公开记录
软件健康报告模式 0.27.0 · 指标 2.5.0 · 2026-08-01 20:46 UTC

kubescape / kubevuln

Kubevuln is an in-cluster component of the Kubescape security platform. It scans container images for vulnerabilities, using Grype as its engine.

GoApache-2.0★ 26 星标⑂ 35 复刻始于 2022年3月在 GitHub 上查看 ↗
类型网络服务如何判定

kubescape/kubevuln 的健康指数为 100 分中的 86 分,处于「优秀」区间。 其得分最高的类别是Vitality(94/100),最低的是Security(59/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

86
总分 / 100
优秀

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均,再依据公开记录的分布进行校准,使各等级具有百分位含义;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 34(存在风险)的上限。

86
卓越93-100公开记录中的最高层级(约前 5%);基本满足所有检验标准
优秀80-92各方面均表现强劲;仅有少量不足
良好65-79健康;不足之处有限且可控
中等50-64可接受,但存在明显不足;建议进行审查
薄弱35-49多个领域存在实质性薄弱环节
存在风险20-34存在重大薄弱环节;采用时应保持审慎
危急1-19问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

加权总体分 72 经校准后在公布的指数量表上为 86(记录校准 2026-08-02)。

所有权

Kubescape组织
287 关注者65 个公开仓库始于 2022年2月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/kubescape/kubevulnv0.3.159-13011 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

94卓越 · 占总体的 21%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
26.3/36提交节奏 — 52 周中有 38 周有提交
18/18提交量 — 最近一年 160 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year160
human_commit_share0.88
days_since_last_push0
active_weeks_last_year38

发布纪律

100卓越
评分方式
27/27有发布版本 — 已发布 100 个发布版本
36/36发布时效 — 最近一次发布版本于 11 天前
27/27发布节奏 — 约每 6.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count100
latest_release_tagv0.3.159
releases_from_tags
days_since_latest_release11
mean_days_between_releases6.2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

62中等 · 占总体的 17%
评分方式
22.7/60星标 — 26 个星标
12.8/25复刻 — 35 个复刻
0/15关注者 — 0 位关注者
所用输入
forks35
stars26
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
readme_badges
has_contributing
has_issue_template
has_code_of_conduct
readme_badge_services
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

67良好 · 占总体的 23%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
6.7/22.5提交分布 — 头号贡献者编写了 70% 的提交
13.5/13.5贡献者广度 — 19 位贡献者
6/10OpenSSF Scorecard:Contributors — project has 2 contributing companies or organizations -- score normalized to 6
所用输入
bus_factor1
contributors_sampled19
top_contributor_share0.703
评分方式
30/42议题解决 — 71% 的议题已关闭
27.4/30PR 接受 — 已裁定的 PR 中 331/362 已合并
0/13Newcomer PR acceptance — 30 天内没有首次贡献者的 PR 得到裁决
9/15OpenSSF Scorecard:Code-Review — Found 16/23 approved changesets -- score normalized to 6
所用输入
merged_prs331
open_issues14
closed_issues35
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0.714
closed_unmerged_prs31
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
已排除计分(无数据或不适用):newcomer_pr_acceptance。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
17.7/25所有者影响力 — kubescape 有 287 位关注者
21.8/25既往记录 — 65 个公开仓库,账户约 4 年
所用输入
followers287
owner_typeOrganization
is_verified
owner_loginkubescape
public_repos65
account_age_days1,615
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 11 天前
20/20版本历史 — 130 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/kubescape/kubevuln
ecosystemsgo
any_deprecated
min_days_since_publish11

工程质量

基础的工程与文档实践是否到位?

74良好 · 占总体的 19%

工程实践

66良好
评分方式
24/24CI 工作流 — 6 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
18/20OpenSSF Scorecard:CI-Tests — 22 out of 23 merged PRs checked by a CI test -- score normalized to 9
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

85优秀
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
10/10主题标签 — 4 个主题标签
10/10Wiki
所用输入
topicskubernetes, kubescape, vulnerability-detection, kubescape-helm
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

59中等 · 占总体的 16%

安全态势

63中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.2/2.5CI-Tests — 22 out of 23 merged PRs checked by a CI test -- score normalized to 9
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
4.5/7.5Code-Review — Found 16/23 approved changesets -- score normalized to 6
1.5/2.5Contributors — project has 2 contributing companies or organizations -- score normalized to 6
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
4.5/5SAST — SAST tool is not run on all commits -- score normalized to 9
4.5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 20 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6.3
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。
评分方式
5.8/35直接依赖不含已知公告 — 5 个受影响:google.golang.org/grpc v1.80.0 (critical 9.1), github.com/distribution/distribution v2.8.2+incompatible (high 7.5), github.com/docker/docker v28.5.2+incompatible (high 8.8),另有 2 个
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
25.6/40没有长期未处理的公告 — 3 个携带公告的软件包超过 90 天未处理;最早一条发布于 516 天前
所用输入
sourceosv
advisories30
affected_packages11
assessed_packages445
unassessed_packages0
affected_by_severitycritical 1, high 2, moderate 2, unknown 6
direct_affected_packages5
已排除计分(无数据或不适用):间接依赖不含已知公告。 其余权重已重新归一化。 已将 445 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?权重刻意设小(4%):代理工具链是一项真实的维护信号,但完全不具备的仓库仍可达到 100/100。

65良好 · 占总体的 4%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 88 次人类提交中有 83 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.943
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 41 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 12 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.41
toolchain_manifestsgo.mod
dependency_bot_commit_share0.12
评分方式
45/45可类型检查的代码 — Go(静态类型)
55/55可控的文件大小 — 采样的 70 个源文件中有 0 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes51,686
source_files_sampled70
oversized_source_files0
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — pkg/sbomscanner/v1/proto/scanner.proto
0/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_filespkg/sbomscanner/v1/proto/scanner.proto

关键数据

26GitHub 星标
19贡献者
160最近 12 个月提交数
0距最近推送天数
100发布版本数
1巴士系数(bus factor)
14开放议题
Go软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 35 ⇿
0Star
35Fork
93发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

01325383562022-092024-082026-07
主版本 0次版本 0修订 93

每个点涵盖 4 天。

OpenSSF Scorecard 6.3 / 10
6.3综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-08-01 20:45 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
9CI-Tests22 out of 23 merged PRs checked by a CI test -- score normalized to 9
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
6Code-ReviewFound 16/23 approved changesets -- score normalized to 6
6Contributorsproject has 2 contributing companies or organizations -- score normalized to 6
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
9SASTSAST tool is not run on all commits -- score normalized to 9
9Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities20 existing vulnerabilities detected
直接依赖 45
注册表软件包版本约束清单文件
Gogithub.com/DmitriyVTitov/sizev1.5.0go.mod
Gogithub.com/Masterminds/semver/v3v3.4.0go.mod
Gogithub.com/adrg/xdgv0.5.3go.mod
Gogithub.com/akyoto/cachev1.0.6go.mod
Gogithub.com/anchore/cliov0.0.0-20250715152405-a0fa658e5084go.mod
Gogithub.com/anchore/grypev0.99.1go.mod
Gogithub.com/anchore/stereoscopev0.1.9go.mod
Gogithub.com/anchore/syftv1.32.0go.mod
Gogithub.com/aquilax/truncatev1.0.0go.mod
Gogithub.com/armosec/armoapi-gov0.0.718go.mod
Gogithub.com/armosec/utils-gov0.0.58go.mod
Gogithub.com/armosec/utils-k8s-gov0.0.35go.mod
Gogithub.com/cenkalti/backoff/v5v5.0.3go.mod
Gogithub.com/deckarep/golang-set/v2v2.7.0go.mod
Gogithub.com/distribution/distributionv2.8.2+incompatiblego.mod
Gogithub.com/docker/dockerv28.5.2+incompatiblego.mod
Gogithub.com/eapache/go-resiliencyv1.3.0go.mod
Gogithub.com/gammazero/workerpoolv1.1.3go.mod
Gogithub.com/gin-gonic/ginv1.9.1go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-containerregistryv0.20.6go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/hashicorp/go-multierrorv1.1.1go.mod
Gogithub.com/kinbiko/jsonassertv1.2.0go.mod
Gogithub.com/kubescape/backendv0.0.40go.mod
Gogithub.com/kubescape/go-loggerv0.0.33go.mod
Gogithub.com/kubescape/k8s-interfacev0.0.214go.mod
Gogithub.com/kubescape/storagev0.0.258go.mod
Gogithub.com/opencontainers/go-digestv1.0.0go.mod
Gogithub.com/openvex/go-vexv0.2.5go.mod
Gogithub.com/spf13/viperv1.21.0go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/testcontainers/testcontainers-gov0.38.0go.mod
Gogo.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelginv0.44.0go.mod
Gogo.opentelemetry.io/otelv1.43.0go.mod
Gogo.opentelemetry.io/otel/tracev1.43.0go.mod
Gogolang.org/x/modv0.35.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogoogle.golang.org/grpcv1.80.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gok8s.io/apimachineryv0.35.0go.mod
Gok8s.io/client-gov0.35.0go.mod
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5go.mod
Gomodernc.org/sqlitev1.38.2go.mod
Goschneider.vip/problemv1.8.1go.mod
全部依赖 445

来自 GitHub 依赖图的完整解析依赖集合:42 个直接依赖与 403 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gogithub.com/adrg/xdgv0.5.3直接
Gogithub.com/akyoto/cachev1.0.6直接
Gogithub.com/anchore/cliov0.0.0-20250715152405-a0fa658e5084直接
Gogithub.com/anchore/grypev0.99.1直接
Gogithub.com/aquilax/truncatev1.0.0直接
Gogithub.com/armosec/armoapi-gov0.0.718直接
Gogithub.com/armosec/utils-gov0.0.58直接
Gogithub.com/armosec/utils-k8s-gov0.0.35直接
Gogithub.com/cenkalti/backoff/v5v5.0.3直接
Gogithub.com/deckarep/golang-set/v2v2.7.0直接
Gogithub.com/distribution/distributionv2.8.2+incompatible直接
Gogithub.com/dmitriyvtitov/sizev1.5.0直接
Gogithub.com/docker/dockerv28.5.2+incompatible直接
Gogithub.com/eapache/go-resiliencyv1.3.0直接
Gogithub.com/gammazero/workerpoolv1.1.3直接
Gogithub.com/gin-gonic/ginv1.9.1直接
Gogithub.com/google/go-cmpv0.7.0直接
Gogithub.com/google/uuidv1.6.0直接
Gogithub.com/hashicorp/go-multierrorv1.1.1直接
Gogithub.com/kinbiko/jsonassertv1.2.0直接
Gogithub.com/kubescape/backendv0.0.40直接
Gogithub.com/kubescape/go-loggerv0.0.33直接
Gogithub.com/kubescape/k8s-interfacev0.0.214直接
Gogithub.com/kubescape/storagev0.0.258直接
Gogithub.com/masterminds/semver/v3v3.4.0直接
Gogithub.com/opencontainers/go-digestv1.0.0直接
Gogithub.com/openvex/go-vexv0.2.5直接
Gogithub.com/spf13/viperv1.21.0直接
Gogithub.com/stretchr/testifyv1.11.1直接
Gogithub.com/testcontainers/testcontainers-gov0.38.0直接
Gogo.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelginv0.44.0直接
Gogo.opentelemetry.io/otelv1.43.0直接
Gogo.opentelemetry.io/otel/tracev1.43.0直接
Gogolang.org/x/modv0.35.0直接
Gogolang.org/x/oauth2v0.36.0直接
Gogoogle.golang.org/grpcv1.80.0直接
Gogoogle.golang.org/protobufv1.36.11直接
Gok8s.io/apimachineryv0.35.0直接
Gok8s.io/client-gov0.35.0直接
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5直接
Gomodernc.org/sqlitev1.38.2直接
Goschneider.vip/problemv1.8.1直接
Gocel.dev/exprv0.25.1间接
Gocloud.google.com/gov0.123.0间接
Gocloud.google.com/go/authv0.18.2间接
Gocloud.google.com/go/auth/oauth2adaptv0.2.8间接
Gocloud.google.com/go/compute/metadatav0.9.0间接
Gocloud.google.com/go/containerv1.45.0间接
Gocloud.google.com/go/iamv1.5.3间接
Gocloud.google.com/go/monitoringv1.24.3间接
Gocloud.google.com/go/storagev1.61.3间接
Gocyphar.com/go-pathrsv0.2.1间接
Godario.cat/mergov1.0.2间接
Gogithub.com/acobaugh/osreleasev0.1.0间接
Gogithub.com/adalogics/go-fuzz-headersv0.0.0-20240806141605-e8a1dd7889d6间接
Gogithub.com/adamkorcz/go-118-fuzz-buildv0.0.0-20250520111509-a70c2aa677fa间接
Gogithub.com/agext/levenshteinv1.2.3间接
Gogithub.com/agnivade/levenshteinv1.2.1间接
Gogithub.com/anchore/archiver/v3v3.5.3-0.20241210171143-5b1d8d1c7c51间接
Gogithub.com/anchore/fangsv0.0.0-20250716230140-94c22408c232间接
Gogithub.com/anchore/go-collectionsv0.0.0-20241211140901-567f400e9a46间接
Gogithub.com/anchore/go-homedirv0.0.0-20250319154043-c29668562e4d间接
Gogithub.com/anchore/go-loggerv0.0.0-20250318195838-07ae343dd722间接
Gogithub.com/anchore/go-lzov0.1.0间接
Gogithub.com/anchore/go-macholibrev0.0.0-20250320151634-807da7ad2331间接
Gogithub.com/anchore/go-rpmdbv0.0.0-20250516171929-f77691e1faec间接
Gogithub.com/anchore/go-struct-converterv0.0.0-20250211213226-cce56d595160间接
Gogithub.com/anchore/go-syncv0.0.0-20250714163430-add63db73ad1间接
Gogithub.com/anchore/go-versionv1.2.2-0.20210903204242-51efa5b487c4间接
Gogithub.com/anchore/packageurl-gov0.1.1-0.20250220190351-d62adb6e1115间接
Gogithub.com/andybalholm/brotliv1.2.0间接
Gogithub.com/apparentlymart/go-textseg/v15v15.0.0间接
Gogithub.com/aquasecurity/go-pep440-versionv0.0.1间接
Gogithub.com/aquasecurity/go-versionv0.0.1间接
Gogithub.com/armosec/gojayv1.2.17间接
Gogithub.com/asaskevich/govalidatorv0.0.0-20230301143203-a9d515a09cc2间接
Gogithub.com/aws/aws-sdk-go-v2v1.41.5间接
Gogithub.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamv1.7.8间接
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.12间接
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.12间接
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.20间接
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.21间接
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.21间接
Gogithub.com/aws/aws-sdk-go-v2/internal/iniv1.8.6间接
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.22间接
Gogithub.com/aws/aws-sdk-go-v2/service/ecrv1.45.1间接
Gogithub.com/aws/aws-sdk-go-v2/service/eksv1.48.5间接
Gogithub.com/aws/aws-sdk-go-v2/service/iamv1.53.6间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.7间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/checksumv1.9.13间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.21间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/s3sharedv1.19.21间接
Gogithub.com/aws/aws-sdk-go-v2/service/s3v1.97.3间接
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.0.8间接
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.30.13间接
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.35.17间接
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.41.9间接
Gogithub.com/aws/smithy-gov1.24.2间接
Gogithub.com/aymanbagabas/go-osc52/v2v2.0.1间接
Gogithub.com/azure/azure-sdk-for-go/sdk/azcorev1.17.0间接
Gogithub.com/azure/azure-sdk-for-go/sdk/azidentityv1.7.0间接
Gogithub.com/azure/azure-sdk-for-go/sdk/internalv1.10.0间接
Gogithub.com/azure/azure-sdk-for-go/sdk/resourcemanager/authorization/armauthorizationv1.0.0间接
Gogithub.com/azure/azure-sdk-for-go/sdk/resourcemanager/authorization/armauthorization/v2v2.1.1间接
Gogithub.com/azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v2v2.4.0间接
Gogithub.com/azure/go-ansitermv0.0.0-20250102033503-faa5f7b0171c间接
Gogithub.com/azuread/microsoft-authentication-library-for-gov1.2.2间接
Gogithub.com/becheran/wildmatch-gov1.0.0间接
Gogithub.com/beorn7/perksv1.0.1间接
Gogithub.com/bgentry/go-netrcv0.0.0-20140422174119-9fd32a8b3d3d间接
Gogithub.com/bitnami/go-versionv0.0.0-20250505154626-452e8c5ee607间接
Gogithub.com/blakesmith/arv0.0.0-20190502131153-809d4375e1fb间接
Gogithub.com/blang/semver/v4v4.0.0间接
Gogithub.com/bmatcuk/doublestar/v2v2.0.4间接
Gogithub.com/bmatcuk/doublestar/v4v4.9.1间接
Gogithub.com/bodgit/plumbingv1.3.0间接
Gogithub.com/bodgit/sevenzipv1.6.1间接
Gogithub.com/bodgit/windowsv1.0.1间接
Gogithub.com/briandowns/spinnerv1.23.2间接
Gogithub.com/burntsushi/tomlv1.5.0间接
Gogithub.com/bytedance/sonicv1.9.1间接
Gogithub.com/cenkalti/backoff/v4v4.3.0间接
Gogithub.com/cespare/xxhash/v2v2.3.0间接
Gogithub.com/charmbracelet/colorprofilev0.3.1间接
Gogithub.com/charmbracelet/lipglossv1.1.0间接
Gogithub.com/charmbracelet/x/ansiv0.9.3间接
Gogithub.com/charmbracelet/x/cellbufv0.0.13间接
Gogithub.com/charmbracelet/x/termv0.2.1间接
Gogithub.com/chenzhuoyu/base64xv0.0.0-20221115062448-fe3a3abad311间接
Gogithub.com/cilium/ciliumv1.17.16间接
Gogithub.com/cilium/ebpfv0.17.1间接
Gogithub.com/cloudflare/circlv1.6.3间接
Gogithub.com/cncf/xds/gov0.0.0-20251210132809-ee656c7534f5间接
Gogithub.com/containerd/cgroups/v3v3.0.5间接
Gogithub.com/containerd/containerdv1.7.33间接
Gogithub.com/containerd/containerd/apiv1.9.0间接
Gogithub.com/containerd/continuityv0.4.5间接
Gogithub.com/containerd/errdefsv1.0.0间接
Gogithub.com/containerd/errdefs/pkgv0.3.0间接
Gogithub.com/containerd/fifov1.1.0间接
Gogithub.com/containerd/logv0.1.0间接
Gogithub.com/containerd/platformsv0.2.1间接
Gogithub.com/containerd/stargz-snapshotter/estargzv0.16.3间接
Gogithub.com/containerd/ttrpcv1.2.7间接
Gogithub.com/containerd/typeurl/v2v2.2.3间接
Gogithub.com/containers/commonv0.64.2间接
Gogithub.com/coreos/go-oidc/v3v3.15.0间接
Gogithub.com/cpuguy83/dockercfgv0.3.2间接
Gogithub.com/cyclonedx/cyclonedx-gov0.9.2间接
Gogithub.com/cyphar/filepath-securejoinv0.6.1间接
Gogithub.com/datadog/zstdv1.5.7间接
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33cc间接
Gogithub.com/deitch/magicv0.0.0-20240306090643-c67ab88f10cb间接
Gogithub.com/diskfs/go-diskfsv1.7.0间接
Gogithub.com/distribution/referencev0.6.0间接
Gogithub.com/docker/cliv29.2.0+incompatible间接
Gogithub.com/docker/distributionv2.8.3+incompatible间接
Gogithub.com/docker/docker-credential-helpersv0.9.3间接
Gogithub.com/docker/go-connectionsv0.6.0间接
Gogithub.com/docker/go-eventsv0.0.0-20250114142523-c867878c5e32间接
Gogithub.com/docker/go-unitsv0.5.0间接
Gogithub.com/dsnet/compressv0.0.2-0.20230904184137-39efe44ab707间接
Gogithub.com/dustin/go-humanizev1.0.1间接
Gogithub.com/ebitengine/puregov0.8.4间接
Gogithub.com/elliotchance/phpserializev1.4.0间接
Gogithub.com/emicklei/go-restful/v3v3.12.2间接
Gogithub.com/emirpasic/godsv1.18.1间接
Gogithub.com/envoyproxy/go-control-plane/envoyv1.36.0间接
Gogithub.com/envoyproxy/protoc-gen-validatev1.3.0间接
Gogithub.com/facebookincubator/nvdtoolsv0.1.5间接
Gogithub.com/fatih/colorv1.19.0间接
Gogithub.com/felixge/fgprofv0.9.5间接
Gogithub.com/felixge/httpsnoopv1.0.4间接
Gogithub.com/francoispqt/gojayv1.2.13间接
Gogithub.com/fsnotify/fsnotifyv1.9.0间接
Gogithub.com/fxamacker/cbor/v2v2.9.0间接
Gogithub.com/gabriel-vasile/mimetypev1.4.10间接
Gogithub.com/gammazero/dequev0.2.0间接
Gogithub.com/gin-contrib/ssev0.1.0间接
Gogithub.com/github/go-spdx/v2v2.3.3间接
Gogithub.com/glebarez/go-sqlitev1.22.0间接
Gogithub.com/glebarez/sqlitev1.11.0间接
Gogithub.com/go-git/gcfgv1.5.1-0.20230307220236-3a3c6141e376间接
Gogithub.com/go-git/go-billy/v5v5.9.0间接
Gogithub.com/go-git/go-git/v5v5.19.1间接
Gogithub.com/go-ini/iniv1.67.0间接
Gogithub.com/go-jose/go-jose/v4v4.1.4间接
Gogithub.com/go-logr/logrv1.4.3间接
Gogithub.com/go-logr/stdrv1.2.2间接
Gogithub.com/go-ole/go-olev1.2.6间接
Gogithub.com/go-openapi/analysisv0.23.0间接
Gogithub.com/go-openapi/errorsv0.22.2间接
Gogithub.com/go-openapi/jsonpointerv0.21.2间接
Gogithub.com/go-openapi/jsonreferencev0.21.0间接
Gogithub.com/go-openapi/loadsv0.22.0间接
Gogithub.com/go-openapi/specv0.21.0间接
Gogithub.com/go-openapi/strfmtv0.23.0间接
Gogithub.com/go-openapi/swagv0.23.1间接
Gogithub.com/go-openapi/validatev0.24.0间接
Gogithub.com/go-playground/localesv0.14.1间接
Gogithub.com/go-playground/universal-translatorv0.18.1间接
Gogithub.com/go-playground/validator/v10v10.14.0间接
Gogithub.com/go-restruct/restructv1.2.0-alpha间接
Gogithub.com/go-viper/mapstructure/v2v2.4.0间接
Gogithub.com/gobwas/globv0.2.3间接
Gogithub.com/goccy/go-jsonv0.10.2间接
Gogithub.com/goccy/go-yamlv1.18.0间接
Gogithub.com/gocsaf/csaf/v3v3.3.0间接
Gogithub.com/gogo/protobufv1.3.2间接
Gogithub.com/gohugoio/hashstructurev0.5.0间接
Gogithub.com/golang-jwt/jwt/v5v5.3.0间接
Gogithub.com/golang/groupcachev0.0.0-20241129210726-2c02b8208cf8间接
Gogithub.com/golang/snappyv1.0.0间接
Gogithub.com/google/gnostic-modelsv0.7.0间接
Gogithub.com/google/licensecheckv0.3.1间接
Gogithub.com/google/pprofv0.0.0-20250630185457-6e76a2b096b5间接
Gogithub.com/google/s2a-gov0.1.9间接
Gogithub.com/googleapis/enterprise-certificate-proxyv0.3.14间接
Gogithub.com/googleapis/gax-go/v2v2.17.0间接
Gogithub.com/googlecloudplatform/opentelemetry-operations-go/detectors/gcpv1.31.0间接
Gogithub.com/googlecloudplatform/opentelemetry-operations-go/exporter/metricv0.55.0间接
Gogithub.com/googlecloudplatform/opentelemetry-operations-go/internal/resourcemappingv0.55.0间接
Gogithub.com/gookit/colorv1.6.0间接
Gogithub.com/gorilla/muxv1.8.1间接
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.28.0间接
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16b间接
Gogithub.com/hashicorp/aws-sdk-go-base/v2v2.0.0-beta.72间接
Gogithub.com/hashicorp/errwrapv1.1.0间接
Gogithub.com/hashicorp/go-cleanhttpv0.5.2间接
Gogithub.com/hashicorp/go-getterv1.8.6间接
Gogithub.com/hashicorp/go-versionv1.8.0间接
Gogithub.com/hashicorp/golang-lru/v2v2.0.7间接
Gogithub.com/hashicorp/hcl/v2v2.24.0间接
Gogithub.com/huandu/xstringsv1.5.0间接
Gogithub.com/iancoleman/strcasev0.3.0间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/intevation/gvalv1.3.0间接
Gogithub.com/intevation/jsonpathv0.2.1间接
Gogithub.com/jbenet/go-contextv0.0.0-20150711004518-d14ea06fba99间接
Gogithub.com/jinzhu/copierv0.4.0间接
Gogithub.com/jinzhu/inflectionv1.0.0间接
Gogithub.com/jinzhu/nowv1.1.5间接
Gogithub.com/jmespath/go-jmespathv0.4.0间接
Gogithub.com/josharian/internv1.0.0间接
Gogithub.com/json-iterator/gov1.1.12间接
Gogithub.com/kastenhq/goversionv0.0.0-20230811215019-93b2f8823953间接
Gogithub.com/kevinburke/ssh_configv1.2.0间接
Gogithub.com/klauspost/compressv1.18.5间接
Gogithub.com/klauspost/cpuid/v2v2.3.0间接
Gogithub.com/klauspost/pgzipv1.2.6间接
Gogithub.com/knqyf263/go-apk-versionv0.0.0-20200609155635-041fdbb8563f间接
Gogithub.com/knqyf263/go-deb-versionv0.0.0-20241115132648-6f4aee6ccd23间接
Gogithub.com/kubescape/opa-utilsv0.0.283间接
Gogithub.com/kubescape/rbac-utilsv0.0.21-0.20230806101615-07e36f555520间接
Gogithub.com/kylelemons/godebugv1.1.0间接
Gogithub.com/leodido/go-urnv1.2.4间接
Gogithub.com/lucasb-eyer/go-colorfulv1.2.0间接
Gogithub.com/lufia/plan9statsv0.0.0-20211012122336-39d0f177ccd0间接
Gogithub.com/mackerelio/go-osstatv0.2.5间接
Gogithub.com/magiconair/propertiesv1.8.10间接
Gogithub.com/mailru/easyjsonv0.9.0间接
Gogithub.com/masahiro331/go-mvn-versionv0.0.0-20250131095131-f4974fa13b8a间接
Gogithub.com/masterminds/goutilsv1.1.1间接
Gogithub.com/masterminds/sprig/v3v3.3.0间接
Gogithub.com/mattn/go-colorablev0.1.14间接
Gogithub.com/mattn/go-isattyv0.0.21间接
Gogithub.com/mattn/go-runewidthv0.0.16间接
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957d间接
Gogithub.com/mholt/archivesv0.1.5间接
Gogithub.com/microsoft/go-winiov0.6.2间接
Gogithub.com/microsoft/hcsshimv0.13.0间接
Gogithub.com/mikelolasagasti/xzv1.0.1间接
Gogithub.com/minio/minlzv1.0.1间接
Gogithub.com/mitchellh/copystructurev1.2.0间接
Gogithub.com/mitchellh/go-homedirv1.1.0间接
Gogithub.com/mitchellh/go-wordwrapv1.0.1间接
Gogithub.com/mitchellh/mapstructurev1.5.0间接
Gogithub.com/mitchellh/reflectwalkv1.0.2间接
Gogithub.com/moby/docker-image-specv1.3.1间接
Gogithub.com/moby/go-archivev0.1.0间接
Gogithub.com/moby/lockerv1.0.1间接
Gogithub.com/moby/patternmatcherv0.6.0间接
Gogithub.com/moby/sys/mountinfov0.7.2间接
Gogithub.com/moby/sys/sequentialv0.6.0间接
Gogithub.com/moby/sys/signalv0.7.1间接
Gogithub.com/moby/sys/userv0.4.0间接
Gogithub.com/moby/sys/usernsv0.1.0间接
Gogithub.com/moby/termv0.5.2间接
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1dd间接
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31ee间接
Gogithub.com/morikuni/aecv1.0.0间接
Gogithub.com/muesli/termenvv0.16.0间接
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822间接
Gogithub.com/ncruces/go-strftimev0.1.9间接
Gogithub.com/nix-community/go-nixv0.0.0-20250101154619-4bdde671e0a1间接
Gogithub.com/nwaples/rardecodev1.1.3间接
Gogithub.com/nwaples/rardecode/v2v2.2.0间接
Gogithub.com/oklog/ulidv1.3.1间接
Gogithub.com/olekukonko/errorsv1.1.0间接
Gogithub.com/olekukonko/llv0.0.9间接
Gogithub.com/olekukonko/tablewriterv1.0.9间接
Gogithub.com/olvrng/ujsonv1.1.0间接
Gogithub.com/oneofone/xxhashv1.2.8间接
Gogithub.com/open-policy-agent/opav1.4.0间接
Gogithub.com/opencontainers/image-specv1.1.1间接
Gogithub.com/opencontainers/runtime-specv1.2.1间接
Gogithub.com/opencontainers/selinuxv1.13.1间接
Gogithub.com/package-url/packageurl-gov0.1.3间接
Gogithub.com/pandatix/go-cvssv0.6.2间接
Gogithub.com/pborman/indentv1.2.1间接
Gogithub.com/pelletier/go-tomlv1.9.5间接
Gogithub.com/pelletier/go-toml/v2v2.2.4间接
Gogithub.com/petermattis/goidv0.0.0-20241211131331-93ee7e083c43间接
Gogithub.com/pierrec/lz4/v4v4.1.22间接
Gogithub.com/pjbgf/sha1cdv0.6.0间接
Gogithub.com/pkg/browserv0.0.0-20240102092130-5ac0b6a4141c间接
Gogithub.com/pkg/errorsv0.9.1间接
Gogithub.com/pkg/profilev1.7.0间接
Gogithub.com/pkg/xattrv0.4.12间接
Gogithub.com/planetscale/vtprotobufv0.6.1-0.20240319094008-0393e58bdf10间接
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2间接
Gogithub.com/power-devops/perfstatv0.0.0-20210106213030-5aafc221ea8c间接
Gogithub.com/prometheus/client_golangv1.23.2间接
Gogithub.com/prometheus/client_modelv0.6.2间接
Gogithub.com/prometheus/commonv0.66.1间接
Gogithub.com/prometheus/procfsv0.17.0间接
Gogithub.com/protonmail/go-cryptov1.3.0间接
Gogithub.com/rcrowley/go-metricsv0.0.0-20201227073835-cf1acfcdf475间接
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daec间接
Gogithub.com/rivo/unisegv0.4.7间接
Gogithub.com/rust-secure-code/go-rustauditv0.0.0-20250226111315-e20ec32e963c间接
Gogithub.com/sagikazarmark/locaferov0.11.0间接
Gogithub.com/saintfish/chardetv0.0.0-20230101081208-5e3ef4b5456d间接
Gogithub.com/santhosh-tekuri/jsonschema/v6v6.0.2间接
Gogithub.com/sasha-s/go-deadlockv0.3.5间接
Gogithub.com/sassoftware/go-rpmutilsv0.4.0间接
Gogithub.com/scylladb/go-setv1.0.3-0.20200225121959-cc7b2070d91e间接
Gogithub.com/seccomp/libseccomp-golangv0.11.0间接
Gogithub.com/sergi/go-diffv1.4.0间接
Gogithub.com/shirou/gopsutil/v4v4.25.5间接
Gogithub.com/shopspring/decimalv1.4.0间接
Gogithub.com/sirupsen/logrusv1.9.4-0.20230606125235-dd1b4c2e81af间接
Gogithub.com/skeema/knownhostsv1.3.1间接
Gogithub.com/sorairolake/lzip-gov0.3.8间接
Gogithub.com/sourcegraph/concv0.3.1-0.20240121214520-5f936abd7ae8间接
Gogithub.com/spdx/gordfv0.0.0-20250128162952-000978ccd6fb间接
Gogithub.com/spdx/tools-golangv0.5.5间接
Gogithub.com/spf13/aferov1.15.0间接
Gogithub.com/spf13/castv1.10.0间接
Gogithub.com/spf13/cobrav1.10.1间接
Gogithub.com/spf13/pflagv1.0.10间接
Gogithub.com/spiffe/go-spiffe/v2v2.6.0间接
Gogithub.com/starry-s/zipv0.2.3间接
Gogithub.com/stripe/stripe-go/v74v74.30.0间接
Gogithub.com/subosito/gotenvv1.6.0间接
Gogithub.com/sylabs/sif/v2v2.22.0间接
Gogithub.com/sylabs/squashfsv1.0.6间接
Gogithub.com/tchap/go-patricia/v2v2.3.3间接
Gogithub.com/therootcompany/xzv1.0.1间接
Gogithub.com/tklauser/go-sysconfv0.3.12间接
Gogithub.com/tklauser/numcpusv0.6.1间接
Gogithub.com/twitchyliquid64/golang-asmv0.15.1间接
Gogithub.com/ugorji/go/codecv1.2.11间接
Gogithub.com/ulikunitz/xzv0.5.15间接
Gogithub.com/uptrace/opentelemetry-go-extra/otelutilv0.3.2间接
Gogithub.com/uptrace/opentelemetry-go-extra/otelzapv0.3.2间接
Gogithub.com/uptrace/uptrace-gov1.43.0间接
Gogithub.com/vbatts/go-mtreev0.5.4间接
Gogithub.com/vbatts/tar-splitv0.12.1间接
Gogithub.com/vifraa/gopomv1.0.0间接
Gogithub.com/vishvananda/netlinkv1.3.1间接
Gogithub.com/vishvananda/netnsv0.0.5间接
Gogithub.com/wagoodman/go-partybusv0.0.0-20230516145632-8ccac152c651间接
Gogithub.com/wagoodman/go-progressv0.0.0-20230925121702-07e42b3cdba0间接
Gogithub.com/x448/float16v0.8.4间接
Gogithub.com/xanzy/ssh-agentv0.3.3间接
Gogithub.com/xeipuuv/gojsonpointerv0.0.0-20190905194746-02993c407bfb间接
Gogithub.com/xeipuuv/gojsonreferencev0.0.0-20180127040603-bd5ef7bd5415间接
Gogithub.com/xi2/xzv0.0.0-20171230120015-48954b6210f8间接
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41e间接
Gogithub.com/yashtewari/glob-intersectionv0.2.0间接
Gogithub.com/yl2chen/cidrangerv1.0.2间接
Gogithub.com/yusufpapurcu/wmiv1.2.4间接
Gogithub.com/zclconf/go-ctyv1.16.3间接
Gogo.etcd.io/bboltv1.4.3间接
Gogo.mongodb.org/mongo-driverv1.17.7间接
Gogo.opencensus.iov0.24.0间接
Gogo.opentelemetry.io/auto/sdkv1.2.1间接
Gogo.opentelemetry.io/contrib/bridges/otelslogv0.18.0间接
Gogo.opentelemetry.io/contrib/detectors/gcpv1.39.0间接
Gogo.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpcv0.63.0间接
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.62.0间接
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.68.0间接
Gogo.opentelemetry.io/contrib/processors/minsevv0.16.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpv0.19.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.43.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.43.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.43.0间接
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.43.0间接
Gogo.opentelemetry.io/otel/logv0.19.0间接
Gogo.opentelemetry.io/otel/metricv1.43.0间接
Gogo.opentelemetry.io/otel/sdkv1.43.0间接
Gogo.opentelemetry.io/otel/sdk/logv0.19.0间接
Gogo.opentelemetry.io/otel/sdk/metricv1.43.0间接
Gogo.opentelemetry.io/proto/otlpv1.10.0间接
Gogo.uber.org/multierrv1.11.0间接
Gogo.uber.org/zapv1.27.1间接
Gogo.yaml.in/yaml/v2v2.4.3间接
Gogo.yaml.in/yaml/v3v3.0.4间接
Gogo4.orgv0.0.0-20230225012048-214862532bf5间接
Gogo4.org/netipxv0.0.0-20231129151722-fdeea329fbba间接
Gogolang.org/x/archv0.3.0间接
Gogolang.org/x/cryptov0.52.0间接
Gogolang.org/x/expv0.0.0-20260410095643-746e56fc9e2f间接
Gogolang.org/x/netv0.55.0间接
Gogolang.org/x/syncv0.20.0间接
Gogolang.org/x/sysv0.45.0间接
Gogolang.org/x/termv0.43.0间接
Gogolang.org/x/textv0.37.0间接
Gogolang.org/x/timev0.15.0间接
Gogolang.org/x/toolsv0.44.0间接
Gogolang.org/x/xerrorsv0.0.0-20240903120638-7835f813f4da间接
Gogoogle.golang.org/apiv0.271.0间接
Gogoogle.golang.org/genprotov0.0.0-20260128011058-8636f8732409间接
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260414002931-afd174a4e478间接
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260414002931-afd174a4e478间接
Gogopkg.in/evanphx/json-patch.v4v4.13.0间接
Gogopkg.in/inf.v0v0.9.1间接
Gogopkg.in/warnings.v0v0.1.2间接
Gogopkg.in/yaml.v3v3.0.1间接
Gogorm.io/gormv1.30.2间接
Gok8s.io/apiv0.35.0间接
Gok8s.io/apiextensions-apiserverv0.35.0间接
Gok8s.io/apiserverv0.35.0间接
Gok8s.io/component-basev0.35.0间接
Gok8s.io/klog/v2v2.130.1间接
Gok8s.io/kube-openapiv0.0.0-20250910181357-589584f1c912间接
Gomodernc.org/libcv1.66.3间接
Gomodernc.org/mathutilv1.7.1间接
Gomodernc.org/memoryv1.11.0间接
Gosigs.k8s.io/controller-runtimev0.21.0间接
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730间接
Gosigs.k8s.io/randfillv1.0.0间接
Gosigs.k8s.io/structured-merge-diff/v6v6.3.0间接
Gosigs.k8s.io/yamlv1.6.0间接
依赖安全公告 11

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 445 个包,其中也包含从不交付的开发与测试版本固定:11 个存在已知公告,5 个为直接依赖。

软件包版本关系严重程度公告数修复版本
google.golang.org/grpcv1.80.0直接严重21.82.1
github.com/distribution/distributionv2.8.2+incompatible直接63.1.1
github.com/docker/dockerv28.5.2+incompatible直接1029.3.1
github.com/anchore/grypev0.99.1直接20.104.1
github.com/nwaples/rardecodev1.1.3间接22.2.0
go.opentelemetry.io/otelv1.43.0直接未知11.44.0
github.com/containerd/containerdv1.7.33间接未知32.3.2
github.com/klauspost/compressv1.18.5间接未知11.18.7
golang.org/x/cryptov0.52.0间接未知1
golang.org/x/netv0.55.0间接未知10.56.0
golang.org/x/textv0.37.0间接未知10.39.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "kubernetes",
        "kubescape",
        "vulnerability-detection",
        "kubescape-helm"
      ],
      "is_fork": false,
      "size_kb": 32408,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 502301,
        "Makefile": 343,
        "Dockerfile": 699
      },
      "pushed_at": "2026-08-01T14:19:17Z",
      "created_at": "2022-03-13T16:54:24Z",
      "owner_type": "Organization",
      "updated_at": "2026-08-01T14:19:22Z",
      "description": "Kubevuln is an in-cluster component of the Kubescape security platform. It scans container images for vulnerabilities, using Grype as its engine.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Kubescape",
      "type": "Organization",
      "login": "kubescape",
      "company": null,
      "location": null,
      "followers": 287,
      "avatar_url": "https://avatars.githubusercontent.com/u/100554170?v=4",
      "created_at": "2022-02-28T05:48:05Z",
      "is_verified": null,
      "public_repos": 65,
      "account_age_days": 1615
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.3.159",
          "kind": "patch",
          "published_at": "2026-07-21T12:13:28Z"
        },
        {
          "tag": "v0.3.154",
          "kind": "patch",
          "published_at": "2026-06-25T13:11:14Z"
        },
        {
          "tag": "v0.3.153",
          "kind": "patch",
          "published_at": "2026-06-25T06:02:15Z"
        },
        {
          "tag": "v0.3.152",
          "kind": "patch",
          "published_at": "2026-06-21T11:24:50Z"
        },
        {
          "tag": "v0.3.151",
          "kind": "patch",
          "published_at": "2026-06-19T11:49:00Z"
        },
        {
          "tag": "v0.3.150",
          "kind": "patch",
          "published_at": "2026-06-16T07:22:38Z"
        },
        {
          "tag": "v0.3.149",
          "kind": "patch",
          "published_at": "2026-06-09T15:44:38Z"
        },
        {
          "tag": "v0.3.146",
          "kind": "patch",
          "published_at": "2026-05-27T14:44:36Z"
        },
        {
          "tag": "v0.3.145",
          "kind": "patch",
          "published_at": "2026-05-26T16:54:51Z"
        },
        {
          "tag": "v0.3.144",
          "kind": "patch",
          "published_at": "2026-05-26T07:58:24Z"
        },
        {
          "tag": "v0.3.142",
          "kind": "patch",
          "published_at": "2026-05-19T15:19:33Z"
        },
        {
          "tag": "v0.3.141",
          "kind": "patch",
          "published_at": "2026-05-12T15:24:23Z"
        },
        {
          "tag": "v0.3.138",
          "kind": "patch",
          "published_at": "2026-05-06T16:16:19Z"
        },
        {
          "tag": "v0.3.137",
          "kind": "patch",
          "published_at": "2026-05-05T12:30:04Z"
        },
        {
          "tag": "v0.3.136",
          "kind": "patch",
          "published_at": "2026-05-04T13:37:43Z"
        },
        {
          "tag": "v0.3.134",
          "kind": "patch",
          "published_at": "2026-04-29T13:52:15Z"
        },
        {
          "tag": "v0.3.132",
          "kind": "patch",
          "published_at": "2026-04-20T08:25:56Z"
        },
        {
          "tag": "v0.3.129",
          "kind": "patch",
          "published_at": "2026-04-17T15:46:06Z"
        },
        {
          "tag": "v0.3.119",
          "kind": "patch",
          "published_at": "2026-04-02T06:44:34Z"
        },
        {
          "tag": "v0.3.114",
          "kind": "patch",
          "published_at": "2026-03-29T09:11:50Z"
        },
        {
          "tag": "v0.3.110",
          "kind": "patch",
          "published_at": "2026-03-03T20:53:18Z"
        },
        {
          "tag": "v0.3.109",
          "kind": "patch",
          "published_at": "2026-02-24T17:27:40Z"
        },
        {
          "tag": "v0.3.108",
          "kind": "patch",
          "published_at": "2026-02-24T12:42:00Z"
        },
        {
          "tag": "v0.3.105",
          "kind": "patch",
          "published_at": "2026-02-05T07:40:33Z"
        },
        {
          "tag": "v0.3.104",
          "kind": "patch",
          "published_at": "2026-01-19T14:06:21Z"
        },
        {
          "tag": "v0.3.103",
          "kind": "patch",
          "published_at": "2026-01-16T15:56:43Z"
        },
        {
          "tag": "v0.3.98",
          "kind": "patch",
          "published_at": "2025-11-21T20:21:39Z"
        },
        {
          "tag": "v0.3.97",
          "kind": "patch",
          "published_at": "2025-11-12T06:43:13Z"
        },
        {
          "tag": "v0.3.96",
          "kind": "patch",
          "published_at": "2025-11-07T09:01:51Z"
        },
        {
          "tag": "v0.3.95",
          "kind": "patch",
          "published_at": "2025-11-05T17:22:16Z"
        },
        {
          "tag": "v0.3.94",
          "kind": "patch",
          "published_at": "2025-10-22T07:30:00Z"
        },
        {
          "tag": "v0.3.93",
          "kind": "patch",
          "published_at": "2025-09-29T16:03:47Z"
        },
        {
          "tag": "v0.3.92",
          "kind": "patch",
          "published_at": "2025-09-23T05:19:09Z"
        },
        {
          "tag": "v0.3.91",
          "kind": "patch",
          "published_at": "2025-09-18T11:31:47Z"
        },
        {
          "tag": "v0.3.90",
          "kind": "patch",
          "published_at": "2025-09-17T16:37:13Z"
        },
        {
          "tag": "v0.3.89",
          "kind": "patch",
          "published_at": "2025-09-17T13:12:11Z"
        },
        {
          "tag": "v0.3.88",
          "kind": "patch",
          "published_at": "2025-09-16T14:47:53Z"
        },
        {
          "tag": "v0.3.87",
          "kind": "patch",
          "published_at": "2025-09-11T16:27:54Z"
        },
        {
          "tag": "v0.3.86",
          "kind": "patch",
          "published_at": "2025-09-01T06:02:25Z"
        },
        {
          "tag": "v0.3.85",
          "kind": "patch",
          "published_at": "2025-08-21T06:52:55Z"
        },
        {
          "tag": "v0.3.84",
          "kind": "patch",
          "published_at": "2025-08-18T07:08:18Z"
        },
        {
          "tag": "v0.3.83",
          "kind": "patch",
          "published_at": "2025-08-05T11:48:32Z"
        },
        {
          "tag": "v0.3.82",
          "kind": "patch",
          "published_at": "2025-07-16T08:09:24Z"
        },
        {
          "tag": "v0.3.80",
          "kind": "patch",
          "published_at": "2025-06-18T13:19:26Z"
        },
        {
          "tag": "v0.3.78",
          "kind": "patch",
          "published_at": "2025-05-21T06:46:00Z"
        },
        {
          "tag": "v0.3.77",
          "kind": "patch",
          "published_at": "2025-05-20T13:51:17Z"
        },
        {
          "tag": "v0.3.76",
          "kind": "patch",
          "published_at": "2025-05-16T19:30:32Z"
        },
        {
          "tag": "v0.3.75",
          "kind": "patch",
          "published_at": "2025-05-15T11:09:35Z"
        },
        {
          "tag": "v0.3.74",
          "kind": "patch",
          "published_at": "2025-04-28T09:55:52Z"
        },
        {
          "tag": "v0.3.72",
          "kind": "patch",
          "published_at": "2025-04-15T10:29:13Z"
        },
        {
          "tag": "v0.3.69",
          "kind": "patch",
          "published_at": "2025-03-27T10:11:58Z"
        },
        {
          "tag": "v0.3.67",
          "kind": "patch",
          "published_at": "2025-03-20T12:15:16Z"
        },
        {
          "tag": "v0.3.66",
          "kind": "patch",
          "published_at": "2025-03-11T17:03:09Z"
        },
        {
          "tag": "v0.3.65",
          "kind": "patch",
          "published_at": "2025-03-04T08:16:30Z"
        },
        {
          "tag": "v0.3.62",
          "kind": "patch",
          "published_at": "2025-02-17T15:28:47Z"
        },
        {
          "tag": "v0.3.61",
          "kind": "patch",
          "published_at": "2025-02-13T13:22:35Z"
        },
        {
          "tag": "v0.3.58",
          "kind": "patch",
          "published_at": "2025-01-28T15:53:09Z"
        },
        {
          "tag": "v0.3.57",
          "kind": "patch",
          "published_at": "2025-01-26T15:18:48Z"
        },
        {
          "tag": "v0.3.55",
          "kind": "patch",
          "published_at": "2025-01-23T11:24:47Z"
        },
        {
          "tag": "v0.3.54",
          "kind": "patch",
          "published_at": "2025-01-15T15:35:42Z"
        },
        {
          "tag": "v0.3.53",
          "kind": "patch",
          "published_at": "2025-01-07T16:40:55Z"
        },
        {
          "tag": "v0.3.52",
          "kind": "patch",
          "published_at": "2024-12-25T11:25:39Z"
        },
        {
          "tag": "v0.3.51",
          "kind": "patch",
          "published_at": "2024-12-23T16:57:19Z"
        },
        {
          "tag": "v0.3.49",
          "kind": "patch",
          "published_at": "2024-12-20T13:14:46Z"
        },
        {
          "tag": "v0.3.48",
          "kind": "patch",
          "published_at": "2024-12-16T13:33:57Z"
        },
        {
          "tag": "v0.3.46",
          "kind": "patch",
          "published_at": "2024-12-13T14:51:36Z"
        },
        {
          "tag": "v0.3.41",
          "kind": "patch",
          "published_at": "2024-12-04T16:36:23Z"
        },
        {
          "tag": "v0.3.39",
          "kind": "patch",
          "published_at": "2024-11-28T15:30:18Z"
        },
        {
          "tag": "v0.3.38",
          "kind": "patch",
          "published_at": "2024-11-25T08:42:23Z"
        },
        {
          "tag": "v0.3.36",
          "kind": "patch",
          "published_at": "2024-10-10T07:34:24Z"
        },
        {
          "tag": "v0.3.34",
          "kind": "patch",
          "published_at": "2024-09-30T19:36:38Z"
        },
        {
          "tag": "v0.3.33",
          "kind": "patch",
          "published_at": "2024-09-04T20:24:39Z"
        },
        {
          "tag": "v0.3.30",
          "kind": "patch",
          "published_at": "2024-08-22T07:55:29Z"
        },
        {
          "tag": "v0.3.25",
          "kind": "patch",
          "published_at": "2024-06-05T08:33:42Z"
        },
        {
          "tag": "v0.3.22",
          "kind": "patch",
          "published_at": "2024-06-03T12:14:20Z"
        },
        {
          "tag": "v0.3.21",
          "kind": "patch",
          "published_at": "2024-05-29T11:53:47Z"
        },
        {
          "tag": "v0.3.20",
          "kind": "patch",
          "published_at": "2024-05-27T14:58:38Z"
        },
        {
          "tag": "v0.3.19",
          "kind": "patch",
          "published_at": "2024-05-27T12:28:16Z"
        },
        {
          "tag": "v0.3.18",
          "kind": "patch",
          "published_at": "2024-05-01T08:20:46Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2024-02-06T06:12:26Z"
        },
        {
          "tag": "v0.2.110",
          "kind": "patch",
          "published_at": "2023-08-18T09:46:06Z"
        },
        {
          "tag": "v0.2.109",
          "kind": "patch",
          "published_at": "2023-08-17T16:10:28Z"
        },
        {
          "tag": "v0.2.107",
          "kind": "patch",
          "published_at": "2023-08-17T09:27:28Z"
        },
        {
          "tag": "v0.2.106",
          "kind": "patch",
          "published_at": "2023-08-16T14:23:06Z"
        },
        {
          "tag": "v0.2.105",
          "kind": "patch",
          "published_at": "2023-08-16T10:12:05Z"
        },
        {
          "tag": "v0.2.99",
          "kind": "patch",
          "published_at": "2023-06-27T12:25:07Z"
        },
        {
          "tag": "v0.1.19",
          "kind": "patch",
          "published_at": "2023-03-05T12:57:56Z"
        },
        {
          "tag": "v0.1.14",
          "kind": "patch",
          "published_at": "2023-02-26T17:24:16Z"
        },
        {
          "tag": "v0.1.12",
          "kind": "patch",
          "published_at": "2023-02-26T09:38:53Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2023-02-02T08:16:50Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2023-01-11T11:59:37Z"
        },
        {
          "tag": "v0.0.46",
          "kind": "patch",
          "published_at": "2023-01-08T12:33:09Z"
        },
        {
          "tag": "v0.0.45",
          "kind": "patch",
          "published_at": "2022-10-13T08:58:06Z"
        },
        {
          "tag": "v0.0.44",
          "kind": "patch",
          "published_at": "2022-08-14T11:39:47Z"
        },
        {
          "tag": "v0.0.43",
          "kind": "patch",
          "published_at": "2022-08-14T08:59:19Z"
        },
        {
          "tag": "v0.0.42",
          "kind": "patch",
          "published_at": "2022-08-11T17:33:03Z"
        },
        {
          "tag": "v0.0.40",
          "kind": "patch",
          "published_at": "2022-08-10T12:34:28Z"
        },
        {
          "tag": "v0.0.39",
          "kind": "patch",
          "published_at": "2022-08-10T11:32:31Z"
        },
        {
          "tag": "v0.0.38",
          "kind": "patch",
          "published_at": "2022-08-10T08:55:54Z"
        },
        {
          "tag": "v0.0.37",
          "kind": "patch",
          "published_at": "2022-08-10T06:08:53Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9115f31515f597327864b7f9daeca14d326fee4b",
          "body": "* fix: send actual lifecycle status in BackendAdapter.SendStatus\n\nFixes #406\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n* test: assert independent expected status per SendStatus lifecycle step\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n* fix: use statuses table directly and guard test invocation\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n---------\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>",
          "is_bot": false,
          "headline": "fix: send actual lifecycle status in BackendAdapter.SendStatus (#407)",
          "author_name": "Arnav Vinod Deshpande",
          "author_login": "rootp1",
          "committed_at": "2026-08-01T14:19:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc4af14d6a5df77f8c92b8e2c3c8a81fc1b08b14",
          "body": "…ver an object without labels or annotations (#405)\n\nmergeMaps in repositories/apiserver.go wrote into the destination map\nwithout checking whether it was nil. A Kubernetes object with no\nmetadata.labels / metadata.annotations decodes to a nil map, so any Store*\nupdate path that merged over such an \n[…]\ned objects with nil maps, so they\nexercise the same update path a malformed stored object would and would\nhave caught this regression.\n\nFixes #402\n\nSigned-off-by: Adesh Deshmukh <adeshkd123@gmail.com>",
          "is_bot": false,
          "headline": "fix: mergeMaps panics on nil map, crashing the process when storing o…",
          "author_name": "Adesh Deshmukh",
          "author_login": "AdeshDeshmukh",
          "committed_at": "2026-08-01T14:00:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33b467b700f493981f09fdd1def315c716378e8c",
          "body": "* fix: set action_statement on affected VEX statements\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n* fix: clear impact_statement and backfill stale affected VEX statements\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n* test: align stale-affected VEX test with upstream reset-to-not-affected fix\n\n[…]\notp1 <arnav.iitr@gmail.com>\n\n* fix: clear action_statement on reset and drop unreachable backfill\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n---------\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>",
          "is_bot": false,
          "headline": "fix: set action_statement on affected VEX statements (#404)",
          "author_name": "Arnav Vinod Deshpande",
          "author_login": "rootp1",
          "committed_at": "2026-08-01T13:58:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fede5c244ce41dbbf7b4bfe1c77d5483f632b6fe",
          "body": "* fix: revalidate SECURITY-INSIGHTS.yml and gate it in CI\n\nThe manifest failed validation against the very schema it declares. The\nv1.0.0 property is `status`; the file used `stage`, a name dropped during\nv1.0.0 development (ossf/security-insights#52), so it was authored against\na pre-release draft \n[…]\nxternal fetches; corrected the stale\n  \"weekly\" wording left over from the cron change.\n\nSigned-off-by: 1PoPTRoN <vrxn.arp1traj@gmail.com>\n\n---------\n\nSigned-off-by: 1PoPTRoN <vrxn.arp1traj@gmail.com>",
          "is_bot": false,
          "headline": "fix: revalidate SECURITY-INSIGHTS.yml and gate it in CI (#388)",
          "author_name": "Arpit Raj",
          "author_login": "1PoPTRoN",
          "committed_at": "2026-08-01T13:43:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a5e45e3c984efe8bc368187338402ccfd4353b03",
          "body": "…401)\n\nupdateVEX reused the previously stored statement status and only ever\npromoted matches to affected, so a CVE/package pair that stopped being\nrelevant stayed marked affected forever. Reset every statement to the\nnot_affected baseline before reapplying the current filtered manifest,\nmatching createVEX's behavior.\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>",
          "is_bot": false,
          "headline": "fix: reset VEX statements to not_affected before reapplying update (#…",
          "author_name": "Arnav Vinod Deshpande",
          "author_login": "rootp1",
          "committed_at": "2026-07-31T14:49:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eeba9828e53b57ab34c7d86c2cfa590ed302c692",
          "body": "…maryStub/StoreSBOM (#399)\n\nThe four Store methods in repositories/apiserver.go always returned nil\nregardless of whether the Create-on-conflict retry succeeded. Failures were\nonly logged. This made scan.go GenerateSBOM's ReasonSBOMStorageFailed\nbranch (L127-131) dead code in production, and left sc\n[…]\n.DefaultRetry.Steps times). Repository-side failure logs are demoted\nfrom Warning to Debug since the caller now owns the reported log.\n\nFixes #398\n\nSigned-off-by: Adesh Deshmukh <adeshkd123@gmail.com>",
          "is_bot": false,
          "headline": "fix: surface storage failures in StoreCVE/StoreCVESummary/StoreCVESum…",
          "author_name": "Adesh Deshmukh",
          "author_login": "AdeshDeshmukh",
          "committed_at": "2026-07-31T13:49:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22be3a52cb33a50be17a4eb41a8ccca50ad83e1d",
          "body": "In repositories/apiserver.go GetCVE and GetSBOM, the case err != nil\nbranch swallowed non-NotFound errors by returning (zero, nil),\nindistinguishable from the manifest-not-present path. Now returns a\nwrapped error matching the existing pattern in GetContainerProfile.\n\nThe repository-level Warning is\n[…]\nl (L108/200/213/415/427) with imageSlug context.\n\nAdds transient-error tests for both GetCVE and GetSBOM using fake\nclientset reactors.\n\nRefs #390\n\nSigned-off-by: Adesh Deshmukh <adeshkd123@gmail.com>",
          "is_bot": false,
          "headline": "fix: surface transient apiserver errors in GetCVE/GetSBOM (#396)",
          "author_name": "Adesh Deshmukh",
          "author_login": "AdeshDeshmukh",
          "committed_at": "2026-07-31T10:19:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "904722435c22057be132c2fe234acddf47eff892",
          "body": "…tatements (#394)\n\n* fix: correct swapped vulnerability ID/name in VEX update path\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n* fix: match appended VEX statement by ID and PURL in regression test\n\nMatching by ID alone could assert a pre-existing create-path statement\nfor duplicate CVE IDs across\n[…]\nt detection to avoid false-positive swaps\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\n\n---------\n\nSigned-off-by: rootp1 <arnav.iitr@gmail.com>\nCo-authored-by: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix VEX update path swapping vulnerability ID and name for appended s…",
          "author_name": "Arnav Vinod Deshpande",
          "author_login": "rootp1",
          "committed_at": "2026-07-31T09:32:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0bec821fff29caf960729b612ea885adae927768",
          "body": "In repositories/apiserver.go (StoreCVE L351, StoreCVESummary L588,\nStoreSBOM filtered L1127, StoreSBOM unfiltered L1160) the\nretry-exhaustion warning logs helpers.Error(err) — the original\nIsAlreadyExists sentinel — instead of helpers.Error(retryErr) —\nthe actual Get/Update failure. StoreCVESummaryS\n[…]\nest parse\nfailure warning logs helpers.Error(err) (guaranteed nil at that\npoint) instead of helpers.Error(e) (the actual parse error).\n\nFixes #389\n\nSigned-off-by: Adesh Deshmukh <adeshkd123@gmail.com>",
          "is_bot": false,
          "headline": "fix: log real error instead of preceding sentinel/nil at 5 sites (#395)",
          "author_name": "Adesh Deshmukh",
          "author_login": "AdeshDeshmukh",
          "committed_at": "2026-07-31T07:30:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2131f54ecc34e25449ee0ce0b8efc962e0029fe0",
          "body": "…#386)\n\nBumps [go.mongodb.org/mongo-driver](https://github.com/mongodb/mongo-go-driver) from 1.17.6 to 1.17.7.\n- [Release notes](https://github.com/mongodb/mongo-go-driver/releases)\n- [Commits](https://github.com/mongodb/mongo-go-driver/compare/v1.17.6...v1.17.7)\n\n---\nupdated-dependencies:\n- depende\n[…]\ner\n  dependency-version: 1.17.7\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump go.mongodb.org/mongo-driver from 1.17.6 to 1.17.7 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T12:06:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "95d26f991c0f2e50302c59eab8f1ea180fac5eaa",
          "body": "…385)\n\n* chore(deps): Bump github.com/cilium/cilium from 1.17.15 to 1.17.16\n\nBumps [github.com/cilium/cilium](https://github.com/cilium/cilium) from 1.17.15 to 1.17.16.\n- [Release notes](https://github.com/cilium/cilium/releases)\n- [Changelog](https://github.com/cilium/cilium/blob/1.17.16/CHANGELOG.\n[…]\n-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/cilium/cilium from 1.17.15 to 1.17.16 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T11:09:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89996487ea408c01bca4f8eabdbb0ff4a417950d",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): remove workflow_dispatch trigger from pr-merged",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-07-20T08:10:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c5045f763812100f9dd9c8492392276c61884fe",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix CI",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-07-20T08:07:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9335f52420017d759018619bb10990785bbca91a",
          "body": "….33 (#384)\n\nBumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.32 to 1.7.33.\n- [Release notes](https://github.com/containerd/containerd/releases)\n- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)\n- [Commits](https://github.com/con\n[…]\nrd\n  dependency-version: 1.7.33\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/containerd/containerd from 1.7.32 to 1.7…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T05:55:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f1b79eac9f780ce00783c2066b7f46151610b0ca",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix CI",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-07-20T05:45:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "26608409ecdef7e5a24b7e23e8cec1aa8a969b2b",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix CI",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-07-20T05:39:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc05ac4a5d350171923a02d445734c63db065b06",
          "body": "…lectors (#383)\n\n* [ LFX 2026 ] feat: scope vulnerability SecurityExceptions by match selectors\n\nSigned-off-by: yugal07 <yashsadhwani544@gmail.com>\n\n* fix(securityexception): fail closed on unresolved match selectors and distinguish core vs unknown API group\n\nSigned-off-by: yugal07 <yashsadhwani544@\n[…]\n): match image patterns against digest-bearing refs and reject empty resource entries\n\nSigned-off-by: yugal07 <yashsadhwani544@gmail.com>\n\n---------\n\nSigned-off-by: yugal07 <yashsadhwani544@gmail.com>",
          "is_bot": false,
          "headline": "[ LFX 2026 ] feat: scope vulnerability SecurityExceptions by match se…",
          "author_name": "Yugal Sadhwani",
          "author_login": "yugal07",
          "committed_at": "2026-07-20T05:24:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dbf6c9b45ca0469e0f6733e4ec40ed3fa5c36b1",
          "body": "…channel (#381) (#382)\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix: raise gRPC client/server message limits on sbom-scanner sidecar …",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-06-25T13:04:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ac3793b9feda54d6f166dc8e5001e746ef3ade5",
          "body": "The SBOM scanner sidecar runs Syft's RPM (redhat) cataloger but, unlike\nthe main HTTP binary, does not import grype and therefore never pulls a\nsqlite driver transitively. Since Syft v1.32.0 the cataloger requires a\ndriver registered as \"sqlite\" to read newer sqlite-backed RPM databases\n(rpmdb.sqlit\n[…]\ning doc describes the sbom-scanner sidecar or RPM/sqlite cataloging\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sbomscanner): register sqlite driver for newer RPM databases (#380)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-06-25T05:54:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b582a47b4884e48139afb3dcd41bc191cac6c829",
          "body": "…reference (#377)\n\n* fix(sbomscanner): normalize the image reference exactly once\n\nOn the sidecar SBOM path the image reference was normalized twice: the adapter (SidecarSBOMAdapter.CreateSBOM via NormalizeImageID) normalizes it before sending the gRPC request, then scannerServer.CreateSBOM normaliz\n[…]\nif double-normalization is reintroduced.\n\nSigned-off-by: kooomix <eranm@armosec.io>\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\n\nDocs-exempt: test-only change, no behavioral or API change",
          "is_bot": false,
          "headline": "fix(sbomscanner): don't double-normalize an already-normalized image …",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-06-21T11:18:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "97eee73f48682de5281ab50aa8df75495417d5d7",
          "body": "…navailable (#376)\n\n* Initial plan\n\n* Add backend service discovery fallback to clusterData\n\n* Refine URL normalization in service fallback\n\n* Add coverage for service URL fallback helpers\n\n* Log and surface discovery fallback errors\n\n* Use clearer assertions in config fallback test\n\n* Address config fallback cleanup nits\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Fall back to clusterData backend URLs when API service discovery is u…",
          "author_name": "Copilot",
          "author_login": "Copilot",
          "committed_at": "2026-06-19T11:42:43Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b7e1fccb7fa9a565a1efaaa80292108d7735d792",
          "body": "…ks (#374)\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix: detach HTTP request context from cancellation for background tas…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-06-16T07:15:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54958224e2e968b328ad0c20e6918172d2d01df3",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "chore(deps): update go-logger to v0.0.33 (#373)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-06-09T15:36:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "108798cde0bc8915ec6eff41d8443ba10827541d",
          "body": "…tion (#371)\n\nRequired by the actions/attest-build-provenance step added to the shared\nincluster-comp-pr-merged.yaml workflow in kubescape/workflows.\n\nSigned-off-by: Varadraj75 <agrawalvaradraj2007@gmail.com>",
          "is_bot": false,
          "headline": "feat: add attestations: write permission for image provenance attesta…",
          "author_name": "Varad Raj Agrawal",
          "author_login": "Varadraj75",
          "committed_at": "2026-06-09T11:49:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9453ec4003cad99c31979ac211a959e8c7b51fa",
          "body": "…vendors\n\nAdaptive CPE matching for trusted image vendors",
          "is_bot": false,
          "headline": "Merge pull request #372 from kubescape/adaptive-cve-matching-trusted-…",
          "author_name": "Ben Hirschberg",
          "author_login": "slashben",
          "committed_at": "2026-06-09T11:43:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5863faeeebd23bd3dce06de9c5fe925e5c0f4e61",
          "body": "…list copy\n\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Address CodeRabbit nitpicks: modern config example, defensive vendor-…",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-06-08T12:46:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a84e83bc919c725bc06cad03d078723fe58ce0d5",
          "body": "LoadConfig resolved the matching mode from the unmarshalled struct fields,\nbut with AutomaticEnv a value supplied purely via environment variable is\nvisible to IsSet/GetString yet is not populated by Unmarshal. The previous\ncode therefore took the IsSet branch, left CVEMatchingMode empty, and failed\n[…]\ndVendors\n  fallback on the struct\n- correct the over-claimed \"unreachable\" comment (NewGrypeAdapter is exported\n  and takes a raw mode; falls back to CPE-on safely)\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Fix env-var override for matching mode; address review feedback",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-06-08T12:40:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "46173269bdea8306cd77ec5bd8abdb7c7435aa2a",
          "body": "Replace the boolean useDefaultMatchers with a three-mode cveMatchingMode\nconfig (off/on/adaptive), defaulting to adaptive. In adaptive mode, CPE\nmatching stays enabled for arbitrary images but is disabled per-scan for\nimages from trusted vendors (echo, chainguard, wolfi, minimos), which rely\non the \n[…]\nanifest is annotated with\nkubescape.io/cve-matching-mode and kubescape.io/vendor-trusted-match for\nobservability.\n\nImplements the proposal in designs-and-proposals.\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Add adaptive CPE matching mode for trusted image vendors",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-06-08T12:23:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c906ef94a709ca02e6a9e14c1a45b0f905b0f4e9",
          "body": "…… (#370)\n\n* fix(scan): classify MANIFEST_SCHEMA_UNSUPPORTED + write per-workload stub summary\n\nSigned-off-by: Harshit Gandhi <gandhiharshit716@gmail.com>\n\n* bumped the armoapi-go version to v0.0.718\n\nSigned-off-by: Harshit Gandhi <gandhiharshit716@gmail.com>\n\n* fix(repositories): don't overwrite a \n[…]\nx(scan): gate schema-unsupported stub writes to workload-scoped scans\n\nSigned-off-by: Harshit Gandhi <gandhiharshit716@gmail.com>\n\n---------\n\nSigned-off-by: Harshit Gandhi <gandhiharshit716@gmail.com>",
          "is_bot": false,
          "headline": "fix(scan): classify MANIFEST_SCHEMA_UNSUPPORTED + write per-workload …",
          "author_name": "Harshit Gandhi",
          "author_login": "harshitg927",
          "committed_at": "2026-06-05T06:24:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1a8c15d314f911f45f10c094a40b8efe96f118a",
          "body": "…368)\n\nNewGrypeAdapterFixedDB takes no flag and leaves useDefaultMatchers=false,\nso consumers (e.g. armosec/vulnerability-scanner) that need their tests\nto mirror production matcher mode have no clean way to do it short of\nreflection on the unexported field.\n\nAdd NewGrypeAdapterFixedDBWithMatchers(u\n[…]\nefaultMatchers bool); keep\nthe existing NewGrypeAdapterFixedDB as a thin wrapper passing false so\nno current callers need changes.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(grype): expose useDefaultMatchers on the fixed-DB constructor (#…",
          "author_name": "Jonathan Green",
          "author_login": "jnathangreeg",
          "committed_at": "2026-05-27T14:37:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a154919819a297bb89ff172618abfc39f4ae02ff",
          "body": "- github.com/cilium/cilium v1.17.14 → v1.17.15 (GHSA-gj49-89wh-h4gj)\n- github.com/docker/docker v28.5.0 → v28.5.2 (GHSA-x744-4wpc-v9h2, latest available)\n- golang.org/x/crypto v0.50.0 → v0.52.0 (GO-2026-5005..GO-2026-5033)\n- golang.org/x/net v0.53.0 → v0.55.0 (GO-2026-5025..GO-2026-5030)\n- golang.org/x/sys v0.43.0 → v0.45.0 (GO-2026-5024, also required by x/crypto and x/net)\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): bump dependencies to fix security advisories (#367)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-05-26T16:47:20Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a4dbdbd46db7fdd61fb2333def8556294a4ffe29",
          "body": "…#366)\n\nBumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.19.0 to 5.19.1.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)\n- [Commits](https://github.com/go-git/go-git/compare/v5.19.0...v5.19.\n[…]\nv5\n  dependency-version: 5.19.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T07:51:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "75b632d06e0ce2375cee1685baf7aea912591c98",
          "body": "….32 (#365)\n\nBumps [github.com/containerd/containerd](https://github.com/containerd/containerd) from 1.7.29 to 1.7.32.\n- [Release notes](https://github.com/containerd/containerd/releases)\n- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md)\n- [Commits](https://github.com/con\n[…]\nrd\n  dependency-version: 1.7.32\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/containerd/containerd from 1.7.29 to 1.7…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-26T07:50:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "42e73fc943dabd2a883f6dae15c0c12973adcad4",
          "body": "…364)\n\nvulnerability.Provider embeds io.Closer but the old store was never\nclosed when LoadVulnerabilityDB succeeded on a refresh cycle, leaking\na SQLite file descriptor and its GORM connection resources every 24h.\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: close previous grype DB store before replacing on 24h refresh (#…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-05-19T15:10:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "181f1f2c86494449853befc7ee35d99c01f2cad9",
          "body": "…#363)\n\nBumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.18.0 to 5.19.0.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md)\n- [Commits](https://github.com/go-git/go-git/compare/v5.18.0...v5.19.\n[…]\nv5\n  dependency-version: 5.19.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-12T15:15:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f16d189a2148cab7768d91149e6f189a37f38c52",
          "body": "* refactor: use viper instance with key delimiter for nested config support\n\nSigned-off-by: Mitch Murphy <mitch.murphy@gmail.com>\n\n* feat: add proxyRegistryMap to clusterData.json and update related tests\n\nSigned-off-by: Mitch Murphy <mitch.murphy@gmail.com>\n\n---------\n\nSigned-off-by: Mitch Murphy <mitch.murphy@gmail.com>",
          "is_bot": false,
          "headline": "fix: set viper delim key and test proxyRegistryMap (#361)",
          "author_name": "Mitch Murphy",
          "author_login": "mkm29",
          "committed_at": "2026-05-12T15:15:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9a1a7595b6cc926bf70b8a1b1894c224b3f24b9",
          "body": "…am from 1.7.7 to 1.7.8 (#360)\n\n* chore(deps): Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream\n\nBumps [github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream](https://github.com/aws/aws-sdk-go-v2) from 1.7.7 to 1.7.8.\n- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)\n- [Comm\n[…]\n-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstre…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-07T12:46:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84ce435b422efe49dc9c96d81b7d323081d951e4",
          "body": "* get services from API, removing sidecar requirement\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\n\n# Conflicts:\n#\tgo.mod\n#\tgo.sum\n\n* fix: restore services.json fallback, add 30s timeout to API discovery\n\nservices.json in configDir is now checked first before falling back to\nlive \n[…]\ncom>\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\n\n---------\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "get services from API, removing sidecar requirement (#340)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-05-06T16:08:53Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5b35fdf8f19a72ef50e6a4ca66351ab3ba81c8d4",
          "body": "…#358)\n\n* feat: add riskAcceptance flag for SecurityException CRD integration\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\n\n* fix: improve error handling for partial container profiles in ScanCP\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\n\n---------\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "feat: add riskAcceptance flag for SecurityException CRD integration (…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-05-05T12:24:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c34660adbaa5ad4177e72e0fd4107493d31781c5",
          "body": "* add debug log for grype DB url\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\n\n* Warn if Grype DB root dir is not writable\n\n---------\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "add debug log for grype DB url (#357)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-05-04T13:31:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3745fe5cb054ad52638515efb5560ae44aac4fa6",
          "body": "Signed-off-by: yugal07 <yashsadhwani544@gmail.com>",
          "is_bot": false,
          "headline": "fixing a FIXME (#356)",
          "author_name": "Yugal Sadhwani",
          "author_login": "yugal07",
          "committed_at": "2026-05-04T08:33:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e5178352d3660e6ab94fb7d8d6a5103542de66e",
          "body": "… (#355)\n\n* perf: disable file-digest/metadata/executable catalogers\n\nThese three catalogers iterate every file in the scan tree and dominate\ntransient allocation, but their outputs are not consumed downstream in the\nvulnerability scan pipeline. Disabling them saves ~200 MB peak RSS on\ngitlab-ee and\n[…]\n now disabled, so\n$.files[i] no longer carries digests or metadata keys; update fixtures to\nmatch the slimmer output\nSigned-off-by: Ben <ben@armosec.io>\n\n---------\n\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "perf: switch to kubescape/syft v1.32.0-ks.2 + disable file catalogers…",
          "author_name": "Ben Hirschberg",
          "author_login": "slashben",
          "committed_at": "2026-04-29T13:42:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b420fb22e74ba3149eee5d9a795c829b3d0fe08",
          "body": "…#354)\n\nBumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.17.1 to 5.18.0.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Commits](https://github.com/go-git/go-git/compare/v5.17.1...v5.18.0)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-git/go\n[…]\nv5\n  dependency-version: 5.18.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/go-git/go-git/v5 from 5.17.1 to 5.18.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-21T05:12:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9293523d7c733f47ce86648eb00d0b1363390fb4",
          "body": "* feat: registry proxy/mirror rewriting support\n\nAdd proxyRegistryMap config field and rewriteImageRef helper so image\npulls are redirected through a registry mirror while SBOM annotations\nretain the original image reference.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: \n[…]\ncom>\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\n\n---------\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: registry proxy/mirror rewriting support (#352)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-20T08:18:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7c80e87bccb45db4a2da58a09f5144df1162e78c",
          "body": "* feat: GCP Workload Identity fallback for 401 Unauthorized\n\nWhen Syft gets a 401 pulling from a GCP registry (gcr.io or\n*-docker.pkg.dev), try Application Default Credentials before\nfalling back to anonymous access. This lets the scanner work\ntransparently inside GKE with Workload Identity enabled.\n[…]\n---------\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>\nCo-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat: GCP Workload Identity fallback for 401 Unauthorized (#351)",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-20T08:00:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "12610ceb070f93ebb6292b84f9d4df6076aba210",
          "body": "…lity-exceptions\n\nfix(exceptions): normalize vulnerability ID casing and trim whitespace",
          "is_bot": false,
          "headline": "Merge pull request #353 from kubescape/fix/case-insensitive-vulnerabi…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-20T06:17:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6784e9beec1acc7c328df0a9f45c73643e527f62",
          "body": "grype's vulnerability IDs are case-sensitive and advisory sources do not\nshare a single casing convention: CVE IDs are uppercase while GHSA IDs\nuse a lowercase suffix (e.g. GHSA-jc7w-c686-c4v9). A case-sensitive\nequality check in getCVEExceptionMatchCVENameFromList caused exceptions\nto silently fail\n[…]\noid producing a\nblank policy name that could match unintended vulnerabilities.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix(exceptions): normalize vulnerability ID casing and trim whitespace",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-20T05:57:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e0373b1c25f525db206a7994904ba7211e93189",
          "body": "fix: handle nil storage in relevancy provider initialization",
          "is_bot": false,
          "headline": "Merge pull request #346 from kubescape/no-storage",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-17T15:37:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6270db6fe02e7f655ac9f9d3a5c801f872846db",
          "body": "Fix: enable SecurityException CRDs in keepLocal mode",
          "is_bot": false,
          "headline": "Merge pull request #349 from kubescape/fix/security-exception-keeplocal",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-17T15:37:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47985c94389677f935bc68a07e3b46e8f6ce831a",
          "body": "chore(deps): update docker/cli to v29.2.0",
          "is_bot": false,
          "headline": "Merge pull request #350 from kubescape/fix/dependabot-security-bumps",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-17T12:25:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6848b9001ea9124349181def5cd13104d2a1b32",
          "body": "…ESummary\n\n- TestApplySecurityExceptions_ExpiredOnFix now sets Actions: [Ignore]\n  so it actually tests expiredOnFix behavior, not the action check\n- Add comment explaining why StoreCVESummary uses original cve + filteredCvep\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: ExpiredOnFix test now sets Ignore action, add comment at StoreCV…",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-17T12:16:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a4472d4ac0050bd5c6e1e3a76ae086ec40a0feaf",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "chore(deps): update docker/cli to v29.2.0",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-17T12:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01b049f88fbe9079ff6d5f74fe622749f06e71e1",
          "body": "…eck Ignore action\n\n- applyExceptionsToManifest returns a filtered copy, preserving the\n  original for SubmitCVE (cloud reports keep ExceptionApplied metadata)\n- Cache-hit branches only re-store when exceptions actually changed\n  the manifest (avoids unnecessary writes, preserves relevancy data)\n- A\n[…]\nion before filtering\n- Use context.WithoutCancel instead of context.Background for CRD listing\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: address review — deep-copy for storage, restore cache guards, ch…",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-17T11:23:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd3d66684d908faf6844e44730bbeb0ee99178f3",
          "body": "The scan context may be canceled by rate limiting before the dynamic\nclient completes the CRD listing. Use a detached context with a 30s\ntimeout for SecurityException listing.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: use detached context for CRD listing to avoid context cancellation",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-16T21:12:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "de9ce5c504c40a8bba2393effa507a8f7a5ac220",
          "body": "The dynamic client for SecurityException CRDs shares the default\nrate limiter (QPS=5) with the typed client, causing context canceled\nerrors during concurrent scans. Give it a dedicated config with\nhigher QPS/Burst limits.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: increase QPS for dynamic client to avoid rate limiting",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-16T21:09:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f57f6af729896f586e4ee3bf0de32f8a01ff4a51",
          "body": "The ScanCVE and ScanCP methods skip the CVE scan when a cached manifest\nexists, which also skipped exception filtering. Now exceptions are\napplied to cached manifests too, and the filtered result is re-stored.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: also apply exceptions to cached CVE manifests",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-16T21:05:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3c05ab2d8fe2903805afa7cd4fec9df25f3cac55",
          "body": "Calls platform.GetCVEExceptions and filters GrypeDocument.Matches\nbefore StoreCVE/StoreCVESummary. Excepted CVEs move to IgnoredMatches.\nApplies to all three scan paths: full CVE, filtered CVE, and ScanCVE.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "feat: apply SecurityExceptions before storing vulnerability manifests",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-16T21:00:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1b05cb6a80f258d9593276198cc9ec3db2b1a2d7",
          "body": "Moves excepted CVEs from GrypeDocument.Matches to IgnoredMatches\nwith AppliedIgnoreRules for audit trail. Respects expiredOnFix.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "feat: add ApplySecurityExceptions to filter stored manifests",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-16T20:59:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "615784cd3deb58b1a71b5ae30941ad52835010aa",
          "body": "MockPlatform.GetCVEExceptions() was returning empty, bypassing\nSecurityException CRDs when kubevuln runs without cloud credentials.\n\n- Add SecurityExceptionRepository to MockPlatform\n- Lift seRepo initialization before the keepLocal/cloud branch\n- Export ConvertToVulnerabilityExceptionPolicies for c\n[…]\nis a no-op. This will be addressed when the operator watcher triggers\nfull rescans in Phase 2.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: enable SecurityException CRDs in keepLocal mode",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-16T20:34:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da240195cc800ba5a458fb054de157b93036fbeb",
          "body": "chore(deps): fix dependabot security alerts (aws-sdk-go-v2, go-jose)",
          "is_bot": false,
          "headline": "Merge pull request #348 from kubescape/fix/dependabot-security-bumps",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-16T13:37:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d58f1bf6bbb64c94428cee3581a92851300dec6",
          "body": "…egration\n\nIntegrate SecurityException CRDs into vulnerability scanning",
          "is_bot": false,
          "headline": "Merge pull request #342 from kubescape/feature/security-exception-int…",
          "author_name": "Ben Hirschberg",
          "author_login": "slashben",
          "committed_at": "2026-04-16T12:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58f95add22ae7299afb6072a2277f5ef5e3ab4ac",
          "body": "…lerts\n\n- aws/protocol/eventstream v1.7.7 -> v1.7.8 (DoS via EventStream panic, #107)\n- aws-sdk-go-v2/service/s3 v1.97.1 -> v1.97.3 (same CVE, #108)\n- go-jose/go-jose/v4 v4.1.3 -> v4.1.4 (panic in JWE decryption, #98)\n\nSkipped syft and grype bumps (coordinated separately with backend).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "chore(deps): bump aws-sdk-go-v2, go-jose to fix dependabot security a…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-16T12:33:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "da3cf562e30fef8bcd06c8ec3193c06f24efcf1d",
          "body": "chore(deps): update go-logger to v0.0.28",
          "is_bot": false,
          "headline": "Merge pull request #347 from kubescape/bump",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-16T07:04:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edf135f64e57242594d95ee03923ef9336f32598",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "chore(deps): update go-logger to v0.0.28",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-16T06:47:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e4cc5516ce3c68047901f9aa61c7944cb9ce38e6",
          "body": "- Add fakedynamic.NewSimpleDynamicClient to NewFakeAPIServerStorage\n- Move NoOpSecurityExceptionRepository from adapters/v1 to repositories\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: add fake DynamicClient, move NoOp to repositories",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-15T17:42:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "72bc6a5473812f51f06a08178a07e7d52fc5ed97",
          "body": "Resolve go.mod/go.sum conflicts by accepting main's dependency\nversions and running go mod tidy.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Merge branch 'main' into feature/security-exception-integration",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-15T16:16:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "667b29a2b7d9686633dc44a1b1b2caf0d1664d0c",
          "body": "Signed-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "fix: handle nil storage in relevancy provider initialization",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-15T15:22:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "999792fa99c7c515e1890b63aa5e057f627e3b61",
          "body": "…ection\n\n- Move CRD fetching from adapter to repositories/apiserver.go\n- Use runtime.DefaultUnstructuredConverter instead of JSON round-trip\n- Rename types from v1 to v1beta1 (new API, may evolve)\n- Replace setter+nil-check with constructor injection\n- Add NoOpSecurityExceptionRepository for test/lo\n[…]\neful degradation: CRD list errors log warning, return empty\n- Skip empty-attribute designators\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "refactor: address review - repository layer, v1beta1, constructor inj…",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-15T10:14:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "22779762eea47287d81eaced20609bc242f2d1d4",
          "body": "Define CRD types locally in pkg/securityexception/v1/ instead of\nimporting from kubescape/storage. This avoids the aggregated API vs\nCRD confusion — types are plain Go structs with JSON tags, no scheme\nregistration, no deepcopy generation, no codegen.\n\n- Add pkg/securityexception/v1/types.go with al\n[…]\ngo.mod replace directive for storage\n\nCloses dependency on kubescape/storage#309 (now closed).\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "refactor: move SecurityException types from storage to local package",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-14T18:26:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c9b1314b13db66fafe9d1f4627cdae07499a3766",
          "body": "…om/hashicorp/go-getter-1.8.6\n\nchore(deps): Bump github.com/hashicorp/go-getter from 1.7.9 to 1.8.6",
          "is_bot": false,
          "headline": "Merge pull request #343 from kubescape/dependabot/go_modules/github.c…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-14T11:57:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd4ca5c43268762a49a05aaeb405623e8e4c3fdb",
          "body": "Bumps [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter) from 1.7.9 to 1.8.6.\n- [Release notes](https://github.com/hashicorp/go-getter/releases)\n- [Commits](https://github.com/hashicorp/go-getter/compare/v1.7.9...v1.8.6)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/hashicorp/go-getter\n  dependency-version: 1.8.6\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): Bump github.com/hashicorp/go-getter from 1.7.9 to 1.8.6",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-14T07:04:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c44bd451ffdfbfbda853e40857a8df23c835feb2",
          "body": "Implement adapter to fetch SecurityException and ClusterSecurityException\nCRDs from the cluster and merge them into the existing CVE exception\npipeline. This enables GitOps-native vulnerability risk acceptance using\nKubernetes custom resources.\n\n- Task 9: SecurityExceptionAdapter with dynamic client\n[…]\nons in GetCVEExceptions()\n- Task 11: Startup wiring in cmd/http/main.go with graceful fallback\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Add SecurityException CRD integration for vulnerability scanning",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-12T11:27:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "09085ccb3131be770615aa649a3b33aacf769c2f",
          "body": "…-design\n\nAdd SecurityException CRD design doc and review",
          "is_bot": false,
          "headline": "Merge pull request #341 from kubescape/feature/security-exception-crd…",
          "author_name": "Ben Hirschberg",
          "author_login": "slashben",
          "committed_at": "2026-04-12T06:16:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d664f77644532dcf916116d31eb6d801a5aed8b",
          "body": "- Replace status.conditions reference with Events (no status subresource)\n- Clarify expiry controller triggers rescans, not status writes\n- Add language identifier to fenced code block\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Fix contradictions in design doc flagged by CodeRabbitAI review",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-12T06:13:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a680ba4cdee38c3297fc688a1ec3d718bec85a67",
          "body": "Design document for GitOps-native SecurityException CRD (kubescape.io/v1)\nthat provides declarative, in-cluster exception management for vulnerability\nand posture findings. Includes review notes with resolutions.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "Add SecurityException CRD design doc and review",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-04-09T10:36:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "220f08eb4ed676a3500cd840e56e21bbc2cd13c1",
          "body": "…reporting\n\nfeat: add scan failure reporting (SUB-7105)",
          "is_bot": false,
          "headline": "Merge pull request #334 from kubescape/feature/SUB-7105-scan-failure-…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-02T06:36:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6d8e5025045278c278807e061ec8a712e8d3c01",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: pin armoapi-go to v0.0.694 release",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:51:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f26d3cd2201b3262deaa1be04d5d620c6c93fc1d",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: pin armoapi-go to PR #625 commit (reason codes + Error field)",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:51:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9d017d61a4c594e213f55f999adbec19aa4cfb9f",
          "body": "Rebase onto main (includes PR #335 sidecar adapter). New classifiers:\n- ErrScannerCrashed → ReasonScannerOOMKilled (via errors.Is)\n- context.DeadlineExceeded → ReasonScanTimeout\n- TooLarge + \"scanner OOM\" annotation → ReasonScannerOOMKilled\n  (classifySBOMStatusWithAnnotation for sidecar crash-exhausted images)\n\nBump armoapi-go to pick up new reason codes.\n19 classifier tests + 6 adapter tests pass.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n# Conflicts:\n#\tgo.mod",
          "is_bot": false,
          "headline": "feat: add sidecar OOM/timeout classification, rebase on main",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:51:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9a051755dd3a3be06f27c7f5c2cdb7708588af39",
          "body": "Replace pseudo-version with release tag for scan failure reason\ncodes and ReasonFriendlyText().\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: bump armoapi-go to v0.0.692 (release tag)",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "baa9449ebacada89c2cd1b316385332f36269c33",
          "body": "Update armoapi-go to 4952f80 which changes Reason* constants from\nhuman-friendly text to short codes. No code changes — kubevuln\nalready uses constants by name.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: bump armoapi-go to use enum reason codes",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1fd8fc0ae8c1fc92501696f45a9df121154f31d0",
          "body": "Address CodeRabbit review: classifySBOMError now catches \"403 Forbidden\"\nin the string-based fallback path alongside \"401 Unauthorized\".\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: add 403 Forbidden string fallback in SBOM error classifier",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "52a2d23a24ae29eef108728f2809564bc1b5ac36",
          "body": "Replace raw error strings in FailureReason with human-friendly constants\nfrom scanfailure.Reason*. Add separate Error field for raw R&D debugging.\n\n- Add classifySBOMError() using errors.As(*transport.Error) for auth\n  failures, with string-based fallbacks for MANIFEST_UNKNOWN\n- Add classifySBOMStat\n[…]\nus-based failures pass nil scanErr (no synthetic errors)\n- 11 classifier tests + 6 adapter tests (including HTTP non-2xx coverage)\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: structured failure reasons with error classification",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a8b3f3039abdec524adb27df5d25b7d0b1514df7",
          "body": "The careportreceiver endpoint is /k8s/v2/scanFailure, not\n/k8s/v2/vulnScanFailure. Fixed URL and test assertion.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: correct scan failure endpoint URL",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4b9bd01e3f3c400403094b40317f0ef1520dbab5",
          "body": "- Check HTTP status code and drain response body before close\n- Use identifiers.AttributeRegistryName constant instead of raw string\n- Instrument GenerateSBOM with ReportScanFailure at failure points\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: address code review findings in ReportScanFailure",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dfbe2d091a39438a846ce5aac36eea341dfd2a87",
          "body": "kubevuln doesn't expose a /metrics endpoint, so the counter would\nnever be scraped. Structured logging is sufficient for observability.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor: remove unused Prometheus counter from ReportScanFailure",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0cdc9d06e498bcf0ff56978c7ac1fb85e433caf7",
          "body": "Add ReportScanFailure to the Platform interface to send structured\nScanFailureReport payloads to POST /k8s/v2/vulnScanFailure when\nvulnerability scans fail.\n\n- BackendAdapter builds ScanFailureReport with Workloads list,\n  ImageHash, JobID, ContainerName; detects registry scans via Args\n- Instrument\n[…]\nn_failure_report_errors_total\n- 4 unit tests covering workload scan, registry scan, missing context,\n  and HTTP error scenarios\n\nJira: SUB-7105\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add scan failure reporting to Platform port",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e6bf26ed2df3d4115925f794d278bb25735bb8fe",
          "body": "Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: update armoapi-go to v0.0.689",
          "author_name": "kooomix",
          "author_login": "kooomix",
          "committed_at": "2026-04-02T05:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "57314bfd401a0eae644709cbc3607b49fe55009a",
          "body": "add test coverage for filterSBOM including dynamicpathdetector.DynamicIdentifier",
          "is_bot": false,
          "headline": "Merge pull request #339 from kubescape/test-dynamic-filepath",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-01T16:20:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8b26373b51f9e29303e6800b815d23f90cee6b65",
          "body": "…cIdentifier\n\nSigned-off-by: Matthias Bertschy <matthias.bertschy@gmail.com>",
          "is_bot": false,
          "headline": "add test coverage for filterSBOM including dynamicpathdetector.Dynami…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-01T16:01:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c79a3e61b8a99fce949aacff7f1b4e272c9511d",
          "body": "…om/cilium/cilium-1.17.14\n\nBump github.com/cilium/cilium from 1.16.17 to 1.17.14",
          "is_bot": false,
          "headline": "Merge pull request #338 from kubescape/dependabot/go_modules/github.c…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-01T13:53:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9f8cbc075bf3a5704f5374beefe4cb1417cfbdc",
          "body": "Bumps [github.com/cilium/cilium](https://github.com/cilium/cilium) from 1.16.17 to 1.17.14.\n- [Release notes](https://github.com/cilium/cilium/releases)\n- [Changelog](https://github.com/cilium/cilium/blob/1.17.14/CHANGELOG.md)\n- [Commits](https://github.com/cilium/cilium/compare/1.16.17...1.17.14)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/cilium/cilium\n  dependency-version: 1.17.14\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump github.com/cilium/cilium from 1.16.17 to 1.17.14",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T13:24:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1e1ba81309691b267ec852dc9fdd43e72c1b31a",
          "body": "…om/go-git/go-git/v5-5.17.1\n\nBump github.com/go-git/go-git/v5 from 5.16.5 to 5.17.1",
          "is_bot": false,
          "headline": "Merge pull request #337 from kubescape/dependabot/go_modules/github.c…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-04-01T13:22:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "66118b75cf5aab3cdb29041ff7aba467d50e111e",
          "body": "Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.16.5 to 5.17.1.\n- [Release notes](https://github.com/go-git/go-git/releases)\n- [Commits](https://github.com/go-git/go-git/compare/v5.16.5...v5.17.1)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/go-git/go-git/v5\n  dependency-version: 5.17.1\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump github.com/go-git/go-git/v5 from 5.16.5 to 5.17.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-04-01T12:38:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91720fba4f0582bc7d3ce67b942d2f69371af111",
          "body": "…olang.org/grpc-1.79.3\n\nBump google.golang.org/grpc from 1.74.0 to 1.79.3",
          "is_bot": false,
          "headline": "Merge pull request #336 from kubescape/dependabot/go_modules/google.g…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-03-29T19:20:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b5f425ab57f1f8eec3bbf98e5b3e52a71b4a57a",
          "body": "feat: SBOM scanner sidecar for memory-isolated SBOM generation",
          "is_bot": false,
          "headline": "Merge pull request #335 from kubescape/feature/sbom-scanner-sidecar",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-03-29T09:04:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e6ed3f08fdf51a804b3d7a11213ebc5f9ddc740",
          "body": "The platform variable was computed but never passed to any of the three\nsyft.GetSource() calls, breaking multi-arch image resolution. Parse the\nplatform string into an image.Platform and pass it via WithPlatform().\n\nAlso document the known Syft limitation where cataloguers ignore context\ncancellation (anchore/syft#3705).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "fix: pass platform to syft.GetSource for multi-arch image resolution",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-03-27T11:16:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ed21457ea0a63ab13b65863252ef2e4dfd78773a",
          "body": "Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.74.0 to 1.79.3.\n- [Release notes](https://github.com/grpc/grpc-go/releases)\n- [Commits](https://github.com/grpc/grpc-go/compare/v1.74.0...v1.79.3)\n\n---\nupdated-dependencies:\n- dependency-name: google.golang.org/grpc\n  dependency-version: 1.79.3\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump google.golang.org/grpc from 1.74.0 to 1.79.3",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-03-25T10:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36cd416631edaa617ab114fd0c4ea2540959e89e",
          "body": "Kubevuln OOM-kills when Syft generates SBOMs for large container images,\ncrashing the entire pod and losing Grype DB state + in-flight scans.\n\nThis adds an opt-in sidecar container that runs Syft in a separate memory\ncgroup, following the same pattern implemented for node-agent (PR #753).\n\n- gRPC se\n[…]\nkward compatible: without SBOM_SCANNER_SOCKET env var, kubevuln\n  uses the in-process SyftAdapter as before\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Ben <ben@armosec.io>",
          "is_bot": false,
          "headline": "feat: add SBOM scanner sidecar for memory-isolated SBOM generation",
          "author_name": "Ben",
          "author_login": "slashben",
          "committed_at": "2026-03-23T19:20:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "736e887f5fb0deb37dfc6582fabce75805ce7586",
          "body": "…elemetry.io/otel/sdk-1.40.0\n\nBump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0",
          "is_bot": false,
          "headline": "Merge pull request #331 from kubescape/dependabot/go_modules/go.opent…",
          "author_name": "Matthias Bertschy",
          "author_login": "matthyx",
          "committed_at": "2026-03-03T20:46:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 160,
      "latest_release_at": "2026-07-21T12:13:28Z",
      "latest_release_tag": "v0.3.159",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 38,
      "days_since_latest_release": 11,
      "mean_days_between_releases": 6.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/kubescape/kubevuln",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/kubescape/kubevuln",
          "is_deprecated": false,
          "latest_version": "v0.3.159",
          "repository_url": "https://github.com/kubescape/kubevuln",
          "versions_count": 130,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-21T12:06:49Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 11
        }
      ]
    },
    "popularity": {
      "forks": 35,
      "stars": 26,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2022-09-14",
            "count": 1
          },
          {
            "date": "2022-09-17",
            "count": 1
          },
          {
            "date": "2022-09-27",
            "count": 1
          },
          {
            "date": "2022-10-05",
            "count": 1
          },
          {
            "date": "2022-12-25",
            "count": 1
          },
          {
            "date": "2022-12-29",
            "count": 1
          },
          {
            "date": "2023-01-30",
            "count": 1
          },
          {
            "date": "2023-02-21",
            "count": 1
          },
          {
            "date": "2023-03-12",
            "count": 1
          },
          {
            "date": "2023-03-13",
            "count": 1
          },
          {
            "date": "2023-05-30",
            "count": 1
          },
          {
            "date": "2023-06-03",
            "count": 2
          },
          {
            "date": "2023-06-24",
            "count": 1
          },
          {
            "date": "2023-07-02",
            "count": 1
          },
          {
            "date": "2023-07-25",
            "count": 1
          },
          {
            "date": "2024-06-06",
            "count": 1
          },
          {
            "date": "2025-01-22",
            "count": 1
          },
          {
            "date": "2025-04-04",
            "count": 1
          },
          {
            "date": "2025-05-14",
            "count": 1
          },
          {
            "date": "2025-06-18",
            "count": 1
          },
          {
            "date": "2026-01-27",
            "count": 1
          },
          {
            "date": "2026-04-21",
            "count": 1
          },
          {
            "date": "2026-05-07",
            "count": 1
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-27",
            "count": 1
          },
          {
            "date": "2026-07-28",
            "count": 1
          },
          {
            "date": "2026-07-29",
            "count": 3
          },
          {
            "date": "2026-07-30",
            "count": 1
          },
          {
            "date": "2026-08-01",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 35,
        "total_forks": 35
      },
      "star_history": null,
      "open_issues_and_prs": 21
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "pkg/sbomscanner/v1/proto/scanner.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 51686,
      "source_files_sampled": 70,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.80.0",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf",
              "GO-2026-6061"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 2,
            "oldest_advisory_days": 10
          },
          {
            "name": "github.com/distribution/distribution",
            "direct": true,
            "version": "v2.8.2+incompatible",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3p65-76g6-3w7r",
              "GHSA-6pjf-3r9x-m592",
              "GHSA-f2g3-hh2r-cwgc",
              "GO-2025-3460",
              "GO-2026-5094",
              "GO-2026-5185"
            ],
            "fixed_version": "3.1.1",
            "advisory_count": 6,
            "oldest_advisory_days": 516
          },
          {
            "name": "github.com/docker/docker",
            "direct": true,
            "version": "v28.5.2+incompatible",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-pxq6-2prw-chj9",
              "GHSA-rg2x-37c3-w2rh",
              "GHSA-vp62-88p7-qqf5",
              "GHSA-x744-4wpc-v9h2",
              "GHSA-x86f-5xw2-fm2r",
              "GO-2026-4883",
              "GO-2026-4887",
              "GO-2026-5617",
              "GO-2026-5668",
              "GO-2026-5746"
            ],
            "fixed_version": "29.3.1",
            "advisory_count": 10,
            "oldest_advisory_days": 127
          },
          {
            "name": "github.com/anchore/grype",
            "direct": true,
            "version": "v0.99.1",
            "severity": "moderate",
            "ecosystem": "go",
            "cvss_score": 6.2,
            "advisory_ids": [
              "GHSA-6gxw-85q2-q646",
              "GO-2025-4160"
            ],
            "fixed_version": "0.104.1",
            "advisory_count": 2,
            "oldest_advisory_days": 249
          },
          {
            "name": "github.com/nwaples/rardecode",
            "direct": false,
            "version": "v1.1.3",
            "severity": "moderate",
            "ecosystem": "go",
            "cvss_score": 5.3,
            "advisory_ids": [
              "GHSA-rwvp-r38j-9rgg",
              "GO-2025-4020"
            ],
            "fixed_version": "2.2.0",
            "advisory_count": 2,
            "oldest_advisory_days": 295
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.43.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5158"
            ],
            "fixed_version": "1.44.0",
            "advisory_count": 1,
            "oldest_advisory_days": 8
          },
          {
            "name": "github.com/containerd/containerd",
            "direct": false,
            "version": "v1.7.33",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5064",
              "GO-2026-5338",
              "GO-2026-5622"
            ],
            "fixed_version": "2.3.2",
            "advisory_count": 3,
            "oldest_advisory_days": 40
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.5",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5841"
            ],
            "fixed_version": "1.18.7",
            "advisory_count": 1,
            "oldest_advisory_days": 5
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.52.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 24
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5942"
            ],
            "fixed_version": "0.56.0",
            "advisory_count": 1,
            "oldest_advisory_days": 18
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.37.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 18
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 2,
          "unknown": 6,
          "critical": 1,
          "moderate": 2
        },
        "advisory_count": 30,
        "affected_count": 11,
        "assessed_count": 445,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 5
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/DmitriyVTitov/size",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/Masterminds/semver/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.4.0"
        },
        {
          "name": "github.com/adrg/xdg",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.3"
        },
        {
          "name": "github.com/akyoto/cache",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.6"
        },
        {
          "name": "github.com/anchore/clio",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250715152405-a0fa658e5084"
        },
        {
          "name": "github.com/anchore/grype",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.99.1"
        },
        {
          "name": "github.com/anchore/stereoscope",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.9"
        },
        {
          "name": "github.com/anchore/syft",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.0"
        },
        {
          "name": "github.com/aquilax/truncate",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/armosec/armoapi-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.718"
        },
        {
          "name": "github.com/armosec/utils-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.58"
        },
        {
          "name": "github.com/armosec/utils-k8s-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.35"
        },
        {
          "name": "github.com/cenkalti/backoff/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.0.3"
        },
        {
          "name": "github.com/deckarep/golang-set/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.7.0"
        },
        {
          "name": "github.com/distribution/distribution",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.8.2+incompatible"
        },
        {
          "name": "github.com/docker/docker",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v28.5.2+incompatible"
        },
        {
          "name": "github.com/eapache/go-resiliency",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.0"
        },
        {
          "name": "github.com/gammazero/workerpool",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.3"
        },
        {
          "name": "github.com/gin-gonic/gin",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.1"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-containerregistry",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.6"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/hashicorp/go-multierror",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.1"
        },
        {
          "name": "github.com/kinbiko/jsonassert",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/kubescape/backend",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.40"
        },
        {
          "name": "github.com/kubescape/go-logger",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.33"
        },
        {
          "name": "github.com/kubescape/k8s-interface",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.214"
        },
        {
          "name": "github.com/kubescape/storage",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.258"
        },
        {
          "name": "github.com/opencontainers/go-digest",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/openvex/go-vex",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.5"
        },
        {
          "name": "github.com/spf13/viper",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.21.0"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.38.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "golang.org/x/mod",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.80.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "k8s.io/utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260319190234-28399d86e0b5"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.38.2"
        },
        {
          "name": "schneider.vip/problem",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/adrg/xdg",
            "direct": true,
            "version": "v0.5.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/akyoto/cache",
            "direct": true,
            "version": "v1.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/clio",
            "direct": true,
            "version": "v0.0.0-20250715152405-a0fa658e5084",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/grype",
            "direct": true,
            "version": "v0.99.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aquilax/truncate",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/armosec/armoapi-go",
            "direct": true,
            "version": "v0.0.718",
            "ecosystem": "go"
          },
          {
            "name": "github.com/armosec/utils-go",
            "direct": true,
            "version": "v0.0.58",
            "ecosystem": "go"
          },
          {
            "name": "github.com/armosec/utils-k8s-go",
            "direct": true,
            "version": "v0.0.35",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": true,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/deckarep/golang-set/v2",
            "direct": true,
            "version": "v2.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/distribution/distribution",
            "direct": true,
            "version": "v2.8.2+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dmitriyvtitov/size",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/docker",
            "direct": true,
            "version": "v28.5.2+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/eapache/go-resiliency",
            "direct": true,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gammazero/workerpool",
            "direct": true,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gin-gonic/gin",
            "direct": true,
            "version": "v1.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-multierror",
            "direct": true,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kinbiko/jsonassert",
            "direct": true,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kubescape/backend",
            "direct": true,
            "version": "v0.0.40",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kubescape/go-logger",
            "direct": true,
            "version": "v0.0.33",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kubescape/k8s-interface",
            "direct": true,
            "version": "v0.0.214",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kubescape/storage",
            "direct": true,
            "version": "v0.0.258",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masterminds/semver/v3",
            "direct": true,
            "version": "v3.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/go-digest",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openvex/go-vex",
            "direct": true,
            "version": "v0.2.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/viper",
            "direct": true,
            "version": "v1.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go",
            "direct": true,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin",
            "direct": true,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.80.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": true,
            "version": "v0.0.0-20260319190234-28399d86e0b5",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.38.2",
            "ecosystem": "go"
          },
          {
            "name": "schneider.vip/problem",
            "direct": true,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.1",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go",
            "direct": false,
            "version": "v0.123.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/auth",
            "direct": false,
            "version": "v0.18.2",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/auth/oauth2adapt",
            "direct": false,
            "version": "v0.2.8",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/compute/metadata",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/container",
            "direct": false,
            "version": "v1.45.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/iam",
            "direct": false,
            "version": "v1.5.3",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/monitoring",
            "direct": false,
            "version": "v1.24.3",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/storage",
            "direct": false,
            "version": "v1.61.3",
            "ecosystem": "go"
          },
          {
            "name": "cyphar.com/go-pathrs",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "dario.cat/mergo",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/acobaugh/osrelease",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/adalogics/go-fuzz-headers",
            "direct": false,
            "version": "v0.0.0-20240806141605-e8a1dd7889d6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/adamkorcz/go-118-fuzz-build",
            "direct": false,
            "version": "v0.0.0-20250520111509-a70c2aa677fa",
            "ecosystem": "go"
          },
          {
            "name": "github.com/agext/levenshtein",
            "direct": false,
            "version": "v1.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/agnivade/levenshtein",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/archiver/v3",
            "direct": false,
            "version": "v3.5.3-0.20241210171143-5b1d8d1c7c51",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/fangs",
            "direct": false,
            "version": "v0.0.0-20250716230140-94c22408c232",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-collections",
            "direct": false,
            "version": "v0.0.0-20241211140901-567f400e9a46",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-homedir",
            "direct": false,
            "version": "v0.0.0-20250319154043-c29668562e4d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-logger",
            "direct": false,
            "version": "v0.0.0-20250318195838-07ae343dd722",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-lzo",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-macholibre",
            "direct": false,
            "version": "v0.0.0-20250320151634-807da7ad2331",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-rpmdb",
            "direct": false,
            "version": "v0.0.0-20250516171929-f77691e1faec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-struct-converter",
            "direct": false,
            "version": "v0.0.0-20250211213226-cce56d595160",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-sync",
            "direct": false,
            "version": "v0.0.0-20250714163430-add63db73ad1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/go-version",
            "direct": false,
            "version": "v1.2.2-0.20210903204242-51efa5b487c4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anchore/packageurl-go",
            "direct": false,
            "version": "v0.1.1-0.20250220190351-d62adb6e1115",
            "ecosystem": "go"
          },
          {
            "name": "github.com/andybalholm/brotli",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/apparentlymart/go-textseg/v15",
            "direct": false,
            "version": "v15.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aquasecurity/go-pep440-version",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aquasecurity/go-version",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/armosec/gojay",
            "direct": false,
            "version": "v1.2.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/asaskevich/govalidator",
            "direct": false,
            "version": "v0.0.0-20230301143203-a9d515a09cc2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": false,
            "version": "v1.41.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream",
            "direct": false,
            "version": "v1.7.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": false,
            "version": "v1.32.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": false,
            "version": "v1.19.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.21",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.21",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/ini",
            "direct": false,
            "version": "v1.8.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.22",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ecr",
            "direct": false,
            "version": "v1.45.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/eks",
            "direct": false,
            "version": "v1.48.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/iam",
            "direct": false,
            "version": "v1.53.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/checksum",
            "direct": false,
            "version": "v1.9.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.21",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/s3shared",
            "direct": false,
            "version": "v1.19.21",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/s3",
            "direct": false,
            "version": "v1.97.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.0.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.30.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.35.17",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": false,
            "version": "v1.41.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": false,
            "version": "v1.24.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-osc52/v2",
            "direct": false,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/azcore",
            "direct": false,
            "version": "v1.17.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/azidentity",
            "direct": false,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/internal",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/resourcemanager/authorization/armauthorization",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/resourcemanager/authorization/armauthorization/v2",
            "direct": false,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/resourcemanager/containerservice/armcontainerservice/v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/go-ansiterm",
            "direct": false,
            "version": "v0.0.0-20250102033503-faa5f7b0171c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azuread/microsoft-authentication-library-for-go",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/becheran/wildmatch-go",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bgentry/go-netrc",
            "direct": false,
            "version": "v0.0.0-20140422174119-9fd32a8b3d3d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bitnami/go-version",
            "direct": false,
            "version": "v0.0.0-20250505154626-452e8c5ee607",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blakesmith/ar",
            "direct": false,
            "version": "v0.0.0-20190502131153-809d4375e1fb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blang/semver/v4",
            "direct": false,
            "version": "v4.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bmatcuk/doublestar/v2",
            "direct": false,
            "version": "v2.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bmatcuk/doublestar/v4",
            "direct": false,
            "version": "v4.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bodgit/plumbing",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bodgit/sevenzip",
            "direct": false,
            "version": "v1.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bodgit/windows",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/briandowns/spinner",
            "direct": false,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bytedance/sonic",
            "direct": false,
            "version": "v1.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/lipgloss",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": false,
            "version": "v0.9.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/cellbuf",
            "direct": false,
            "version": "v0.0.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chenzhuoyu/base64x",
            "direct": false,
            "version": "v0.0.0-20221115062448-fe3a3abad311",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cilium/cilium",
            "direct": false,
            "version": "v1.17.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cilium/ebpf",
            "direct": false,
            "version": "v0.17.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudflare/circl",
            "direct": false,
            "version": "v1.6.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cncf/xds/go",
            "direct": false,
            "version": "v0.0.0-20251210132809-ee656c7534f5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/cgroups/v3",
            "direct": false,
            "version": "v3.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/containerd",
            "direct": false,
            "version": "v1.7.33",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/containerd/api",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/continuity",
            "direct": false,
            "version": "v0.4.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs/pkg",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/fifo",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/log",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/platforms",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/stargz-snapshotter/estargz",
            "direct": false,
            "version": "v0.16.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/ttrpc",
            "direct": false,
            "version": "v1.2.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/typeurl/v2",
            "direct": false,
            "version": "v2.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containers/common",
            "direct": false,
            "version": "v0.64.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-oidc/v3",
            "direct": false,
            "version": "v3.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cpuguy83/dockercfg",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cyclonedx/cyclonedx-go",
            "direct": false,
            "version": "v0.9.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cyphar/filepath-securejoin",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/datadog/zstd",
            "direct": false,
            "version": "v1.5.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/deitch/magic",
            "direct": false,
            "version": "v0.0.0-20240306090643-c67ab88f10cb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/diskfs/go-diskfs",
            "direct": false,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/distribution/reference",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/cli",
            "direct": false,
            "version": "v29.2.0+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/distribution",
            "direct": false,
            "version": "v2.8.3+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/docker-credential-helpers",
            "direct": false,
            "version": "v0.9.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-connections",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-events",
            "direct": false,
            "version": "v0.0.0-20250114142523-c867878c5e32",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-units",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dsnet/compress",
            "direct": false,
            "version": "v0.0.2-0.20230904184137-39efe44ab707",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ebitengine/purego",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/elliotchance/phpserialize",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.12.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emirpasic/gods",
            "direct": false,
            "version": "v1.18.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/envoyproxy/go-control-plane/envoy",
            "direct": false,
            "version": "v1.36.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/envoyproxy/protoc-gen-validate",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/facebookincubator/nvdtools",
            "direct": false,
            "version": "v0.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fatih/color",
            "direct": false,
            "version": "v1.19.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/fgprof",
            "direct": false,
            "version": "v0.9.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/francoispqt/gojay",
            "direct": false,
            "version": "v1.2.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gabriel-vasile/mimetype",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gammazero/deque",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gin-contrib/sse",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/github/go-spdx/v2",
            "direct": false,
            "version": "v2.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/glebarez/go-sqlite",
            "direct": false,
            "version": "v1.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/glebarez/sqlite",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/gcfg",
            "direct": false,
            "version": "v1.5.1-0.20230307220236-3a3c6141e376",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/go-billy/v5",
            "direct": false,
            "version": "v5.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-git/go-git/v5",
            "direct": false,
            "version": "v5.19.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ini/ini",
            "direct": false,
            "version": "v1.67.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": false,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ole/go-ole",
            "direct": false,
            "version": "v1.2.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/analysis",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/errors",
            "direct": false,
            "version": "v0.22.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.21.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/loads",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/spec",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/strfmt",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.23.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/validate",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-playground/locales",
            "direct": false,
            "version": "v0.14.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-playground/universal-translator",
            "direct": false,
            "version": "v0.18.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-playground/validator/v10",
            "direct": false,
            "version": "v10.14.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-restruct/restruct",
            "direct": false,
            "version": "v1.2.0-alpha",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobwas/glob",
            "direct": false,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/goccy/go-json",
            "direct": false,
            "version": "v0.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/goccy/go-yaml",
            "direct": false,
            "version": "v1.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gocsaf/csaf/v3",
            "direct": false,
            "version": "v3.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gogo/protobuf",
            "direct": false,
            "version": "v1.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gohugoio/hashstructure",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": false,
            "version": "v5.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/groupcache",
            "direct": false,
            "version": "v0.0.0-20241129210726-2c02b8208cf8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/snappy",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/licensecheck",
            "direct": false,
            "version": "v0.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/pprof",
            "direct": false,
            "version": "v0.0.0-20250630185457-6e76a2b096b5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/s2a-go",
            "direct": false,
            "version": "v0.1.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googleapis/enterprise-certificate-proxy",
            "direct": false,
            "version": "v0.3.14",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googleapis/gax-go/v2",
            "direct": false,
            "version": "v2.17.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googlecloudplatform/opentelemetry-operations-go/detectors/gcp",
            "direct": false,
            "version": "v1.31.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googlecloudplatform/opentelemetry-operations-go/exporter/metric",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googlecloudplatform/opentelemetry-operations-go/internal/resourcemapping",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gookit/color",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/mux",
            "direct": false,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.28.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hako/durafmt",
            "direct": false,
            "version": "v0.0.0-20210608085754-5c1018a4e16b",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/aws-sdk-go-base/v2",
            "direct": false,
            "version": "v2.0.0-beta.72",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/errwrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-cleanhttp",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-getter",
            "direct": false,
            "version": "v1.8.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-version",
            "direct": false,
            "version": "v1.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/golang-lru/v2",
            "direct": false,
            "version": "v2.0.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/hcl/v2",
            "direct": false,
            "version": "v2.24.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/huandu/xstrings",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/iancoleman/strcase",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/intevation/gval",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/intevation/jsonpath",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jbenet/go-context",
            "direct": false,
            "version": "v0.0.0-20150711004518-d14ea06fba99",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/copier",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/inflection",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/now",
            "direct": false,
            "version": "v1.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jmespath/go-jmespath",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kastenhq/goversion",
            "direct": false,
            "version": "v0.0.0-20230811215019-93b2f8823953",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kevinburke/ssh_config",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/cpuid/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/pgzip",
            "direct": false,
            "version": "v1.2.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/knqyf263/go-apk-version",
            "direct": false,
            "version": "v0.0.0-20200609155635-041fdbb8563f",
            "ecosystem": "go"
          },
          {
            "name": "github.com/knqyf263/go-deb-version",
            "direct": false,
            "version": "v0.0.0-20241115132648-6f4aee6ccd23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kubescape/opa-utils",
            "direct": false,
            "version": "v0.0.283",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kubescape/rbac-utils",
            "direct": false,
            "version": "v0.0.21-0.20230806101615-07e36f555520",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kylelemons/godebug",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/leodido/go-urn",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lufia/plan9stats",
            "direct": false,
            "version": "v0.0.0-20211012122336-39d0f177ccd0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mackerelio/go-osstat",
            "direct": false,
            "version": "v0.2.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/magiconair/properties",
            "direct": false,
            "version": "v1.8.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masahiro331/go-mvn-version",
            "direct": false,
            "version": "v0.0.0-20250131095131-f4974fa13b8a",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masterminds/goutils",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masterminds/sprig/v3",
            "direct": false,
            "version": "v3.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": false,
            "version": "v0.1.14",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.21",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mgutz/ansi",
            "direct": false,
            "version": "v0.0.0-20200706080929-d51e80ef957d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mholt/archives",
            "direct": false,
            "version": "v0.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/hcsshim",
            "direct": false,
            "version": "v0.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mikelolasagasti/xz",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/minio/minlz",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/copystructure",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/go-homedir",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/go-wordwrap",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": false,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/reflectwalk",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/docker-image-spec",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/go-archive",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/locker",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/patternmatcher",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/mountinfo",
            "direct": false,
            "version": "v0.7.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/sequential",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/signal",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/user",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/userns",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/term",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/morikuni/aec",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/termenv",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v0.1.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nix-community/go-nix",
            "direct": false,
            "version": "v0.0.0-20250101154619-4bdde671e0a1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nwaples/rardecode",
            "direct": false,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nwaples/rardecode/v2",
            "direct": false,
            "version": "v2.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/olekukonko/errors",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/olekukonko/ll",
            "direct": false,
            "version": "v0.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/olekukonko/tablewriter",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/olvrng/ujson",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oneofone/xxhash",
            "direct": false,
            "version": "v1.2.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/open-policy-agent/opa",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/image-spec",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/runtime-spec",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/selinux",
            "direct": false,
            "version": "v1.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/package-url/packageurl-go",
            "direct": false,
            "version": "v0.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pandatix/go-cvss",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pborman/indent",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml",
            "direct": false,
            "version": "v1.9.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml/v2",
            "direct": false,
            "version": "v2.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/petermattis/goid",
            "direct": false,
            "version": "v0.0.0-20241211131331-93ee7e083c43",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pierrec/lz4/v4",
            "direct": false,
            "version": "v4.1.22",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pjbgf/sha1cd",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/browser",
            "direct": false,
            "version": "v0.0.0-20240102092130-5ac0b6a4141c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/profile",
            "direct": false,
            "version": "v1.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/xattr",
            "direct": false,
            "version": "v0.4.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/planetscale/vtprotobuf",
            "direct": false,
            "version": "v0.6.1-0.20240319094008-0393e58bdf10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/power-devops/perfstat",
            "direct": false,
            "version": "v0.0.0-20210106213030-5aafc221ea8c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.66.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.17.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/protonmail/go-crypto",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rcrowley/go-metrics",
            "direct": false,
            "version": "v0.0.0-20201227073835-cf1acfcdf475",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rust-secure-code/go-rustaudit",
            "direct": false,
            "version": "v0.0.0-20250226111315-e20ec32e963c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sagikazarmark/locafero",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/saintfish/chardet",
            "direct": false,
            "version": "v0.0.0-20230101081208-5e3ef4b5456d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/santhosh-tekuri/jsonschema/v6",
            "direct": false,
            "version": "v6.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sasha-s/go-deadlock",
            "direct": false,
            "version": "v0.3.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sassoftware/go-rpmutils",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/scylladb/go-set",
            "direct": false,
            "version": "v1.0.3-0.20200225121959-cc7b2070d91e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/seccomp/libseccomp-golang",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sergi/go-diff",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shirou/gopsutil/v4",
            "direct": false,
            "version": "v4.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shopspring/decimal",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.9.4-0.20230606125235-dd1b4c2e81af",
            "ecosystem": "go"
          },
          {
            "name": "github.com/skeema/knownhosts",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sorairolake/lzip-go",
            "direct": false,
            "version": "v0.3.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sourcegraph/conc",
            "direct": false,
            "version": "v0.3.1-0.20240121214520-5f936abd7ae8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spdx/gordf",
            "direct": false,
            "version": "v0.0.0-20250128162952-000978ccd6fb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spdx/tools-golang",
            "direct": false,
            "version": "v0.5.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/afero",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": false,
            "version": "v1.10.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spiffe/go-spiffe/v2",
            "direct": false,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/starry-s/zip",
            "direct": false,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stripe/stripe-go/v74",
            "direct": false,
            "version": "v74.30.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/subosito/gotenv",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sylabs/sif/v2",
            "direct": false,
            "version": "v2.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sylabs/squashfs",
            "direct": false,
            "version": "v1.0.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tchap/go-patricia/v2",
            "direct": false,
            "version": "v2.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/therootcompany/xz",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/go-sysconf",
            "direct": false,
            "version": "v0.3.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/numcpus",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/twitchyliquid64/golang-asm",
            "direct": false,
            "version": "v0.15.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ugorji/go/codec",
            "direct": false,
            "version": "v1.2.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ulikunitz/xz",
            "direct": false,
            "version": "v0.5.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uptrace/opentelemetry-go-extra/otelutil",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uptrace/opentelemetry-go-extra/otelzap",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/uptrace/uptrace-go",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vbatts/go-mtree",
            "direct": false,
            "version": "v0.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vbatts/tar-split",
            "direct": false,
            "version": "v0.12.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vifraa/gopom",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vishvananda/netlink",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/vishvananda/netns",
            "direct": false,
            "version": "v0.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/wagoodman/go-partybus",
            "direct": false,
            "version": "v0.0.0-20230516145632-8ccac152c651",
            "ecosystem": "go"
          },
          {
            "name": "github.com/wagoodman/go-progress",
            "direct": false,
            "version": "v0.0.0-20230925121702-07e42b3cdba0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xanzy/ssh-agent",
            "direct": false,
            "version": "v0.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xeipuuv/gojsonpointer",
            "direct": false,
            "version": "v0.0.0-20190905194746-02993c407bfb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xeipuuv/gojsonreference",
            "direct": false,
            "version": "v0.0.0-20180127040603-bd5ef7bd5415",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xi2/xz",
            "direct": false,
            "version": "v0.0.0-20171230120015-48954b6210f8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yashtewari/glob-intersection",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yl2chen/cidranger",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yusufpapurcu/wmi",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zclconf/go-cty",
            "direct": false,
            "version": "v1.16.3",
            "ecosystem": "go"
          },
          {
            "name": "go.etcd.io/bbolt",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "go.mongodb.org/mongo-driver",
            "direct": false,
            "version": "v1.17.7",
            "ecosystem": "go"
          },
          {
            "name": "go.opencensus.io",
            "direct": false,
            "version": "v0.24.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/bridges/otelslog",
            "direct": false,
            "version": "v0.18.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/detectors/gcp",
            "direct": false,
            "version": "v1.39.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
            "direct": false,
            "version": "v0.63.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": false,
            "version": "v0.62.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
            "direct": false,
            "version": "v0.68.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/processors/minsev",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp",
            "direct": false,
            "version": "v0.19.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/log",
            "direct": false,
            "version": "v0.19.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/log",
            "direct": false,
            "version": "v0.19.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": false,
            "version": "v1.27.1",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.3",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "go4.org",
            "direct": false,
            "version": "v0.0.0-20230225012048-214862532bf5",
            "ecosystem": "go"
          },
          {
            "name": "go4.org/netipx",
            "direct": false,
            "version": "v0.0.0-20231129151722-fdeea329fbba",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/arch",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.52.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260410095643-746e56fc9e2f",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.44.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/xerrors",
            "direct": false,
            "version": "v0.0.0-20240903120638-7835f813f4da",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/api",
            "direct": false,
            "version": "v0.271.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto",
            "direct": false,
            "version": "v0.0.0-20260128011058-8636f8732409",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": false,
            "version": "v0.0.0-20260414002931-afd174a4e478",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260414002931-afd174a4e478",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/warnings.v0",
            "direct": false,
            "version": "v0.1.2",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/gorm",
            "direct": false,
            "version": "v1.30.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiserver",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/component-base",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": false,
            "version": "v2.130.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20250910181357-589584f1c912",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.66.3",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/controller-runtime",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 445,
        "direct_count": 42,
        "indirect_count": 403
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 7,
        "merged_prs": 331,
        "open_issues": 14,
        "closed_ratio": 0.714,
        "closed_issues": 35,
        "closed_unmerged_prs": 31
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "matthyx",
          "commits": 362,
          "avatar_url": "https://avatars.githubusercontent.com/u/20683409?v=4"
        },
        {
          "type": "User",
          "login": "slashben",
          "commits": 35,
          "avatar_url": "https://avatars.githubusercontent.com/u/59160382?v=4"
        },
        {
          "type": "User",
          "login": "Daniel-GrunbergerCA",
          "commits": 29,
          "avatar_url": "https://avatars.githubusercontent.com/u/84905812?v=4"
        },
        {
          "type": "User",
          "login": "amirmalka",
          "commits": 27,
          "avatar_url": "https://avatars.githubusercontent.com/u/30172060?v=4"
        },
        {
          "type": "User",
          "login": "rcohencyberarmor",
          "commits": 14,
          "avatar_url": "https://avatars.githubusercontent.com/u/84019060?v=4"
        },
        {
          "type": "User",
          "login": "kooomix",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/26850299?v=4"
        },
        {
          "type": "User",
          "login": "refaelm92",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/34322086?v=4"
        },
        {
          "type": "User",
          "login": "rootp1",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/190367958?v=4"
        },
        {
          "type": "User",
          "login": "AdeshDeshmukh",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/233792877?v=4"
        },
        {
          "type": "User",
          "login": "jnathangreeg",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/175541076?v=4"
        }
      ],
      "contributors_sampled": 19,
      "top_contributor_share": 0.703
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "offline-db.yaml",
        "pr-created.yaml",
        "pr-image.yaml",
        "pr-merged.yaml",
        "scorecard.yml",
        "security-insights.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 9,
            "reason": "22 out of 23 merged PRs checked by a CI test -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 6,
            "reason": "Found 16/23 approved changesets -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 6,
            "reason": "project has 2 contributing companies or organizations -- score normalized to 6",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 9,
            "reason": "SAST tool is not run on all commits -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 9,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "20 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9115f31515f597327864b7f9daeca14d326fee4b",
        "ran_at": "2026-08-01T20:45:44Z",
        "aggregate_score": 6.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-08-01T14:20:30Z",
      "oldest_open_prs": [
        {
          "number": 323,
          "created_at": "2026-01-30T13:05:59Z",
          "last_comment_at": "2026-03-18T18:22:20Z",
          "last_comment_author": "Mujib-Ahasan"
        },
        {
          "number": 392,
          "created_at": "2026-07-29T15:58:02Z",
          "last_comment_at": "2026-07-31T13:34:25Z",
          "last_comment_author": "matthyx"
        },
        {
          "number": 409,
          "created_at": "2026-07-31T18:05:41Z",
          "last_comment_at": "2026-07-31T18:06:32Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 412,
          "created_at": "2026-08-01T09:48:05Z",
          "last_comment_at": "2026-08-01T10:07:09Z",
          "last_comment_author": "bhuvan-somisetty"
        },
        {
          "number": 413,
          "created_at": "2026-08-01T09:55:25Z",
          "last_comment_at": "2026-08-01T09:56:07Z",
          "last_comment_author": "coderabbitai"
        },
        {
          "number": 415,
          "created_at": "2026-08-01T11:01:30Z",
          "last_comment_at": "2026-08-01T14:22:19Z",
          "last_comment_author": "rootp1"
        },
        {
          "number": 417,
          "created_at": "2026-08-01T14:22:02Z",
          "last_comment_at": "2026-08-01T14:22:11Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-08-01T14:19:17Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 322,
          "created_at": "2024-08-28T08:27:35Z",
          "last_comment_at": "2026-01-30T13:08:09Z",
          "last_comment_author": "Mujib-Ahasan"
        },
        {
          "number": 254,
          "created_at": "2024-12-10T14:13:16Z",
          "last_comment_at": "2026-06-01T13:36:16Z",
          "last_comment_author": "yugal07"
        },
        {
          "number": 362,
          "created_at": "2026-05-08T11:08:25Z",
          "last_comment_at": "2026-05-12T13:57:44Z",
          "last_comment_author": "matthyx"
        },
        {
          "number": 369,
          "created_at": "2026-06-01T08:09:57Z",
          "last_comment_at": "2026-06-02T07:21:46Z",
          "last_comment_author": "harshitg927"
        },
        {
          "number": 387,
          "created_at": "2026-07-27T14:56:12Z",
          "last_comment_at": "2026-07-28T09:27:35Z",
          "last_comment_author": "HerambInamke"
        },
        {
          "number": 390,
          "created_at": "2026-07-29T11:42:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 391,
          "created_at": "2026-07-29T11:53:12Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 397,
          "created_at": "2026-07-31T07:19:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 408,
          "created_at": "2026-07-31T18:01:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 410,
          "created_at": "2026-08-01T07:55:57Z",
          "last_comment_at": "2026-08-01T08:07:59Z",
          "last_comment_author": "bhuvan-somisetty"
        },
        {
          "number": 411,
          "created_at": "2026-08-01T09:02:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 414,
          "created_at": "2026-08-01T11:01:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 416,
          "created_at": "2026-08-01T14:21:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 418,
          "created_at": "2026-08-01T20:03:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/kubescape/kubevuln",
    "host": "github.com",
    "name": "kubevuln",
    "owner": "kubescape"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "excellent",
      "name": "Overall health",
      "note": "The weighted overall 72 is calibrated to 86 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 72,
            "calibrated": 86,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 86,
      "inputs": {
        "security": 59,
        "vitality": 94,
        "community": 62,
        "governance": 67,
        "calibration": "2026-08-02",
        "engineering": 74,
        "ai_readiness": 65,
        "weighted_overall_raw": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "exceptional",
        "name": "Vitality",
        "value": 94,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "commits_last_year": 160,
              "human_commit_share": 0.88,
              "days_since_last_push": 0,
              "active_weeks_last_year": 38
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "38/52 weeks with commits",
                "points": 26.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 38
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "160 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 160
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.3.159",
              "releases_from_tags": false,
              "days_since_latest_release": 11,
              "mean_days_between_releases": 6.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 11 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~6.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 6.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 3,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 3 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 62,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "weak",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "forks": 35,
              "stars": 26,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "26 stars",
                "points": 22.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "35 forks",
                "points": 12.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 35
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 67,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "weak",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 19,
              "top_contributor_share": 0.703
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 70% of commits",
                "points": 6.7,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 70
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "19 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 76,
            "inputs": {
              "merged_prs": 331,
              "open_issues": 14,
              "closed_issues": 35,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.714,
              "closed_unmerged_prs": 31,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "71% of issues closed",
                "points": 30,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 71
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "331/362 decided PRs merged",
                "points": 27.4,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 331,
                      "decided": 362
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 16/23 approved changesets -- score normalized to 6",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "followers": 287,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "kubescape",
              "public_repos": 65,
              "account_age_days": 1615
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "287 followers of kubescape",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 287,
                      "login": "kubescape"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "65 public repos, account ~4 yr old",
                "points": 21.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 65
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 4
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/kubescape/kubevuln"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 11
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 11 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 11
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "130 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 130
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 66,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "22 out of 23 merged PRs checked by a CI test -- score normalized to 9",
                "points": 18,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "kubernetes",
                "kubescape",
                "vulnerability-detection",
                "kubescape-helm"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "4 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "22 out of 23 merged PRs checked by a CI test -- score normalized to 9",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 16/23 approved changesets -- score normalized to 6",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 2 contributing companies or organizations -- score normalized to 6",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "20 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "weak",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 445 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 445
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "source": "osv",
              "advisories": 30,
              "affected_packages": 11,
              "assessed_packages": 445,
              "unassessed_packages": 0,
              "affected_by_severity": "critical 1, high 2, moderate 2, unknown 6",
              "direct_affected_packages": 5
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "5 affected: google.golang.org/grpc v1.80.0 (critical 9.1), github.com/distribution/distribution v2.8.2+incompatible (high 7.5), github.com/docker/docker v28.5.2+incompatible (high 8.8), +2 more",
                "points": 5.8,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 5,
                      "packages": "google.golang.org/grpc v1.80.0 (critical 9.1), github.com/distribution/distribution v2.8.2+incompatible (high 7.5), github.com/docker/docker v28.5.2+incompatible (high 8.8)"
                    }
                  },
                  {
                    "code": "advisories_affected_more",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "3 advisory-carrying package(s) unaddressed past 90 days; oldest published 516 days ago",
                "points": 25.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 3,
                      "oldest": 516
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "exceptional",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 445,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 4
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 65,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "weak",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.943,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "83 of 88 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 83,
                      "sampled": 88
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.41,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.12
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "41 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 41,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "12 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 12,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "exceptional",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 51686,
              "source_files_sampled": 70,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/70 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 70,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "weak",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": false,
              "api_schema_files": [
                "pkg/sbomscanner/v1/proto/scanner.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "pkg/sbomscanner/v1/proto/scanner.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "pkg/sbomscanner/v1/proto/scanner.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "top": [
        "application"
      ],
      "labels": [
        "network-service"
      ],
      "scores": {
        "library": 3,
        "network-service": 7
      },
      "primary": "network-service",
      "evidence": [
        {
          "tier": "dependencies",
          "label": "network-service",
          "source": "dep:github.com/gin-gonic/gin",
          "weight": 4
        },
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:go",
          "weight": 3
        },
        {
          "tier": "structure",
          "label": "network-service",
          "source": "api_schema",
          "weight": 3
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": false
    },
    "metrics_version": "2.5.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-01T20:46:08.115546Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/kubescape/kubevuln.svg",
  "full_name": "kubescape/kubevuln",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v2.5.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.