原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": true,
"size_kb": 3914,
"has_wiki": true,
"homepage": "https://stackoverflow.com/questions/tagged/azure-ad-msal+python",
"languages": {
"Shell": 741,
"Python": 763117
},
"pushed_at": "2026-05-29T17:17:45Z",
"created_at": "2026-05-29T22:48:02Z",
"owner_type": "User",
"updated_at": "2026-05-29T22:48:03Z",
"description": "Microsoft Authentication Library (MSAL) for Python makes it easy to authenticate to Microsoft Entra ID. General docs are available here https://learn.microsoft.com/entra/msal/python/ Stable APIs are documented here https://msal-python.readthedocs.io. Questions can be asked on www.stackoverflow.com with tag \"msal\" + \"python\".",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "dev",
"license_spdx_raw": "NOASSERTION",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": null,
"name": "Neha Bhargava",
"type": "User",
"login": "neha-bhargava",
"company": "@microsoft ",
"location": "Redmond, WA",
"followers": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/61847233?v=4",
"created_at": "2020-03-05T19:17:42Z",
"is_verified": null,
"public_repos": 10,
"account_age_days": 2332
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": false
},
"activity": {
"releases": [
{
"tag": "1.36.0",
"kind": "minor",
"published_at": "2026-04-08T18:14:52Z"
},
{
"tag": "1.35.1",
"kind": "patch",
"published_at": "2026-03-04T21:39:36Z"
},
{
"tag": "1.35.0",
"kind": "minor",
"published_at": "2026-02-24T10:43:37Z"
},
{
"tag": "1.34.0",
"kind": "minor",
"published_at": "2025-09-22T22:53:10Z"
},
{
"tag": "1.33.0",
"kind": "minor",
"published_at": "2025-07-22T01:34:10Z"
},
{
"tag": "1.32.3",
"kind": "patch",
"published_at": "2025-04-25T12:39:11Z"
},
{
"tag": "1.32.2",
"kind": "patch",
"published_at": "2025-04-25T01:51:53Z"
},
{
"tag": "1.32.1",
"kind": "patch",
"published_at": "2025-04-24T16:41:04Z"
},
{
"tag": "1.32.0",
"kind": "minor",
"published_at": "2025-03-11T22:49:30Z"
},
{
"tag": "1.31.1",
"kind": "patch",
"published_at": "2024-11-01T04:01:25Z"
},
{
"tag": "1.31.0",
"kind": "minor",
"published_at": "2024-09-06T15:51:45Z"
},
{
"tag": "1.30.0",
"kind": "minor",
"published_at": "2024-07-17T03:51:38Z"
},
{
"tag": "1.29.0",
"kind": "minor",
"published_at": "2024-06-22T01:56:52Z"
},
{
"tag": "1.28.1",
"kind": "patch",
"published_at": "2024-06-11T09:18:48Z"
},
{
"tag": "1.28.0",
"kind": "minor",
"published_at": "2024-03-19T06:48:45Z"
},
{
"tag": "1.27.0",
"kind": "minor",
"published_at": "2024-02-22T20:18:54Z"
},
{
"tag": "1.26.0",
"kind": "minor",
"published_at": "2023-12-05T08:59:20Z"
},
{
"tag": "1.25.0",
"kind": "minor",
"published_at": "2023-11-03T23:47:00Z"
},
{
"tag": "1.24.1",
"kind": "patch",
"published_at": "2023-09-29T07:42:24Z"
},
{
"tag": "1.24.0",
"kind": "minor",
"published_at": "2023-09-12T16:35:03Z"
},
{
"tag": "1.23.0",
"kind": "minor",
"published_at": "2023-07-22T17:08:32Z"
},
{
"tag": "1.22.0",
"kind": "minor",
"published_at": "2023-04-17T16:50:46Z"
},
{
"tag": "1.21.0",
"kind": "minor",
"published_at": "2023-01-31T20:17:14Z"
},
{
"tag": "1.20.0",
"kind": "minor",
"published_at": "2022-10-07T04:49:22Z"
},
{
"tag": "1.19.0",
"kind": "minor",
"published_at": "2022-09-21T04:09:56Z"
},
{
"tag": "1.18.0",
"kind": "minor",
"published_at": "2022-05-31T20:32:08Z"
},
{
"tag": "1.17.0",
"kind": "minor",
"published_at": "2022-02-11T20:13:42Z"
},
{
"tag": "1.16.0",
"kind": "minor",
"published_at": "2021-10-29T22:30:27Z"
},
{
"tag": "1.15.0",
"kind": "minor",
"published_at": "2021-10-01T21:53:34Z"
},
{
"tag": "1.14.0",
"kind": "minor",
"published_at": "2021-08-26T18:41:57Z"
},
{
"tag": "1.13.0",
"kind": "minor",
"published_at": "2021-07-20T22:05:17Z"
},
{
"tag": "1.12.0",
"kind": "minor",
"published_at": "2021-05-19T19:42:11Z"
},
{
"tag": "1.11.0",
"kind": "minor",
"published_at": "2021-04-09T14:55:23Z"
},
{
"tag": "1.10.0",
"kind": "minor",
"published_at": "2021-03-08T20:39:15Z"
},
{
"tag": "1.9.0",
"kind": "minor",
"published_at": "2021-02-09T07:44:35Z"
},
{
"tag": "1.8.0",
"kind": "minor",
"published_at": "2020-12-16T01:51:03Z"
},
{
"tag": "1.7.0",
"kind": "minor",
"published_at": "2020-12-07T17:43:57Z"
},
{
"tag": "1.6.0",
"kind": "minor",
"published_at": "2020-11-02T06:28:09Z"
},
{
"tag": "1.5.1",
"kind": "patch",
"published_at": "2020-10-21T19:48:54Z"
},
{
"tag": "1.5.0",
"kind": "minor",
"published_at": "2020-09-03T21:46:33Z"
},
{
"tag": "1.4.3",
"kind": "patch",
"published_at": "2020-07-25T01:02:55Z"
},
{
"tag": "1.4.2",
"kind": "patch",
"published_at": "2020-07-23T22:22:44Z"
},
{
"tag": "1.4.1",
"kind": "patch",
"published_at": "2020-06-26T21:41:58Z"
},
{
"tag": "1.4.0",
"kind": "minor",
"published_at": "2020-06-25T22:21:47Z"
},
{
"tag": "1.3.0",
"kind": "minor",
"published_at": "2020-05-15T03:23:26Z"
},
{
"tag": "1.2.0",
"kind": "minor",
"published_at": "2020-03-31T19:45:27Z"
},
{
"tag": "1.1.0",
"kind": "minor",
"published_at": "2020-01-23T23:09:09Z"
},
{
"tag": "1.0.0",
"kind": "major",
"published_at": "2019-11-01T23:14:04Z"
},
{
"tag": "0.9.0",
"kind": "minor",
"published_at": "2019-10-31T19:00:13Z"
},
{
"tag": "0.8.0",
"kind": "minor",
"published_at": "2019-10-19T00:10:07Z"
},
{
"tag": "0.7.0",
"kind": "minor",
"published_at": "2019-09-25T22:57:37Z"
},
{
"tag": "0.6.1",
"kind": "patch",
"published_at": "2019-08-13T20:42:29Z"
},
{
"tag": "0.6.0",
"kind": "minor",
"published_at": "2019-07-31T18:52:40Z"
},
{
"tag": "0.5.1",
"kind": "patch",
"published_at": "2019-07-10T22:05:50Z"
},
{
"tag": "0.5.0",
"kind": "minor",
"published_at": "2019-07-08T21:00:22Z"
},
{
"tag": "0.4.1",
"kind": "patch",
"published_at": "2019-06-18T18:05:06Z"
},
{
"tag": "0.4.0",
"kind": "minor",
"published_at": "2019-05-22T19:23:30Z"
},
{
"tag": "0.3.1",
"kind": "patch",
"published_at": "2019-04-16T23:56:32Z"
},
{
"tag": "0.3.0",
"kind": "minor",
"published_at": "2019-04-02T21:55:37Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2019-03-05T21:06:19Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2018-12-12T19:28:13Z"
}
],
"recent_commits": [
{
"oid": "ebb980f1636e1b3a097ec6dbfd197fb88c5b9e7a",
"body": null,
"is_bot": false,
"headline": "Update version to 1.37.0 (#922)",
"author_name": "Avery-Dunn",
"author_login": "Avery-Dunn",
"committed_at": "2026-05-29T17:17:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c504b419a5a604a761d80d3f46365077ed8e6a21",
"body": "…(#895)\n\n* Add ADO pipeline hyperlinks to CI-AND-RELEASE-PIPELINES.md\n\n* Add Python 3.8 to ADO CI matrix\n\n* Move benchmarks from GH Actions to ADO; remove cb job from GH workflow\n\n* Remove GH Actions CI/CD workflow — tests and publish fully covered by ADO pipelines 3064 and 3067\n\n* Address Copilot r\n[…]\ned the version for sku for rc\n\n* Update template-pipeline-stages.yml\n\n* Update template-pipeline-stages.yml\n\n* Resolved comments\n\n---------\nCo-authored-by: Nilesh Choudhary <nichoudhary@microsoft.com>",
"is_bot": false,
"headline": "Migrate CI/CD from GitHub Actions to ADO; remove GH Actions workflow …",
"author_name": "Ryan Auld",
"author_login": "RyAuld",
"committed_at": "2026-05-21T22:14:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "192a82dcd6c5371ece4f14f9701b0134b2e92a07",
"body": "* Added a soft warning if callback is not callable\n\n* updated crypto version max to 51\n\n* removed support for 3.8 and added doc\n\n* Updated in warning placement\n\n* updated a fix for get()",
"is_bot": false,
"headline": "Removed support for Python 3.8 (#910)",
"author_name": "Nilesh Choudhary",
"author_login": "4gust",
"committed_at": "2026-05-21T15:53:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "08aa7fd273e93933617e74be842da15d3e36bf25",
"body": "…(#918)\n\n* First draft of FIC support\n\n* Small fixes and feedback\n\n* PR feedback\n\n* PR feedback\n\n* Add integration tests\n\n* Adjust SNI behavior around .pfx files\n\n* Revert pfx changes and disable tests",
"is_bot": false,
"headline": "Add User Federated Identity Credential (user_fic) grant type support …",
"author_name": "Avery-Dunn",
"author_login": "Avery-Dunn",
"committed_at": "2026-05-20T21:53:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4f58ec792571d9b0e015a8d20661a0554a9536d",
"body": "Document the MSI v2 mTLS flow in Python, detailing the problem, solution, and technical findings related to using KeyGuard-protected certificates.",
"is_bot": false,
"headline": "Add documentation for MSI v2 mTLS in Python (#904)",
"author_name": "Gladwin Johnson",
"author_login": "gladjohn",
"committed_at": "2026-05-20T08:14:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5866feb9b1158547f3379fe33ca5c89f65fafd84",
"body": "Add design document for MSI v2 In-Memory Key Approach, detailing goals, .NET reference implementation, Python implementation design, comparison with KeyGuard, and API design.",
"is_bot": false,
"headline": "Create design document for MSI v2 In-Memory Key Approach (#905)",
"author_name": "Gladwin Johnson",
"author_login": "gladjohn",
"committed_at": "2026-05-20T08:12:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "651d54b8bc3c0882f9dd4771f76b86b1a7c99373",
"body": "Bump the minimum required version of pymsalruntime from\n0.14/0.17/0.18 to 0.20.6 across all supported platforms\n(Windows, macOS, Linux).\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Update pymsalruntime minimum version to 0.20.6 (#919)",
"author_name": "fengga",
"author_login": "fengga",
"committed_at": "2026-05-20T08:08:54Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "895b581704dbd66c47ec2590d57ff7aff503a235",
"body": null,
"is_bot": false,
"headline": "Use unsigned redirect uri for mac broker flows (#907)",
"author_name": "fengga",
"author_login": "fengga",
"committed_at": "2026-05-12T17:55:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8ea1eaaae97f416254bfe7f606d6c6babb80afed",
"body": "…#913)\n\n* Switch FMI tests from disabled IDLABS_APP_FMI to MISE-App-FMICLIENT\n\n- Client ID: 4df2cbbb -> 3bf56293 (MISE-App-FMICLIENT in id4slab1 tenant)\n- Tenant ID: f645ad92 -> 10c419d4 (id4slab1.onmicrosoft.com)\n- FMI Scope: 3091264c -> aa464f73 (MISE-App-FMIResource)\n- Note: TestFMIIntegration (R\n[…]\n\ncausing a hard failure unrelated to our changes.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Switch FMI tests from disabled IDLABS_APP_FMI to MISE-App-FMICLIENT (…",
"author_name": "Ryan Auld",
"author_login": "RyAuld",
"committed_at": "2026-05-11T22:37:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "faf5dce2f72a5716c12b901eb52dea27e30d3e58",
"body": "* Initial plan\n\n* Bump cryptography dependency ceiling to <50 (N+3)\n\nAgent-Logs-Url: https://github.com/AzureAD/microsoft-authentication-library-for-python/sessions/f2f7ccee-f03f-4253-b23a-c0fc969f0a1c\n\nCo-authored-by: gladjohn <90415114+gladjohn@users.noreply.github.com>\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: gladjohn <90415114+gladjohn@users.noreply.github.com>",
"is_bot": false,
"headline": "Bump cryptography dependency ceiling to <50 (N+3) (#906)",
"author_name": "Copilot",
"author_login": "Copilot",
"committed_at": "2026-04-27T14:22:36Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "016092efe77035ba6ab4b75000a20ecdb0acdc8d",
"body": "* Initial plan\n\n* Add MSAL client metadata headers to IMDS managed identity requests\n\nAdd x-client-SKU, x-client-Ver, and x-ms-client-request-id headers to\n_obtain_token_on_azure_vm() for IMDS token requests. Update existing\nIMDS tests to assert the new headers and validate UUID correlation IDs.\n\nAg\n[…]\ngladjohn@users.noreply.github.com>\n\n---------\n\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>\nCo-authored-by: gladjohn <90415114+gladjohn@users.noreply.github.com>",
"is_bot": false,
"headline": "Forward MSAL client metadata headers through IMDS to ESTS (#902)",
"author_name": "Copilot",
"author_login": "Copilot",
"committed_at": "2026-04-14T15:21:36Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "67136fe2115b8279e33037af3a986fb264a8545f",
"body": "* Escape username to protect against xml injection vulnerability\n\n* Add test",
"is_bot": false,
"headline": "Escape username parameter (#901)",
"author_name": "Dharshan BJ",
"author_login": "DharshanBJ",
"committed_at": "2026-04-10T17:47:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3ba722660e838f58659f8f501a2624044266247",
"body": "* added a additional check for domain checking in b2c\n\n* updated comment",
"is_bot": false,
"headline": "Fix OIDC issuer domain spoofing in B2C host validation (#896)",
"author_name": "Nilesh Choudhary",
"author_login": "4gust",
"committed_at": "2026-04-07T17:07:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a92f2498d221c673d6e725e7f99d958bd189c5a",
"body": "…neration (#894)\n\n* Use cryptographically secure randomness for PKCE, state, and nonce generation\n\n* Update tests/test_oidc.py\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n* Update tests/test_oidc.py\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n* U\n[…]\n+ashok672@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\nCo-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Use cryptographically secure randomness for PKCE, state, and nonce ge…",
"author_name": "Ashok Kumar Ramakrishnan",
"author_login": "ashok672",
"committed_at": "2026-04-07T16:41:23Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ecf515a542feb3bcdfa34ed69144c793ed3be4b6",
"body": "* Added withFmi method for cca app\n\n* Added Cache support for fmi keys\n\n* updated the cache key ext\n\n* updated cache key excluded\n\n* Update msal/token_cache.py\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>\n\n* updated API for fmi\n\n---------\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>",
"is_bot": false,
"headline": "Added withFmi method for cca app (#876)",
"author_name": "Nilesh Choudhary",
"author_login": "4gust",
"committed_at": "2026-04-07T16:36:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eb7806838f0bc13f2f38fd1bf62a1f8991bbe197",
"body": "…in permissions (#884)\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "Potential fix for code scanning alert no. 74: Workflow does not conta…",
"author_name": "Avery-Dunn",
"author_login": "Avery-Dunn",
"committed_at": "2026-04-07T16:35:32Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "6de712edbf3310aa4af163a51ac8b9eeb9dbe65c",
"body": "* Add documentation for Managed Identity v2 Hackathon\n\nDocument the results and outcomes of the Managed Identity v2 Multi-Language Implementation Hackathon, highlighting the achievements and deliverables.\n\n* Apply suggestions from code review\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply\n[…]\nikes/prototype/2026_MS_SecurityHackathon_MSIV2.md\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Add documentation for Managed Identity v2 Hackathon (#885)",
"author_name": "Gladwin Johnson",
"author_login": "gladjohn",
"committed_at": "2026-04-07T16:28:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1f71ede35133ed2a2fa707928e60de6d4f067566",
"body": "* Add ADO CI/release pipelines with SDL, e2e tests, and ESRP publish support\n\n* Use Python runpy to read __version__ in Validate stage instead of grep/sed\n\n* Remove duplicate _clean_env in test_e2e.py; import from lab_config instead\n\n* Pass LabAuth secret via env var to avoid bash command substituti\n[…]\nRELEASE-PIPELINES.md\n\n* Address review comments: rename _clean_env to clean_env, fix __all__, fix doc diagram, drop redundant import os\n\n* Clarify cron comment: 07:45 UTC = 11:45 PM PST / 12:45 AM PDT",
"is_bot": false,
"headline": "Add ADO CI, SDL, and release pipelines with e2e test enablement (#890)",
"author_name": "Ryan Auld",
"author_login": "RyAuld",
"committed_at": "2026-03-31T17:46:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e4e692c5acaa798bd3f24f8178b042fd9a98ab0d",
"body": "* Fix PoP flow in the test app\n\nCurrently the test app sends both PoP parameters (see placeholder_auth_scheme definition)\nand also passes req_cnf and token type. There parameters are not\ncompatible. If application passes PoP parameters, then MSAL (or the\nbroker) owns the key and does the signing of \n[…]\n728472+Copilot@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Petar Dimov <petard@ntdev.microsoft.com>\nCo-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>",
"is_bot": false,
"headline": "Fix the PoP flow in the console app (#887)",
"author_name": "PetarSDimov",
"author_login": "PetarSDimov",
"committed_at": "2026-03-25T17:10:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2de45aeb534a05cfff0d85e96c4f330c102ef607",
"body": "* Instance discovery remains cloud local on known clouds\n\n* More changes and address PR comments\n\n* Try to fix tests\n\n---------\n\nCo-authored-by: Feng Gao <fengga@microsoft.com>",
"is_bot": false,
"headline": "Instance discovery remains cloud local on known clouds (#875)",
"author_name": "Bogdan Gavril",
"author_login": "bgavrilMS",
"committed_at": "2026-02-27T13:41:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09c8821cca91fc01345f080b1c75b124b1ad47f1",
"body": null,
"is_bot": false,
"headline": "Create RELEASE_GUIDE.md (#880)",
"author_name": "Nilesh Choudhary",
"author_login": "4gust",
"committed_at": "2026-02-24T11:38:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1310faca65e452b09e347fdee52da1fe400ce48f",
"body": "* removed some log that were alerted\n\n* Added back logging of the oidc url",
"is_bot": false,
"headline": "Removed logs that were causing Alerts (#878)",
"author_name": "Nilesh Choudhary",
"author_login": "4gust",
"committed_at": "2026-02-24T10:26:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "733a83cc09a85192607cc012b51638d4bcce76f7",
"body": "* Security: Remove unsafe PowerShell fallback in WSL\n\n* Remove unnecessary blank lines in authcode.py\n\n---------\n\nCo-authored-by: Ashok Kumar Ramakrishnan <83938949+ashok672@users.noreply.github.com>",
"is_bot": false,
"headline": "Security: Remove unsafe PowerShell fallback in WSL (#866)",
"author_name": "Rin",
"author_login": "RinZ27",
"committed_at": "2026-02-23T13:04:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7e0e11368457ee6ef6c44df75e5218ac984eef9",
"body": "* Add OIDC issuer validation and related tests\n\n* Remove check on known hosts and adjust error message towards regular authority API\n\n* Updated the trusted host list and added region check logic\n\n* Update test_authority.py\n\n* Updated the version for crypto, as 48 is deperecated\n\n* Updated one condi\n[…]\necking on host checking\n\n* adding issuer for some missing tests\n\n* Update authority.py\n\n* updated with new regional cloud URL's\n\n---------\n\nCo-authored-by: Nilesh Choudhary <nichoudhary@microsoft.com>",
"is_bot": false,
"headline": "Add OIDC issuer validation (#840)",
"author_name": "Avery-Dunn",
"author_login": "Avery-Dunn",
"committed_at": "2026-02-19T13:29:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "58cf0736d48a9bbc2c855983705c1b5f278709ec",
"body": "* Separate manual tests and remove unused settings from E2E\n\n* Remove non sn/i test case\n\n* Remove unused test\n\n* Improve ADO logs\n\n* Skip some tests on ADO",
"is_bot": false,
"headline": "Separate manual tests and remove unused settings from E2E (#874)",
"author_name": "Bogdan Gavril",
"author_login": "bgavrilMS",
"committed_at": "2026-02-18T10:04:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c0963357b113cad6455ae5b3cd22c049f358ade7",
"body": "* Remove usage of Lab API for integration test config\n\n* Add missing dependencies\n\n* Potential fix for code scanning alert no. 79: Clear-text logging of sensitive information\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>\n\n---------\n\nCo-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "Remove usage of Lab API for integration test config (#870)",
"author_name": "Avery-Dunn",
"author_login": "Avery-Dunn",
"committed_at": "2026-02-06T19:26:46Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "60d340147af1996c899053a9150b25b4635d04aa",
"body": "… (#868)\n\n* Initial changes\n\n* Deprecate response_mode parameter, better messages and more robust test\n\n* Update test_response_mode.py\n\n* Update authcode.py\n\n* Update application.py\n\n* Fix test failure in state_mismatch test\n\n* Fix for review comments\n\n* Update authcode.py\n\n* Update test_response_m\n[…]\nfy response_mode=form_post in a better spot\n\n* Treat parameter-less HTTP GET as error, while still keeping the welcome page and abort feature\n\n---------\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>",
"is_bot": false,
"headline": "Add form_post response mode support for system browser authentication…",
"author_name": "Ashok Kumar Ramakrishnan",
"author_login": "ashok672",
"committed_at": "2026-02-04T00:45:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eac15a91aa3922319ff0ba3d86ef9031b44f4a67",
"body": "SHA1 thumbprint in client assertion remains the only recognized way for some IDPs that MSAL supports, like ADFS.",
"is_bot": false,
"headline": "Suppress CodeQL warning (#867)",
"author_name": "Bogdan Gavril",
"author_login": "bgavrilMS",
"committed_at": "2026-01-06T16:57:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3464e6cb13f29bd730f49fc2ddf1c7a25b7c398",
"body": null,
"is_bot": false,
"headline": "Explicitly remove issuer from the OIDC discovery",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-11-14T23:11:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02d8b4c735dc1ad6eefff8506151d6bb3df898a0",
"body": null,
"is_bot": false,
"headline": "Support Python 3.14",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-11-01T03:00:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0dec594f18b76afb422396e710b0834cbac352b",
"body": "…made-optional\n\nThumbprint for certificate made optional",
"is_bot": false,
"headline": "Merge pull request #835 from vi7us/vitcurda/20250624/cert-thumbprint-…",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-11-01T02:38:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c50ec4a7d168bdec6b2773bba496afcfb0921d2",
"body": null,
"is_bot": false,
"headline": "Cleaner implementation and precise docs on SHA256",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-10-31T21:42:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bbeb4948b6e16b505f3b9ea1d9bfe9e3371f07b3",
"body": "update as per discussion",
"is_bot": false,
"headline": "certificate made optionall",
"author_name": "Vit Curda",
"author_login": null,
"committed_at": "2025-10-28T21:32:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "14bcad3e79b34c1b077d874abc1502e012426f00",
"body": null,
"is_bot": false,
"headline": "Remove the reliance on socket.getfqdn()",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-10-22T22:03:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83c102f266f3d9d25b26ac1e91e1abb6280634d6",
"body": "This is not a breaking change, because the pre-existing implementation\nwill error out anyway, but with a less meaningful exception.",
"is_bot": false,
"headline": "Explicitly rejecting empty hostname",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-10-22T22:00:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "85c0f06ad19534cae6fd4cd6fc0ea1c84c2e9708",
"body": null,
"is_bot": false,
"headline": "Consolidate 6 boxes into 4",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-10-20T22:00:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b3d4a0419836d633452f2bea3de2b128fab0689b",
"body": null,
"is_bot": false,
"headline": "Document how to use sha256 for client credential",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-10-20T22:00:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "59fa195804532bbc5708e13fa5b6245827d469b6",
"body": null,
"is_bot": false,
"headline": "Update pymsalruntime version range to handle the latest 0.20.0 release",
"author_name": "Dharshan BJ",
"author_login": "DharshanBJ",
"committed_at": "2025-10-15T18:32:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2a138a5a56444f3a52c5bf33751cc32ad006d126",
"body": null,
"is_bot": false,
"headline": "Demonstrates the behavior of mismatching scope",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-10-03T17:41:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "562d72e295f807bba99d5eee9029591d9ccee60c",
"body": "* ROPC deprecation\n\n* sample edit\n\n* reenable e2e tests\n\n* reenable tests\n\n* edit\n\n* remove import\n\n* fix wording\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>\n\n* edits\n\n* add comment\n\n* format\n\n* docstring changes\n\n---------\n\nCo-authored-by: Bogdan Gavril <bogavril@microsoft.com>",
"is_bot": false,
"headline": "ROPC deprecation (#855)",
"author_name": "Ugonna Akali",
"author_login": "Ugonnaak1",
"committed_at": "2025-09-30T17:47:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f803aec300d13f4a55c78941409c60befb2c8f1f",
"body": "* ADFS labs were decommissioned since late July 2025\n\n* MSAL Python 1.34.0b1\n\n* Declare support for Python 3.13\n\n* Bumping cryptography which also drops Python 3.7\n\n* 1.34.0b1 + minor changes = 1.34.0",
"is_bot": false,
"headline": "Release 1.34.0 (#853)",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-09-22T23:49:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2337a69a680139cac54521cfbe4fedef137a2b06",
"body": "Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.4.2 to 1.13.0.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/v1.4.2...v1.13.0)\n\n---\nupdated-dependencies:\n- depen\n[…]\nndency-version: 1.13.0\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "Bump pypa/gh-action-pypi-publish in /.github/workflows (#849)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-06T06:57:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cff139e0d84038f43cfb7d285fb1adbc16fc900f",
"body": null,
"is_bot": false,
"headline": "Set Redirect Uri for broker silent flow on Linux platform (#846)",
"author_name": "xinyuxu1026",
"author_login": "xinyuxu1026",
"committed_at": "2025-08-29T18:49:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bebbdd4b61b5d858980bf34eae2825dfec30a54d",
"body": null,
"is_bot": false,
"headline": "ADFS labs were decommissioned since late July 2025",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-08-20T16:25:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "923a7321a53df28e6acce1c5c182b59262bd9ca0",
"body": null,
"is_bot": false,
"headline": "MSAL Python 1.33.0 (#841)",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-07-22T19:39:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70fd4d1599fc15c876c8eaccd29b9f7ae73fecd6",
"body": "* Add claims challenge parameter in initiate_device_flow\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update msal/oauth2cli/oauth2.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update oauth2.py\n\n* Update oauth2.py\n\n---------\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>",
"is_bot": false,
"headline": "Add claims challenge parameter in initiate_device_flow (#839)",
"author_name": "Ashok Kumar Ramakrishnan",
"author_login": "ashok672",
"committed_at": "2025-07-18T07:45:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b1d8cd71145a8b1889b490f9b0dfbe4b1ac3a7f1",
"body": null,
"is_bot": false,
"headline": "Use lowercase environment value during searching",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-06-14T02:34:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d49296c1b2a929a6ab11380e237daa89a5298512",
"body": null,
"is_bot": false,
"headline": "Bump version number (#827)",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-06-04T12:02:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4c632c82808e7a3a73635718d92a8c3fc09dc871",
"body": "A recent customer troubleshooting case reveals that the Linux broker\nneeds a specific redirect_uri as its prerequisite",
"is_bot": false,
"headline": "Linux broker needs a specific redirect_uri",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-06-02T19:51:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db1c3848456696920fb5fb21c1a25a5e9323e443",
"body": null,
"is_bot": false,
"headline": "Cryptography shipped a new version during weekend",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-05-20T09:59:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "deb61fa1f67d6863c4137a3a0c04db791b0d3a72",
"body": null,
"is_bot": false,
"headline": "Improve test cases to test header-less response",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-05-15T23:51:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "62855d4a3ffe7b7dcc0b3d08e1e4896be66701a7",
"body": null,
"is_bot": false,
"headline": "Properly throw MsalServiceError exception",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-05-15T23:35:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db889c7da3226ea7717f26b6f0613b19c635f507",
"body": null,
"is_bot": false,
"headline": "Remind developers about http_cache's unstable format",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-05-09T02:03:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a1a0ff6570137e18ac8f3ed6f1e5d21d9fbf2e9",
"body": null,
"is_bot": false,
"headline": "Add dependency management suggestions",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-05-06T19:38:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37d9af53b75800044926b8c6aa4e5b4317cf5c5b",
"body": "Merge release 1.32.3 back to dev branch",
"is_bot": false,
"headline": "Merge pull request #816 from AzureAD/release-1.32.3",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-05-05T21:14:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dd4fe699256bd4b16ecc3e1b36bf04b511814e23",
"body": null,
"is_bot": false,
"headline": "MSAL Python 1.32.3",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-25T12:39:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3c87ba934f24471f9642a58588dff8650192117f",
"body": null,
"is_bot": false,
"headline": "Allow more http response headers",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-25T12:11:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e60467c22a79bc0e613283024216e553230b4fda",
"body": null,
"is_bot": false,
"headline": "MSAL 1.32.2",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-25T01:51:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04b5245c3db12390abf59cc58493f3b8f8ed725b",
"body": null,
"is_bot": false,
"headline": "Tolerate an http response object with no headers",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-25T00:39:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9156a30f6fded731ac48ad7f7e0d63246198ba74",
"body": null,
"is_bot": false,
"headline": "MSAL Python 1.32.1",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-24T16:41:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c3cd281736c8a2aa436b71ed2c260662fd35b3d",
"body": null,
"is_bot": false,
"headline": "Improve IndividualCache test cases",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-24T04:56:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29d1ac1558d6f87754fef71ed950bd806919d803",
"body": null,
"is_bot": false,
"headline": "Only cache desirable data in http cache",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-24T04:56:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1321e3793eebd35aac7b80b64e3a6aa49a32a51a",
"body": "* Fix username/password assert in broker test\n\nSigned-off-by: Emmanuel Ferdman <emmanuelferdman@gmail.com>\n\n* Update tests/broker-test.py\n\nCo-authored-by: Ray Luo <rayluo.mba@gmail.com>\n\n---------\n\nSigned-off-by: Emmanuel Ferdman <emmanuelferdman@gmail.com>\nCo-authored-by: Ray Luo <rayluo.mba@gmail.com>",
"is_bot": false,
"headline": "Fix username/password validation in broker test (#807)",
"author_name": "Emmanuel Ferdman",
"author_login": "emmanuel-ferdman",
"committed_at": "2025-04-14T22:14:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4eb7bd105b2281a253ab94d4b81f56ca1504f500",
"body": "* Enable broker support on Linux\n\n* update version number\n\n* Update sample/interactive_sample.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n* Update tests/broker-test.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com\n[…]\ny Luo <rayluo@microsoft.com>\n\n* Bump up msal py version to 1.33\n\n* Update msal/application.py\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>\n\n---------\n\nCo-authored-by: Ray Luo <rayluo@microsoft.com>",
"is_bot": false,
"headline": "Enable broker support on Linux for WSL (#766)",
"author_name": "Dharshan BJ",
"author_login": "DharshanBJ",
"committed_at": "2025-04-07T19:48:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bcc54a99e42b41239efc80235b51822fbbf2ef81",
"body": "Update deprecated TokenCache API usage",
"is_bot": false,
"headline": "Merge pull request #805 from pvaneck/update-deprecated-api",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-04T22:13:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "28a67a7ab551e6010a7b69c7c9d7b68aa69f69fc",
"body": null,
"is_bot": false,
"headline": "Use v1.29+ TokenCache.search() instead of find()",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-04T22:07:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45e39669ca8e3fd768610d748235c3775ca4db84",
"body": "There was a place in `ManagedIdentityClient` where the `TokenCache.find`\nmethod was still being used, leading to some deprecation warnings being\nprinted. This updates that to use `TokenCache.search`.\n\nSigned-off-by: Paul Van Eck <paulvaneck@microsoft.com>",
"is_bot": false,
"headline": "Update deprecated TokenCache API usage",
"author_name": "Paul Van Eck",
"author_login": "pvaneck",
"committed_at": "2025-04-04T22:07:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2f9747fa995e55fe4034308d9d23133523827e09",
"body": null,
"is_bot": false,
"headline": "ManagedIdentityClient sends xms_cc and token_sha256_to_refresh to SF",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-04-03T03:18:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "30dce4ecc63d93ef34b89c052aab1a1231395ce6",
"body": "This used to cause issue with MSAL 1.32 and MSAL EX <= 1.2 running\ninside read-only container",
"is_bot": false,
"headline": "Swallow exception during optional check",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-29T08:31:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4db4a8c2d740c5315f60f07a7e1ee58667b2a759",
"body": "…microsoft-authentication-library-for-python/issues/97",
"is_bot": false,
"headline": "This typo fix will probably resolve https://github.com/MicrosoftDocs/…",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-25T02:38:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "137dee46c9189b9d02105d92f8dcac5fd39a9266",
"body": null,
"is_bot": false,
"headline": "Update error hints for where to get OBO test apps",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-12T21:46:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b92b4f18cb176231ae494639d24aeb19bd457d73",
"body": null,
"is_bot": false,
"headline": "Bumping version number to 1.32.0",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-11T22:49:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "04e740e32bf18047109b1c1892671f0f177428e0",
"body": null,
"is_bot": false,
"headline": "Merge branch 'release-1.31.2' into merge",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-11T20:00:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "689e8624b5987be529ab91f8786a1105ee505f23",
"body": null,
"is_bot": false,
"headline": "Support pod identity",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-11T00:35:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb3e21cf501587dccb71676a3d06f9ea24476102",
"body": null,
"is_bot": false,
"headline": "ADFSv2 and ADFSv3 labs are decommissioned",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-03-10T23:54:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6d3d0d22a61b5b71a4a501dfb57aaa21462c4e6",
"body": null,
"is_bot": false,
"headline": "Skip authority discovery in test_application.py",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-21T07:51:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f22994f93e1f49d6fb6234bbc8a7a1c90604b247",
"body": "…only arguments",
"is_bot": false,
"headline": "enable_broker_on_windows and enable_broker_on_mac present as keyword-…",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-20T20:05:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e2a4ec0d4af3bf44c1f1608903440e5f6e75aa9",
"body": null,
"is_bot": false,
"headline": "Specify verify=True to hopefully satisfy CodeQL",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-20T19:21:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a565ba20e5bc83b65219086f3e55302d59b0ea00",
"body": null,
"is_bot": false,
"headline": "E2e attempts broker albeit PyMsalRuntime init fails",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-20T09:15:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f15c399b6c34f1dbf838ccf077286290b3ee4d0",
"body": null,
"is_bot": false,
"headline": "Fix incorrect login_hint detection",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-20T05:37:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d168cfd77e0f28bc16302698344db07c1f9e5d8",
"body": null,
"is_bot": false,
"headline": "We have long been switched to use Github actions",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-13T19:41:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0340f5e78d49195917c5682f082e461e9825a2a9",
"body": null,
"is_bot": false,
"headline": "Enable Issue-Sentinel to scan for similar issues (#790)",
"author_name": "Dharshan BJ",
"author_login": "DharshanBJ",
"committed_at": "2025-02-11T21:33:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "971f110cddaf1a98f4021340282fa5fa1d4d699a",
"body": null,
"is_bot": false,
"headline": "Add test case to show that OBO supports SP",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-08T05:14:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c84adf6723491edd4905a477e6e8da4df266313",
"body": null,
"is_bot": false,
"headline": "Adds dSTS authority (as if it were an oidc_authority)",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-08T00:52:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6508d992f4bbfcae21c7f1175c24e4076ade0ad5",
"body": null,
"is_bot": false,
"headline": "Try to suppress another verify=False",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-02-07T23:57:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a37d3a329f7329fe0761579d7a52240ff1cd2fa3",
"body": "* Pass Sku and Ver to MsalRuntime\r\n\r\n* edit suggestions\r\n\r\n* suggestion edits\r\n\r\n* whitespace",
"is_bot": false,
"headline": "Pass Sku and Ver to MsalRuntime (#786)",
"author_name": "Ugonna Akali",
"author_login": "Ugonnaak1",
"committed_at": "2025-02-07T01:08:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf27fc6d28320dc1384b98ca7bd9844a3a6f809f",
"body": null,
"is_bot": false,
"headline": "MSAL Python 1.31.2b1",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-28T05:19:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "388b86d31559cda8be9b797fefe61dc11dc7c757",
"body": null,
"is_bot": false,
"headline": "Pin ubuntu 22.04 so that we can still test on Py37",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-27T05:14:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f27f4b227e6c7ed336a8ce6fcd606c581f806cd2",
"body": null,
"is_bot": false,
"headline": "Supports GUID/scope and https://contoso.com//scope",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-26T04:51:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5420c59aaa9b1fd657ce0c7b5f3168ce732c6045",
"body": null,
"is_bot": false,
"headline": "Relax the upper bound after testing the latest one",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-25T02:14:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f3d1336751a19cb8a7c0575e68ffbea66581008",
"body": null,
"is_bot": false,
"headline": "Update the hint of where to get a lab certificate",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-23T21:32:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3803ae22c8c712fd6f74db8576f219e31c94039d",
"body": null,
"is_bot": false,
"headline": "Suppress a false positive CodeQL alarm",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-15T18:16:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37badb876e1dc7c23022445f241bc8bf954c49f2",
"body": null,
"is_bot": false,
"headline": "Py3.7 is unavailable on ubuntu 24.04",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2025-01-15T06:00:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b3175631c03c5b5476aaf29239c31878ab80b23",
"body": "[skip ci]",
"is_bot": false,
"headline": "Set up CI with Azure Pipelines",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2024-12-02T18:53:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5196d84f2aaf6d9927259d78815d5c1c21f9cc8",
"body": null,
"is_bot": false,
"headline": "Relax the upper bound after testing the latest one",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2024-12-02T18:43:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5f8b67b7496effdae0da79cd62e1b6d7fb36997",
"body": null,
"is_bot": false,
"headline": "Remove Dockerfile containing 3rd party image",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2024-12-02T18:43:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "60007ac58d94947287ba15be36e83ea1978b4cc1",
"body": null,
"is_bot": false,
"headline": "Some helpers to test Python 3.14 via docker",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2024-11-27T08:08:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d85e8a20b1fd1b28ae9bd8b77bb93fdade6f8b7",
"body": null,
"is_bot": false,
"headline": "SystemAssigned",
"author_name": "jiasli",
"author_login": "jiasli",
"committed_at": "2024-11-21T03:51:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec3c5006852dc2dd75b08c1e572792aa1955d8b0",
"body": null,
"is_bot": false,
"headline": "Merge branch 'release-1.31.1' into dev",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2024-11-21T03:42:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7826ea8ffc998ae66b0f340ebd53e52ddd20d1f0",
"body": "…)\" (#769)\n\nThis reverts commit 7db6c2ccdd121ad730517ebd5e6195feec06ed41.",
"is_bot": false,
"headline": "Revert \"allow MI endpoint changing through environment variable (#754…",
"author_name": "Ray Luo",
"author_login": "rayluo",
"committed_at": "2024-11-19T23:02:15Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 61,
"commits_last_year": 40,
"latest_release_at": "2026-04-08T18:14:52Z",
"latest_release_tag": "1.36.0",
"releases_from_tags": true,
"days_since_last_push": 56,
"active_weeks_last_year": 22,
"days_since_latest_release": 107,
"mean_days_between_releases": 58.2
},
"community": {
"has_readme": false,
"has_license": false,
"has_description": false,
"has_contributing": false,
"health_percentage": null,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "msal",
"exists": true,
"license": "MIT",
"keywords": [
"Development Status :: 5 - Production/Stable",
"License :: OSI Approved :: MIT License",
"Operating System :: OS Independent",
"Programming Language :: Python",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3 :: Only",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.14",
"Programming Language :: Python :: 3.9"
],
"ecosystem": "pypi",
"matches_repo": false,
"registry_url": "https://pypi.org/project/msal/",
"is_deprecated": false,
"latest_version": "1.37.0",
"repository_url": "https://github.com/AzureAD/microsoft-authentication-library-for-python",
"versions_count": 73,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 211811791,
"first_published_at": "2018-12-12T19:53:29.898022Z",
"latest_published_at": "2026-05-29T19:49:05.561373Z",
"latest_version_yanked": null,
"days_since_latest_publish": 56
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"sample"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"docs/Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 140501,
"source_files_sampled": 65,
"oversized_source_files": 3,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"docs/requirements.txt",
"requirements.txt",
"setup.cfg",
"setup.py"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 9,
"malicious_count": 0,
"assessed_package": "pypi:msal@1.37.0",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "requests",
"manifest": "setup.cfg",
"ecosystem": "pypi",
"version_constraint": ">=2.0.0,<3"
},
{
"name": "PyJWT",
"manifest": "setup.cfg",
"ecosystem": "pypi",
"version_constraint": ">=1.0.0,<3"
},
{
"name": "cryptography",
"manifest": "setup.cfg",
"ecosystem": "pypi",
"version_constraint": ">=2.5,<51"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "rayluo",
"commits": 1131,
"avatar_url": "https://avatars.githubusercontent.com/u/821550?v=4"
},
{
"type": "User",
"login": "abhidnya13",
"commits": 55,
"avatar_url": "https://avatars.githubusercontent.com/u/12730799?v=4"
},
{
"type": "User",
"login": "bgavrilMS",
"commits": 7,
"avatar_url": "https://avatars.githubusercontent.com/u/12273384?v=4"
},
{
"type": "User",
"login": "fengga",
"commits": 7,
"avatar_url": "https://avatars.githubusercontent.com/u/62267180?v=4"
},
{
"type": "User",
"login": "DharshanBJ",
"commits": 6,
"avatar_url": "https://avatars.githubusercontent.com/u/22018221?v=4"
},
{
"type": "User",
"login": "Avery-Dunn",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/62066438?v=4"
},
{
"type": "User",
"login": "4gust",
"commits": 5,
"avatar_url": "https://avatars.githubusercontent.com/u/107404295?v=4"
},
{
"type": "User",
"login": "tonybaloney",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/1532417?v=4"
},
{
"type": "User",
"login": "ashok672",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/83938949?v=4"
},
{
"type": "User",
"login": "chlowell",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/10964656?v=4"
}
],
"contributors_sampled": 41,
"top_contributor_share": 0.893
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"RunIssueSentinel.yml",
"python-package.yml"
],
"has_docs_dir": true,
"linter_configs": [
"tox.ini"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 3 contributing companies or organizations -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "ebb980f1636e1b3a097ec6dbfd197fb88c5b9e7a",
"ran_at": "2026-07-25T07:20:40Z",
"aggregate_score": 4.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": null,
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": null,
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/neha-bhargava/microsoft-authentication-library-for-python",
"host": "github.com",
"name": "microsoft-authentication-library-for-python",
"owner": "neha-bhargava"
},
"metrics": {
"overall": {
"key": "overall",
"band": "at_risk",
"name": "Overall health",
"note": null,
"notes": [],
"value": 43,
"inputs": {
"security": 53,
"vitality": 57,
"community": 9,
"governance": 28,
"engineering": 68
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "moderate",
"name": "Vitality",
"value": 57,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "at_risk",
"name": "Development activity",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"commits_last_year": 40,
"human_commit_share": 0.99,
"days_since_last_push": 56,
"active_weeks_last_year": 22
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 56 days ago",
"points": 18,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 56
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "22/52 weeks with commits",
"points": 15.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 22
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "40 commits in the last year",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 40
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "good",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 70,
"inputs": {
"releases_count": 61,
"latest_release_tag": "1.36.0",
"releases_from_tags": true,
"days_since_latest_release": 107,
"mean_days_between_releases": 58.2
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "61 version tags (no GitHub releases)",
"points": 16.2,
"status": "partial",
"details": [
{
"code": "version_tags_no_releases",
"params": {
"count": 61
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 107 days ago",
"points": 27,
"status": "partial",
"details": [
{
"code": "release_recency",
"params": {
"days": 107
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~58.2 days",
"points": 19.8,
"status": "partial",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 58.2
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 9,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "critical",
"name": "Community health",
"note": null,
"notes": [],
"value": 19,
"inputs": {
"has_readme": false,
"has_license": false,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "critical",
"name": "Sustainability & Governance",
"value": 28,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 35,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 41,
"top_contributor_share": 0.893
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 89% of commits",
"points": 2.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 89
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "41 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 41
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "critical",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution",
"pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 1,
"inputs": {
"merged_prs": 0,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 45,
"inputs": {
"followers": 6,
"owner_type": "User",
"is_verified": null,
"owner_login": "neha-bhargava",
"public_repos": 10,
"account_age_days": 2332
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "6 followers of neha-bhargava",
"points": 6.1,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 6,
"login": "neha-bhargava"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "10 public repos, account ~6 yr old",
"points": 19.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 10
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 68,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": "tox.ini",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tox.ini"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://stackoverflow.com/questions/tagged/azure-ad-msal+python",
"has_readme": false,
"has_docs_dir": true,
"has_description": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://stackoverflow.com/questions/tagged/azure-ad-msal+python",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 53,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 41,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 4.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 3 contributing companies or organizations -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the pypi:msal@1.37.0 runtime dependency closure — what installing the published package pulls in — 9 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "pypi:msal@1.37.0",
"assessed": 9
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 9,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 9,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 14
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 49,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 25,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.465,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "46 of 99 human commits state their intent (structured subject or explanatory body)",
"points": 24.8,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 46,
"sampled": 99
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [
"docs/Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0.1,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.01
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "docs/Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": "tox.ini",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "tox.ini"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "10 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 10,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "1 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 1,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 52,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 140501,
"source_files_sampled": 65,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/65 source files over 60KB",
"points": 52.5,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 65,
"oversized": 3
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"sample"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "sample",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "sample"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Community profile unavailable",
"pypi package 'msal' points at a different repository (https://github.com/AzureAD/microsoft-authentication-library-for-python); excluded from ecosystem scoring",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-25T07:20:57.222223Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/neha-bhargava/microsoft-authentication-library-for-python.svg",
"full_name": "neha-bhargava/microsoft-authentication-library-for-python",
"license_state": "custom",
"license_spdx": null
}