公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-30 17:50 UTC

fivetwenty-io / proxmox-apiclient-go

Proxmox PVE API Client for Go

Go未检测到许可证★ 0 星标⑂ 0 复刻始于 2025年8月在 GitHub 上查看 ↗

fivetwenty-io/proxmox-apiclient-go 的健康指数为 100 分中的 53 分,处于「中等」区间。 其得分最高的类别是Engineering Quality(74/100),最低的是Community & Adoption(22/100)。 最近一次更新在 10 天前。 近期的大部分工作由 1 位贡献者完成。

53
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

53
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

2 关注者23 个公开仓库始于 2023年1月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/fivetwenty-io/proxmox-apiclient-go/v3v3.8.2-2910 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

73良好 · 占总体的 22%
评分方式
28.8/36推送新近度 — 最近一次推送于 10 天前
7.6/36提交节奏 — 52 周中有 11 周有提交
16.5/18提交量 — 最近一年 67 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year67
human_commit_share1
days_since_last_push10
active_weeks_last_year11

发布纪律

88优秀
评分方式
16.2/27有发布版本 — 29 个版本标签(无 GitHub 发布版本)
36/36发布时效 — 最近一次发布版本于 10 天前
27/27发布节奏 — 约每 3.1 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count29
latest_release_tagv3.8.2
releases_from_tags
days_since_latest_release10
mean_days_between_releases3.1
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

22危急 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

45存在风险
评分方式
22.5/22.5README
0/22.5许可证 — 未检测到许可证文件
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

39存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 5 contributing companies or organizations
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
0/38.3PR 接受 — 已裁定的 PR 中 0/4 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs4
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
3.4/25所有者影响力 — fivetwenty-io 有 2 位关注者
17.1/25既往记录 — 23 个公开仓库,账户约 3 年
所用输入
followers2
owner_typeOrganization
is_verified
owner_loginfivetwenty-io
public_repos23
account_age_days1,288
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 10 天前
20/20版本历史 — 29 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/fivetwenty-io/proxmox-apiclient-go/v3
ecosystemsgo
any_deprecated
min_days_since_publish10

工程质量

基础的工程与文档实践是否到位?

74良好 · 占总体的 20%

工程实践

80良好
评分方式
24/24CI 工作流 — 3 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yml
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

65中等
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

58中等 · 占总体的 16%

安全态势

58中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
0/2.5许可证 — license file not detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
5/5SAST — SAST tool detected: CodeQL
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate5.8
已排除计分(无数据或不适用):ci_tests, packaging, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

63中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 67 次人类提交中有 61 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.91
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yml
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 67 次提交中没有代理编写的提交
5/8自动化维护 — 已配置依赖自动化,但在抽样提交中未观察到
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
50.4/55可控的文件大小 — 采样的 192 个源文件中有 16 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes804,668
source_files_sampled192
oversized_source_files16

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

0GitHub 星标
1贡献者
67最近 12 个月提交数
10距最近推送天数
29发布版本数
1巴士系数(bus factor)
0开放议题
Go软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 5.8 / 10
5.8综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-30 17:50 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
0Licenselicense file not detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
10SASTSAST tool detected: CodeQL
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
直接依赖 3
注册表软件包版本约束清单文件
Gogithub.com/gorilla/websocketv1.5.3go.mod
Gogo.uber.org/zapv1.27.0go.mod
Gogolang.org/x/termv0.34.0go.mod
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 6644,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "Go": 1241298,
        "Makefile": 12296
      },
      "pushed_at": "2026-07-20T12:55:26Z",
      "created_at": "2025-08-20T03:16:13Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T12:56:44Z",
      "description": "Proxmox PVE API Client for Go",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": null,
      "default_branch": "main",
      "license_spdx_raw": null,
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://fivetwenty.io",
      "name": "FiveTwenty Inc.",
      "type": "Organization",
      "login": "fivetwenty-io",
      "company": null,
      "location": "United States of America",
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/123042834?v=4",
      "created_at": "2023-01-19T02:24:31Z",
      "is_verified": null,
      "public_repos": 23,
      "account_age_days": 1288
    },
    "license": {
      "state": "absent",
      "spdx_id": null,
      "raw_spdx": null,
      "file_present": false,
      "scorecard_found": false,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v3.8.2",
          "kind": "patch",
          "published_at": "2026-07-20T12:55:18Z"
        },
        {
          "tag": "v3.8.1",
          "kind": "patch",
          "published_at": "2026-07-10T01:20:45Z"
        },
        {
          "tag": "v3.8.0",
          "kind": "minor",
          "published_at": "2026-07-09T18:47:49Z"
        },
        {
          "tag": "v3.7.0",
          "kind": "minor",
          "published_at": "2026-07-09T12:26:16Z"
        },
        {
          "tag": "v3.6.0",
          "kind": "minor",
          "published_at": "2026-07-08T21:20:42Z"
        },
        {
          "tag": "v3.5.0",
          "kind": "minor",
          "published_at": "2026-07-07T23:18:02Z"
        },
        {
          "tag": "v3.4.0",
          "kind": "minor",
          "published_at": "2026-07-07T17:57:45Z"
        },
        {
          "tag": "v3.3.1",
          "kind": "patch",
          "published_at": "2026-07-04T09:58:05Z"
        },
        {
          "tag": "v3.3.0",
          "kind": "minor",
          "published_at": "2026-07-04T01:21:14Z"
        },
        {
          "tag": "v3.2.10",
          "kind": "patch",
          "published_at": "2026-06-22T16:30:41Z"
        },
        {
          "tag": "v3.2.9",
          "kind": "patch",
          "published_at": "2026-06-22T15:55:13Z"
        },
        {
          "tag": "v3.2.8",
          "kind": "patch",
          "published_at": "2026-06-22T12:57:50Z"
        },
        {
          "tag": "v3.2.7",
          "kind": "patch",
          "published_at": "2026-06-04T21:49:28Z"
        },
        {
          "tag": "v3.2.6",
          "kind": "patch",
          "published_at": "2026-06-04T19:31:09Z"
        },
        {
          "tag": "v3.2.5",
          "kind": "patch",
          "published_at": "2026-06-03T20:04:55Z"
        },
        {
          "tag": "v3.2.4",
          "kind": "patch",
          "published_at": "2026-06-03T13:41:49Z"
        },
        {
          "tag": "v3.2.3",
          "kind": "patch",
          "published_at": "2026-06-02T13:28:04Z"
        },
        {
          "tag": "v3.2.2",
          "kind": "patch",
          "published_at": "2026-06-02T12:56:09Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2026-06-02T03:27:02Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-06-02T02:26:05Z"
        },
        {
          "tag": "v3.1.7",
          "kind": "patch",
          "published_at": "2026-05-21T14:01:34Z"
        },
        {
          "tag": "v3.1.6",
          "kind": "patch",
          "published_at": "2026-05-20T19:25:31Z"
        },
        {
          "tag": "v3.1.5",
          "kind": "patch",
          "published_at": "2026-05-19T22:31:28Z"
        },
        {
          "tag": "v3.1.4",
          "kind": "patch",
          "published_at": "2026-05-19T21:21:32Z"
        },
        {
          "tag": "v3.1.3",
          "kind": "patch",
          "published_at": "2026-05-19T20:30:12Z"
        },
        {
          "tag": "v3.1.2",
          "kind": "patch",
          "published_at": "2026-05-19T13:37:39Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2026-05-19T13:20:01Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-05-18T18:28:44Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2025-11-19T20:20:55Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "0f40c15f70a2f02e769200b257036e0d32f2a894",
          "body": "A failed DNS lookup or a failed TCP dial means the request never reached\nthe server, so retrying can only reproduce the same failure at the same\ncost. An unreachable host was dialed four times, which turned a host that\nsilently drops SYNs into a multi-minute wait before any error surfaced.\n\nClassify\n[…]\ne makes the outermost layer, so\nit counted the whole retry loop as a single call and asserted nothing.\nMove it inside retryMiddleware and drive it with a post-connect error so\nit tests what it claims.",
          "is_bot": false,
          "headline": "fix(http): stop retrying failures to establish a connection",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-20T12:55:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4696c1505be53dd9a6fbaa90fb125ca6f6067358",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog for v3.8.1",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-10T01:20:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d46e3b2f326b5175b018ae771302970607ed9624",
          "body": "The Rust-based products (Proxmox Backup Server, Proxmox Datacenter\nManager) parse the API token Authorization value as TOKENID:TOKENSECRET\n(proxmox-auth-api splits on ':'), while PVE's Perl parser expects\nTOKENID=SECRET. GetHeaders emitted the '=' form unconditionally, so\ntoken authentication agains\n[…]\nAPIToken.\n\nAdd end-to-end Authorization header assertions for PVE, PBS, and PDM\nclients against real HTTP test servers, tightening the existing PBS/PDM\nprefix-only checks to pin the full header value.",
          "is_bot": false,
          "headline": "fix(auth): use colon token secret separator for PBS and PDM API tokens",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-10T01:15:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a50cd0a34434ae6c4b0b62b49e2d8f1b4dd78b52",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog for v3.8.0",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T18:47:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "329f84595de25842bee2af4b5b48ff7a4b134008",
          "body": "…HTTP\n\nGenerated methods whose isResponseEmptyOk is true (array/aliased-\nRawMessage returns, e.g. access.ListAcl) fall back to a zero-value\nresponse when resp.Data is nil; methods with a populated required\nobject return schema (e.g. access.GetUsersToken) instead return an\nerror. The generated smoke tests always send a non-nil \"data\" value,\nso neither branch was previously exercised at runtime. Cover both over\na real HTTP round trip: null data, no \"data\" key at all, and the\nstrict error path.",
          "is_bot": false,
          "headline": "test: exercise the nil-data tolerant and strict decode branches over …",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T18:41:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0821dafe97a071afac2243660ee6586c757a4ff4",
          "body": "…hema\n\nThe pdm-apidoc.json entry for GET /pve/remotes/{remote}/updates declares\n\"returns\": {\"type\": \"null\"} because the PDM Rust handler's #[api(...)]\nmacro omits its \"returns:\" key, even though the handler returns real\ndata. Transcribe the schema from pdm-api-types' RemoteUpdateSummary\n(nodes, remote-type, status, optional status-message) so the generated\nresponse is a typed struct instead of an aliased []json.RawMessage, and\nso a real object-shaped body decodes correctly.",
          "is_bot": false,
          "headline": "fix(pdm): type the pve remote updates response from the PDM source sc…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T18:38:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7bfac3cfeb7222fa175e3cb2252d5651076d7e75",
          "body": null,
          "is_bot": false,
          "headline": "docs: changelog for v3.7.0",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T12:26:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a7dac8a5d66fd6c2a2f73fb21b4adae99c4daff",
          "body": "Matches the generated smoke test's package convention and avoids\ninline error handling in the hand-written LXC/QEMU regression test.",
          "is_bot": false,
          "headline": "test(pdm): move sparse config round-trip test to the pve_test package",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T12:11:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6a2393c8a39d65eba333792d36262fb3e8d82bd",
          "body": "…emas\n\nThe PDM apidoc enumerates every possible slot for numbered-slot guest\nconfig families (dev0..dev255, mp0..mp255, net0..net31, unused,\nipconfig, scsi, virtio, hostpci, usb, virtiofs, sata, serial, parallel)\nwithout ever marking the unused ones \"optional\", so RETURNS schema\nstructs generated no\n[…]\nes keeps\nsingle word+digits names like \"sha256\" or \"smbios1\" out of the\nheuristic, and requiring a zero suffix excludes small fixed pairs like\nAD/LDAP's \"server1\"/\"server2\" that are not slot families.",
          "is_bot": false,
          "headline": "fix(pvegen): treat numbered slot properties as optional in return sch…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T12:09:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1ee1ac174e7b12e12b40dadb12b330ed7a89acd3",
          "body": "Generated POST/PUT methods built their form body by marshaling the whole\nparams struct to JSON and re-decoding it into a map[string]interface{}.\nThat round-trip destroyed json.RawMessage fields: an object-valued field\ndecoded into a Go map and was then serialized as a Proxmox\ncomma-joined \"k=v,k=v\" \n[…]\nginal typed param via\njson.Marshal (which compacts the RawMessage's JSON text) and replaces\nthe map entry with that string. Scalar params, []string params, and\nmap-valued Raw API params are untouched.",
          "is_bot": false,
          "headline": "fix(http): send json.RawMessage params as JSON text form values",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T11:54:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eeba90c28ae6356c29c1401340c0677b84437ce8",
          "body": "Populate the pdm dialect's returnsOverrides table for the PDM\nremote-proxy and listing endpoints whose vendored pdm-apidoc.json\nentry declares \"returns\": {\"type\": \"null\"} even though every one of\nthem returns real data: node/journal listing, the auto-install\nprepared-answer lookup, the PVE/PBS remot\n[…]\n\"value\" field optional so it\ngenerates as *string, matching the documented \"only present when\nregenerate=true\" contract.\n\nRegenerated pkg/pdm/{access,autoinstall,nodes,pbs,pve} from the\nupdated table.",
          "is_bot": false,
          "headline": "fix(pdm): correct return schemas for data-bearing and mistyped endpoints",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T11:37:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca1c513e32bf89506ec283b0ef21b093fc2bc290",
          "body": "Add a returnsOverrides map[string]*schema to dialectConfig, keyed\n\"VERB /path\" like the existing methodNameOverrides table, and consult\nit in collectEndpoints right after the endpoint's info is read from\nthe tree. This is the single choke point every downstream consumer\n(responseGoType, renderObject\n[…]\nly returns a value\nwhen regenerate=true) legitimately return no data, and the generator\nwas previously always treating a populated object schema as strict,\nproducing a hard error on a successful call.",
          "is_bot": false,
          "headline": "feat(pvegen): support per-endpoint returns-schema overrides",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-09T11:36:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb3b0ee19be80eca9b2569c6ad6afb582e0f1ae1",
          "body": "Pulls in the crypto/tls fix for GO-2026-5856; govulncheck is clean\nagainst the 1.26.5 standard library.",
          "is_bot": false,
          "headline": "chore: require Go 1.26.5 toolchain",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:20:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df45d73a0c1ddfc4284b0c3f2ca6eb4c2932ce5f",
          "body": "Hoist the \"GET /version\" methodNameOverrides key shared by the pve,\npbs, and pdm dialects into overrideGetVersion, alongside the existing\nmethodPrefixGet/namespaceVersion/namespaceRoot constants.",
          "is_bot": false,
          "headline": "refactor(pvegen): name the GET /version override key constant",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:15:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dc43938437200e770b2bc5e7d2151ef6e9c4df9",
          "body": "Match _data/README.md's terminology for the 327 PDM bindings\n(\"method-operations\") instead of \"endpoints\" in the README's PDM\nsection and the CHANGELOG v3.6.0 entry.",
          "is_bot": false,
          "headline": "docs: use method-operations terminology for the PDM binding count",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:11:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9da4fa663a03c225861bc34886bd8f000c75159b",
          "body": "Include pkg/pdm in verify-generated's drift check and diff output\nalongside pkg/api and pkg/pbs, and add the generated pkg/pdm\nsubdirectories to GOSEC_EXCLUDE_DIRS to match the existing pkg/api\nand pkg/pbs entries. Update the pkgImportRoot doc comment in\ncmd/pvegen/main.go to mention pkg/pdm.",
          "is_bot": false,
          "headline": "chore: extend generate and security gates to pkg/pdm",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:11:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76b73dff4a705d3b965bb199638d7d3b4d7a2194",
          "body": null,
          "is_bot": false,
          "headline": "docs: document pkg/pdm bindings and backfill the v3.5.0 changelog entry",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T21:02:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90795709c8a090a292e0327dde45ab2ee4123f2d",
          "body": "…IToken, PDMAuthCookie)",
          "is_bot": false,
          "headline": "feat(pdm): add client preset with PDM wire defaults (port 8443, PDMAP…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T20:58:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "357f700f283f2ce4b0f324ce921a48a0400cb868",
          "body": "…g/pdm",
          "is_bot": false,
          "headline": "feat(pdm): add generated Proxmox Datacenter Manager bindings under pk…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T20:54:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7bc1af9beb813e24f4317de0ce6de8b5c317d41",
          "body": null,
          "is_bot": false,
          "headline": "feat(pdm): vendor Proxmox Datacenter Manager 1.1.6 API specification",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-08T20:49:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26d04713d0104cbdac364cbd7a974ddcb2569a16",
          "body": "PVE renders documented integers inconsistently: a value documented as an\ninteger may arrive as a JSON number or as a string (the firewall rule\nposition on /cluster/firewall/groups/{group}/{pos} is a concrete case).\nPlain int64 response fields fail to decode such payloads.\n\nMirror the existing PVEBoo\n[…]\ntring, null) that marshals\nback out as a native JSON number, and retype generated response integer\nfields via responseIntType in pvegen. Request params keep plain int64 so\nquery encoding is unchanged.",
          "is_bot": false,
          "headline": "Add tolerant client.PVEInt for response integer fields",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-07T23:18:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1842fbc53b5fbc209fd903766b3d04ea8fb29510",
          "body": "Add typed bindings for the PBS JSON API (346 endpoints across access,\nadmin, config, nodes, tape, status, version, ping, pull, and push),\ngenerated from the vendored _data/pbs-apidoc.json. The HTTP/2\nchunk-protocol endpoints (/backup, /reader) and the GET / directory\nindex are excluded.\n\ncmd/pvegen \n[…]\ntrip asserting the PBSAPIToken Authorization header.\n\nverify-generated and the gosec/golangci generated-code exclusions now\ncover pkg/pbs; README, _data/README, and CHANGELOG document the new\nsurface.",
          "is_bot": false,
          "headline": "feat(pbs): add generated Proxmox Backup Server bindings under pkg/pbs",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-07T17:57:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "182ad66cb142a01a0c48c88795f8709f78c8772f",
          "body": "The library is growing Proxmox Backup Server support alongside PVE, so\nthe module moves from fivetwenty-io/pve-apiclient-go/v3 to\nfivetwenty-io/proxmox-apiclient-go/v3. No Go API changes.\n\n- Rewrite module path in go.mod, all imports, and pvegen output\n- Update User-Agent to proxmox-apiclient-go/1.0\n[…]\ng/proxmox-apiclient-go/\n  with automatic fallback to the legacy pve-apiclient-go location\n- Fix goreleaser release target owner (proxmox -> fivetwenty-io)\n- Document the path migration in MIGRATION.md",
          "is_bot": false,
          "headline": "Rename module to proxmox-apiclient-go",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-07T17:06:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f3e97d7186667da8e9cd00e966f9767db14608e",
          "body": null,
          "is_bot": false,
          "headline": "Bump golang.org/x/sys to v0.44.0",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T09:58:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad7e756619590192f37c6ceb2a337bb8de99bf11",
          "body": "Add a README section explaining the relationship between the generated\npkg/api bindings, the hand-written convenience packages, and the\nclient/transport layers. Replace inaccurate or missing package doc\ncomments on qemu, lxc, network, storage, tasks, cloudinit, pool, batch,\nand compatibility with descriptions of what each package actually does.",
          "is_bot": false,
          "headline": "Document package layering and correct package doc comments",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "632d3cd91e913da415b811529bd35f27b17b96f0",
          "body": "Brings lxc in line with the other typed API packages, which all expose\nan interface plus constructor for mockability.",
          "is_bot": false,
          "headline": "Add Service interface and NewService constructor to lxc package",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab24bf4d461e74677084077a070b8c871fc03ad1",
          "body": "…ardening\n\nSetTimeout and SetKeepAlive on the public client now reach the\nunderlying HTTP transport instead of being silently dropped, CSRF\ntokens are propagated on ticket-authenticated write requests, and\nAPITokenName/CSRFToken accessors are exposed. Retries apply random\njitter to backoff delays to\n[…]\ncannot bypass\ncertificate verification. Cached HTTP responses report exact sizes to\nthe cache via CacheSize. New options cover manual fingerprint\nverification callbacks and the fingerprint cache path.",
          "is_bot": false,
          "headline": "Wire client options through the transport; add retry jitter and TLS h…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7583a97cf69078d38d6b8da8549e4b760f6463c",
          "body": "Manual verification was a stub that always rejected. Unknown\nfingerprints can now be routed to a caller-supplied callback carrying\nhost, port, and certificate details, and accepted fingerprints are\ntrusted for the session. The trust-on-first-use fingerprint cache is\nnow actually loaded and saved (NewVerifierWithCache), with writes\nperformed under the verifier lock.",
          "is_bot": false,
          "headline": "Implement manual fingerprint verification and persist the TOFU cache",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e4306ba8a484ab6f1903b4aa77e3ce8fbe504ab",
          "body": "…ntries\n\nSize accounting marshaled every value to JSON on Set, costing CPU and\ninflating byte payloads ~33% via base64, which skewed evictions. Sizes\nare now computed type-aware, and values may implement the new Sizer\ninterface (CacheSize() int64) to report exact sizes. Corrupt list\nelements no longer panic eviction paths; they are removed and counted\nin CacheStats.Corrupted.",
          "is_bot": false,
          "headline": "Estimate cache entry sizes without JSON marshaling; survive corrupt e…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:21:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8aef3b16e621545685531450830ea97b3861129d",
          "body": "Read previously discarded any decoded data that did not fit the caller's\nbuffer, silently corrupting streams read with small buffers. The\nremainder is now buffered and returned by subsequent reads. Add package\ndocumentation describing the streaming model.",
          "is_bot": false,
          "headline": "Buffer unread remainder in stream Reader to honor io.Reader contract",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a7acd23ef7c87f38d1f11557b8e51a41e8b278d",
          "body": "Set read/write deadlines before the handshake rather than after, so a\nstalled server cannot hang Connect indefinitely. Message handlers are\ntracked by entry so RemoveHandler removes the exact handler registered\ninstead of matching by function pointer. Handler dispatch is bounded by\na semaphore (Config.MaxConcurrentHandlers) so a slow handler cannot\nspawn unbounded goroutines, and read deadlines are refreshed per frame.",
          "is_bot": false,
          "headline": "Fix websocket handshake deadlines, handler removal, and dispatch bounds",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa56e3e69e8c7c1694b45573ed73bf6ff2a72b6b",
          "body": "Login, TFA submission, and logout previously trusted any response body\nregardless of status code. Each now verifies a 2xx status before\ndecoding, and response bodies are read through a 4096-byte bounded\nreader so a misbehaving server cannot exhaust memory.\n\nNewTicketAuthenticatorFromTicket parses th\n[…]\n to anchor renewal timing, falling back to the current time\nwhen unparsable. Password prompts read through an injectable descriptor\nso non-terminal input falls back to line reading instead of failing.",
          "is_bot": false,
          "headline": "Gate auth flows on HTTP status and bound response body reads",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "390b0634539f08e52a8924ce49c1b8aa0b704f15",
          "body": "Replace the outcome-agnostic generated smoke tests with behavioral ones:\neach endpoint subtest now runs against a mock server and asserts the HTTP\nmethod, encoded path and parameters, response decoding, API error\npropagation, and the nil-context guard (via a typed nil variable so\nstaticcheck SA1012 \n[…]\ntor gains testgen.go plus unit tests for name sanitization,\npath expression building, and sample-value selection. Anchor the pvegen\nignore pattern to the repo root so cmd/pvegen sources are trackable.",
          "is_bot": false,
          "headline": "Generate behavioral smoke tests for API bindings",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-07-04T01:20:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bb75f4b8ec4ee27bddb9c18312a6d8da80e0804",
          "body": "The internal HTTPClient interface and internalHTTPAdapter already carry\nSetHeader/RemoveHeader, but they were never surfaced on the public Client.\nAdd them to the Client interface and forward from *client to httpClient so\ncallers can set a custom User-Agent (or other headers) at construction time\nwithout reaching into internal packages.",
          "is_bot": false,
          "headline": "Expose SetHeader/RemoveHeader on the public Client interface",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-22T16:30:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a531754dc900db86028e8113e374aa2e093f75dd",
          "body": "Release v3.2.9.\n\nAdded:\n- Client.Close()/HTTPClient.Close() release the cache cleanup goroutine\n  and close idle connections; idempotent.\n\nFixed:\n- Cache no longer panics on a second Close() (close-once).\n- Stream no longer leaks a per-stream goroutine; removed an inert metrics\n  collector that prod\n[…]\nr-focused tests plus a\n  regression test per fix above.\n- Tightened lint config (varnamelen short-name allowances, recvcheck\n  exclusion for the Marshal/Unmarshal pair) and fixed substantive findings.",
          "is_bot": false,
          "headline": "Add Close(), fix cache/stream/pool/auth/batch bugs, lift coverage",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-22T15:55:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac2043c90d29cd0b63ce4b30f63c76b896eac667",
          "body": "…ation\n\nRequest params were marshaled to JSON and decoded into map[string]interface{}\nwith a plain json.Unmarshal, turning every number into float64. The form\nencoder's fallback (fmt.Sprintf(\"%v\", float64)) then rendered any value >= 1e6\nin scientific notation (e.g. bwlimit=1048576 -> \"1.048576e+06\"\n[…]\ner and keep their exact digits. Add json.Number, float64,\nand float32 cases to the form encoder that emit plain decimal, which also\nhardens any body map decoded without UseNumber. Regenerate bindings.",
          "is_bot": false,
          "headline": "fix(http): encode large integer params in decimal, not scientific not…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-22T12:57:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8dea091cda036e195cb4a34100c7a3cee8782d8c",
          "body": null,
          "is_bot": false,
          "headline": "Bump Go version to 1.26.4",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-08T19:48:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "740e6bd526c9ade394d00e34c0e34f5dc7c8f571",
          "body": "…ort knobs\n\ntasks.Service gains GetStatus(ctx, node, upid) for single-shot status reads\nwithout polling, enabling callers to drive progress-aware adaptive intervals.\nStatus struct gains Progress float64 (range [0,1]) populated by parseProgress\nwhich tolerates float64/int/int64 JSON variants from PVE\n[…]\nec. createHTTPTransport applies each when non-zero; all-zero\npreserves byte-identical behaviour to the prior transport (KeepAlive fallback,\nLongTimeout idle, no DialContext, no TLS handshake timeout).",
          "is_bot": false,
          "headline": "Add GetStatus/Progress adaptive-poll API and configurable HTTP transp…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-04T21:49:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3598952c263d32846c31e9bd65f6c5c18b7203aa",
          "body": "term.ReadPassword received syscall.Stdin directly, which is an int on\nUnix but a syscall.Handle (uintptr) on Windows, breaking windows/* builds.\nConvert to int explicitly so the call compiles on every GOOS.",
          "is_bot": false,
          "headline": "Fix windows cross-compilation in PromptPassword",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-04T19:31:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "023019cfb5f98c85e690562465443fbe3e9a7dc5",
          "body": "PVE renders documented numbers inconsistently — the pressure-stall (PSI)\nmetrics on container and VM status arrive as JSON strings rather than\nnumbers — which made typed status responses fail to decode real payloads\nwith 'cannot unmarshal string ... into float64'. Add a tolerant PVEFloat\ntype (accep\n[…]\n empty string as 0, marshals as\na native JSON number) and emit it from the generator for response float\nfields; request params keep plain float64. Regenerated bindings retype 24\nresponse float fields.",
          "is_bot": false,
          "headline": "Add tolerant client.PVEFloat for response number fields",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-03T20:04:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b13945e3b63f85db34807c25e1b2e1e40fbdb67",
          "body": "The Proxmox VE API renders booleans inconsistently across endpoints:\nas a JSON boolean, a number (1/0), or a string (\"1\"/\"0\", \"true\"/\"false\",\n\"yes\"/\"no\", \"\"). Typed get-by-id responses with *bool fields (QEMU status\nagent, user enable, role privileges, ...) failed to decode real payloads\nwith \"canno\n[…]\nw emits *client.PVEBool\nfor boolean fields in response structs while request parameter structs keep\nplain bool, so query encoding is unchanged. Regenerated bindings retype 150\nresponse boolean fields.",
          "is_bot": false,
          "headline": "Decode PVE's loosely-typed response booleans",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-03T13:41:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5926c6a8d35683ab00d0da8f8862c60601dae224",
          "body": "Custom headers:\n- Back Client.SetHeader/RemoveHeader with a mutex-guarded header map instead\n  of no-op stubs. Headers are applied to every request via applyCustomHeaders\n  in both the standard and upload request builders, after the default headers\n  (so callers may override User-Agent) and before a\n[…]\ntrics/Timeout/Header/Compression middlewares)\n  that was never wired into the client; the active request pipeline lives in\n  client.go. Drop its tests and the now-unused log import and sentinel error.",
          "is_bot": false,
          "headline": "Implement custom request headers; remove unused middleware framework",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T13:28:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bfb8b514b7251b08c5d104a6c9e1d1712cc915a3",
          "body": "Correctness:\n- compatibility: GetDeprecatedFeatures looked up the feature matrix by display\n  name instead of the map key, so it always returned empty; key it like\n  GetNewFeatures does.\n- qemu: Snapshot copied snapname into the caller's opts map; build a fresh map.\n- tasks: the poller returned a ha\n[…]\nin the streaming benchmark instead of deferring\n  inside the b.N loop.\n- Make the websocket ping test assert pings actually fire.\n- gofmt previously unformatted test files and the zap logging adapter.",
          "is_bot": false,
          "headline": "Quality review and remediation",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T12:56:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0476b159698d1fc0eb5609c059d0800080837677",
          "body": "…ed fixtures\n\nRename short-scoped variables to descriptive names, add t.Parallel to\nparallel-safe tests, defer response-body closes, use two-value type\nassertions, propagate real contexts, and extract repeated literals into\nshared constants across the suite and examples. Behavior of the code under\ntest is unchanged.",
          "is_bot": false,
          "headline": "test: descriptive names, parallel-safe subtests, closed bodies, dedup…",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:27:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae08d8da41af88bb0b95f2dd62d73c3582323011",
          "body": "Wrap errors crossing package boundaries (WebSocket Conn I/O and proxy POST,\nstream close) so failures carry context; promote repeated content-type,\nlog-field, realm, and protocol literals to named constants; convert an\nif/else chain to a switch; and split oversized transport, streaming, and\ndisk-attach helpers into focused sub-functions. No exported API or behavior\nchange.",
          "is_bot": false,
          "headline": "refactor: wrap boundary errors, extract constants, reduce complexity",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:26:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35067be42c7f1a1ccd6313b9a5c06cfaa0f3d5c5",
          "body": "Rename terse locals to descriptive names, extract render helpers to lower\nfunction length and cognitive complexity, introduce named constants and\nsentinel errors, and preallocate where size is known. Verified byte-for-byte\nidentical output via go generate (zero drift in pkg/api/*_gen.go).",
          "is_bot": false,
          "headline": "refactor(pvegen): clarify generator internals; emitted output unchanged",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:26:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f65a143b8bff5e7609cb2513de983ad206d13b1",
          "body": "…domain-inherent rules\n\nMirror a single gosec scope across the Makefile and CI: skip generator-\nemitted bindings (pkg/api/*_gen.go) and rules that are inherent to a\nProxmox API client rather than defects — G117 (request structs marshal\ncredentials), G123 (deliberate certificate pinning), G402 (opt-in\nInsecureSkipVerify), G704 (HTTP to a caller-configured host). Add the\nmatching gosec exclusions to .golangci.yml and migrate gomodguard to\ngomodguard_v2.",
          "is_bot": false,
          "headline": "build: scope gosec and golangci-lint, exclude generated bindings and …",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T03:26:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28aa38dde5f5f995dd175cb40d13a0244d0ee0ae",
          "body": "Regenerate typed bindings from the Proxmox VE 9.2 spec (444 endpoints /\n675 method-operations). Adds cluster-wide QEMU listing, QEMU CPU flags,\ncustom CPU model CRUD, and Nodes().DeleteCephFs, plus optional SDN\nfabric/controller/zone and access-domain parameters. All additive; no\nexported symbol rem\n[…]\nation (NewTicketAuthenticatorFromTicket);\n  propagate UpdateTicket/UpdateCSRFToken to the active authenticator.\n\nRefresh _data/apidoc.json to 9.2 and document the bracket-matched\nextraction procedure.",
          "is_bot": false,
          "headline": "feat: cover PVE 9.2 API surface and harden transport",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-06-02T02:26:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d731027327399700615fc7e95c97ef1d9d9fc558",
          "body": "PVE stores disk values in option-string format: the volid is followed\nby comma-separated options (e.g. \"data:vm-9003-disk-0,size=64G\"). The\nprior exact string match returned (¬\"\", false) for every disk that PVE\nhad decorated with a size or other option, leading callers to treat\nthe disk as not attached and re-attach it at a fresh slot — a\nduplicate that surfaces as ambiguous attachment (\"disk found on N VMs\")\nat the next config scan.\n\nMatch equality first, then the \"<volid>,\" prefix.",
          "is_bot": false,
          "headline": "fix(qemu): FindDiskIDByVolID matches PVE option-string disk values",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-21T14:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ca26039f54efb1a4b3655e56d386cad40ae981a",
          "body": "PVE's DELETE /nodes/{node}/storage/{storage}/content/{volume} queues an\nasynchronous `imgdel` task that runs under the per-storage lockfile.\nDeleteVolume and DeleteVolumeIfExists were throwing away the returned\nUPID, so callers had no way to await completion. When the storage lock\nis contended (e.g.\n[…]\n the\nUPID. Existing methods are kept and now delegate to the async variants\n(discarding the UPID), with doc-comment warnings about the queued-imgdel\nhazard for delete-then-reupload-same-name patterns.",
          "is_bot": false,
          "headline": "fix(storage): expose imgdel UPID for delete-then-upload safety",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-20T19:25:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "819f73328ff31c0be3f5caa5b57653ac53b7c3d9",
          "body": "PVE rejects /nodes/<node>/storage/<storage>/upload with HTTP 400\nwhen \"filename\" appears both in the multipart form fields AND as the\nfile part name. Pass it only as the part name, matching the fix\nalready applied to Storage().Upload.\n\nAffects both Attach (user-data upload) and AttachWithNetwork\n(network-data upload).",
          "is_bot": false,
          "headline": "fix(cloudinit): Attach must not send filename as form field",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T22:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f0335e233a20ea4b22d212d55c7ed344abcfffa",
          "body": "PVE rejects the request with HTTP 400 when the `filename` part name\nappears both as a form-data field and as the multipart file part name.\nThe file part already carries the destination name via its own filename\nattribute; the explicit form field is redundant and breaks the upload.",
          "is_bot": false,
          "headline": "fix(storage): Upload must not send filename as form field",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T21:21:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf43ceb6c9e704774afa987de3217eaaa284a19",
          "body": "Upload sends a file to a PVE storage pool as a given content type and\nreturns the upload UPID. DeleteVolumeIfExists mirrors DeleteVolume but\nreports whether the volume was present, returning (false, nil) on 404\ninstead of silently swallowing it.",
          "is_bot": false,
          "headline": "feat(storage): add Upload + DeleteVolumeIfExists",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T20:30:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "267b2211819dd243f4315004b6b71c0665545b45",
          "body": "PVE's PUT /qemu/{vmid}/config with delete:scsiN does not actually\nremove the disk reference from the VM config — it demotes the disk\nto a new unusedN slot. A subsequent DELETE /qemu/{vmid} then\ndestroys every disk still referenced (unusedN included), silently\nnuking persistent volumes the caller int\n[…]\ns can\ntreat \"detach\" as fully detached and rely on it surviving a later\nVM destroy.\n\nTests cover the two-PUT sweep, the no-op direct unusedN detach,\nand confirm bare volid vs \"volid,options\" matching.",
          "is_bot": false,
          "headline": "fix(qemu): sweep unusedN slot after DetachDisk",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:37:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c63b4ff10824f40b55243f0429acbc32d31653ba",
          "body": "PVE's /nodes/{node}/qemu/{vmid}/resize endpoint accepts PUT, not POST.\nResizeDisk was calling postUPID, which returned HTTP 405 against any\nmodern PVE.\n\nInline a PutCtx call that handles the two response shapes the endpoint\nemits (bare UPID string or object with \"upid\" key) and update the\nexisting httptest mock to expect PUT.",
          "is_bot": false,
          "headline": "fix(qemu): use PUT for /resize endpoint",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:20:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a25233360a1871919f7d664724ec0b391e36a866",
          "body": "POST /nodes/{node}/storage/{storage}/content rejects two of the params\nthe SDK was sending and expects a different shape for size:\n\n  - \"content\" is not in the schema and triggers\n    \"property is not defined in schema\" against any real PVE node.\n  - \"size\" must be a string with optional 'M' or 'G' \n[…]\n\"content\", switch size to \"<n>G\" string form, and only include\nformat when the caller supplied one. Behavior is now compatible with\nthe full storage-type matrix (dir/nfs/cifs/rbd/lvm/lvmthin/zfspool).",
          "is_bot": false,
          "headline": "fix(storage): align CreateVolume params with PVE /content schema",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:19:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99161034b512564df580c517c8e2f43238f00d04",
          "body": "SSLVerifyNone / SSLVerifyPeer / SSLVerifyHost / SSLVerifyFull were\ndeclared in the same const block as ProtocolHTTP / ProtocolHTTPS.\nBecause the protocol constants are explicit string values rather than\ntyped assignments, iota continues incrementing through them — so\nSSLVerifyNone = iota evaluated t\n[…]\nelf-signed PVE clusters failed.\n\nMove the SSL constants into their own const block so iota restarts at\n0. No API change; callers that already used client.SSLVerifyNone now\nget the documented behavior.",
          "is_bot": false,
          "headline": "fix(client): split SSLVerifyMode iota into dedicated const block",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-19T13:19:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b74e6779db32890a4d7bd3a7378e905e3dcf0dac",
          "body": "The form-encoding fix landed in RequestBuilder.AddFormParam\n(internal/http/request.go) but the production hot path used by all\n666 generated bindings goes through buildRequestWithContext, which\nstill serialized params via fmt.Sprintf(\"%v\", value).\n\nEffect on the live wire: booleans serialized as \"tr\n[…]\nptest server and assert the wire\nformat directly, not via the encoder helper.\n\nAlso fixes pkg/stream/stream_test.go:499 (err := redeclaration that\nprevented stream tests from building under newer Go).",
          "is_bot": false,
          "headline": "fix: form-encoding bypass in production request path",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-18T18:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af3a0cf21f71f5f16319978e45f464aa90d8cf7d",
          "body": "Generates typed bindings for all 667 PVE 9.x endpoints, implements 12\nWebSocket/streaming methods, fixes correctness bugs, raises coverage on\npreviously-untested packages, and adds user-facing docs.\n\nGenerated coverage:\n- cmd/pvegen extended from single-namespace emitter to data-driven\n  walk over a\n[…]\nmat, websocket concurrency)\n\nAll 27 packages pass go build, go vet, go test -race -count=1.\nHand-written library coverage 71.8%; generated bindings cover the\nfull 667-endpoint surface via smoke tests.",
          "is_bot": false,
          "headline": "feat: full PVE 9.x coverage, WebSocket support, user docs",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-18T18:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee18e87f892d2460f783882f06e0bffe4577cb87",
          "body": "Bug fixes:\n- APIToken auth header now splits USER@REALM!ID=SECRET via\n  auth.ParseAPIToken instead of doubling the raw string into Token.ID\n  and Token.Secret.\n- TicketAuthenticator gains sync.RWMutex; all ticket-field accesses\n  guarded. 4 race-detector tests at 50–100 goroutines.\n- Form encoding a\n[…]\npoints)\n- Smoke namespace pkg/api/version with typed Service\n- make generate + make verify-generated targets, idempotent\n\nModule path stays at v3. All packages: go build, go vet, go test -race\nexit 0.",
          "is_bot": false,
          "headline": "feat: codegen pipeline, auth fixes, form encoding",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2026-05-18T18:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb7181dea87ff8c587cfa1a6b57d688427fa8169",
          "body": "- Add missing imports (strings, errors) to fix compilation errors\n- Fix errcheck warning in cache.go by explicitly ignoring hash write error\n- Fix variable shadowing in detector_test.go (use = instead of :=)",
          "is_bot": false,
          "headline": "fix: Post-rebase compilation and linting fixes",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-11-19T20:20:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9118a11861a6e2b2a96b835685e7e2a84cc9dae0",
          "body": null,
          "is_bot": false,
          "headline": "Updated functionality based on parity with perl",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-11-19T15:45:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0853239860c51361e9b7222af947775664e6040",
          "body": null,
          "is_bot": false,
          "headline": "Proxmox VE API client library for Go",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-11-19T15:45:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b37a02a84603cff5eeb4756ee4b81f4b593e8a3",
          "body": null,
          "is_bot": false,
          "headline": "golangci-lint passes",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-09-08T16:11:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c79136c9aa79e8a35e5abbf01ec95dfd171ff7d",
          "body": "- Module path is github.com/fivetwenty-io/pve-apicilent-go\n- Update all import statements and references across codebase\n- Update documentation links and examples\n- Update CI/CD configuration files",
          "is_bot": false,
          "headline": "refactor: Module path, documentation",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-08-20T20:01:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a18849ae5d09c4427ebb9c601b6640f42e1858eb",
          "body": "Implements a full-featured Go client library for the Proxmox VE API with:\n- Complete authentication support (tickets, API tokens, TFA)\n- SSL fingerprint verification and certificate caching\n- Connection pooling and batch operations\n- WebSocket support for real-time console access\n- Stream API suppor\n[…]\nmentations demonstrating basic, auth, and advanced usage\n- Extensive test coverage with unit and integration tests\n- CI/CD pipelines with GitHub Actions\n- Documentation for migration and compatibility",
          "is_bot": false,
          "headline": "feat: Add Proxmox VE API client library for Go",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-08-20T03:15:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef4e687dd6fa391ea68b31ef7584c945c8ad5b61",
          "body": null,
          "is_bot": false,
          "headline": "Initial repository.",
          "author_name": "Wayne E. Seguin",
          "author_login": "wayneeseguin",
          "committed_at": "2025-08-18T17:03:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 29,
      "commits_last_year": 67,
      "latest_release_at": "2026-07-20T12:55:18Z",
      "latest_release_tag": "v3.8.2",
      "releases_from_tags": true,
      "days_since_last_push": 10,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 10,
      "mean_days_between_releases": 3.1
    },
    "community": {
      "has_readme": true,
      "has_license": false,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 37,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/fivetwenty-io/proxmox-apiclient-go/v3",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/fivetwenty-io/proxmox-apiclient-go/v3",
          "is_deprecated": false,
          "latest_version": "v3.8.2",
          "repository_url": "https://github.com/fivetwenty-io/proxmox-apiclient-go",
          "versions_count": 29,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T12:55:18Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 10
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 7
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 804668,
      "source_files_sampled": 192,
      "oversized_source_files": 16,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/gorilla/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.3"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.27.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 7,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 4
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "wayneeseguin",
          "commits": 67,
          "avatar_url": "https://avatars.githubusercontent.com/u/18?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 0,
            "reason": "license file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool detected: CodeQL",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "0f40c15f70a2f02e769200b257036e0d32f2a894",
        "ran_at": "2026-07-30T17:50:10Z",
        "aggregate_score": 5.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-20T12:56:26Z",
      "oldest_open_prs": [
        {
          "number": 1,
          "created_at": "2025-08-20T04:48:42Z",
          "last_comment_at": "2025-08-20T04:48:43Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 2,
          "created_at": "2025-08-20T04:49:41Z",
          "last_comment_at": "2025-08-20T04:49:41Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 4,
          "created_at": "2025-08-20T05:35:41Z",
          "last_comment_at": "2025-08-20T05:35:41Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 5,
          "created_at": "2025-08-20T05:35:44Z",
          "last_comment_at": "2025-08-20T05:35:44Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 7,
          "created_at": "2025-10-13T22:31:15Z",
          "last_comment_at": "2025-10-13T22:31:15Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 10,
          "created_at": "2025-12-08T22:24:44Z",
          "last_comment_at": "2025-12-08T22:24:44Z",
          "last_comment_author": "dependabot"
        },
        {
          "number": 11,
          "created_at": "2025-12-08T22:24:47Z",
          "last_comment_at": "2025-12-08T22:24:47Z",
          "last_comment_author": "dependabot"
        }
      ],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/fivetwenty-io/proxmox-apiclient-go",
    "host": "github.com",
    "name": "proxmox-apiclient-go",
    "owner": "fivetwenty-io"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 58,
        "vitality": 73,
        "community": 22,
        "governance": 39,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 73,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "commits_last_year": 67,
              "human_commit_share": 1,
              "days_since_last_push": 10,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 10 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "67 commits in the last year",
                "points": 16.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 67
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 29,
              "latest_release_tag": "v3.8.2",
              "releases_from_tags": true,
              "days_since_latest_release": 10,
              "mean_days_between_releases": 3.1
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "29 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 10 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~3.1 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 3.1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 10,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 10 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 22,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "at_risk",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 45,
            "inputs": {
              "has_readme": true,
              "has_license": false,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "no license file detected",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "license_absent",
                    "params": {}
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 39,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 4
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/4 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 4
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "fivetwenty-io",
              "public_repos": 23,
              "account_age_days": 1288
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of fivetwenty-io",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "fivetwenty-io"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "23 public repos, account ~3 yr old",
                "points": 17.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 23
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 3
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/fivetwenty-io/proxmox-apiclient-go/v3"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 10
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 10 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 10
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "29 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 29
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 58,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 58,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 5.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool detected: CodeQL",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 63,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.91,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "61 of 67 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 61,
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 67",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 67
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 95,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 804668,
              "source_files_sampled": 192,
              "oversized_source_files": 16
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "16/192 source files over 60KB",
                "points": 50.4,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 192,
                      "oversized": 16
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-30T17:50:15.107507Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/f/fivetwenty-io/proxmox-apiclient-go.svg",
  "full_name": "fivetwenty-io/proxmox-apiclient-go",
  "license_state": "absent",
  "license_spdx": null
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.