency upgrades within SemVer lines\n\nTwo related fixes for updating a crate that is (or coexists with) multiple\nSemVer-incompatible versions in one Cargo.lock:\n\n- Validate: only compare the target against the locked instance in the same\n  Cargo caret line.\n[…]\nin (name@from=to)\nhandling -- the @from marker only supplies the base name, and the\nexact-match / refused-downgrade case is owned by pinPrecise and\nverifyTransitiveUpgrade, so Validate defers to them.",
          "is_bot": false,
          "headline": "fix(rust): validate and land dependency upgrades within SemVer lines …",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-14T15:46:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "127737bb840067cbd549fff03f549260817573bb",
          "body": "…toml (#155)\n\n* feat(rust): edit Cargo.toml for SemVer-breaking direct dependency bumps\n\nWhen a direct dependency must be upgraded across a SemVer boundary (e.g.\ntracing-subscriber 0.2 -> 0.3, rand 0.8 -> 0.9), cargo update alone cannot\ncross the caret line, so operators fell back to a fragile exter\n[…]\nr =precise) via invertedTreeSpec; a request matching no\nlocked line is ErrAmbiguousTarget. As a safety net, ParseTree now refuses multiple\ndepth-0 roots instead of silently dropping all but the first.",
          "is_bot": false,
          "headline": "feat(rust): resolve SemVer-constrained CVE upgrades by editing Cargo.…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-13T14:06:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41d8008f844653060e84e95b5a896ad2d12dc2a4",
          "body": "…allow-list (#150)\n\nAdd two missing endpoints to the harden-runner egress allow-list:\n\n- goreleaser.com:443 — goreleaser-action resolves download URLs through\n  this host (EAI_AGAIN failure)\n- uploads.github.com:443 — goreleaser uploads release artifacts through\n  this host, separate from api.github.com\n\nFollow-up to #147 and #148.",
          "is_bot": false,
          "headline": "fix(ci): add goreleaser.com and uploads.github.com to release egress …",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-07T15:57:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4859c6498ed4cb2df255e9de94c7d5db1f8abf",
          "body": "Add tuf-repo-cdn.sigstore.dev, fulcio.sigstore.dev, and rekor.sigstore.dev\nto the harden-runner egress allow-list. The release workflow uses cosign\nkeyless signing (sign-blob via goreleaser) which contacts Fulcio for\ncertificates and Rekor for the transparency log, and the cosign installer\nuses the TUF CDN for trust root verification.\n\nFollow-up to #147 which added raw.githubusercontent.com.",
          "is_bot": false,
          "headline": "fix(ci): add sigstore endpoints to release workflow egress allow-list",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-07T15:14:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f612a78d32bc72fcc0958a9cb3fcf150666baa59",
          "body": "…149)\n\nDerive direct dependencies from the Cargo.lock graph: a local/workspace\ncrate (no source) has a dependencies array that lists exactly the crates\ndeclared in Cargo.toml. Those are direct; everything reachable only\ntransitively is indirect.\n\n- parse the source field from Cargo.lock\n- set Depend\n[…]\n and\n  record directCount/indirectCount metadata\n- report direct/indirect counts in analyze text output; per-package\n  classification is available via the Transitive flag in json/yaml\n\nCloses AUTO-824",
          "is_bot": false,
          "headline": "feat(rust): distinguish direct vs indirect dependencies in analyze (#…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-07T14:57:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d07c8e0ac9ae13366a5d5a2a8e47f6d9c2253685",
          "body": "Add raw.githubusercontent.com:443 to the harden-runner egress allow-list.\nThe cosign-installer v4.1.2 (bumped in #70) downloads its public key from\nthis host for signature verification, causing the release workflow to fail\nwith 'Could not resolve host: raw.githubusercontent.com'.\n\nRemove attacker.example.com:443, which was auto-captured from the\nStepSecurity baseline in #41 — it's a test fixture URL from go-tests\nthat was erroneously copied into the release workflow.",
          "is_bot": false,
          "headline": "fix(ci): fix release workflow egress allow-list for cosign installer",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-06T20:58:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90b4995839ae2038938284776bfca20bea79b569",
          "body": "What:\n\nWhen a language ecosystem has multiple potential build tools to choose\nfrom (java, python), standardize the metadata as `buildTool` and display\nit in the text output of `omnibump analyze` and `omnibump\nanalyze-remote`. The `language` should always show the ecosystem the package belongs to.\n\nWhy:\n\nIt's useful information to have, especially when developing CVE\nremediation features, to know if the correct build tool has been\nselected.",
          "is_bot": false,
          "headline": "chore(analyze): Add build tool to text output, if set (#146)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-06T19:53:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d383de5bb22b765dd48982c1cf16aa5a993228f",
          "body": null,
          "is_bot": false,
          "headline": "docs(ruby): add Ruby language documentation to README and usage examples",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-06T14:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "121127028a9dd7d6d76523cf5488f8f7214afcdf",
          "body": "…n (#141)\n\npinPrecise previously pinned name@version=precise targets unconditionally, even when the precise version was older than what's currently locked. Compare against SemVer and skip the pin with a warning instead.",
          "is_bot": false,
          "headline": "fix(rust): refuse to downgrade packages when pinning a precise versio…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-07-02T14:39:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3c72a509911ee71b976f169a1e243fc8e0e6f59",
          "body": "Add gem-dir overlay mode to the Ruby plugin, mirroring the Python --venv\npattern. When --gem-dir is specified, omnibump installs patched gems\ndirectly into an existing gem directory using gem install --install-dir,\nreplacing freeform runs: steps in melange YAML files.\n\nKey design decisions:\n- Valida\n[…]\nrsion comparison uses segment-by-segment numeric comparison matching\n  RubyGems Gem::Version behavior, with pre-release segment ordering\n- Same-version gems are skipped to avoid unnecessary reinstalls",
          "is_bot": false,
          "headline": "feat(ruby): add --gem-dir overlay mode for CVE remediation",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-07-01T21:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aed36f3f49b543f567dbfb080adfc7e50a64599d",
          "body": "…ons (#135)\n\n* feat(gradle): force managed pins on bundled non-classpath configurations\n\nomnibump's managed resolutionStrategy.force block only matched the compile\nand runtime classpaths — the configurations that normally ship. A fat-jar\nbuild can bundle an extra, custom-named configuration into the\n[…]\ned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gradle): force managed pins on bundled non-classpath configurati…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-07-01T14:24:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9e2d05055abe858afaffee5c8c73f3866bbb2840",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.6 to 0.5.7.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...192e21d79ab29983730a13\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 (#131)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T21:27:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ba0fee429ffac6377a3d661a171ef3a2ee7959d",
          "body": "…y matches (#139)\n\nWhen a caller passes --replaces pkg=pkg@vX with no existing replace\ndirective in go.mod, resolveAndFilterPackages was silently dropping the\npackage because semver.Compare(currentVersion, resolvedVersion) == 0.\nThe version-equality skip exists to avoid no-op require updates, but a\n\n[…]\nFilterPackagesForTest helper with\na call to the real function, stubbing resolveListCommand via a new\nresolveListCommand variable (same pattern as commandContext) so no\nexternal go list calls are made.",
          "is_bot": false,
          "headline": "fix(golang): apply new replace directives when require version alread…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-06-30T21:26:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46a62a8a64c1a00099869ca3b3f860e3954b0a03",
          "body": "…xamples\n\nAdd Python to the supported languages table, features list, and quick start\nsection in README.md. Add comprehensive Python section to usage-examples.md\nwith 10 examples covering pyproject.toml, requirements.txt, setup.cfg,\nPipfile, inline updates, venv mode, build tool override, analyze, CVE\nremediation, and version resolution.\n\nCloses AUTO-429",
          "is_bot": false,
          "headline": "docs(python): add Python language documentation to README and usage e…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-30T20:56:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c894405758fb12f42f90c813047bbeff3d394f8e",
          "body": "…ategy (#138)\n\n* fix(rust): show upgrade-from version in analyze output and harden strategy\n\nWhat:\nFix `omnibump analyze` mislabeling existing Rust crates as \"(new)\" in the\nDirect Dependency Updates section, and make RecommendStrategy resolve the fix\nversion from the crates.io index without sacrific\n[…]\nindirect resolver).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\n\n---------\n\nSigned-off-by: Adam Israel <adam.israel@chainguard.dev>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(rust): show upgrade-from version in analyze output and harden str…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-30T20:15:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d80b4920ef62715102b684eb6af39026126c3890",
          "body": "…ate (#133)\n\nDo a better job when we can't find an inline version to upgrade to\ncleanly. If the SemVer is incompatible and the crate can't be upgraded, `omnibump`\nshould fail. Otherwise, proceed with the upgrade.",
          "is_bot": false,
          "headline": "fix(rust): Fix issue where Rust is passing when it can't upgrade a cr…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-26T15:38:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d5a60228c5b11049dbe952bca819e81ed52451e2",
          "body": "* fix(ci): set persist-credentials false on checkout steps\n\nEvery actions/checkout step now explicitly sets persist-credentials: false. None of the affected jobs perform git writes relying on the persisted GITHUB_TOKEN credential store: build, go-tests, and verify run read-only operations, and relea\n[…]\n be restored into the signed-release build and\ncontaminate published artifacts. Set cache: false so the release build pulls\nno PR-writable cache (zizmor cache-poisoning, release.yaml).\n\nRefs: PSEC-923",
          "is_bot": false,
          "headline": "fix(ci): GitHub Actions security hardening (#130)",
          "author_name": "Steve Beattie",
          "author_login": "stevebeattie",
          "committed_at": "2026-06-26T06:37:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c4c4b6757c9440c76597350b656574eb6c596af",
          "body": "…rgeting (#129)\n\nWhat:\nTurn the `classifier` field on a Maven dependency pin into a three-way selector:\n- unset/empty: match every variant — the classifier-less dependency and all\n  classifier'd ones (a wildcard)\n- \"none\": match only the classifier-less dependency, leaving classifier'd\n  siblings un\n[…]\nrgets one classifier, and \"none\" targets only the classifier-less dependency.\n\nCloses https://linear.app/chainguard/issue/AUTO-753\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): match all classifier variants by default, with opt-in ta…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-23T13:58:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4671d3855b0419de3a0b1a84f2bb2fae1cb8584a",
          "body": "…ncy graph rather than taking it directly from the advisory. (#127)\n\n* feat(rust): upgrade reverse dependencies and support precise pins\n\nReplace the per-crate updatePackage loop with upgradeReverseDependencies,\nwhich routes Rust CVE remediation through cargo's own resolver. For a given\ntarget it di\n[…]\n Wrap the ambiguous-target error with a static ErrAmbiguousTarget sentinel\n  (err113), add scoped //nolint:gosec on the cargo subprocess calls (G204),\n  and reformat utils_test.go (gofmt/gci/gofumpt).",
          "is_bot": false,
          "headline": "feat(rust): resolves the fix version using the upstream Cargo depende…",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-22T15:20:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6becebfe07904b314b432f4629ef1fc1e1b7bfd",
          "body": "Maven keys dependencyManagement by groupId:artifactId:type:classifier, but\nomnibump matched and wrote dependencies by groupId:artifactId only. As a\nresult a deps entry could not pin a classifier'd artifact (e.g. the native\nnetty transports netty-transport-native-kqueue:osx-x86_64 /\n-epoll:linux-x86_\n[…]\nement entry. Validate, the version-conflict dedup key,\nand the analyzer/precedence keys are all classifier-aware.\n\nCloses AUTO-753\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): support <classifier> in dependency bumping (#126)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-22T14:42:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a0932d8c811d336fbcfd75615ee929af01d69604",
          "body": "…ings (#122)\n\n* feat(gradle): manage pins via settings block (constraints + substitution)\n\nRework Gradle transitive/coordinate pinning: emit dependency constraints\n(require) and dependencySubstitution rules in the root settings script via\ngradle.beforeProject, so they apply before any configuration \n[…]\n to match renderManagedBlock. No behavior change.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gradle): pin versions via a before-resolution force block in sett…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-22T14:33:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd44e0e6c051b4dcde59f1b36653b6dfeeaf6de7",
          "body": "For unit tests added in PR #127, we'll need access to `static.crates.io`\nin order to run live `cargo update` and `cargo metadata` commands.",
          "is_bot": false,
          "headline": "chore(go-tests): Add static.crates.io to allowed-endpoints (#128)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-22T13:17:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c966108f19ae8f83603a0f24205af96ecbb61f0",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#125)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:46:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "345aa6242c02dc6e50d73321884bd41fe0aaa45e",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.36.1 to 0.36.2.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.36.1...v0.36.2)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.36.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 (#124)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:45:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9e7a1a845e5e704df6b1ab8c53976e1cde7c9db",
          "body": "Bumps [golang.org/x/tools](https://github.com/golang/tools) from 0.45.0 to 0.46.0.\n- [Release notes](https://github.com/golang/tools/releases)\n- [Commits](https://github.com/golang/tools/compare/v0.45.0...v0.46.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/tools\n  dependency-version:\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/tools from 0.45.0 to 0.46.0 (#123)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T08:44:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0c98e344bea347d9ac2a1c3f39161a6cf4f0ebd",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#99)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4595705eee3281aba38cf20dc3ecbf623c45e948",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.1 to 4.36.2.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/8\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 (#113)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:19:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc1f53fe73aa0e9f3cb6a4e77e9a03ac76c04d3b",
          "body": "Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.36.0 to 0.37.0.\n- [Commits](https://github.com/golang/mod/compare/v0.36.0...v0.37.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/mod\n  dependency-version: 0.37.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/mod from 0.36.0 to 0.37.0 (#114)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-18T08:19:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d4f1585bac858926556f8608a4a9f7a5ad9923c",
          "body": "analyze-remote returned almost no information for Gradle projects. The\nJava case always used the Maven analyzer with the aggregated Java\nmanifest set, so a Gradle repository's build files were XML-parsed and\ndiscarded, and GradleAnalyzer.AnalyzeRemote was an unimplemented stub.\n\nBuild the Gradle pro\n[…]\n and variables the same way local analyze does, and route\nJava repositories to the correct build tool with a paths-based detector\nso each tool searches only its own manifest patterns.\n\nCloses AUTO-728",
          "is_bot": false,
          "headline": "feat(gradle): support analyze-remote for Gradle projects (#119)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-17T20:16:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6be57d2ef600cd4c33e2ba7445aef7055d745ecb",
          "body": "Match the sentinel error value instead of its message string so the\ntest stays valid if the wording changes.",
          "is_bot": false,
          "headline": "test(rust): assert ErrCargoLockNotFound with errors.Is (#121)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-17T19:17:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0727b87dd4fb6cf0a620fddbeb8460b70dc45f86",
          "body": "If we run a `cargo update`, we need to re-read the `Cargo.lock` so we're\nnot working against a stale list of packages. This is a bug that leads\nto `omnibump` failures w/ `--update`\n\n- Refactors the code that reads `Cargo.lock` so that it's reusable\n- Re-read `Cargo.lock` post-update\n- Update test data to verify fix",
          "is_bot": false,
          "headline": "fix(rust): Re-read Cargo.lock after `cargo update` (#120)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-17T15:59:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6ac23996628e6ffaab83f40f75397a8ce16499a",
          "body": "Adds Gemfile.lock parsing, direct text-based version updates (no Bundler\nCLI dependency), analysis, and validation for Ruby projects.\n\n- ruby.go: Language interface (Detect, Update, Validate, --show-diff)\n- analyzer.go: Analyzer interface (Analyze, AnalyzeRemote, RecommendStrategy)\n- parser.go: Gemf\n[…]\n performed via direct Gemfile.lock text editing — no\nRuby/Bundler CLI required — matching the deployment model where omnibump\nruns in melange build sandboxes without guaranteed toolchain availability.",
          "is_bot": false,
          "headline": "feat: implement Ruby language plugin for omnibump",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-16T15:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "81d611c45bbbad6aa428d8698fa113526336da1b",
          "body": "* feat(gradlefile): add Gradle file parsing and editing library\n\nWhat: introduce pkg/gradlefile, a self-contained parsing and editing\nlibrary for the Gradle files omnibump patches - the Gradle analog of\nthe gopom library Maven support builds on. Files parse into typed\nmodels with byte spans; edits a\n[…]\nopic.com>\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gradle): bring Gradle support to parity with Maven (#108)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-16T07:09:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5119b4d7af90c36ae79580e2e0f67be0a596f080",
          "body": "* fix(rust): Handle package names pinned to specific versions\n\nWith Cargo, you can depend on multiple versions of a crate by pinning\nthe version to the crate name, i.e., `rand@0.9.2` to only upgrade that\nversion of the crate.\n\nThese upgrades were silently failing because we were matching on the\nenti\n[…]\nstring (`rand@0.9.2`) instead of looking for the crate by\nname (`rand`) and then checking its version.\n\n* Move function call outside of loop\n\nThe `strings.Cut(...)` doesn't need to be inside the loop.",
          "is_bot": false,
          "headline": "fix(rust): Handle package names pinned to specific crate versions (#117)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-16T02:11:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "061adbd8174891cafe0c13b09f7e5f5579e3f15e",
          "body": "…rements-pinned.txt\n\nParseInlinePackages now handles Python's == separator (e.g. urllib3==2.7.0)\nbefore the JS single-= path. Venv mode no longer requires == prefix in the\nversion field. The --manifest flag is supported via resolveManifest which\nskips auto-detection when a path is provided. resolveLanguage no longer\nassumes Maven when --manifest is set. requirements-pinned.txt is recognized\nas a valid manifest filename.",
          "is_bot": false,
          "headline": "fix(python): support == version separator, --manifest flag, and requi…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-15T14:59:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6532afc0842b11afbf7c4e4969f002765ddd8a60",
          "body": "…s (#110)\n\n* fix(cli): merge file and inline inputs instead of dropping inline ones\n\nWhat: loadUpdateConfig now loads file inputs (--deps/--properties files)\nand inline inputs (--packages/--replaces/--props) and merges them,\ninstead of returning only the file inputs whenever a file flag is set.\nAdds\n[…]\nionally, and quoted error values survive empty or\nwhitespace strings legibly.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): merge file and inline inputs instead of dropping inline one…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-11T16:45:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f8b3f3de97c4b69350339c40cb68b76557d408c7",
          "body": "… requested ref (#109)\n\n* fix(analyze-remote): discover manifest files from the git tree at the requested ref\n\nWhat: GitHubFetcher.SearchFiles now sources candidate paths from\nListFilePaths (Git Tree API at the exact ref) and filters them by\nfilename, instead of querying the GitHub Code Search API. \n[…]\nopic.com>\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(analyze-remote): discover manifest files from the git tree at the…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-11T16:06:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8ef89d04c4ed980275fc2a0ef7e46f12d111c879",
          "body": "* AUTO-692: Add an explicit `update` flag\n\nAdd a distinct `--update` flag to `omnibump` to handle dependency\nupdates, to disambiguate between `--tidy`, which performs a\nfundamentally different task (version bumping versus correctness and\nhygiene).\n\n* fix(omnibump): Allow endpoint for index.crates.io\n\nAllow the `index.crates.io` endpoint so we can run/test `cargo update`.\n\n---------\n\nSigned-off-by: Adam Israel <adam.israel@chainguard.dev>",
          "is_bot": false,
          "headline": "AUTO-692: Add an explicit `update` flag (#111)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-11T15:38:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33e300d1d06704cacdc26007a7ac3e73a6ddc938",
          "body": null,
          "is_bot": false,
          "headline": "feat: parse optional-dependencies and PEP 735 dependency-groups",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cdf429bd0fb9df00c24a31ecd82f1c1c635bedcb",
          "body": null,
          "is_bot": false,
          "headline": "feat: wire Python language plugin and CLI flags",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd814eda9c4d02ff957eeb750f31453667e6db05",
          "body": null,
          "is_bot": false,
          "headline": "feat: add Python venv mode with PEP 440 version ordering",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01497aba38c5788ac31c3ff30e460a40b0bcc029",
          "body": null,
          "is_bot": false,
          "headline": "feat: add Python manifest parsing, updating, and build tool detection",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-10T21:01:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6eb3afbb45e822d822873e1dcdae27dbd4d93dc",
          "body": "To avoid future code duplication as support for more build tools is\nadded, extract ValidatePathWithinRoot into a new pkg/utils package so\nthe logic lives in one place.\n\nErrUnsafePomPath in the maven package is kept as an alias for\nutils.ErrUnsafePath so existing errors.Is checks continue to work\nwithout any caller changes.\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(utils): centralise path boundary validation (#107)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-09T16:11:56Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "88567739ce5cabeb6867eb8e7bc4f3576cbb7dbe",
          "body": "…e CLI (#103)\n\n* feat(maven): implement AnalyzeRemote and wire Java into analyze-remote CLI\n\nWhat:\n- Implement MavenAnalyzer.AnalyzeRemote(ctx, files map[string][]byte) to analyse\n  pom.xml files fetched by the existing remote fetcher infrastructure. Parsing\n  uses xml.Unmarshal directly (gopom.Pars\n[…]\n-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): implement AnalyzeRemote and wire Java into analyze-remot…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-09T15:12:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "98909521b34c0c4bb0351e787eabcce604c311bb",
          "body": "* test: add failing test for non-existent path in validatePathWithinRoot\n\n* fix: skip non-existent parent POM paths instead of crashing\n\nWhen a module POM declares a <parent> whose resolved path does not\nexist on disk (e.g. a corporate super-POM not present in the build\ntree), filepath.EvalSymlinks \n[…]\nhard failure instead of letting\nthe sibling-walk fallback run.\n\nCheck os.Stat before calling validatePathWithinRoot. A non-existent\nparent path means the chain ended, not that a boundary was violated.",
          "is_bot": false,
          "headline": "fix: skip non-existent parent POM paths instead of crashing (#106)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-09T07:56:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "460b52918e0fd3395a6e22db363bc1d9a3f8660b",
          "body": "* test: add failing test for sibling module property resolution\n\nAdd test case for property resolution across sibling Maven modules.\nUpdate error text expectations to match the new fallback behavior.\nThese tests will fail until the updater gains project-tree-walk support.\n\n* fix: fall back to projec\n[…]\nthe project tree via findProjectRoot + findMavenPoms for sibling\nmodules that define it. Preserves the root-boundary security invariant\nby surfacing ErrUnsafePomPath if the parent chain was cut short.",
          "is_bot": false,
          "headline": "fix: resolve Maven properties defined in sibling modules (#105)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-08T22:53:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a8464e863689c63e48cb1da7ac5aa2e02f3c630",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/7\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 (#98)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-08T14:06:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0647c91c9f8dd2652524e96ac56a40bb06f6bed",
          "body": "Signed-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "chore(README): update information about contributions (#102)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-08T12:49:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a46e11d8bb64fda4a352cb9a0d5aa55c8f931877",
          "body": "Summary\nThe --show-diff flag was only implemented for Go. Rust, PHP, and JS all copied the flag into their internal config types but never read it — --show-diff was silently ignored.\n\nThis adds the same before/after snapshot + cmp.Diff pattern to all three:\n\nRust: diffs Cargo.lock before and after D\n[…]\n\nPHP: diffs all manifest files (from the detected build tool) before and after buildTool.Update\nFollows the existing Go implementation in pkg/languages/golang/updater.go.\n\n🤖 Generated with Claude Code",
          "is_bot": false,
          "headline": "feat: implement --show-diff for rust, php, and js languages (#100)",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-06-05T18:22:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "80250b9966017d3d99afd53ac79e3c8a44b9973d",
          "body": "…sal boundary (#97)\n\nMaven projects commonly declare version properties in a parent POM\nreferenced via <parent><relativePath>. Before this change the analyzer\nhad no concept of where a property came from, showing properties in\nparent POMs as '(new)' with a warning, even though the update command\nfou\n[…]\n shows [manifest: X] next to each property in Property\n  Usage and manifest: above each property update in the Strategy section.\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven/analyze): surface property source file and add path traver…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-04T15:51:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7aed66d7c1a7819aa297e1cc7df2db98305f748c",
          "body": "….0 (#55)\n\nBumps [step-security/action-actionlint](https://github.com/step-security/action-actionlint) from 1.69.1 to 1.72.0.\n- [Release notes](https://github.com/step-security/action-actionlint/releases)\n- [Commits](https://github.com/step-security/action-actionlint/compare/d364e70a116a460ed220d67b\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/action-actionlint from 1.69.1 to 1.72…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:19:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "685c4ab1725bf595f096c2e1447da83efccee295",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/cad07c2e89fa2edd6e2d7bab4c1aa38e53f76003...6f9f17788090df1f26\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#70)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:18:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b07df3d107a615da6c8cd5a60c2537403fa5a32a",
          "body": "Bumps [golang.org/x/mod](https://github.com/golang/mod) from 0.35.0 to 0.36.0.\n- [Commits](https://github.com/golang/mod/compare/v0.35.0...v0.36.0)\n\n---\nupdated-dependencies:\n- dependency-name: golang.org/x/mod\n  dependency-version: 0.36.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golang.org/x/mod from 0.35.0 to 0.36.0 (#76)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:17:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12535b80743b591ac7366d37115b32c48a0cde7f",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.35.3 to 0.36.1.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.3...v0.36.1)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.36.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.35.3 to 0.36.1 (#77)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f06247b15ac31f1ea26291cdee4071ef45b875c",
          "body": "Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.0.0 to 7.2.2.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/ec59f474b9834571250b370d4735c50f8e2d1e29...5daf1e\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.0.0 to 7.2.2 (#84)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:16:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fa4d3f1a18fbbc41ef95bc69102143ba1ffac84",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.3 to 0.5.6.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/b1d7e1fb5de872772f31590499237e7cce841e8e...5f14fd08f7cf1cb1609c1e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 (#86)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:15:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25bf7b196fae4d9ce2b3abacf2e09ac557f6d386",
          "body": "…#91)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.0 to 9.2.1.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/1e7e51e771db61008b38414a730f564565cf7c\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:14:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "386464b48dd197b8f5025368b4c0ebf82f969dd0",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.1 to 4.36.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/c\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.35.1 to 4.36.0 (#92)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af25208e6988be721a7e0150a6c7275615440563",
          "body": "…#93)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.0 to 2.19.4.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/8d3c67de8e2fe68ef647c8db1e6a09f647780f40...9\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.19.0 to 2.19.4 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-03T13:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47e3ca2831bcf2e551771a632a8361f6edf9ab1e",
          "body": "…iling (#96)\n\nWhen a dependency version references \\${project.version}, omnibump was failing\nwith an error because it could not locate where the property is set. \\${project.version}\nis a Maven built-in that refers to the project's own <version> tag, not a\nconfigurable property, so the dependency cannot be bumped this way. Instead of\nerroring, log an informational message and continue.\n\nCloses https://linear.app/chainguard/issue/AUTO-655/",
          "is_bot": false,
          "headline": "fix(maven): skip dependencies using \\${project.version} instead of fa…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-03T13:12:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfbb6e3ef25e95a0b153c54c5c4f234414e2c082",
          "body": "* feat: Wire up support for tidy-compat\n\nAdd and wire up the `--tidy-compat` flag.\n\n* chore(tests): Add Unit + Integration tests, plus supporting changes\n\nThe biggest change here is to use an interface to call\n`exec.CommandContext` in `runner.go`, so that the call can be mocked by\nthe new unit test.\n\nAlso adds an integration test, w/ test go project, to verify Go is doing\nwhat we expect it to.",
          "is_bot": false,
          "headline": "feat: add go tidy compat support to omnibump (#95)",
          "author_name": "Adam Israel",
          "author_login": "AdamIsrael",
          "committed_at": "2026-06-01T14:39:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88629f453e84633fecb6bfbb57a23f88223b1442",
          "body": "omnibump doesn't support JS right now. There's no pipeline in `melange`\nfor bumping JS dependencies either. This means that JS users have to\nmanually update their package.json with error-prone scripts or direct\ncalls to the package managers.\n\nHere we add `js` as a first-class language. JS is detecte\n[…]\nually specifying, a list may be given, for cases when there is more\nthan one manager involved (e.g. in a migration).\n\nThe updater tries to make minimal edits: to preserve existing keys and\nformatting.",
          "is_bot": false,
          "headline": "feat(js): add JavaScript language support (#72)",
          "author_name": "Iain Lane",
          "author_login": "iainlane",
          "committed_at": "2026-06-01T12:45:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbbf87765dda27715b80bee46e3e72c3cfa3773a",
          "body": "* fix(maven): update properties in the POM that defines them\n\nWhat:\n- Resolve Maven property updates to the POM where the property is declared.\n- Check the current POM first, then the direct parent POM, including parent relativePath values that point to a directory.\n- Route dependency patches that u\n[…]\neira@chainguard.dev>\n\n* fix(maven): add mavenLanguageName const\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "fix(maven): resolve property updates from parent POMs (#90)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-06-01T07:39:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2bee3b7985626d4dd62a0353a08c41f72007f25f",
          "body": "… manifests (#87)\n\nDetectLanguage iterates a Go map, so when multiple languages match the\nsame directory, which one wins depends on map iteration order — which is\nrandomized per-process in Go. This is currently masked for omnibump's own\nrepo by PR #79 (testdata skip), but any project where two langu\n[…]\ninel error.\n\nBoth callers (analyze.go, root.go) now handle the case where\nDetectLanguage returns a valid language name alongside a warning error,\nlogging the ambiguity instead of treating it as fatal.",
          "is_bot": false,
          "headline": "fix: make language auto-detection deterministic and prefer root-level…",
          "author_name": "Justin Vreeland",
          "author_login": "justinvreeland",
          "committed_at": "2026-05-26T17:13:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26ff3a82dc3a052c6fd8b8678059d25d321c010d",
          "body": "…t (#82)\n\nWhat: walkXMLFiles now guards the isSkippableDirectory check with\npath != rootDir, ensuring the root of each walk is never filtered out\nregardless of its directory name. Adds regression tests for\nwalkXMLFiles, Detect(), and Analyze() covering projects rooted in\ndirectories named build, tar\n[…]\nvenPom fast-path\nbut Analyze() — which always calls analyzeAllPoms then walkXMLFiles —\nreturned ErrNoPOMsFound for every file in the project.\n\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(java/maven): do not skip walk root when its name matches skip lis…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-20T18:54:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6c07db24d92534d167d4ff8c69dbd2dafd668faa",
          "body": "* feat(maven): auto-resolve property refs when patching deps\n\nWhen a dependency's version is a Maven property reference (e.g.\n${log4j2.version}), omnibump now automatically updates the backing\nproperty to the target version instead of warning and skipping the\npatch entirely. If the caller already su\n[…]\n https://linear.app/chainguard/issue/AUTO-628\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(maven): auto-resolve property references when patching deps (#80)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-20T12:13:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25c832f3051c8fc5ca29f417907888900c630c68",
          "body": "…ction (#79)\n\nWhat: isSkippableDirectory now includes \"testdata\", \"vendor\", and \"test\",\npreventing hasMavenPom() from scanning those directories during recursive\nPOM detection. Adds TestMavenDetect_SkippedDirectories to assert that a\nvalid pom.xml inside any skipped directory does not trigger Maven \n[…]\n, causing omnibump to fail with\n\"pom.xml not found\" on a valid Go project.\n\nCloses https://linear.app/chainguard/issue/AUTO-619/\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(java/maven): skip testdata, vendor, and test dirs during POM dete…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-18T13:55:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1251778a4cfe240f21512e0efea7bdff97eb7fb8",
          "body": "…om.xml (#73)\n\nMaven.Detect() now falls back to a recursive directory scan when no root\npom.xml is found, allowing projects like Apache Cassandra (Ant-based, with\nPOMs under .build/) to be identified as Maven projects automatically.\n\nMavenAnalyzer.Analyze() now always delegates to analyzeAllPoms() w\n[…]\ntory, findMavenPoms,\nMaven.Detect() recursive cases, and MavenAnalyzer.Analyze() multi-POM\naggregation (702 total, all passing).\n\nCo-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(java/maven): recursive POM discovery for projects without root p…",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-14T13:55:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6ba57225cb9f650ec31922a22cee980fbc287597",
          "body": "When fetchFromProxy receives a 404, it now returns ErrModuleVersionNotFound\nrather than ErrProxyRequestFailed. This lets callers use errors.Is to detect\nthat a version simply does not exist on the proxy, as opposed to a transient\nnetwork failure, without changing omnibump update behavior (DetectCoUpdates\ncontinues to warn and continue on any CheckTransitiveRequirements error).",
          "is_bot": false,
          "headline": "fix(golang): distinguish proxy 404 as ErrModuleVersionNotFound (#71)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-07T17:36:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "106c534838a3ebefe590d279d35aff57f1df3b49",
          "body": "* feat(java/maven): content-based Maven POM detection via IsMavenPom\n\nReplace filename-only detection with XML parsing:\n- Add IsMavenPom() that parses XML and validates the root element is\n  <project> with namespace http://maven.apache.org/POM/4.0.0\n- Thread manifestFile through Language.Detect() an\n[…]\na.go to flatten nested blocks (nestif)\n- Split manifest pre-detection and directory detection into separate if blocks (nestif)\n\n---------\n\nSigned-off-by: David Negreira <david.negreira@chainguard.dev>",
          "is_bot": false,
          "headline": "feat(java/maven): content-based Maven POM detection via IsMavenPom (#67)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-07T17:09:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9a3a3e57595be7bf57eebd2eae55f1b0eb2a636e",
          "body": "Some Maven projects use a non-standard manifest filename. Add a\n--manifest flag that lets callers specify the exact path to the\nmanifest file to update, falling back to <dir>/pom.xml when unset.\n\nResolves SUS-596",
          "is_bot": false,
          "headline": "feat(java/maven): add --manifest flag for custom pom.xml path (#66)",
          "author_name": "David Negreira",
          "author_login": "dnegreira",
          "committed_at": "2026-05-06T13:56:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d4886c89991ebe81860ff7fc4bbd64fe5a020df",
          "body": "…rom being co-updated (#65)\n\n* fix(golang): prevent independent golang.org/x and gopkg.in packages from being co-updated\n\nTwo layered fixes for the golang.org/x/* family bug where bumping\ngolang.org/x/net pulled every other golang.org/x/* package as a co-update\nat the same target version, causing un\n[…]\n cases and trim verbose comment\n\n* fix: address golangci-lint findings\n\nFlatten else-if to remove extra nesting (nestif complexity 5→3).\nAcknowledge fmt.Fprint return value in test handler (errcheck).",
          "is_bot": false,
          "headline": "fix(golang): prevent independent golang.org/x and gopkg.in packages f…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-05T22:01:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3186cf086064973ca214cedf67ea6886d8601d2",
          "body": "Both functions are needed by callers (e.g. cve-remediation bot) that want\nto perform pre-creation viability checks without reimplementing the\ndetection logic:\n\n- DetectCoUpdates: runs the full co-update analysis against a go.mod,\n  returning required missing deps and API compat alerts with recommend\n[…]\nd\n  minimum compatible versions.\n- FindMinCompatibleVersion: finds the lowest version of a package above\n  its current version whose go.mod requires a given dependency at or\n  above a minimum version.",
          "is_bot": false,
          "headline": "feat(golang): export DetectCoUpdates and FindMinCompatibleVersion (#64)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-04T21:44:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5392beefc43b0aca18747fa1decd47a43a8ecdc9",
          "body": "…set (#63)\n\n* feat(golang): reduce required co-package updates to minimal necessary set\n\n- Filter CheckTransitiveRequirements to only flag direct project deps;\n  indirect deps are resolved automatically by Go's MVS and cannot cause\n  API breakage in the project's own code\n- Add FindVersionGroupPacka\n[…]\nanch where it is used\n- Remove duplicate familyRoot argument from log message\n- Use distinct Reason string for cross-major packages so it doesn't\n  incorrectly say 'both at X' when the versions differ",
          "is_bot": false,
          "headline": "fix(golang): reduce required co-package updates to minimal necessary …",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-05-04T21:16:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "96a8f2ef03e7758ea4738fa3354c89a074d2bc8f",
          "body": "…ts (#60)\n\n* fix(golang): warn instead of error on transitive co-update requirements\n\n* fix(lint): remove unused nolint directives and convert checkMissingTransitiveDeps to void\n\n* fix(security): resolve gosec G703/G704/prealloc lint findings\n\n* fix(security): construct proxy URL from struct fields to eliminate G704 taint path\n\n* fix(security): parse proxy path through url.Parse to break G704 taint chain",
          "is_bot": false,
          "headline": "fix(golang): warn instead of error on transitive co-update requiremen…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-22T18:25:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d6ae7c44329db2040d15feba2897e5d7c6df186",
          "body": "…#59)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.18.0 to 2.19.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/6c3c2f2c1c457b00c10c4848d6f5491db3b629df...8\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.18.0 to 2.19.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T01:31:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe28291046b7208e29b7f20821eec2f551d94905",
          "body": "Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.5.2 to 0.5.3.\n- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)\n- [Commits](https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f3159\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 (#52)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T01:20:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6e703f2374cf01e5bdd2ce46e57766956a8971b",
          "body": "…#56)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.18.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/v2.16.0...6c3c2f2c1c457b00c10c4848d6f5491db3\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.16.0 to 2.18.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-22T00:17:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c3a25bae26d8699e66e5b5efdf93966101ab87a1",
          "body": "…y (#57)\n\n* fix(golang): dedup suggested command packages and reduce log verbosity\n\nFixes a bug where the same package appeared twice in the suggested update\ncommand when it existed in both the filtered update set and the transitive\nco-update requirements at different versions. The command builder n\n[…]\nedundant internal-step messages\n(go get, AddRequire, replace) and downgrading per-package skip and analysis\nlogs to Debug level.\n\n* fix(golang): use map[string]struct{} for set type and fix formatting",
          "is_bot": false,
          "headline": "fix(golang): dedup suggested command packages and reduce log verbosit…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-21T19:16:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29c353c59acecb4db901f884def22ecea3dab834",
          "body": "* fix: handle +incompatible versions and vendor go.sum updates\n\nFixes issues where packages with +incompatible suffix were not resolved correctly,\nand vendor directories failed due to missing go.sum entries.\n\n- Resolve all semantic versions through go list to get canonical forms\n- Handles +incompati\n[…]\nline in indirect_resolver_test.go\n\n* fix: use go 1.25 in test go.mod fixtures\n\n* fix: restore go 1.26 in downgrade test fixture\n\n* fix: extract resolvePackageVersion helper to reduce nestif complexity",
          "is_bot": false,
          "headline": "feat: detect transitive dependency requirements  (#26)",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-15T16:46:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c0b14475020d8a3642e6cb83e74c141ce236705",
          "body": "* feat: add PHP language support with Composer build tool\n\nRestructure to match Java pattern where PHP is the language and Composer\nis a build tool underneath it. This allows for future addition of other\nPHP build tools.\n\n- Add pkg/languages/php/ with language detection and build tool interface\n- Ad\n[…]\n package-level documentation\nand Example functions demonstrating the public API for both the\nphp and composer packages.\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add PHP language support with Composer build tool (#50)",
          "author_name": "Thomas Bechtold",
          "author_login": "toabctl",
          "committed_at": "2026-04-14T14:03:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9c9785986745c30cb047b291351d72c7e5974c4a",
          "body": "…] (#47)\n\nSigned-off-by: Steve Beattie <steve.beattie@chainguard.dev>",
          "is_bot": false,
          "headline": "chore(workflows): add actionlint and zizmor action linters [SECINT-75…",
          "author_name": "Steve Beattie",
          "author_login": "stevebeattie",
          "committed_at": "2026-04-07T12:28:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c1997b9c829e3e100ab5ffe81018ea1fab3bbec",
          "body": "Bumps [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) from 0.35.2 to 0.35.3.\n- [Commits](https://github.com/kubernetes/apimachinery/compare/v0.35.2...v0.35.3)\n\n---\nupdated-dependencies:\n- dependency-name: k8s.io/apimachinery\n  dependency-version: 0.35.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump k8s.io/apimachinery from 0.35.2 to 0.35.3 (#35)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:35:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf8678c0e978cd7a3a166978600c6c8d6870510a",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 4.1.0 to 4.1.1.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/ba7bc0a3fef59531c69a25acd34668d6d3fe6f22...cad07c2e89fa2edd6e\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigstore/cosign-installer from 4.1.0 to 4.1.1 (#39)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ffeb5a6e760f3f3fdbfcd3eca68c9f61e9fa0f1",
          "body": "Bumps [sigs.k8s.io/release-utils](https://github.com/kubernetes-sigs/release-utils) from 0.12.3 to 0.12.4.\n- [Release notes](https://github.com/kubernetes-sigs/release-utils/releases)\n- [Commits](https://github.com/kubernetes-sigs/release-utils/compare/v0.12.3...v0.12.4)\n\n---\nupdated-dependencies:\n-\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump sigs.k8s.io/release-utils from 0.12.3 to 0.12.4 (#43)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "44e97c6510110dc859501de949a5a2ed578e76a3",
          "body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.32.6 to 4.35.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/0\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 4.32.6 to 4.35.1 (#45)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a2bd14d17fff9dd99838f4bcb6307439bb6713",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.3.0 to 6.4.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4b73464bb391d4059bd26b0524d20df3927bd417...4a3601121dd01d1626a1e23e37211e3254c1c06c)\n\n---\nupdated\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.3.0 to 6.4.0 (#46)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:31:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f22d33724321a115f747691421590076327c5d1a",
          "body": "…#44)\n\nBumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.16.0 to 2.16.1.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594...f\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump step-security/harden-runner from 2.16.0 to 2.16.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-02T14:30:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2f3487913b86ce427152d1c7eef3819b9a4139d0",
          "body": "…oring (#42)\n\n* fix(golang): warn and skip packages superseded by major version upgrades after tidy\n\nWhen go mod tidy runs after updating a batch of dependencies, packages\nthat migrated to a new major version path (e.g. containerd/v2 replacing\ncontainerd) are legitimately removed from go.mod. Previo\n[…]\nire passes into separate helper functions to reduce\nDoUpdate complexity from 36 to acceptable levels. Remove unused ctx parameter\nfrom addRequirePackage function to satisfy revive and unparam linters.",
          "is_bot": false,
          "headline": "fix(golang): warn and skip missing packages after tidy instead of err…",
          "author_name": "Kyle Steere",
          "author_login": "kbsteere",
          "committed_at": "2026-04-01T21:57:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 42,
      "commits_last_year": 133,
      "latest_release_at": "2026-07-27T00:21:30Z",
      "latest_release_tag": "v0.23.1",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 3.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/chainguard-dev/omnibump",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/chainguard-dev/omnibump",
          "is_deprecated": false,
          "latest_version": "v0.23.1",
          "repository_url": "https://github.com/chainguard-dev/omnibump",
          "versions_count": 51,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-24T08:13:59Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        }
      ]
    },
    "popularity": {
      "forks": 10,
      "stars": 13,
      "watchers": 3,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-23",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 1
          },
          {
            "date": "2026-03-05",
            "count": 1
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-25",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-07-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 10,
        "total_forks": 10
      },
      "star_history": null,
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod",
        "pkg/languages/golang/testdata/bye/go.mod",
        "pkg/languages/golang/testdata/confd/go.mod",
        "pkg/languages/golang/testdata/hello/go.mod",
        "pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod",
        "pkg/languages/golang/testdata/tidy-compat/go.mod",
        "pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle",
        "pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kafka-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kayenta-style/build.gradle",
        "pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/opensearch-style/build.gradle",
        "pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle",
        "pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle",
        "pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle",
        "pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts",
        "pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts",
        "testdata/maven-simple/pom.xml"
      ],
      "largest_source_bytes": 88710,
      "source_files_sampled": 157,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.33.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 13
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 50,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/aquasecurity/go-pep440-version",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.1"
        },
        {
          "name": "github.com/chainguard-dev/clog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.1"
        },
        {
          "name": "github.com/chainguard-dev/gopom",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250828200639-b1a78ac4b263"
        },
        {
          "name": "github.com/charmbracelet/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/ghodss/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-github/v75",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v75.0.0"
        },
        {
          "name": "github.com/samber/lo",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.53.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tidwall/gjson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.0"
        },
        {
          "name": "github.com/tidwall/sjson",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.5"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20231006140011-7918f672742d"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.38.0"
        },
        {
          "name": "golang.org/x/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.48.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "sigs.k8s.io/release-utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.12.4"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/aquasecurity/go-pep440-version",
            "direct": true,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chainguard-dev/clog",
            "direct": true,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chainguard-dev/gopom",
            "direct": true,
            "version": "v0.0.0-20250828200639-b1a78ac4b263",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/log",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ghodss/yaml",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v75",
            "direct": true,
            "version": "v75.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/samber/lo",
            "direct": true,
            "version": "v1.53.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/gjson",
            "direct": true,
            "version": "v1.19.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/sjson",
            "direct": true,
            "version": "v1.2.5",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": true,
            "version": "v0.0.0-20231006140011-7918f672742d",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": true,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": true,
            "version": "v0.48.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/release-utils",
            "direct": true,
            "version": "v0.12.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aquasecurity/go-version",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-osc52/v2",
            "direct": false,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": false,
            "version": "v0.2.3-0.20250311203215-f60798e515dc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/lipgloss",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/cellbuf",
            "direct": false,
            "version": "v0.0.13-0.20250311204145-2c3ea96c31dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/clipperhouse/uax29/v2",
            "direct": false,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/common-nighthawk/go-figure",
            "direct": false,
            "version": "v0.0.0-20210622060536-734e95fb86be",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logfmt/logfmt",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kr/text",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/termenv",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/match",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/pretty",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.33.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools/go/packages/packagestest",
            "direct": false,
            "version": "v0.1.1-deprecated",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/xerrors",
            "direct": false,
            "version": "v0.0.0-20231012003039-104605ab7028",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/check.v1",
            "direct": false,
            "version": "v1.0.0-20180628173108-788fd7840127",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 50,
        "direct_count": 18,
        "indirect_count": 32
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 129,
        "open_issues": 3,
        "closed_ratio": 0.4,
        "closed_issues": 2,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 2,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "kbsteere",
          "commits": 27,
          "avatar_url": "https://avatars.githubusercontent.com/u/13925027?v=4"
        },
        {
          "type": "User",
          "login": "dnegreira",
          "commits": 23,
          "avatar_url": "https://avatars.githubusercontent.com/u/5215383?v=4"
        },
        {
          "type": "User",
          "login": "AdamIsrael",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/125008?v=4"
        },
        {
          "type": "User",
          "login": "justinvreeland",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/3758821?v=4"
        },
        {
          "type": "User",
          "login": "stevebeattie",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/1686002?v=4"
        },
        {
          "type": "User",
          "login": "iainlane",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/321014?v=4"
        },
        {
          "type": "User",
          "login": "toabctl",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/276317?v=4"
        }
      ],
      "contributors_sampled": 7,
      "top_contributor_share": 0.31
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "actionlint.yaml",
        "build.yaml",
        "codeql.yaml",
        "go-tests.yaml",
        "release.yaml",
        "verify.yaml",
        "zizmor.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "composer.lock",
        "go.sum",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "3 out of the last 3 releases have a total of 3 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "152 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "e74d9117492fe4b08630f52c03398a8f5bdf690c",
        "ran_at": "2026-07-28T03:30:54Z",
        "aggregate_score": 8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T00:21:36Z",
      "oldest_open_prs": [
        {
          "number": 151,
          "created_at": "2026-07-07T16:03:50Z",
          "last_comment_at": "2026-07-22T15:36:22Z",
          "last_comment_author": "kbsteere"
        },
        {
          "number": 165,
          "created_at": "2026-07-23T14:25:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 167,
          "created_at": "2026-07-23T14:25:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 169,
          "created_at": "2026-07-23T14:27:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-24T08:14:00Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 112,
          "created_at": "2026-06-11T08:51:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 118,
          "created_at": "2026-06-16T07:33:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 134,
          "created_at": "2026-06-28T15:02:23Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/chainguard-dev/omnibump",
    "host": "github.com",
    "name": "omnibump",
    "owner": "chainguard-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 73,
      "inputs": {
        "security": 84,
        "vitality": 88,
        "community": 38,
        "governance": 71,
        "engineering": 80
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 88,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 133,
              "human_commit_share": 0.67,
              "days_since_last_push": 1,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "133 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 133
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 42,
              "latest_release_tag": "v0.23.1",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 3.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "42 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 42
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "3 out of the last 3 releases have a total of 3 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 38,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 27,
            "inputs": {
              "forks": 10,
              "stars": 13,
              "watchers": 3,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "13 stars",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 13
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "10 forks",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "3 watchers",
                "points": 1.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 71,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 7,
              "top_contributor_share": 0.31
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 31% of commits",
                "points": 15.5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 31
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "7 contributors",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "merged_prs": 129,
              "open_issues": 3,
              "closed_issues": 2,
              "issue_closed_ratio": 0.4,
              "closed_unmerged_prs": 31
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "40% of issues closed",
                "points": 18.7,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 40
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "129/160 decided PRs merged",
                "points": 30.8,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 129,
                      "decided": 160
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "followers": 844,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "chainguard-dev",
              "public_repos": 116,
              "account_age_days": 1839
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "844 followers of chainguard-dev",
                "points": 21,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 844,
                      "login": "chainguard-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "116 public repos, account ~5 yr old",
                "points": 23.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 116
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/chainguard-dev/omnibump"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "51 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 51
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 80,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "7 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "cargo",
                "go",
                "gradle",
                "maven"
              ],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 84,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "3 out of the last 3 releases have a total of 3 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "152 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 50 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 50
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 50,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 50,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 12
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 79,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "67 of 67 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 67,
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "composer.lock",
                "go.sum",
                "uv.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.19,
              "toolchain_manifests": [
                "go.mod",
                "pkg/languages/golang/testdata/aws-efs-csi-driver/go.mod",
                "pkg/languages/golang/testdata/bye/go.mod",
                "pkg/languages/golang/testdata/confd/go.mod",
                "pkg/languages/golang/testdata/hello/go.mod",
                "pkg/languages/golang/testdata/kubernetes-csi-external-attacher/go.mod",
                "pkg/languages/golang/testdata/tidy-compat/go.mod",
                "pkg/languages/java/gradle/testdata/elasticsearch-style/build.gradle",
                "pkg/languages/java/gradle/testdata/elasticsearch-typed-vars-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafbat-rule-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafka-deps-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kafka-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kayenta-style/build.gradle",
                "pkg/languages/java/gradle/testdata/kotlin-val-collision/app/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/kotlin-val-collision/lib/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/opensearch-style/build.gradle",
                "pkg/languages/java/gradle/testdata/opensearch-style/qa/build.gradle",
                "pkg/languages/java/gradle/testdata/simple-kotlin/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/sonarqube-style/build.gradle",
                "pkg/languages/java/gradle/testdata/spring-boot-real/build.gradle",
                "pkg/languages/java/gradle/testdata/spring-boot-style/build.gradle.kts",
                "pkg/languages/java/gradle/testdata/strictly-style/build.gradle.kts",
                "testdata/maven-simple/pom.xml"
              ],
              "dependency_bot_commit_share": 0.33
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "19 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 19,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "33 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 33,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 88710,
              "source_files_sampled": 157,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/157 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 157,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T03:31:20.595249Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/chainguard-dev/omnibump.svg",
  "full_name": "chainguard-dev/omnibump",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.