原始 JSON 报告 机器可读
{
"data": {
"icon": {
"bytes": 6675,
"width": 200,
"height": 200,
"rejected": [],
"collected": true,
"media_type": "image/png",
"source_url": "https://avatars.githubusercontent.com/u/151565802?v=4&s=256",
"source_type": "avatar",
"content_hash": "e11f9840f56122d183881c97480cd882ebe2ca972166d36e21fe578bea05e011",
"candidates_considered": 1
},
"repo": {
"topics": [
"auto-labeling",
"conventional-commits",
"github-actions",
"releases"
],
"is_fork": false,
"size_kb": 305,
"has_wiki": false,
"homepage": null,
"languages": {
"Dockerfile": 255
},
"pushed_at": "2026-07-30T04:26:34Z",
"created_at": "2024-12-22T00:04:05Z",
"owner_type": "Organization",
"updated_at": "2026-07-30T04:26:44Z",
"description": "Centralized Reusable GitHub Actions",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Dockerfile",
"significant_languages": [
"Dockerfile"
]
},
"owner": {
"blog": null,
"name": "GitHub",
"type": "Organization",
"login": "github-community-projects",
"company": null,
"location": null,
"followers": 102,
"avatar_url": "https://avatars.githubusercontent.com/u/151565802?v=4",
"created_at": "2023-11-20T18:08:56Z",
"is_verified": null,
"public_repos": 18,
"account_age_days": 988
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.2.3",
"kind": "patch",
"published_at": "2026-07-29T22:22:52Z"
},
{
"tag": "v1.2.2",
"kind": "patch",
"published_at": "2026-07-08T18:56:43Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2026-06-22T21:23:13Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2026-06-22T21:06:09Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-05-28T00:28:45Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2026-05-11T00:53:07Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2026-05-10T22:56:30Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-05-08T15:56:32Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-03-20T18:14:29Z"
},
{
"tag": "v0.5.8",
"kind": "patch",
"published_at": "2026-03-19T02:28:55Z"
},
{
"tag": "v0.5.7",
"kind": "patch",
"published_at": "2026-03-17T03:44:08Z"
},
{
"tag": "v0.5.6",
"kind": "patch",
"published_at": "2026-03-15T23:00:50Z"
},
{
"tag": "v0.5.5",
"kind": "patch",
"published_at": "2025-12-16T03:46:58Z"
},
{
"tag": "v0.5.4",
"kind": "patch",
"published_at": "2025-09-18T04:47:25Z"
},
{
"tag": "v0.5.3",
"kind": "patch",
"published_at": "2025-08-20T14:01:45Z"
},
{
"tag": "v0.5.2",
"kind": "patch",
"published_at": "2025-08-05T15:10:58Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2025-05-30T14:05:57Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2025-04-07T23:38:46Z"
},
{
"tag": "v0.4.6",
"kind": "patch",
"published_at": "2025-02-20T04:22:57Z"
},
{
"tag": "v0.4.5",
"kind": "patch",
"published_at": "2025-01-25T17:13:31Z"
},
{
"tag": "v0.4.4",
"kind": "patch",
"published_at": "2025-01-25T16:39:00Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2025-01-25T16:14:27Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2025-01-25T09:11:04Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2025-01-25T05:50:49Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2025-01-25T05:32:36Z"
},
{
"tag": "v0.3.6",
"kind": "patch",
"published_at": "2025-01-21T18:53:46Z"
},
{
"tag": "v0.3.5",
"kind": "patch",
"published_at": "2025-01-11T07:19:08Z"
},
{
"tag": "v0.3.4",
"kind": "patch",
"published_at": "2025-01-05T07:44:22Z"
},
{
"tag": "v0.3.3",
"kind": "patch",
"published_at": "2025-01-04T17:40:37Z"
},
{
"tag": "v0.3.2",
"kind": "patch",
"published_at": "2025-01-03T16:02:18Z"
},
{
"tag": "v0.3.1",
"kind": "patch",
"published_at": "2025-01-03T05:18:50Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2025-01-03T05:07:12Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2025-01-03T04:55:01Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2025-01-03T04:41:44Z"
},
{
"tag": "v0.1.2",
"kind": "patch",
"published_at": "2025-01-03T04:16:58Z"
},
{
"tag": "v0.1.1",
"kind": "patch",
"published_at": "2025-01-03T04:07:05Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2025-01-03T03:57:34Z"
}
],
"recent_commits": [
{
"oid": "25891ed12c80c983b2f3b3c335ed8e560d7baea9",
"body": "Bumps the dependencies group with 3 updates: [release-drafter/release-drafter/autolabeler](https://github.com/release-drafter/release-drafter), [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) and [docker/login-action](https://github.com/docker/login-action).\n\n\nU\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 3 updates (#178)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-30T04:26:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "13d124b245cf85ba41d9dd58d6888979043f1a29",
"body": "The auto-author-assign and mark-ready-when-ready workflows trigger on\npull_request, so PRs from forks get a read-only GITHUB_TOKEN and both jobs\nfail (assignees API denied; contents: write denied). Switch both to\npull_request_target, which runs in the base-repo context with a read-write\ntoken even f\n[…]\nhether pull_request_target is acceptable here versus gating the jobs to skip\non fork PRs (which would drop the feature for external contributors instead).\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix(ci): run PR automation via pull_request_target for fork PRs (#169)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-07-29T22:21:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9167ef4833a9f2712399652e0a1f7168a5897463",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump docker/login-action in the dependencies group (#176)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-29T02:49:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d564618b70368ea3e321283503cd7086a1e521a6",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump actions/stale from 10.4.0 to 11.0.0 (#177)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-29T02:48:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29ff622bc9bede4aa4d3ae7f2203b4b394e5f392",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump docker/login-action in the dependencies group (#175)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-25T02:46:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ce7494f4e7469c13ff7b29f65c010003d06b6cd",
"body": "Bumps the dependencies group with 1 update: [docker/login-action](https://github.com/docker/login-action).\n\n\nUpdates `docker/login-action` from 4.4.0 to 4.5.0\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/af1e73f918a0318\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump docker/login-action in the dependencies group (#174)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-24T10:23:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6e342b2069ea1d3245b64478c949cabdaf14220",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump actions/labeler from 6.2.0 to 7.0.0 (#173)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-21T05:33:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f12589199fc0d574eb13366a89c73ed698cd39b8",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 3 updates (#172)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-21T02:51:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea261f1242b9d48164608e461718922a401809cb",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#171)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-17T02:46:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cf25712671a0238b43ec91870a6d60228048d480",
"body": "Bumps the dependencies group with 2 updates: [actions/labeler](https://github.com/actions/labeler) and [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `actions/labeler` from 6.1.0 to 6.2.0\n- [Release notes](https://github.com/actions/labeler/releases)\n- [Commits](https://github.com/acti\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 2 updates (#170)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-11T03:42:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5193129233b450e9174d4d92fcc467919a989882",
"body": "…al (#168)",
"is_bot": false,
"headline": "fix(release): pin checkout ref to base repo to avoid v7 fork-PR refus…",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-07-08T18:55:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d05a9107745320f48d352810644eada6bbe6e1b",
"body": "…up (#166)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.19.4 to 2.20.0\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-08T06:09:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "438f71098c47cda9d7a83895f997e6947cbcd9b9",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump docker/login-action in the dependencies group (#165)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-04T03:06:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "11dd5e835679982ef1f2b2b04256755cc91b4961",
"body": "Bumps the dependencies group with 2 updates: [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [docker/login-action](https://github.com/docker/login-action).\n\n\nUpdates `docker/setup-buildx-action` from 4.1.0 to 4.2.0\n- [Release notes](https://github.com/docker/setup-bui\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 2 updates (#164)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T16:22:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "058dbc6e260e823971cdc8d7b7533b5518ee54a2",
"body": "…(#163)\n\nBumps the dependencies group with 1 update: [docker/build-push-action](https://github.com/docker/build-push-action).\n\n\nUpdates `docker/build-push-action` from 7.2.0 to 7.3.0\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-p\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump docker/build-push-action in the dependencies group …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-02T13:46:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f5f55a6cf269378ff2db64c80f4515a52e4917b",
"body": "…oup (#162)\n\nBumps the dependencies group with 1 update: [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `goreleaser/goreleaser-action` from 7.2.2 to 7.2.3\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://githu\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump goreleaser/goreleaser-action in the dependencies gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-30T03:15:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e04ca4c5ab93b9ab04d33c256bfa1f4ccdfdc80f",
"body": "Bumps the dependencies group with 1 update: [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance).\n\n\nUpdates `actions/attest-build-provenance` from 4.1.0 to 4.1.1\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://gith\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/attest-build-provenance (#161)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-27T03:00:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47b31ad408ed26da05cccde562815d7c1eacf587",
"body": "Bumps the dependencies group with 2 updates: [release-drafter/release-drafter/autolabeler](https://github.com/release-drafter/release-drafter) and [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter/autolabeler` from 7.4.0\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 2 updates (#160)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-26T03:12:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "982bcd8e7cf04eda77f1a65418950ea664a3d525",
"body": "…hub_actions/dependencies-9b7bde0b82\n\nchore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 in the dependencies group",
"is_bot": false,
"headline": "Merge pull request #159 from github-community-projects/dependabot/git…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-06-25T05:27:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c64e60bdd6ba2e5680ee110b3374cbe4de6cd655",
"body": "Bumps the dependencies group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.4.0 to 6.5.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e\n[…]\ngo\n dependency-version: 6.5.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go in the dependencies group",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-25T02:44:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7fc8753b3666b929250bb6241ce4b2d35f316a11",
"body": "…158)\n\n## What/Why\n\nThe old GitHub Actions `contains()` expression was case-insensitive, but\nthe bash replacement introduced in #156 compared labels case-sensitively.\nLowercase labels with `${PR_LABELS,,}` to preserve the original semantics.\n\n## Proof it works\n\nactionlint and shellcheck both pass wi\n[…]\n one-liner fix. AI-assisted (Claude Opus 4.6).\n\n## Review focus\n\nConfirm `${PR_LABELS,,}` (bash 4+ lowercase expansion) works on the\nubuntu-latest runner.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix(release): use case-insensitive label matching in check_release (#…",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-06-22T21:21:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dc84e76ecffde328292b1774abd14e783726f493",
"body": "Bumps alpine from 3.24.0 to 3.24.1.\n\n---\nupdated-dependencies:\n- dependency-name: alpine\n dependency-version: 3.24.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump alpine from 3.24.0 to 3.24.1 (#157)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T21:06:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f7adbde142b474add23fb65218dbb9e0d8e18f1",
"body": "* feat(release): add release-only-with-label input\n\n## What/Why\n\nAdd a `release-only-with-label` boolean input to the release workflow so\nconsumers can restrict release triggers to only the `release` label,\nignoring `breaking`, `feature`, and `vuln` as triggers. Defaults to\n`false` to preserve exist\n[…]\nh label-matching logic in check_release matches the\nprevious GitHub Actions expression semantics.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>\n\n---------\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "feat(release): add release-only-with-label input (#156)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-06-22T21:04:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1af8482927f03f93d0858464a5a3b4471891f18d",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#155)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-19T03:36:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "adb45eec06f1efa6d68fb3e84ea51f2bd16f7ed7",
"body": "…hub_actions/dependencies-24b7a65592\n\nchore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 in the dependencies group",
"is_bot": false,
"headline": "Merge pull request #154 from github-community-projects/dependabot/git…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-06-17T05:16:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ba6090c037408a398e2386637cda2b75afbeb685",
"body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 7.3.1 to 7.4.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n dependency-version: 7.4.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-17T02:44:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "944d6ea41e46d658f24ee69696eae11c69b0845d",
"body": "…oup (#153)\n\nBumps the dependencies group with 1 update: [toshimaru/auto-author-assign](https://github.com/toshimaru/auto-author-assign).\n\n\nUpdates `toshimaru/auto-author-assign` from 3.0.2 to 3.0.3\n- [Release notes](https://github.com/toshimaru/auto-author-assign/releases)\n- [Changelog](https://git\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-16T11:43:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02af89f34ffe961746cf541e4591d2f963ed4c80",
"body": "…oup (#152)\n\nBumps the dependencies group with 1 update: alpine.\n\n\nUpdates `alpine` from 3.23.4 to 3.24.0\n\n---\nupdated-dependencies:\n- dependency-name: alpine\n dependency-version: 3.24.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump alpine from 3.23.4 to 3.24.0 in the dependencies gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-15T21:00:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac95e33e92f631a5c5d4eb102ca1a959c187844d",
"body": "Bumps the dependencies group with 1 update: [mikefarah/yq](https://github.com/mikefarah/yq).\n\n\nUpdates `mikefarah/yq` from 4.53.2 to 4.53.3\n- [Release notes](https://github.com/mikefarah/yq/releases)\n- [Changelog](https://github.com/mikefarah/yq/blob/master/release_notes.txt)\n- [Commits](https://git\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump mikefarah/yq in the dependencies group (#151)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-09T06:54:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "615f069ab92e5489691e2f41735a36f383753bfb",
"body": "Bumps the dependencies group with 1 update: [actions/checkout](https://github.com/actions/checkout).\n\n\nUpdates `actions/checkout` from 6.0.2 to 6.0.3\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout in the dependencies group (#150)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-03T23:12:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "12d9407a7c8903499cbd1dcf91d20bd4faa2eb2e",
"body": "…up (#148)",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-28T04:13:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6d7a83e6fc8275128984b0ed3defa4b8cdc40f85",
"body": "* feat(release): add SBOM-to-archive attestation linkage\n\n## What\n\nAdd a new `attest_sboms` matrix job that runs `actions/attest-sbom` per\n(archive, SBOM) pair after `release_goreleaser` produces artifacts.\nExpose `sbom_matrix` and `is_public` as outputs from `release_goreleaser`,\nupload `dist/` as \n[…]\noff-by: Jason Meridth <jmeridth@gmail.com>\n\n---------\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>\nSigned-off-by: Jason Meridth <jmeridth@gmail.com>\nCo-authored-by: Zack Koppert <zkoppert@github.com>",
"is_bot": false,
"headline": "feat(release): add SBOM-to-archive attestation linkage (#141)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-05-28T00:27:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "50ddb991a26ceb4cc84e344efae73edd78a472eb",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter (#147)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-26T09:53:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf3675aa51a735662ad365889795a7d6b1af1f28",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump alpine from 3.23.3 to 3.23.4 (#146)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-24T22:07:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a6c89b8f8bdf240e7cfa0e2c03313761acb93ff",
"body": "…dates (#145)",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group across 1 directory with 4 up…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-23T21:01:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bacd386ee8af27b7185b4ebbae51bc7172cb9353",
"body": "Bumps the dependencies group with 1 update: [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `actions/stale` from 10.2.0 to 10.3.0\n- [Release notes](https://github.com/actions/stale/releases)\n- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)\n- [Commits](https://githu\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/stale in the dependencies group (#143)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-21T19:18:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0baf7384e0dad7158b50c0e2a9024895147001db",
"body": "Bumps the dependencies group with 2 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner) and [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action).\n\n\nUpdates `step-security/harden-runner` from 2.19.2 to 2.19.3\n- [Release notes](https://gith\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 2 updates (#142)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-19T21:01:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "08173095a682519c9f66a28222ba4534b1821303",
"body": "…up (#140)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.19.1 to 2.19.2\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-18T22:55:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7fa297f22ebc26182bb0af24619d4db53d69eaa",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 3 updates (#139)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-12T09:24:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e92cb6053ace495fe40a5f185988557afcdcecbc",
"body": "… (#138)\n\n* fix(release): create discussion only after publish succeeds\n\n## What\n\nMove the release_discussion job to run after publish_release succeeds instead of in parallel with the build jobs. The publish_release job no longer depends on release_discussion.\n\n## Why\n\nPreviously, the discussion was\n[…]\n` remains `false`, so scope is still optional; this only widens the allowed set when one is used.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>\n\n---------\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix(ci): order discussion after publish + auto-install syft for SBOMs…",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-05-11T00:51:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "592067a69a43d2285f933753d89a7c9d51b96530",
"body": "## What\n\nCollapse the three separate release workflows (release.yaml, release-image.yaml, release-discussion.yaml) into a single release.yaml reusable workflow using a draft-first pattern: create draft, push tags, build artifacts (optional GoReleaser, optional Docker image), create discussion, then \n[…]\nevel if secrets are missing (job-level if: cannot read secrets).\n- publish_release uses -F draft=false (capital F) to send a boolean rather than a string.\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "refactor: consolidate release pipeline with draft-first pattern (#124)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-05-10T22:55:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "84f2a3cc902bb62f5e751f74ea4f03f5628f23b0",
"body": "…hub_actions/dependencies-ce6d608e45\n\nchore(deps): bump release-drafter/release-drafter from 7.2.1 to 7.3.0 in the dependencies group",
"is_bot": false,
"headline": "Merge pull request #137 from github-community-projects/dependabot/git…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-05-09T21:15:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "60e51a56cb66a793a5a50c8008db91516023a13c",
"body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 7.2.1 to 7.3.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n dependency-version: 7.3.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-09T02:42:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "51be22c58e3d4b33b4fbdc1dcf257c481695ce36",
"body": "…fter_breaking\n\nfeat(ci): add Breaking Changes category",
"is_bot": false,
"headline": "Merge pull request #134 from github-community-projects/jm_release_dra…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-05-08T15:56:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "12a913b6a85adf454f5fdea92f9aa9c383342017",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump kenyonj/mark-ready-when-ready (#135)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-08T03:21:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5220699f20641a32c1d969839425904b5cecf90f",
"body": "## What\n\nAdd a new \"💥 Breaking Changes\" category to the release-drafter template, ordered first so it sits above Features. The category collects PRs labeled `breaking`.\n\n## Why\n\nThe `breaking` label already drives a major version bump via version-resolver, but breaking changes were silently bucketed\n[…]\n PR carrying both `breaking` and `feature` labels will appear under Breaking Changes only (release-drafter places each PR in the first matching category).\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "feat(release-drafter): add Breaking Changes category",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-05-07T22:23:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "54923ceee831514b3558d4acefcdfaaf25fe8f62",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump actions/labeler in the dependencies group (#133)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-07T07:11:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "42d143b55b5738da0d146df949b6e2bfcf2535c8",
"body": "…up (#132)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.19.0 to 2.19.1\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-05T09:46:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cb615e677fd3976abafddfbcaad2fa74fe795785",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter (#131)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-30T07:24:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d6b72fc61d52102d4da439085f89361c8e90864",
"body": "…oup (#130)",
"is_bot": true,
"headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-28T10:10:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "54dd5deed5930485bf9ca925a3f81e72d59b7cfe",
"body": "…up (#129)",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-21T02:48:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5badafa2b710edcdc8616819f9ae2a1edb69260",
"body": "…up (#128)",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-16T03:14:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "353391961adcad1270aa655d549fdf57d68a48df",
"body": "…(#127)",
"is_bot": true,
"headline": "chore(deps): bump docker/build-push-action in the dependencies group …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-11T02:43:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ad222460db38d66d512c6f5c51218c0b3d8466d2",
"body": "Bumps the dependencies group with 2 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner) and [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `step-security/harden-runner` from 2.16.1 to 2.17.0\n- [Release notes](https:\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group with 2 updates (#126)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-10T03:44:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "465a8648d16d710aab3e224ea0eb5fca579e6e4b",
"body": "Bumps [kenyonj/mark-ready-when-ready](https://github.com/kenyonj/mark-ready-when-ready) from b6279addd55dd13208965a9eff24b2cf1989a8ef to 0ef6176fc2ddef5bab6cb4ab9517a37f0c153ba4.\n- [Release notes](https://github.com/kenyonj/mark-ready-when-ready/releases)\n- [Commits](https://github.com/kenyonj/mark-\n[…]\n6cb4ab9517a37f0c153ba4\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump kenyonj/mark-ready-when-ready (#125)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-08T02:58:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4f5dcee1eb036b788c9773f863b255cc7da1910b",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump docker/login-action in the dependencies group (#123)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-03T03:10:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3fb884f8eb6fe77f9b59d5fcb6bb3487c918f309",
"body": "…up (#122)",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-01T02:47:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a0cf79bd8756e0a9c1555bf4975eae7ce7a8e8dc",
"body": "…on_updater\n\nfeat: add automatic major version tag update to release workflow",
"is_bot": false,
"headline": "Merge pull request #120 from github-community-projects/jm_major_versi…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-20T18:14:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ce2ae3707aec01dd31e1c98dd565d03b385585c",
"body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "doc: update release doc with new update-major-tag input",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-03-20T03:27:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1e8f0827f6d22df7a230b6de2bce7ed7e0be69c",
"body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix: cleanup of old major-version-updater",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-03-20T03:25:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bc46d499c518406c22e58ac9b61a05c0b654985",
"body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix: persist credentials so username can be found on git push",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-03-20T02:46:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1360e492f68a14c8c3d06569a6c755ef896fc2f2",
"body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix: add claude local settings to gitignore",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-03-20T02:31:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "389119e175b13aa57e1d6f7587086799ba42d53a",
"body": "## What\n\nAdded an `update_major_tag` job to the reusable release workflow that\nforce-updates the major version tag (e.g., `v1`) to point at the latest\nfull semver tag (e.g., `v1.2.3`) after each release. This is controlled\nby a new `update-major-tag` boolean input that defaults to `true`.\n\n## Why\n\nC\n[…]\n.yaml` workflow\n- The calling workflow must have `contents: write` permission for the force-push to succeed (already required by the `create_release` job)\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "feat: add automatic major version tag update to release workflow",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-03-20T02:28:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "469b195f0864a07e52dbf33dd5a145fccf5058c0",
"body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 7.1.0 to 7.1.1\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\nersion-update:semver-patch\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter (#119)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-19T02:50:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d90c7aff008ad7aa4a87b1e23849a5a8691e356",
"body": "… (#117)",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter from 6.4.0 to 7.1.0…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-18T11:39:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed4846f2be1a6bcca82dd1a5f8e8d176fb4e19ea",
"body": "Bumps [kenyonj/mark-ready-when-ready](https://github.com/kenyonj/mark-ready-when-ready) from 33b13c51ba23786efb933701ef253352baf05bdd to b6279addd55dd13208965a9eff24b2cf1989a8ef.\n- [Release notes](https://github.com/kenyonj/mark-ready-when-ready/releases)\n- [Commits](https://github.com/kenyonj/mark-\n[…]\n965a9eff24b2cf1989a8ef\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump kenyonj/mark-ready-when-ready (#114)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-17T04:01:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b4300b59f723a568597c68ec332b1b0174cea7f1",
"body": "…up (#113)\n\nBumps the dependencies group with 1 update: [step-security/harden-runner](https://github.com/step-security/harden-runner).\n\n\nUpdates `step-security/harden-runner` from 2.15.1 to 2.16.0\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.c\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump step-security/harden-runner in the dependencies gro…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-17T03:58:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6381f5d691a1ecf7d80126b0393a803224afd9ba",
"body": "## What\n\nReverted the auto-labeler workflow from the release-drafter v7 autolabeler\nsub-action back to the v6.4.0 main action with disable-releaser: true.\n\n## Why\n\nThe v7 autolabeler sub-action hardcodes a strict check for the pull_request\nevent and rejects pull_request_target. Since this reusable w\n[…]\norkflow; only the autolabeler is pinned to v6\n- Consider opening an upstream issue on release-drafter to support pull_request_target in the v7 autolabeler\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix: revert autolabeler to release-drafter v6.4.0 (#115)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-03-17T03:43:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "30db3296210fe74bc1214e5710f8db5ac6d3a1ad",
"body": "… (#109)\n\n* chore(deps): bump release-drafter/release-drafter from 6.4.0 to 7.0.0\n\nBumps [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) from 6.4.0 to 7.0.0.\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://githu\n[…]\nbot] <support@github.com>\nSigned-off-by: jmeridth <jmeridth@gmail.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: jmeridth <jmeridth@gmail.com>",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter from 6.4.0 to 7.0.0…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-15T23:00:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23927bfee44244f3242122814e8e5ac070dc6670",
"body": null,
"is_bot": false,
"headline": "ci: harden CI runners and pin actions to SHA digests (#110)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-03-14T11:24:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c8d3bdec034700ad7c4d91de7955c087bf94011",
"body": "…when_ready\n\nci: add mark-ready-when-ready workflow",
"is_bot": false,
"headline": "Merge pull request #108 from github-community-projects/jm_mark_ready_…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-13T22:06:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ac5bac210100ae8effcf870ddc75d7caf6e229f",
"body": "## Summary\n\nAdds the [mark-ready-when-ready](https://github.com/kenyonj/mark-ready-when-ready) GitHub Action workflow.\n\nWhen a draft PR has the **Mark Ready When Ready** label applied, this workflow:\n1. Watches for all required checks to pass (two rounds with a pause between)\n2. Verifies results via\n[…]\nA `33b13c5` (includes `contents: write` permission fix)\n- Requires `contents: write` permission for `GITHUB_TOKEN` to call `markPullRequestReadyForReview`\n\nSigned-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "ci: add mark-ready-when-ready workflow",
"author_name": "jmeridth",
"author_login": "jmeridth",
"committed_at": "2026-03-13T21:46:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2c5f863d5f9c249ed39e253e857791d6c6e5bad4",
"body": null,
"is_bot": false,
"headline": "chore: clean up CI config, contributing docs, and PR template (#107)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2026-03-11T07:16:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a0a6feb06180b88c25525cda612f44931ca5dc2",
"body": "Pin alpine base image to alpine:3.23.3 with SHA256 digest to ensure\nreproducible and secure builds, resolving code scanning alert #3.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: pin Docker base image to SHA256 digest (#106)",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-10T19:42:03Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "850f161539b6c770012adc3a703a6ae3d812ae7c",
"body": "…cts (#105)\n\n* build: update references after org transfer to github-community-projects\n\n- Replace all github/ospo-reusable-workflows refs with\n github-community-projects/ospo-reusable-workflows across 10 files\n- Update CODEOWNERS from @github/ospo-github-actions to @zkoppert @jmeridth\n- Fix CONTRI\n[…]\n@gmail.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCo-authored-by: Jason Meridth <jmeridth@gmail.com>\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "build: update references after org transfer to github-community-proje…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-10T19:41:44Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "df5b322d04d2bd507ad44a770744b2357abd2954",
"body": "…ncies-9732075219\n\nchore(deps): bump release-drafter/release-drafter from 6.3.0 to 6.4.0 in the dependencies group",
"is_bot": false,
"headline": "Merge pull request #104 from github/dependabot/github_actions/depende…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-10T04:34:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0459ffd7ebe6ae8e66f1f014363a5e5086e6f8f8",
"body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 6.3.0 to 6.4.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n dependency-version: 6.4.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-10T02:44:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4207841bec4e1e360a791af5f8f90e7ff8fa28dd",
"body": "…ncies-a2c0030222\n\nchore(deps): bump release-drafter/release-drafter from 6.2.0 to 6.3.0 in the dependencies group",
"is_bot": false,
"headline": "Merge pull request #102 from github/dependabot/github_actions/depende…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-07T06:17:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8cd4071ba59fb1d538d5094298ec241fd0975c73",
"body": "Bumps the dependencies group with 1 update: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).\n\n\nUpdates `release-drafter/release-drafter` from 6.2.0 to 6.3.0\n- [Release notes](https://github.com/release-drafter/release-drafter/releases)\n- [Commits](https://github\n[…]\ner\n dependency-version: 6.3.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump release-drafter/release-drafter",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-07T03:42:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f06feadec8e069088ed5298caaca32b23de04bc6",
"body": "…build-push-action-7.0.0\n\nchore(deps): bump docker/build-push-action from 6.19.2 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #100 from github/dependabot/github_actions/docker/…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-06T04:55:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b189cdce3822d90b8ce86e7d7e194932932265ad",
"body": "…setup-buildx-action-4.0.0\n\nchore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0",
"is_bot": false,
"headline": "Merge pull request #101 from github/dependabot/github_actions/docker/…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-06T04:55:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9a1c60d82702d0ee7f8fbee5ab8f512623a60a9",
"body": "Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.12.0 to 4.0.0.\n- [Release notes](https://github.com/docker/setup-buildx-action/releases)\n- [Commits](https://github.com/docker/setup-buildx-action/compare/8d2750c68a42422c14e847fe6c8ac0403b4cbd6f...4d04d5d9486b7\n[…]\ncy-name: docker/setup-buildx-action\n dependency-version: 4.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump docker/setup-buildx-action from 3.12.0 to 4.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-06T03:44:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3465916cecbab84d730364fc2018af804b402759",
"body": "Bumps [docker/build-push-action](https://github.com/docker/build-push-action) from 6.19.2 to 7.0.0.\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-push-action/compare/10e90e3645eae34f1e60eeb005ba3a3d33f178e8...d08e5c354a6adb9ed3448\n[…]\nency-name: docker/build-push-action\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump docker/build-push-action from 6.19.2 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-06T03:44:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "65fc946a71a872575cc356aa0ad44d4064654363",
"body": "…ogin-action-4.0.0\n\nchore(deps): bump docker/login-action from 3.7.0 to 4.0.0",
"is_bot": false,
"headline": "Merge pull request #99 from github/dependabot/github_actions/docker/l…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-03-05T19:01:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d08d18fc2a456c284065ab158d989fb3b0c5164f",
"body": "Bumps [docker/login-action](https://github.com/docker/login-action) from 3.7.0 to 4.0.0.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...b45d80f862d83dbcd57f89517bcf500b2ab88fb2)\n\n[…]\nependency-name: docker/login-action\n dependency-version: 4.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump docker/login-action from 3.7.0 to 4.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-05T03:44:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a53fd45227459b1584ce1cf28b1274dc2cb0a02e",
"body": "…attest-build-provenance-4",
"is_bot": false,
"headline": "Merge pull request #98 from github/dependabot/github_actions/actions/…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-02-26T03:47:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "049d938ca31f362f54afdf303e30ab7e8442cc35",
"body": "Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 3 to 4.\n- [Release notes](https://github.com/actions/attest-build-provenance/releases)\n- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)\n- [Commits](https://github.co\n[…]\nname: actions/attest-build-provenance\n dependency-version: '4'\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/attest-build-provenance from 3 to 4",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-26T03:43:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1787f300d56450330861a36a8dd50efa11971183",
"body": "…cies-ff3cf51067",
"is_bot": false,
"headline": "Merge pull request #97 from github/dependabot/github_actions/dependen…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-02-21T04:22:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1cf1a5043bf8b4b956fef4f473554ff20357ad66",
"body": "…dates\n\nBumps the dependencies group with 2 updates in the / directory: [docker/build-push-action](https://github.com/docker/build-push-action) and [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `docker/build-push-action` from 6.18.0 to 6.19.2\n- [Release notes](https://github.com/docke\n[…]\ne\n dependency-version: 10.2.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group across 1 directory with 2 up…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-17T03:44:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4c74366e5337d8e3518925c227640d92f30f24c8",
"body": "…cies-7ed0a7b455\n\nchore(deps): bump the dependencies group across 1 directory with 2 updates",
"is_bot": false,
"headline": "Merge pull request #95 from github/dependabot/github_actions/dependen…",
"author_name": "Zack Koppert",
"author_login": "zkoppert",
"committed_at": "2026-02-02T19:54:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dd0de19ae95833b9d0b5b777a675a1ab29cd4954",
"body": "…dates\n\nBumps the dependencies group with 2 updates in the / directory: [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) and [docker/login-action](https://github.com/docker/login-action).\n\n\nUpdates `release-drafter/release-drafter` from 6.1.0 to 6.2.0\n- [Release \n[…]\non\n dependency-version: 3.7.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump the dependencies group across 1 directory with 2 up…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-01-29T03:43:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "425eb4597e2ee48576ee11b6a0eb0bf630d7d63d",
"body": "…oup (#93)",
"is_bot": true,
"headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-28T15:46:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "be95309923487509f8df484b932560dac1cf0788",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump toshimaru/auto-author-assign from 2.1.2 to 3.0.0 (#92)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-23T10:20:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7e692137c777843c975004facd93934e37a14c1",
"body": "…p (#91)",
"is_bot": true,
"headline": "chore(deps): bump docker/setup-buildx-action in the dependencies grou…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-20T11:55:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b691dff6b68489c8548e1295d125c93c9c29a4e",
"body": "…oup (#89)",
"is_bot": true,
"headline": "chore(deps): bump toshimaru/auto-author-assign in the dependencies gr…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-16T03:46:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "326810ccf68e02946fa8b51141900ce0fccbd59d",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump actions/stale in the dependencies group (#88)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-04T03:40:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f93c1cab84c95a516e5a836323471c70ae1360a",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 5 to 6 (#87)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-11-24T13:45:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8f81b19525b174210351d8c53b2efe6a316984f8",
"body": "Bumps the dependencies group with 1 update: [actions/stale](https://github.com/actions/stale).\n\n\nUpdates `actions/stale` from 10.0.0 to 10.1.0\n- [Release notes](https://github.com/actions/stale/releases)\n- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)\n- [Commits](https://githu\n[…]\nersion-update:semver-minor\n dependency-group: dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/stale in the dependencies group (#85)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-10-04T02:06:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fbfe59323885c0e09c606d14ec8d49496d838f3a",
"body": null,
"is_bot": true,
"headline": "chore(deps): bump docker/login-action in the dependencies group (#84)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-30T05:45:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "26eec20abba5ae806698592c79628f6906da372c",
"body": "Signed-off-by: jmeridth <jmeridth@gmail.com>",
"is_bot": false,
"headline": "fix: releases when release label by itself without semver label (#81)",
"author_name": "Jason Meridth",
"author_login": "jmeridth",
"committed_at": "2025-09-18T04:47:14Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 37,
"commits_last_year": 113,
"latest_release_at": "2026-07-29T22:22:52Z",
"latest_release_tag": "v1.2.3",
"releases_from_tags": false,
"days_since_last_push": 6,
"active_weeks_last_year": 38,
"days_since_latest_release": 6,
"mean_days_between_releases": 14.8
},
"artifacts": {
"collected": true,
"structure": [
"tree.dockerfile"
],
"declarations": []
},
"community": {
"has_readme": true,
"has_license": true,
"readme_badges": {
"hosts": [],
"total": 0,
"header": 0,
"collected": true,
"has_inspect_badge": false
},
"has_description": true,
"has_contributing": true,
"health_percentage": 87,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": []
},
"popularity": {
"forks": 3,
"stars": 21,
"watchers": 83,
"fork_history": {
"days": [
{
"date": "2025-04-28",
"count": 1
},
{
"date": "2025-08-25",
"count": 1
},
{
"date": "2026-07-08",
"count": 1
}
],
"complete": true,
"collected": 3,
"total_forks": 3
},
"star_history": null,
"open_issues_and_prs": 2
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": null,
"source_files_sampled": 0,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [],
"advisories": {
"error": "No resolved dependencies to assess",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [],
"dependencies": [],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [],
"collected": true,
"truncated": false,
"total_count": 0,
"direct_count": 0,
"indirect_count": 0
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 136,
"open_issues": 2,
"closed_ratio": 0.6,
"closed_issues": 3,
"closed_unmerged_prs": 8
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "jmeridth",
"commits": 66,
"avatar_url": "https://avatars.githubusercontent.com/u/35014?v=4"
},
{
"type": "User",
"login": "zkoppert",
"commits": 18,
"avatar_url": "https://avatars.githubusercontent.com/u/6935431?v=4"
},
{
"type": "User",
"login": "ahpook",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/56753?v=4"
}
],
"contributors_sampled": 3,
"top_contributor_share": 0.776
},
"quality_signals": {
"has_ci": true,
"has_tests": false,
"ci_workflows": [
"actionlint.yaml",
"auto-author-assign.yaml",
"auto-labeler.yaml",
"labeler.yaml",
"mark-ready-when-ready.yml",
"pr-title.yaml",
"release-discussion.yaml",
"release-image.yaml",
"release.yaml",
"stale.yaml",
"test-auto-labeler.yaml",
"test-labeler.yaml",
"test-pr-title.yaml",
"test-release.yaml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 4,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "28 out of 28 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 19 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 9,
"reason": "dependency not pinned by hash detected -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "25891ed12c80c983b2f3b3c335ed8e560d7baea9",
"ran_at": "2026-08-05T08:52:45Z",
"aggregate_score": 8.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"recent_prs": {
"merged_7d": 1,
"decided_7d": 1,
"merged_30d": 2,
"authors_30d": 1,
"decided_30d": 3,
"sample_size": 60,
"window_days": 30,
"sample_exhausted": false,
"authors_probed_30d": 1,
"newcomer_merged_30d": 0,
"bot_prs_excluded_30d": 10,
"newcomer_authors_30d": 0,
"newcomer_decided_30d": 0
},
"ci_last_run_at": "2026-08-05T02:45:54Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-30T04:26:32Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 70,
"created_at": "2025-08-20T22:34:16Z",
"last_comment_at": "2025-09-11T02:03:01Z",
"last_comment_author": "github-actions"
},
{
"number": 149,
"created_at": "2026-06-02T11:07:39Z",
"last_comment_at": "2026-07-07T13:59:19Z",
"last_comment_author": "jmeridth"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/github-community-projects/ospo-reusable-workflows",
"host": "github.com",
"name": "ospo-reusable-workflows",
"owner": "github-community-projects"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": "The weighted overall 71 is calibrated to 84 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 71,
"calibrated": 84,
"calibration": "2026-08-02"
}
}
],
"value": 84,
"inputs": {
"security": 86,
"vitality": 94,
"community": 61,
"governance": 54,
"calibration": "2026-08-02",
"engineering": 72,
"ai_readiness": 34,
"weighted_overall_raw": 71
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "exceptional",
"name": "Vitality",
"value": 94,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"commits_last_year": 113,
"human_commit_share": 0.34,
"days_since_last_push": 6,
"active_weeks_last_year": 38
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "38/52 weeks with commits",
"points": 26.3,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 38
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "113 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 113
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "exceptional",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 37,
"latest_release_tag": "v1.2.3",
"releases_from_tags": false,
"days_since_latest_release": 6,
"mean_days_between_releases": 14.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "37 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 37
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 6 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 6
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~14.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 14.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 6,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 6 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 6
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 61,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 34,
"inputs": {
"forks": 3,
"stars": 21,
"watchers": 83,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "21 stars",
"points": 21.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 21
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "3 forks",
"points": 2.5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 3
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "83 watchers",
"points": 10.6,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 83
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": 0,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 54,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 28,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 3,
"top_contributor_share": 0.776
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 78% of commits",
"points": 5,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 78
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "3 contributors",
"points": 4.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 3
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 19 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 79,
"inputs": {
"merged_prs": 136,
"open_issues": 2,
"closed_issues": 3,
"prs_merged_7d": 1,
"prs_decided_7d": 1,
"prs_merged_30d": 2,
"prs_decided_30d": 3,
"issue_closed_ratio": 0.6,
"closed_unmerged_prs": 8,
"first_time_authors_30d": 0,
"first_time_prs_merged_30d": 0,
"first_time_prs_decided_30d": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "60% of issues closed",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 60
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "136/144 decided PRs merged",
"points": 28.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 136,
"decided": 144
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"followers": 102,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "github-community-projects",
"public_repos": 18,
"account_age_days": 988
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "102 followers of github-community-projects",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 102,
"login": "github-community-projects"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "18 public repos, account ~2 yr old",
"points": 14.7,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 18
}
},
{
"code": "account_age_years",
"params": {
"years": 2
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 72,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_ci": true,
"has_tests": false,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": true
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "14 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 14
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 16,
"status": "met",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 9.6,
"status": "met",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "28 out of 28 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [
"auto-labeling",
"conventional-commits",
"github-actions",
"releases"
],
"has_wiki": false,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "4 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 4
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "excellent",
"name": "Security",
"value": 86,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "excellent",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 86,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 8.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 3,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "28 out of 28 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 19 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 9",
"points": 4.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 12
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 34,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "34 of 34 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 34,
"sampled": 34
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "weak",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 42,
"inputs": {
"has_nix": false,
"has_tests": false,
"lockfiles": [],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.02,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.66
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 11,
"status": "met",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "2 of the last 100 commits agent-authored or agent-credited",
"points": 4,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "66 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 66,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 9",
"points": 9,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "critical",
"name": "Code legibility for models",
"note": "Excluded from scoring (no data or not applicable): Manageable file sizes. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"manageable_file_sizes"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"primary_language": "Dockerfile",
"largest_source_bytes": null,
"source_files_sampled": 0,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Dockerfile without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Dockerfile"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "no source files detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_source_files",
"params": {}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [],
"labels": [],
"scores": {},
"primary": null,
"evidence": [],
"artifacts": [],
"confidence": "none",
"host_extension": false,
"runs_as_process": false,
"consumed_by_code": false
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-08-05T08:53:15.958589Z",
"schema_version": "0.31.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/github-community-projects/ospo-reusable-workflows.svg",
"full_name": "github-community-projects/ospo-reusable-workflows",
"license_state": "standard",
"license_spdx": "MIT"
}