公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-28 22:08 UTC

pitabwire / frame

A simple bootstrap for quickly starting a server based on gocloud framework

GoApache-2.0★ 5 星标⑂ 2 复刻始于 2021年1月在 GitHub 上查看 ↗

pitabwire/frame 的健康指数为 100 分中的 71 分,处于「良好」区间。 其得分最高的类别是Vitality(98/100),最低的是Community & Adoption(38/100)。 最近一次更新在 1 天前。 近期的大部分工作由 1 位贡献者完成。

71
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

71
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Peter Bwire个人账户
8 关注者30 个公开仓库始于 2013年5月@antinvestor

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/pitabwire/frame/v2v2.1.3-211 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

98优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 1 天前
33.2/36提交节奏 — 52 周中有 48 周有提交
18/18提交量 — 最近一年 664 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year664
human_commit_share0.87
days_since_last_push1
active_weeks_last_year48

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 100 个发布版本
36/36发布时效 — 最近一次发布版本于 1 天前
27/27发布节奏 — 约每 0.7 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count100
latest_release_tagv2.1.2
releases_from_tags
days_since_latest_release1
mean_days_between_releases0.7
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

38存在风险 · 占总体的 18%
评分方式
9.8/60星标 — 5 个星标
0/25复刻 — 2 个复刻
0/15关注者 — 1 位关注者
所用输入
forks2
stars5
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

70良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

57中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
46.8/46.8议题解决 — 100% 的议题已关闭
37.2/38.3PR 接受 — 已裁定的 PR 中 663/681 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/23 approved changesets -- score normalized to 0
所用输入
merged_prs663
open_issues0
closed_issues5
issue_closed_ratio1
closed_unmerged_prs18
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
6.9/25所有者影响力 — pitabwire 有 8 位关注者
22.9/25既往记录 — 30 个公开仓库,账户约 13 年
所用输入
followers8
owner_typeUser
is_verified
owner_loginpitabwire
public_repos30
account_age_days4,830
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 1 天前
20/20版本历史 — 21 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/pitabwire/frame/v2
ecosystemsgo
any_deprecated
min_days_since_publish1

工程质量

基础的工程与文档实践是否到位?

96优秀 · 占总体的 20%

工程实践

94优秀
评分方式
24/24CI 工作流 — 9 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yaml
9.6/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

100优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://pitabwire.github.io/frame/
10/10仓库描述
10/10主题标签 — 7 个主题标签
10/10Wiki
所用输入
topicsgo, golang, boilerplate, gocloud, microservice, postgresql, message-queue
has_wiki
homepagehttps://pitabwire.github.io/frame/
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

62中等 · 占总体的 16%

安全态势

52中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/23 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate5.2
已排除计分(无数据或不适用):packaging, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages149
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 149 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

71良好 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 87 次人类提交中有 86 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.989
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yaml
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 13 次为自动依赖更新
1/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 1
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0.13
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.8/55可控的文件大小 — 采样的 297 个源文件中有 1 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes96,081
source_files_sampled297
oversized_source_files1
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — frametests/rpcservice/ping/v1/ping.proto
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_filesframetests/rpcservice/ping/v1/ping.proto

关键数据

5GitHub 星标
1贡献者
664最近 12 个月提交数
1距最近推送天数
100发布版本数
1巴士系数(bus factor)
0开放议题
Go软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 2 ⇿
0Star
2Fork

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

111222212021-092022-112023-12

每个点涵盖 3 天。

OpenSSF Scorecard 5.2 / 10
5.2综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-28 22:07 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests8 out of 8 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/23 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
1Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 1
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
直接依赖 47
注册表软件包版本约束清单文件
Gobuf.build/go/protovalidatev1.2.0go.mod
Goconnectrpc.com/connectv1.20.0go.mod
Goconnectrpc.com/otelconnectv0.9.0go.mod
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/caarlos0/env/v11v11.4.1go.mod
Gogithub.com/exaring/otelpgxv0.11.1go.mod
Gogithub.com/go-jose/go-jose/v4v4.1.4go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/jackc/pgx/v5v5.10.0go.mod
Gogithub.com/lmittmann/tintv1.2.0go.mod
Gogithub.com/moby/moby/apiv1.55.0go.mod
Gogithub.com/nats-io/nats.gov1.52.0go.mod
Gogithub.com/nicksnyder/go-i18n/v2v2.6.1go.mod
Gogithub.com/ory/keto/protov0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0go.mod
Gogithub.com/panjf2000/ants/v2v2.12.1go.mod
Gogithub.com/pitabwire/natspubsubv0.8.4go.mod
Gogithub.com/pitabwire/utilv0.9.1go.mod
Gogithub.com/redis/go-redis/v9v9.21.0go.mod
Gogithub.com/rs/xidv1.6.0go.mod
Gogithub.com/spiffe/go-spiffe/v2v2.8.1go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/testcontainers/testcontainers-gov0.43.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/natsv0.43.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/postgresv0.43.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/valkeyv0.43.0go.mod
Gogithub.com/valkey-io/valkey-gov1.0.76go.mod
Gogo.opentelemetry.io/contrib/bridges/otelslogv0.19.0go.mod
Gogo.opentelemetry.io/contrib/exporters/autoexportv0.69.0go.mod
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0go.mod
Gogo.opentelemetry.io/contrib/propagators/autopropv0.69.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/logv0.20.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/logv0.20.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogocloud.devv0.46.0go.mod
Gogolang.org/x/netv0.57.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/textv0.40.0go.mod
Gogoogle.golang.org/apiv0.290.0go.mod
Gogoogle.golang.org/grpcv1.82.1go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gogorm.io/driver/postgresv1.6.0go.mod
Gogorm.io/gormv1.31.2go.mod
全部依赖 149

来自 GitHub 依赖图的完整解析依赖集合:47 个直接依赖与 102 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gobuf.build/go/protovalidatev1.2.0直接
Goconnectrpc.com/connectv1.20.0直接
Goconnectrpc.com/otelconnectv0.9.0直接
Gogithub.com/burntsushi/tomlv1.6.0直接
Gogithub.com/caarlos0/env/v11v11.4.1直接
Gogithub.com/exaring/otelpgxv0.11.1直接
Gogithub.com/go-jose/go-jose/v4v4.1.4直接
Gogithub.com/golang-jwt/jwt/v5v5.3.1直接
Gogithub.com/jackc/pgx/v5v5.10.0直接
Gogithub.com/lmittmann/tintv1.2.0直接
Gogithub.com/moby/moby/apiv1.55.0直接
Gogithub.com/nats-io/nats.gov1.52.0直接
Gogithub.com/nicksnyder/go-i18n/v2v2.6.1直接
Gogithub.com/ory/keto/protov0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0直接
Gogithub.com/panjf2000/ants/v2v2.12.1直接
Gogithub.com/pitabwire/natspubsubv0.8.4直接
Gogithub.com/pitabwire/utilv0.9.1直接
Gogithub.com/redis/go-redis/v9v9.21.0直接
Gogithub.com/rs/xidv1.6.0直接
Gogithub.com/spiffe/go-spiffe/v2v2.8.1直接
Gogithub.com/stretchr/testifyv1.11.1直接
Gogithub.com/testcontainers/testcontainers-gov0.43.0直接
Gogithub.com/testcontainers/testcontainers-go/modules/natsv0.43.0直接
Gogithub.com/testcontainers/testcontainers-go/modules/postgresv0.43.0直接
Gogithub.com/testcontainers/testcontainers-go/modules/valkeyv0.43.0直接
Gogithub.com/valkey-io/valkey-gov1.0.76直接
Gogo.opentelemetry.io/contrib/bridges/otelslogv0.19.0直接
Gogo.opentelemetry.io/contrib/exporters/autoexportv0.69.0直接
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0直接
Gogo.opentelemetry.io/contrib/propagators/autopropv0.69.0直接
Gogo.opentelemetry.io/otelv1.44.0直接
Gogo.opentelemetry.io/otel/logv0.20.0直接
Gogo.opentelemetry.io/otel/metricv1.44.0直接
Gogo.opentelemetry.io/otel/sdkv1.44.0直接
Gogo.opentelemetry.io/otel/sdk/logv0.20.0直接
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0直接
Gogo.opentelemetry.io/otel/tracev1.44.0直接
Gogocloud.devv0.46.0直接
Gogolang.org/x/netv0.57.0直接
Gogolang.org/x/oauth2v0.36.0直接
Gogolang.org/x/textv0.40.0直接
Gogoogle.golang.org/apiv0.290.0直接
Gogoogle.golang.org/grpcv1.82.1直接
Gogoogle.golang.org/protobufv1.36.11直接
Gogopkg.in/yaml.v3v3.0.1直接
Gogorm.io/driver/postgresv1.6.0直接
Gogorm.io/gormv1.31.2直接
Gobuf.build/gen/go/bufbuild/protovalidate/protocolbuffers/gov1.36.11-20260709200747-435963d16310.1间接
Gocel.dev/exprv0.25.2间接
Gocloud.google.com/go/authv0.22.0间接
Gocloud.google.com/go/auth/oauth2adaptv0.2.8间接
Gocloud.google.com/go/compute/metadatav0.9.0间接
Gocloud.google.com/go/iamv1.12.0间接
Gocloud.google.com/go/pubsubv1.51.0间接
Gocloud.google.com/go/pubsub/v2v2.6.1间接
Godario.cat/mergov1.0.2间接
Gogithub.com/antlr4-go/antlr/v4v4.13.1间接
Gogithub.com/azure/go-ansitermv0.0.0-20250102033503-faa5f7b0171c间接
Gogithub.com/beorn7/perksv1.0.1间接
Gogithub.com/cenkalti/backoff/v4v4.3.0间接
Gogithub.com/cenkalti/backoff/v5v5.0.3间接
Gogithub.com/cespare/xxhash/v2v2.3.0间接
Gogithub.com/containerd/errdefsv1.0.0间接
Gogithub.com/containerd/errdefs/pkgv0.3.0间接
Gogithub.com/containerd/logv0.1.0间接
Gogithub.com/containerd/platformsv0.2.1间接
Gogithub.com/cpuguy83/dockercfgv0.3.2间接
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33cc间接
Gogithub.com/distribution/referencev0.6.0间接
Gogithub.com/docker/go-connectionsv0.8.0间接
Gogithub.com/docker/go-unitsv0.5.0间接
Gogithub.com/ebitengine/puregov0.10.2间接
Gogithub.com/felixge/httpsnoopv1.1.0间接
Gogithub.com/go-logr/logrv1.4.4间接
Gogithub.com/go-logr/stdrv1.2.2间接
Gogithub.com/go-ole/go-olev1.3.0间接
Gogithub.com/google/cel-gov0.30.0间接
Gogithub.com/google/s2a-gov0.1.9间接
Gogithub.com/google/uuidv1.6.0间接
Gogithub.com/google/wirev0.7.0间接
Gogithub.com/googleapis/enterprise-certificate-proxyv0.3.19间接
Gogithub.com/googleapis/gax-go/v2v2.23.0间接
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0间接
Gogithub.com/jackc/pgpassfilev1.0.0间接
Gogithub.com/jackc/pgservicefilev0.0.0-20240606120523-5a60cdf6a761间接
Gogithub.com/jackc/puddle/v2v2.2.2间接
Gogithub.com/jinzhu/inflectionv1.0.0间接
Gogithub.com/jinzhu/nowv1.1.5间接
Gogithub.com/klauspost/compressv1.19.1间接
Gogithub.com/lufia/plan9statsv0.0.0-20260627054121-477a66015f15间接
Gogithub.com/magiconair/propertiesv1.18.11间接
Gogithub.com/mdelapenya/tlscertv0.2.0间接
Gogithub.com/microsoft/go-winiov0.6.2间接
Gogithub.com/moby/docker-image-specv1.3.1间接
Gogithub.com/moby/go-archivev0.2.1间接
Gogithub.com/moby/moby/clientv0.5.0间接
Gogithub.com/moby/patternmatcherv0.6.1间接
Gogithub.com/moby/sys/sequentialv0.7.0间接
Gogithub.com/moby/sys/userv0.4.1间接
Gogithub.com/moby/sys/usernsv0.1.0间接
Gogithub.com/moby/termv0.5.2间接
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822间接
Gogithub.com/nats-io/nkeysv0.4.16间接
Gogithub.com/nats-io/nuidv1.0.1间接
Gogithub.com/opencontainers/go-digestv1.0.0间接
Gogithub.com/opencontainers/image-specv1.1.1间接
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2间接
Gogithub.com/power-devops/perfstatv0.0.0-20240221224432-82ca36839d55间接
Gogithub.com/prometheus/client_golangv1.24.1间接
Gogithub.com/prometheus/client_modelv0.6.2间接
Gogithub.com/prometheus/commonv0.70.1间接
Gogithub.com/prometheus/otlptranslatorv1.0.0间接
Gogithub.com/prometheus/procfsv0.21.1间接
Gogithub.com/shirou/gopsutil/v4v4.26.6间接
Gogithub.com/sirupsen/logrusv1.9.4间接
Gogithub.com/tklauser/go-sysconfv0.4.0间接
Gogithub.com/tklauser/numcpusv0.12.0间接
Gogithub.com/yusufpapurcu/wmiv1.2.4间接
Gogo.opentelemetry.io/auto/sdkv1.2.1间接
Gogo.opentelemetry.io/contrib/bridges/prometheusv0.69.0间接
Gogo.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpcv0.69.0间接
Gogo.opentelemetry.io/contrib/propagators/awsv1.44.0间接
Gogo.opentelemetry.io/contrib/propagators/b3v1.44.0间接
Gogo.opentelemetry.io/contrib/propagators/jaegerv1.44.0间接
Gogo.opentelemetry.io/contrib/propagators/otv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpcv0.20.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttpv0.20.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0间接
Gogo.opentelemetry.io/otel/exporters/stdout/stdoutlogv0.20.0间接
Gogo.opentelemetry.io/otel/exporters/stdout/stdoutmetricv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0间接
Gogo.opentelemetry.io/proto/otlpv1.11.0间接
Gogo.uber.org/atomicv1.11.0间接
Gogo.uber.org/multierrv1.11.0间接
Gogo.yaml.in/yaml/v3v3.0.5间接
Gogolang.org/x/cryptov0.54.0间接
Gogolang.org/x/expv0.0.0-20260718201538-764159d718ef间接
Gogolang.org/x/syncv0.22.0间接
Gogolang.org/x/sysv0.47.0间接
Gogolang.org/x/timev0.15.0间接
Gogolang.org/x/xerrorsv0.0.0-20240903120638-7835f813f4da间接
Gogoogle.golang.org/genprotov0.0.0-20260724162435-b2f20204f0df间接
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260724162435-b2f20204f0df间接
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260724162435-b2f20204f0df间接
依赖安全公告 1

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 149 个包,其中也包含从不交付的开发与测试版本固定:1 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
golang.org/x/cryptov0.54.0间接未知1

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "go",
        "golang",
        "boilerplate",
        "gocloud",
        "microservice",
        "postgresql",
        "message-queue"
      ],
      "is_fork": false,
      "size_kb": 3665,
      "has_wiki": true,
      "homepage": "https://pitabwire.github.io/frame/",
      "languages": {
        "Go": 1427227,
        "Makefile": 2722
      },
      "pushed_at": "2026-07-27T10:22:43Z",
      "created_at": "2021-01-01T16:57:43Z",
      "owner_type": "User",
      "updated_at": "2026-07-27T10:23:40Z",
      "description": "A simple bootstrap for quickly starting a server based on gocloud framework",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://www.linkedin.com/in/pitabwire",
      "name": "Peter Bwire",
      "type": "User",
      "login": "pitabwire",
      "company": "@antinvestor ",
      "location": "Busia",
      "followers": 8,
      "avatar_url": "https://avatars.githubusercontent.com/u/4368681?v=4",
      "created_at": "2013-05-07T19:30:52Z",
      "is_verified": null,
      "public_repos": 30,
      "account_age_days": 4830
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2026-07-27T10:09:49Z"
        },
        {
          "tag": "v2.0.14",
          "kind": "patch",
          "published_at": "2026-07-25T09:56:02Z"
        },
        {
          "tag": "v2.0.13",
          "kind": "patch",
          "published_at": "2026-07-25T09:51:25Z"
        },
        {
          "tag": "v2.0.12",
          "kind": "patch",
          "published_at": "2026-07-24T16:34:08Z"
        },
        {
          "tag": "v2.0.11",
          "kind": "patch",
          "published_at": "2026-07-24T16:27:20Z"
        },
        {
          "tag": "v2.0.10",
          "kind": "patch",
          "published_at": "2026-07-24T16:26:43Z"
        },
        {
          "tag": "v2.0.9",
          "kind": "patch",
          "published_at": "2026-07-24T16:16:19Z"
        },
        {
          "tag": "v2.0.8",
          "kind": "patch",
          "published_at": "2026-07-24T16:16:26Z"
        },
        {
          "tag": "v2.0.7",
          "kind": "patch",
          "published_at": "2026-07-21T18:34:18Z"
        },
        {
          "tag": "v2.0.5",
          "kind": "patch",
          "published_at": "2026-07-21T02:22:26Z"
        },
        {
          "tag": "v2.0.4",
          "kind": "patch",
          "published_at": "2026-07-11T02:21:38Z"
        },
        {
          "tag": "v2.0.3",
          "kind": "patch",
          "published_at": "2026-07-09T20:00:08Z"
        },
        {
          "tag": "v2.0.2",
          "kind": "patch",
          "published_at": "2026-07-06T00:38:27Z"
        },
        {
          "tag": "v2.0.1",
          "kind": "patch",
          "published_at": "2026-06-29T00:43:50Z"
        },
        {
          "tag": "v1.98.4",
          "kind": "patch",
          "published_at": "2026-06-10T21:40:07Z"
        },
        {
          "tag": "v1.98.3",
          "kind": "patch",
          "published_at": "2026-06-10T17:13:37Z"
        },
        {
          "tag": "v1.98.2",
          "kind": "patch",
          "published_at": "2026-06-10T15:58:55Z"
        },
        {
          "tag": "v1.98.1",
          "kind": "patch",
          "published_at": "2026-06-10T09:47:29Z"
        },
        {
          "tag": "v1.98.0",
          "kind": "minor",
          "published_at": "2026-06-08T13:58:47Z"
        },
        {
          "tag": "v1.94.11",
          "kind": "patch",
          "published_at": "2026-06-06T00:44:57Z"
        },
        {
          "tag": "v1.94.10",
          "kind": "patch",
          "published_at": "2026-05-26T00:42:56Z"
        },
        {
          "tag": "v1.94.9",
          "kind": "patch",
          "published_at": "2026-05-21T00:44:59Z"
        },
        {
          "tag": "v1.94.8",
          "kind": "patch",
          "published_at": "2026-05-16T00:37:39Z"
        },
        {
          "tag": "v1.94.7",
          "kind": "patch",
          "published_at": "2026-05-10T08:21:00Z"
        },
        {
          "tag": "v1.94.6",
          "kind": "patch",
          "published_at": "2026-04-20T18:08:05Z"
        },
        {
          "tag": "v1.94.5",
          "kind": "patch",
          "published_at": "2026-04-20T17:55:00Z"
        },
        {
          "tag": "v1.94.4",
          "kind": "patch",
          "published_at": "2026-04-20T15:44:41Z"
        },
        {
          "tag": "v1.94.3",
          "kind": "patch",
          "published_at": "2026-04-20T14:51:28Z"
        },
        {
          "tag": "v1.94.2",
          "kind": "patch",
          "published_at": "2026-04-20T14:02:20Z"
        },
        {
          "tag": "v1.94.1",
          "kind": "patch",
          "published_at": "2026-04-14T12:11:28Z"
        },
        {
          "tag": "v1.94.0",
          "kind": "minor",
          "published_at": "2026-04-14T11:27:22Z"
        },
        {
          "tag": "v1.93.6",
          "kind": "patch",
          "published_at": "2026-04-11T00:26:47Z"
        },
        {
          "tag": "v1.93.5",
          "kind": "patch",
          "published_at": "2026-04-06T00:28:10Z"
        },
        {
          "tag": "v1.93.4",
          "kind": "patch",
          "published_at": "2026-04-03T09:19:24Z"
        },
        {
          "tag": "v1.93.3",
          "kind": "patch",
          "published_at": "2026-04-03T08:57:46Z"
        },
        {
          "tag": "v1.93.2",
          "kind": "patch",
          "published_at": "2026-04-03T08:52:47Z"
        },
        {
          "tag": "v1.93.1",
          "kind": "patch",
          "published_at": "2026-04-03T08:45:48Z"
        },
        {
          "tag": "v1.93.0",
          "kind": "minor",
          "published_at": "2026-03-31T10:11:26Z"
        },
        {
          "tag": "v1.90.2",
          "kind": "patch",
          "published_at": "2026-04-01T00:30:25Z"
        },
        {
          "tag": "v1.90.1",
          "kind": "patch",
          "published_at": "2026-03-31T00:27:19Z"
        },
        {
          "tag": "v1.90.0",
          "kind": "minor",
          "published_at": "2026-03-29T07:24:38Z"
        },
        {
          "tag": "v1.89.0",
          "kind": "minor",
          "published_at": "2026-03-29T06:59:12Z"
        },
        {
          "tag": "v1.88.0",
          "kind": "minor",
          "published_at": "2026-03-28T16:39:01Z"
        },
        {
          "tag": "v1.87.0",
          "kind": "minor",
          "published_at": "2026-03-28T16:05:15Z"
        },
        {
          "tag": "v1.86.0",
          "kind": "minor",
          "published_at": "2026-03-28T15:31:42Z"
        },
        {
          "tag": "v1.85.0",
          "kind": "minor",
          "published_at": "2026-03-28T15:19:54Z"
        },
        {
          "tag": "v1.84.0",
          "kind": "minor",
          "published_at": "2026-03-28T14:54:29Z"
        },
        {
          "tag": "v1.82.2",
          "kind": "patch",
          "published_at": "2026-03-26T00:26:59Z"
        },
        {
          "tag": "v1.82.1",
          "kind": "patch",
          "published_at": "2026-03-25T02:51:19Z"
        },
        {
          "tag": "v1.81.1",
          "kind": "patch",
          "published_at": "2026-03-22T11:04:42Z"
        },
        {
          "tag": "v1.81.0",
          "kind": "minor",
          "published_at": "2026-03-22T10:35:29Z"
        },
        {
          "tag": "v1.80.1",
          "kind": "patch",
          "published_at": "2026-03-19T11:06:44Z"
        },
        {
          "tag": "v1.79.2",
          "kind": "patch",
          "published_at": "2026-03-16T00:27:32Z"
        },
        {
          "tag": "v1.79.1",
          "kind": "patch",
          "published_at": "2026-03-13T18:58:52Z"
        },
        {
          "tag": "v1.78.2",
          "kind": "patch",
          "published_at": "2026-03-12T19:52:56Z"
        },
        {
          "tag": "v1.78.1",
          "kind": "patch",
          "published_at": "2026-03-12T19:25:49Z"
        },
        {
          "tag": "v1.78.0",
          "kind": "minor",
          "published_at": "2026-03-12T16:50:48Z"
        },
        {
          "tag": "v1.77.3",
          "kind": "patch",
          "published_at": "2026-03-12T16:47:15Z"
        },
        {
          "tag": "v1.77.2",
          "kind": "patch",
          "published_at": "2026-03-09T19:07:47Z"
        },
        {
          "tag": "v1.77.1",
          "kind": "patch",
          "published_at": "2026-03-08T11:30:57Z"
        },
        {
          "tag": "v1.77.0",
          "kind": "minor",
          "published_at": "2026-03-07T15:14:32Z"
        },
        {
          "tag": "v1.76.6",
          "kind": "patch",
          "published_at": "2026-03-05T19:12:28Z"
        },
        {
          "tag": "v1.76.5",
          "kind": "patch",
          "published_at": "2026-03-05T02:23:33Z"
        },
        {
          "tag": "v1.76.4",
          "kind": "patch",
          "published_at": "2026-03-01T00:25:53Z"
        },
        {
          "tag": "v1.76.3",
          "kind": "patch",
          "published_at": "2026-02-28T08:39:09Z"
        },
        {
          "tag": "v1.76.2",
          "kind": "patch",
          "published_at": "2026-02-28T08:28:44Z"
        },
        {
          "tag": "v1.76.1",
          "kind": "patch",
          "published_at": "2026-02-27T20:51:19Z"
        },
        {
          "tag": "v1.76.0",
          "kind": "minor",
          "published_at": "2026-02-27T15:20:28Z"
        },
        {
          "tag": "v1.75.0",
          "kind": "minor",
          "published_at": "2026-02-25T16:07:12Z"
        },
        {
          "tag": "v1.74.1",
          "kind": "patch",
          "published_at": "2026-02-26T00:21:36Z"
        },
        {
          "tag": "v1.74.0",
          "kind": "minor",
          "published_at": "2026-02-25T13:39:02Z"
        },
        {
          "tag": "v1.73.0",
          "kind": "minor",
          "published_at": "2026-02-25T11:27:53Z"
        },
        {
          "tag": "v1.72.1",
          "kind": "patch",
          "published_at": "2026-02-11T00:28:31Z"
        },
        {
          "tag": "v1.72.0",
          "kind": "minor",
          "published_at": "2026-02-06T08:02:49Z"
        },
        {
          "tag": "v1.71.1",
          "kind": "patch",
          "published_at": "2026-02-05T04:09:04Z"
        },
        {
          "tag": "v1.71.0",
          "kind": "minor",
          "published_at": "2026-02-04T13:31:03Z"
        },
        {
          "tag": "v1.70.2",
          "kind": "patch",
          "published_at": "2026-01-27T11:22:34Z"
        },
        {
          "tag": "v1.70.1",
          "kind": "patch",
          "published_at": "2026-01-26T13:00:17Z"
        },
        {
          "tag": "v1.70.0",
          "kind": "minor",
          "published_at": "2026-01-25T11:05:00Z"
        },
        {
          "tag": "v1.69.14",
          "kind": "patch",
          "published_at": "2026-01-25T10:13:39Z"
        },
        {
          "tag": "v1.69.13",
          "kind": "patch",
          "published_at": "2025-12-27T06:22:10Z"
        },
        {
          "tag": "v1.69.12",
          "kind": "patch",
          "published_at": "2025-12-19T19:15:37Z"
        },
        {
          "tag": "v1.69.11",
          "kind": "patch",
          "published_at": "2025-12-19T15:56:22Z"
        },
        {
          "tag": "v1.69.10",
          "kind": "patch",
          "published_at": "2025-12-19T09:43:18Z"
        },
        {
          "tag": "v1.69.9",
          "kind": "patch",
          "published_at": "2025-12-19T08:34:49Z"
        },
        {
          "tag": "v1.69.8",
          "kind": "patch",
          "published_at": "2025-12-19T07:34:49Z"
        },
        {
          "tag": "v1.69.7",
          "kind": "patch",
          "published_at": "2025-12-19T05:26:09Z"
        },
        {
          "tag": "v1.69.6",
          "kind": "patch",
          "published_at": "2025-12-19T05:22:02Z"
        },
        {
          "tag": "v1.69.5",
          "kind": "patch",
          "published_at": "2025-12-18T08:46:38Z"
        },
        {
          "tag": "v1.69.4",
          "kind": "patch",
          "published_at": "2025-12-18T08:02:06Z"
        },
        {
          "tag": "v1.69.3",
          "kind": "patch",
          "published_at": "2025-12-17T07:30:26Z"
        },
        {
          "tag": "v1.69.2",
          "kind": "patch",
          "published_at": "2025-12-17T06:57:44Z"
        },
        {
          "tag": "v1.69.1",
          "kind": "patch",
          "published_at": "2025-12-16T08:21:05Z"
        },
        {
          "tag": "v1.69.0",
          "kind": "minor",
          "published_at": "2025-12-13T05:32:08Z"
        },
        {
          "tag": "v1.68.15",
          "kind": "patch",
          "published_at": "2025-12-11T00:18:24Z"
        },
        {
          "tag": "v1.68.14",
          "kind": "patch",
          "published_at": "2025-12-08T09:32:27Z"
        },
        {
          "tag": "v1.68.13",
          "kind": "patch",
          "published_at": "2025-12-06T12:38:32Z"
        },
        {
          "tag": "v1.68.12",
          "kind": "patch",
          "published_at": "2025-12-04T19:08:27Z"
        },
        {
          "tag": "v1.68.11",
          "kind": "patch",
          "published_at": "2025-12-04T18:30:50Z"
        },
        {
          "tag": "v1.68.10",
          "kind": "patch",
          "published_at": "2025-12-04T12:25:04Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2e77d14b44836599674ac7cb8f05b57826a62664",
          "body": "WithDatastore only created DefaultMigrationPoolName when DO_MIGRATION was\ntrue. Job argv [\"setup\"] / DO_SETUP therefore failed migrate steps with\n\"datastore pool is not initialised\". Open the migration pool whenever\nsetup mode is active as well as for legacy migrate.",
          "is_bot": false,
          "headline": "fix(datastore): open migration pool for setup plan jobs",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T10:22:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e3d41fd993f92878960cbf21e5f179374bf74339",
          "body": "Support subdomain-style audiences such as https://profile.stawi.org\n(empty path) in addition to legacy path form under an API host.",
          "is_bot": false,
          "headline": "feat(config): allow host-only OAuth resource audiences",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T10:08:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e785e68f7b62c50f25193bd79384dcc9493aef2",
          "body": "Document Job argv [\"setup\"] (all registered steps) and DO_SETUP as the\ncanonical one-shot path. Legacy migrate / DO_MIGRATION remains supported\nbut is no longer the recommended default for deploys.",
          "is_bot": false,
          "headline": "docs(setup): prefer full setup plan over legacy migrate argv",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T09:55:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1aa8df036c9a215fd4f84a8ef6cd3e65f3d6080",
          "body": "GetRoles only accepted comma-separated strings under ext.roles, so Hydra\nsession extras shaped as [\"internal\"] left IsInternalSystem false. Service\nbots then checked tenancy_access#member instead of #service and permission\nregistration rejected internal SA tokens.\n\nAlso attach X-Serverless-Authorization (Google ID token) on HTTPS HTTP\nclient calls so product OAuth and Cloud Run invoker can both succeed when\nregistering permission manifests against IAM-authenticated tenancy hosts.",
          "is_bot": false,
          "headline": "fix(security): parse JWT roles arrays; dual-auth Cloud Run HTTP",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-27T09:15:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5824b66b3076752d1914c095e7874162fed7fd33",
          "body": "Fix relative link in multi-tenant isolation spec that broke\nmkdocs build --strict. Update direct/indirect Go modules\n(google.golang.org/api and transitive deps) to latest.",
          "is_bot": false,
          "headline": "fix(docs): repair mkdocs strict link; bump go deps",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T22:17:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49269b5592ccaa001d4f952f706b9a7f2d81feb9",
          "body": "The setup plan / no-PreStart contract is released as minor v2.1.0.",
          "is_bot": false,
          "headline": "docs(setup): prefer frame v2.1.0 over v2.0.17 patch series",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T19:20:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1b547c27bcd839879457daaf27d74e779a498ba",
          "body": "Permission manifests publish only via the setup plan (setup.NamePermissions).\nThis keeps Cloud Run cold starts fast and makes deploy-time registration\nfail-closed on the Job.\n\n- Drop PreStart path from WithPermissionRegistration\n- Add ShouldRunSetup + RunSetupForProcess for setup and legacy migrate\n- PERMISSIONS_REGISTER_ON_START deprecated/ignored (default false)\n- Docs: SETUP_JOB.md",
          "is_bot": false,
          "headline": "fix(setup): remove runtime PreStart permission registration",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:33:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20ebb153d5626d7c461e09e8b685661d3d6c3fc2",
          "body": "feat(setup): multi-task setup job (migrate, permissions, bootstrap)",
          "is_bot": false,
          "headline": "Merge pull request #688 from pitabwire/feat/setup-job",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:27:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f558c118f99b2826f43e57a11a6bdc94cc150c6",
          "body": "Move setup out of Frame-specific task funcs into package setup:\n\n- setup.Step / setup.Func — pure Name + Run contract\n- setup.Registry — register + bulk Run / RunAll (fail-closed, ordered)\n- setup.Selection / Select — argv and env without Service coupling\n\nFrame keeps thin adapters (Service.Setup, W\n[…]\netupStep/Func/Task,\nRunSetup, IsSetupMode). WithPermissionRegistration registers an abstract\npermissions Step on the registry.\n\nDocument fully in docs/SETUP_JOB.md, setup/README.md, service.md, index.",
          "is_bot": false,
          "headline": "refactor(setup): abstract Step interface and bulk Registry",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:26:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d369765aecc4fe07026098e70e097872a73d71eb",
          "body": "Add Service.RunSetup / WithSetupTask / IsSetupMode so Cloud Run Jobs can\nrun ordered one-shot steps (schema migrate, permission manifest publish,\nroot/bot bootstrap) instead of relying on every runtime PreStart.\n\nWithPermissionRegistration now:\n- always registers SetupTaskPermissions (fail-closed sy\n[…]\nsync PreStart when PERMISSIONS_REGISTER_ON_START=true\n  (default, Colony parity); set false on CR replicas once setup owns it\n\nLegacy argv migrate alone is unchanged. Prefer setup migrate permissions.",
          "is_bot": false,
          "headline": "feat(setup): multi-task setup job for migrate, permissions, bootstrap",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T18:20:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0f26ca5694efa49cc769b5c6d7b14df6e84bb038",
          "body": "Plaintext insecure credentials broke https AUTHORIZATION_SERVICE_* URIs\non Cloud Run (unexpected EOF on server preface). Use TLS for https and\nattach a Google ID token when ADC can mint one so IAM-authenticated\nKeto services accept invoker calls. Keep insecure for http:// cluster\nURLs.",
          "is_bot": false,
          "headline": "fix(authorizer): TLS + Cloud Run ID token for Keto gRPC",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-26T07:06:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6508c0c9d8a99b84b20f7961a61c12acb45090a2",
          "body": "configWithoutHTTPServer only stubbed two events methods, so Run failed\non ConfigurationEvents before reaching ErrHTTPServerConfigRequired.",
          "is_bot": false,
          "headline": "test(service): implement full ConfigurationEvents in HTTP config test",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T09:55:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2472051cfd17e8230c1f4f4b1116c9b51626b81b",
          "body": "Stamp membership on create from JWT claims, keep access_id immutable on\nrepository updates (with tenant/partition), and prefer profile_id for\ncreated_by/modified_by. Document that access_id is not RLS or Keto scope.",
          "is_bot": false,
          "headline": "fix(data): treat access_id as write attribution only",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T08:55:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a566961a9ac5988a40034873ddc61ea7bb15762",
          "body": "Add Service.ConnectDefaultInterceptors so handlers pick up the service\nClaimsBinder automatically (RequireClaims + no internal Skip under\nHybrid), making transparent isolation one call for Connect stacks.",
          "is_bot": false,
          "headline": "feat(service): wire Secure Profile into Connect default interceptors",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T06:59:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fe7fa916f620f3967edd3e9f5adced0179ce17b",
          "body": "Implement mode-driven multi-tenant isolation so services can opt into\ntransparent RLS enforcement without hand-written tenant filters.\n\n- Security modes: fail_open (default), hybrid, fail_closed\n- SystemPrincipal with scoped bind; AllowGlobal only via allowlist or\n  unforgeable framework migration m\n[…]\nds on untrusted push\n- Tenant-aware cache prefixes (t/ sys/ g/ unset/)\n- Enrollment strict + readiness arming for non-BYPASSRLS roles\n- WithSecureProfile() and design spec under docs/superpowers/specs",
          "is_bot": false,
          "headline": "feat(tenancy): Secure Profile isolation with fail-closed modes",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T06:57:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0fd41dfc501a2c42f1acaaffdf5f923bc9030d88",
          "body": "Normalize and validate tenant/partition IDs, preserve multi-partition\nsets across queue AsMetadata/ClaimsFromMap round-trips, and stop\nblanket-skipping RLS in queue consumers so published tenancy is enforced.",
          "is_bot": false,
          "headline": "fix(tenancy): harden claims validation and auth mapping",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T05:34:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "277b56540f13dc2a966e2e92371f952fcb317993",
          "body": "Register the three standard Kubernetes health endpoints with correct\nsemantics: /livez stays shallow and healthy during drain, /readyz\nreflects startup, termination, and dependency checks, and /healthz\nremains a deprecated readiness alias for compatibility.",
          "is_bot": false,
          "headline": "feat(service): add Kubernetes livez, readyz, and healthz probes",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-25T05:28:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6fc74e26e2a9ee3d8495e839ca796f262f991bb",
          "body": "Frame already registers the GCP Pub/Sub driver; importing frame/v2 is enough.\nAlso fix govet shadow in GCP push envelope Decode.",
          "is_bot": false,
          "headline": "docs(queue): apps need not blank-import gcppubsub",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:33:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7eefd05c0074b17e1df5d15fea4ec1fc82da069",
          "body": "Document and test that FRAME_QUEUE_PUSH_OIDC_ALLOWED_EMAILS matches either\nJWT email or sub (both claims always considered). Note that apps should\nstill blank-import gcppubsub for durable GCP linkage.",
          "is_bot": false,
          "headline": "fix(queue): check OIDC allowlist against both email and sub",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:25:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36d319a824d830cca0fcb6dbf1cd002dd62c76df",
          "body": "- EVENTS_QUEUE_PUBLISH_URL / EVENTS_QUEUE_SUBSCRIBE_URL override the\n  single EVENTS_QUEUE_URL so Cloud Run can publish via gcppubsub://\n  and receive via push:// (POST /_frame/queue/{ref})\n- Decode Google Pub/Sub push envelopes (base64 data + attributes)\n- Document the regional Pub/Sub push pattern for Cloud Run",
          "is_bot": false,
          "headline": "feat(queue): dual events URLs + GCP Pub/Sub push codec",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:23:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a69a59194b5700aeb8e13ac1fe26508eeafa57de",
          "body": "Register gocloud gcppubsub by default so gcppubsub:// topics and\nsubscriptions work without app-level blank imports. Classify the scheme\nas pull/Go Cloud. Add FRAME_QUEUE_PUSH_OIDC_ALLOWED_EMAILS so push OIDC\ncan restrict callers to known service-account email or sub claims.",
          "is_bot": false,
          "headline": "feat(queue): default GCP Pub/Sub driver and OIDC SA allowlist",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-24T16:13:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "426e052c550eb0cd9ea11acd3fb05bac17174875",
          "body": "Queue work is background processing: it should run until the handler\nreturns. Default FRAME_QUEUE_PUSH_HANDLER_TIMEOUT is now 0 (disabled),\nNewHandler no longer forces 25s, and HTTP write timeout auto-unbounds\nwhen push has no handler deadline so long events are not killed mid-flight.",
          "is_bot": false,
          "headline": "fix(queue): no default timeout for push consumers",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-22T05:37:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ab21460693b67966ffd4fcfab9f7644aa75afca",
          "body": "…ntics (#687)\n\nPreserve the design that missing claims does not error and does not filter.\nWhen claims are set, bind session GUCs so RLS applies by default; Skip and\nempty claims clear scope (match-all). Always clear session vars on acquire\nfor unscoped paths and on release so prior principal scope \n[…]\n.\n\nAlso reject partition IDs containing ',' (CSV encoding), document PgBouncer\nsession-mode requirements, and expand provider integration tests for\nreuse, WITH CHECK, and unscoped match-all behaviour.",
          "is_bot": false,
          "headline": "fix(tenancy): harden RLS session binding without changing opt-in sema…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-21T18:33:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04f3426ea592fc5877c2cf4e3542d60b3582eb58",
          "body": "Bumps the production-dependencies group with 5 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.82.0` | `1.82.1` |\n| [github.com/klauspost/compress](https://github.com/klauspost/compress) | `1.19.0` | `1.19.1` |\n| [github.com/prom\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 5 updates (#686)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T13:30:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c7b8e740881e6836b6aac198652015876f833869",
          "body": "Add URL-scheme transport modes so the same SubscribeWorker API works for\nlocal pull (mem/nats), Knative CloudEvents, and Google Cloud Tasks.\n\n- Shared processDelivery path for pull and push\n- Always-mounted POST /_frame/queue/{ref} demux handler\n- Protocol codecs: raw, CloudEvents binary/structured,\n[…]\nlishers: ce+http(s) binary egress and cloudtasks CreateTask REST\n- Push auth: bearer + dedicated Google OIDC; secure-by-default require-auth\n- Fix background-consumer vs NoopDriver terminal error race",
          "is_bot": false,
          "headline": "feat(queue): HTTP push multiplexing for Knative Events and Cloud Tasks",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-20T09:39:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "736f13f64ab8d996a7fb17814b922045306f398d",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-go\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/setup-go from 6 to 7 (#684)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T09:19:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab750ac5ca8515bc9094a826791d7dc6b99f693f",
          "body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-python\n  dependency-\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/setup-python from 6 to 7 (#685)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T09:12:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fc6cf4d3e49f2d15f73b26b58bde4829221e369e",
          "body": "…17 updates (#682)\n\n---\nupdated-dependencies:\n- dependency-name: github.com/lmittmann/tint\n  dependency-version: 1.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: production-dependencies\n- dependency-name: golang.org/x/net\n  dependency-version:\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group across 1 directory with …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T13:36:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2799797c60b120d26009365f488d879eb31c0c06",
          "body": "… (#683)\n\n---\nupdated-dependencies:\n- dependency-name: buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go\n  dependency-version: 1.36.11-20260709200747-435963d16310.1\n  dependency-type: indirect\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T13:35:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0e3ba41f4cbe9bf6973fa801b9e3fee4da9aa0e",
          "body": "…#681)\n\nPlatform invariant: subject is always the profile. Hydra may leave wire\nsub=client_id for client_credentials; after JWT validation we rewrite\nSubject from the profile_id claim so GetSubject/GetProfileID and ReBAC\ncheckers always see the acting profile.",
          "is_bot": false,
          "headline": "fix(security): enforce JWT sub === profile_id via NormalizeIdentity (…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-10T21:54:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e3b4038d8c8adb3ce7729c367b9f2595e748dc3",
          "body": "Profile is the acting principal for ReBAC. Hydra client_credentials\ntokens keep sub=client_id; profile_id is carried in claims. GetProfileID\nnow prefers profile_id, and tenancy/function/resource checkers use it so\nKeto grants remain keyed by profile — never OAuth client_id.",
          "is_bot": false,
          "headline": "fix(security): authorize with profile_id, not JWT sub/client_id (#680)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-10T21:22:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "caf863743bf5e1c5ceac2b98d64e91595be8e1f5",
          "body": "* fix: restore NoopDriver contract so svc.Run returns after start\n\nsendStopError ignored nil after the first-error sync.Once change, so\nWithNoopDriver / WithHTTPTestDriver never woke Run after ListenAndServe\nreturned. Tests then needed go func() { svc.Run(...) } workarounds.\n\nNil is a valid clean ex\n[…]\n invalid queue URLs make Run return an error\ninstead of a false success under NoopDriver.\n\nAlso register a publisher alongside mem:// subscribers in queue tests\n(topic must exist before subscription).",
          "is_bot": false,
          "headline": "fix: restore NoopDriver contract so svc.Run returns after start (#679)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-09T19:59:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82c225edcc8e86b5b8f604fd756970a5a9349994",
          "body": "…tBackGroundConsumer\n\n- Run svc.Run() in goroutine with error channel to avoid blocking\n- Use test driver getter after brief delay to let server start\n- Explicitly stop service and wait for graceful shutdown (context.Canceled)\n- Fix TestBackGroundConsumer to properly handle service stop lifecycle",
          "is_bot": false,
          "headline": "fix: resolve hanging tests in service_http_middleware_test.go and Tes…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-02T20:16:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a4255c2af92cff81b2bb4fa8ee40e94cf9741ee0",
          "body": null,
          "is_bot": false,
          "headline": "resolve merge conflicts from migrating to v2",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-07-02T11:17:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47c3887f3683e193f0759e25b9111f78cd7bdc14",
          "body": "…ility\n\nSecurity fixes (P0):\n- TokenAuthenticator: JWKS refresh now uses service context with 10s timeout, proper shutdown via WaitGroup\n- OIDC discovery: replaced http.DefaultClient with timed http.Client (10s)\n- JWT validation: added WithExpirationRequired() parser option\n\nResilience & correctness\n[…]\n Updated docs for new config options\n- Fixed lint issues (goimports, golines, govet, exhaustive)\n\nTesting:\n- All security tests pass\n- Service tests pass\n- Cache tests pass\n- Lint passes with 0 issues",
          "is_bot": false,
          "headline": "security/resilience: fix critical issues and improve framework reliab…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-30T19:14:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c10bb5b02913ed03b341380631858b2c83f5292a",
          "body": "Bumps the production-dependencies group with 4 updates: [gorm.io/gorm](https://github.com/go-gorm/gorm), [github.com/moby/sys/user](https://github.com/moby/sys), [github.com/prometheus/procfs](https://github.com/prometheus/procfs) and [google.golang.org/api](https://github.com/googleapis/google-api-\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 4 updates (#677)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T13:29:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f4cf2e40f8368378ebbad628bd94b90507824f9",
          "body": "Refs #675",
          "is_bot": false,
          "headline": "feat!: adopt Frame v2 semantic import path (#676)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-29T00:41:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f34e6f2c8019575b512ea9da3c5aedd2a394564",
          "body": "…#674)\n\nRefs #673",
          "is_bot": false,
          "headline": "feat!: standardize typed authentication and authorization contracts (…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-29T00:29:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f84d832a396fcee87c47d21fa45f323b1e52c0b",
          "body": "Bumps the production-dependencies group with 12 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/moby/moby/api](https://github.com/moby/moby) | `1.54.2` | `1.55.0` |\n| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.20.1` | `9.21.0` |\n| [github.com/spiffe/go\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 12 updates (#672)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T13:29:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "726c889a38945386c3d802ac73af279abfd8d23e",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: '7'\n  depen\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/checkout from 6 to 7 (#671)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-22T09:12:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b20eec52789565dedf96f24bbfd7467f928c9c9b",
          "body": "Bumps the production-dependencies group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.20.0` | `9.20.1` |\n| [golang.org/x/net](https://github.com/golang/net) | `0.55.0` | `0.56.0` |\n| [golang.org/x/text](https://g\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 6 updates (#670)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-15T13:37:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d965fed3e9c66002079ed3bf7ed4ec3349ae035",
          "body": "…ments (#669)\n\nThe standard factory for product/business metrics. Counter/FloatCounter/\nHistogram/Gauge/FloatGauge wrappers merge TenantAttributes(ctx) into\nevery measurement, so call sites cannot forget tenant attribution —\nthe existing opt-in WithTenantAttributes pattern proved forgettable\n(23 fin\n[…]\nrd without tenant attributes; explicit per-call attributes are\npreserved. Instrument-creation errors fall back to noop instruments\n(metrics never break the service), matching LatencyMeasure behaviour.",
          "is_bot": false,
          "headline": "feat(telemetry): BusinessMetrics — transparently tenant-scoped instru…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T20:27:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f15a12cc233417e00a24a3fbcb6885aac1a433a3",
          "body": "Tenanted/Unscoped have pointer receivers, so a migrate list passing\nmodels BY VALUE silently failed the interface assertions and the\ntables were skipped during RLS install — no error, no policy. Four\nservices shipped that way (settings refs/vals/audits in profile,\nproperty tables in files, the entir\n[…]\nct values to\npointers before checking, so registration style cannot change\nenforcement. Regression test proves value and pointer registration\nenroll identically (fails on the previous implementation).",
          "is_bot": false,
          "headline": "fix(tenancy): enroll models registered by value (#668)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T17:13:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fe4745e492ebd3b9037772b938b887ef6f0d9090",
          "body": "…est suites (#667)\n\nPromoted from service-fintech apps/limits/tests/rlstest. Wraps the\npostgres tenancy provider with Enable-gated SET ROLE hooks so test\nqueries run under an unprivileged role: testcontainer users are\nsuperusers and bypass FORCE ROW LEVEL SECURITY, so without this no\nsuite actually \n[…]\nr\nlate-created tables).\n\nPackage test proves the gate: superuser sees cross-tenant rows before\nEnable, the scoped role sees none after, own-tenant and claim-less\n(system match-all) reads keep working.",
          "is_bot": false,
          "headline": "feat(frametests): add rlstest — RLS-exercising tenancy provider for t…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T15:58:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca7e497939c05110fbe854199146b4d1d85ccb27",
          "body": "util v0.9.1 fixes MultiHandler fan-out so LOG_LEVEL takes effect on\nstdout even with the OTel telemetry log handler attached.\n\nretract v1.94.12: published accidentally from a stale release draft on\n2026-06-10 — the tag pointed at post-v1.98.0 main and was cached by the\nmodule proxy before deletion.",
          "is_bot": false,
          "headline": "deps: bump pitabwire/util v0.9.0 → v0.9.1; retract v1.94.12 (#666)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-10T09:46:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "58dfe7717e38856b672a853adc829cdf25b71323",
          "body": "…11 updates (#665)\n\nBumps the production-dependencies group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) | `5.9.2` | `5.10.0` |\n| [github.com/redis/go-redis/v9](https://github.com/redis/go-redis) | `9.19.0`\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group across 1 directory with …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-08T14:05:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fcecf051c259f5baea98677b4ca2a711f7f5064c",
          "body": "…ocloud v0.46 (#664)\n\nOTel SDK v1.44 moves its default resource to semconv schema 1.41.0. Frame's\ntelemetry resource was pinned to semconv v1.40.0, so resource.Merge of the\nSDK default with Frame's resource failed with \"conflicting Schema URL\"\n(1.41.0 vs 1.40.0) — breaking service/telemetry init (an\n[…]\nb v0.69, otelpgx\n  v0.11.1) and gocloud.dev v0.45->v0.46.\n\nVerified: resource.Merge(resource.Default(), frame-resource) now succeeds\nwith a unified 1.41.0 schema; build, vet, and telemetry tests pass.",
          "is_bot": false,
          "headline": "feat(telemetry): upgrade to OpenTelemetry v1.44 / semconv v1.41 and g…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-08T13:57:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0436080a544c939882c15b9b39f71f7b18323b72",
          "body": "…rer (#662)\n\nHTTPClientManager auto-attaches the service's outbound OAuth bearer (resolved\nfrom the OAuth config in ctx) to every client it builds, with no per-call\nopt-out — clobbering an external API's own Authorization header (e.g. an API\nkey). Services had to fall back to a bare stdlib client an\n[…]\nlogging) but attaches NO bearer. The OAuth application is extracted to\napplyOutboundOAuth to keep the guard flat. shouldCreateRequestScopedClient\nhonours the flag so InvokeRestService respects it too.",
          "is_bot": false,
          "headline": "feat(client): WithHTTPNoAuth() — manager client without the OAuth bea…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-06-04T11:10:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f2269d4cf9fd34b3b3cf1ca4f7b3cd19c0c82b8",
          "body": "Bumps the production-dependencies group with 8 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [connectrpc.com/connect](https://github.com/connectrpc/connect-go) | `1.19.2` | `1.20.0` |\n| [github.com/exaring/otelpgx](https://github.com/exaring/otelpgx) | `0.10.0` | `0.11.1` |\n| [github.com/p\n[…]\nte:semver-patch\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 8 updates (#660)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-25T19:43:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c0707b540772e17476d197f05459ee5d182af1a",
          "body": "… failure\n\nWhen a service's permission registration fails — Hydra unreachable, the\nsigner endpoint not yet up, tenancy briefly unavailable — the option was\nFatal-ing the process. That is too aggressive: it deadlocks the auth\nservice during a cold rollout, because the auth pod's signer is *itself*.\nW\n[…]\nhe documented invariant (every service's namespace\nreaches tenancy.service_namespaces on every pod start) while making\npod startup tolerant of transient peer unavailability and self-bootstrap\nwindows.",
          "is_bot": false,
          "headline": "fix(permissions): retry-with-backoff instead of Fatal on registration…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-21T22:52:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df294fa783657a77a7b30072c561c4b52f383134",
          "body": "publishManifest pre-marshalled the manifest to JSON bytes and then\npassed those bytes to HTTPClientManager().Invoke — which json.Marshal's\nits payload again. Marshalling []byte yields a base64-encoded JSON\nstring, not the original object, so the tenancy registration endpoint\nsaw a literal string wit\n[…]\nspace/permissions fields and returned\n400 Bad Request.\n\nPass the manifest map directly. Invoke handles JSON encoding once.\nThe drop of the redundant json.Marshal also removes the encoding/json\nimport.",
          "is_bot": false,
          "headline": "fix(permissions): pass manifest map to Invoke, drop double JSON marshal",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-21T21:19:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30846eef4c32a7c1ed29bdfcb69208f23122c09d",
          "body": "…y pod start\n\nWithPermissionRegistration only added its PreStartMethod when\nDoDatabaseMigrate() returned true. The intent was \"register from the\nmigration job, not from the main pod\", but in practice services'\ncmd/main.go runs the migration synchronously *before* svc.Init and\nreturns early — the Pre\n[…]\nhatever the running binary\ndeclares.\n\nConsumers no longer need to invent glue (short-circuit-then-Run-with-\ntimeout, or out-of-band POST helpers) around svc.Run to make this fire\nfrom a migration job.",
          "is_bot": false,
          "headline": "fix(permissions): drop DO_MIGRATION gate so registration runs on ever…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-21T20:13:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "07995fb69e2d8ddb36fcd3be06ee1286d67ca9eb",
          "body": "Bumps the production-dependencies group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/valkey-io/valkey-go](https://github.com/valkey-io/valkey-go) | `1.0.74` | `1.0.75` |\n| [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `1.81.0` | `1.81.1` |\n| [github.com/go\n[…]\nte:semver-minor\n  dependency-group: production-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "deps: bump the production-dependencies group with 6 updates (#659)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T23:25:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b35fbbdc8cf801aca58da39532e98df24b819b2",
          "body": "…658)\n\nBumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token) from 3.1.1 to 3.2.0.\n- [Release notes](https://github.com/actions/create-github-app-token/releases)\n- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md)\n- [Commits](\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "ci(deps): bump actions/create-github-app-token from 3.1.1 to 3.2.0 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-18T16:17:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "962054057189bb65bd83aa8d806cef1c38a47652",
          "body": "…ic Noop handlers\n\nCatch-all-subject consumers (e.g. NATS subscription on\nsvc.X.events.>) previously had to register a NoopHandler for every\nevent type the service intentionally ignored. Forgetting one entry\nturned the message into a permanent retry-storm; remembering all of\nthem risked silently dro\n[…]\nr arrays.\n\nTests cover both modes (existing events_test.go suite remains green;\nnew shared-stream behaviour is exercised by integration tests in the\nopportunities service after the loose-mode opt-in).",
          "is_bot": false,
          "headline": "feat(events): loose-mode manager — ack unknown events without per-top…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-18T05:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f073429940ade4c6f3e585ef2c66b551ca31df2a",
          "body": "http.DefaultTransport's MaxIdleConnsPerHost=2 forces every caller past\nthe second concurrent in-flight to open a new TCP connection per\nrequest. At service-to-service concurrency the upstream's accept queue\nfloods with TIME_WAITs and most requests return \"read: connection reset\nby peer\".\n\nLive trace\n[…]\no: nolint the existing crypto/elliptic X/Y deprecations in the JWT\ntest fixture so the pre-commit lint passes; those are unrelated and\nthe rewrite to crypto/ecdh would touch too much test scaffolding.",
          "is_bot": false,
          "headline": "fix(client): bump MaxIdleConnsPerHost from stdlib default (2) to 64",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-17T20:31:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbde0c25b0d9619d819ef328a07f0723e7af755e",
          "body": "Services typically talk to multiple downstreams with different latency\nprofiles in the same binary — an LLM inference endpoint that wants 5min\nof patience alongside an identity API that should fail fast at 3s. A\nsingle HTTP_CLIENT_TIMEOUT env var sets the service-wide default but\ncannot differentiat\n[…]\n now reachable from .Client):\n  per-call option > env-var / context config > 30s default\n\nTests cover the shared-client identity, the scoped-client divergence,\nand the precedence vs in-context config.",
          "is_bot": false,
          "headline": "feat(client): Manager.Client accepts per-call HTTPOptions",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-17T18:56:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0706a6c82c60d61b458b157b49f3c212f37291a",
          "body": "Outbound http.Client.Timeout was hard-pinned to 30s with no env-var or\nyaml override, leaving callers no path to extend it for slow downstreams\n(e.g. in-cluster LLM inference whose response time exceeds 30s). The\nonly knob was the code-level WithHTTPTimeout option, which is not\nreachable from deploy\n[…]\n vs invalid/empty fallback to defaults\n- context-seeded timeout flows into the constructed client\n- explicit WithHTTPTimeout overrides the context default\n- absence of any config keeps the 30s default",
          "is_bot": false,
          "headline": "feat(client): env-driven HTTP_CLIENT_TIMEOUT / HTTP_CLIENT_IDLE_TIMEOUT",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-17T18:24:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "412380e139007d410383fba11e57ff652d01b3ff",
          "body": null,
          "is_bot": false,
          "headline": "deps: bump pitabwire/natspubsub to v0.8.4",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:59:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adb0bfe4459fe6d83f8e75a2c8a7d178a9bdab79",
          "body": "…t cleanup\n\n- DefaultList now appends tenancy.NewClaimsInterceptor after auth so\n  downstream services get tenancy claims bound automatically.\n- AdvisoryLock doc-comment notes that the pinned conn fires acquire\n  hooks (safe: migrations are typically claim-less; AfterRelease\n  resets any state).\n- NewPool panic comment clarified — only nil-hook contract violation\n  can trip it; structurally unreachable for concrete providers.\n- Test asserts MaxIdleConns=0 invariant on the *sql.DB.",
          "is_bot": false,
          "headline": "feat(security): include tenancy interceptor in DefaultList; misc audi…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f952b5d2a4591ead184f47821600ef356973e67",
          "body": "…terns",
          "is_bot": false,
          "headline": "feat(tenancy): WithSkipEnforcement helper; document worker + perf pat…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6cf6d140aa34c2d9865bfa0a4ea34c25f02840c",
          "body": "…eConnections\n\nThe dialect adapter forces sql.DB MaxIdleConns=0 regardless of the\npool Option, because tenancy hook correctness requires every release\nto flow through pgxpool (and through the hook chain). WithMaxIdle has\nbeen silently ineffective; mark it Deprecated and turn the body into\na no-op so callers immediately see it has no effect. Drop the\nMaxIdle field from Options (it was unread) and stop forwarding\nconfig.GetMaxIdleConnections via WithMaxIdle in datastoreOptsFromConfig.",
          "is_bot": false,
          "headline": "chore(pool): document WithMaxIdle as no-op; stop forwarding GetMaxIdl…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f7a04525158b451ec79c4d29a9401f142a140cb",
          "body": "…entifier quoter\n\nStash the wired adapter on the Provider so Install can delegate\nidentifier quoting back to the adapter (matching whatever dialect\nrules are in force) instead of duplicating the canonical Postgres\ndouble-quote implementation in a file-local pgQuoteIdent. Falls back\nto the canonical rule when the provider is used without WireAdapter\n(e.g. tests that drive Install directly). Receivers on Install and\napplyTenancyPolicy promoted to pointer so they can read p.adapter.",
          "is_bot": false,
          "headline": "refactor(tenancy/postgres): provider holds adapter; drop duplicate id…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c4063eb0896adebdc293e8ea2d71e4b75d925a2",
          "body": "…k snapshot; log hook failures\n\n* tenancy/postgres: collapse the two set_config / RESET round trips in\n  beforeAcquire / afterRelease into a single Exec each, halving the\n  hook overhead on every conn acquire and release. afterRelease now\n  uses `set_config(..., '', false)` so both vars reset in one\n[…]\nrace-detected with the\n  earlier per-acquire RLock pattern).\n* dialect/postgres: log hook failures at WARN before pgxpool drops or\n  destroys the conn, so silent acquire/release errors are observable.",
          "is_bot": false,
          "headline": "perf(tenancy/postgres,dialect/postgres): batch hook SQL; per-pool hoo…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "943f364c44768b2d023d9a5f76a2c161863c176a",
          "body": "…test\n\nWithDatastoreConnectionWithOptions was calling pool.NewPool(ctx) with no\noptions, so WithTenancyProvider and WithDialectAdapter were silently\ndropped — only the pool's internal default Postgres-RLS provider ever\nreceived WireAdapter. Custom providers got only WireGorm (a no-op for\nthe Postgre\n[…]\nes:\n  - WithTenancyProvider(custom) -> WireAdapter called once, override\n    reachable via svc.TenancyProvider()\n  - WithTenancyProvider(nil)    -> svc.TenancyProvider() is nil, no\n    hooks installed",
          "is_bot": false,
          "headline": "fix(frame): WithTenancyProvider now reaches pool.NewPool; regression …",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "87d807ca0f219e56581f7293ad16f4ec9b0866f5",
          "body": "…n *sql.DB\n\nreflect.DeepEqual reaches into pgxpool's mutable state and races with\nbackground acquire/release goroutines; identity is the only meaningful\ncheck anyway.",
          "is_bot": false,
          "headline": "test(datastore): use pointer identity instead of reflect deep-equal o…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "057e5eea4913ec2c85aa44cb9a8878b9e855ef96",
          "body": "Pull the GORM AutoMigrate + tenancy provider install branch out of\nMigrate into a dedicated helper so the top-level flow reads as a\nlinear sequence of early-return steps. Resolves the `nestif`\ncomplaint on the post-Task-16 Migrate function without changing\nbehaviour.",
          "is_bot": false,
          "headline": "refactor(pool): extract applyAutoMigrations to flatten Migrate nesting",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b707c92a5e9e2399ae908aefbc2ba1bfffee4f7",
          "body": "The legacy `package pool` declaration was originally needed because\nthe test reached into the unexported `isRelationAlreadyExistsErr`\nhelper. After Task 16 that helper moved to the dialect adapter and\nthe surviving test only exercises the public Pool API, so flip the\npackage to `pool_test` and silence the `testpackage` linter.",
          "is_bot": false,
          "headline": "refactor(pool): move Migrate sanity test to pool_test package",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f765e4e84e7836bcb02976ae2e1fa9c1dd9db48",
          "body": "Run the project's `make format` hook to normalise import grouping in\nservice.go and tenancy/postgres/provider.go after the Task 1-21\nrefactor. Pure formatting; no behaviour change.",
          "is_bot": false,
          "headline": "chore(lint): goimports sweep across refactored packages",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f9d210d4889dd4c0b306e2e3a3835c1d37be426",
          "body": "…ser caveat",
          "is_bot": false,
          "headline": "docs(datastore): document tenancy package, one-shot model, RLS superu…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dae45882530802e5c96e50caa1378edc99d591db",
          "body": null,
          "is_bot": false,
          "headline": "test(tenancy): end-to-end claims interceptor (testcontainers)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9ba47bb1e394d5f82f1a2d2c3ace0f80745a914",
          "body": "…the right session",
          "is_bot": false,
          "headline": "fix(dialect/postgres): pin connection in AdvisoryLock so unlock hits …",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "50c29da75f2bf4ee50202d57617a941e500e1c14",
          "body": null,
          "is_bot": false,
          "headline": "feat(frame): WithTenancyProvider option + svc.TenancyProvider() accessor",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff3cd718593613ce7287ed718cf20890e7d6cd55",
          "body": null,
          "is_bot": false,
          "headline": "refactor(datastore): delete scopes package (redundant with RLS)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae892e5fef3048127091e413b6b6a32d2eb93190",
          "body": "…ncy.NewClaimsInterceptor",
          "is_bot": false,
          "headline": "refactor(security): remove tenancy-tx interceptor; superseded by tena…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e76114e9cb1705ba20d6005393d134ed60d3405",
          "body": "… nolint markers)",
          "is_bot": false,
          "headline": "chore(tenancy/postgres): post-Task-11 lint cleanup (errors.New + drop…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45a9f2cd1fb4e08793f22462d68dd5b00e444020",
          "body": "…op tx-in-context\n\nStrip all tenancy methods (WithTenancy, WithRequestTx, ContextWithTx,\nTxFromContext) from the Pool interface. Tenancy is now enforced at the\nconnection-acquire level by the configured tenancy.Provider's adapter\nhook -- application code no longer threads transaction-bound contexts.\n[…]\nks at security/interceptors/connect/tenancy_tx.go which still\nreferences pool.WithRequestTx. Task 17 removes that file to restore\nthe build. Pre-commit hook bypassed (--no-verify) for the same reason.",
          "is_bot": false,
          "headline": "refactor(pool): compose dialect.DialectAdapter + tenancy.Provider; dr…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ffd994690cb0022faed9d0880eecba72d177a706",
          "body": null,
          "is_bot": false,
          "headline": "feat(pool): WithDialectAdapter + WithTenancyProvider options",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "858f1ef5bea0d5671391596bd2d9b60f6e71a1b6",
          "body": "…ntainers)",
          "is_bot": false,
          "headline": "test(tenancy/postgres): RLS install + per-acquire enforcement (testco…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3126c40f6df00f4fa468e573d23ff9813115d91",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): Connect claims interceptor (no transactions)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c3962ab338cd38833b68a09cc1c48a5c95dc259",
          "body": null,
          "is_bot": false,
          "headline": "chore(tenancy): simplify test assertion",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c62fc52f5d44daff7b8a4099f9a8a976c624f98d",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): claims context binding, auth derivation, extension helper",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c01fd5f4a4ae0ee9306887a7eb5bae9d1f4b9958",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy/postgres): Install (RLS) + WireAdapter hooks",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98fb9a9bb6a604df28c902128146c8447e78fcf9",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy/postgres): embed RLS DDL fragments",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6762cf64356ef64e6689d24cff9f5d6efe0bcfc0",
          "body": "…oured",
          "is_bot": false,
          "headline": "fix(tenancy): use gorm.Statement.Parse so TableName overrides are hon…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e0380478f61a1b6b6cfa91d0e75ceb229fb5a9f",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): structural enrollment via Tenanted / Unscoped",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b5e66dc4d18392b6ef7654979fec2488acb3492",
          "body": "…test green",
          "is_bot": false,
          "headline": "fix(dialect): close pgxpool via OpenConnection close-fn; integration …",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d17d13990273e4998b1c8933fcaea81a4256f28",
          "body": "…ts; wrap lock errors",
          "is_bot": false,
          "headline": "fix(dialect/postgres): bound release hook timeout; correct doc-commen…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad25d75afbff0a6dbbea416e04efcdafb42fb759",
          "body": null,
          "is_bot": false,
          "headline": "feat(dialect/postgres): Adapter with pgxpool hook plumbing",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85e7e36574d96fa55c1fa5993f865dc0d7c68c89",
          "body": "… caveats",
          "is_bot": false,
          "headline": "docs(dialect/postgres): document NormalizeDSN heuristic and inherited…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9512b8753b4d242c5c649beb3ce9d39ac967eec",
          "body": null,
          "is_bot": false,
          "headline": "feat(dialect/postgres): port DSN normalisation",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "903f9ebec91edb0ea9cee443c319b07a98e71cf8",
          "body": "…ontract",
          "is_bot": false,
          "headline": "refactor(dialect,tenancy): drop gorm-logger leak; clarify ModelInfo c…",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25621e2293102e027b2ab2c81d6a1167f0a74e92",
          "body": null,
          "is_bot": false,
          "headline": "feat(dialect): introduce DialectAdapter abstraction",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "018589ff2a5239dd87bdc41932a782c205558df9",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): declare Provider interface (forward-references dialect)",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf47d20e2ce1b37071d4f5c47876de445ebfb480",
          "body": null,
          "is_bot": false,
          "headline": "test(data): cover overwrite + clear-to-empty; document mirror sync",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b4693e9b0d0a4cb2f2b6ac43422105fd443e6cb",
          "body": null,
          "is_bot": false,
          "headline": "feat(data): BaseModel implements tenancy.Tenanted via setters",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45afd40de10379359b3d7c2c3fa43e860d28df72",
          "body": null,
          "is_bot": false,
          "headline": "test(tenancy): cover nil-receiver contract for Claims",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4771b268448df4c39039f02d26b04afc37782238",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): add immutable Claims with additive ExtendPartitions",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0518cb7ada8e86aabb754f910a520a5b353c228b",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): add compile-time guard for UnscopedMarker",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2289c57d624dc071146f3be76f7187473c3522cc",
          "body": null,
          "is_bot": false,
          "headline": "feat(tenancy): introduce Tenanted and Unscoped markers",
          "author_name": "Peter Bwire",
          "author_login": "pitabwire",
          "committed_at": "2026-05-12T17:57:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 100,
      "commits_last_year": 664,
      "latest_release_at": "2026-07-27T10:09:49Z",
      "latest_release_tag": "v2.1.2",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 48,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 0.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/pitabwire/frame/v2",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/pitabwire/frame/v2",
          "is_deprecated": false,
          "latest_version": "v2.1.3",
          "repository_url": "https://github.com/pitabwire/frame",
          "versions_count": 21,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-27T10:22:03Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 5,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2021-09-24",
            "count": 1
          },
          {
            "date": "2023-12-20",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [
        "frametests/rpcservice/ping/v1/ping.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 96081,
      "source_files_sampled": 297,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 20
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 149,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "buf.build/go/protovalidate",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "connectrpc.com/connect",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.20.0"
        },
        {
          "name": "connectrpc.com/otelconnect",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.0"
        },
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/caarlos0/env/v11",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v11.4.1"
        },
        {
          "name": "github.com/exaring/otelpgx",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.11.1"
        },
        {
          "name": "github.com/go-jose/go-jose/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.1.4"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.10.0"
        },
        {
          "name": "github.com/lmittmann/tint",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.0"
        },
        {
          "name": "github.com/moby/moby/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.55.0"
        },
        {
          "name": "github.com/nats-io/nats.go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.52.0"
        },
        {
          "name": "github.com/nicksnyder/go-i18n/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.6.1"
        },
        {
          "name": "github.com/ory/keto/proto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0"
        },
        {
          "name": "github.com/panjf2000/ants/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.12.1"
        },
        {
          "name": "github.com/pitabwire/natspubsub",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.8.4"
        },
        {
          "name": "github.com/pitabwire/util",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/redis/go-redis/v9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.21.0"
        },
        {
          "name": "github.com/rs/xid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/spiffe/go-spiffe/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.8.1"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/nats",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/postgres",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/valkey",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.43.0"
        },
        {
          "name": "github.com/valkey-io/valkey-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.76"
        },
        {
          "name": "go.opentelemetry.io/contrib/bridges/otelslog",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.19.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/exporters/autoexport",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/contrib/propagators/autoprop",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/log",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.20.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "gocloud.dev",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.46.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.57.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "google.golang.org/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.290.0"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.82.1"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "gorm.io/driver/postgres",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "gorm.io/gorm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.31.2"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "buf.build/go/protovalidate",
            "direct": true,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "connectrpc.com/connect",
            "direct": true,
            "version": "v1.20.0",
            "ecosystem": "go"
          },
          {
            "name": "connectrpc.com/otelconnect",
            "direct": true,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/caarlos0/env/v11",
            "direct": true,
            "version": "v11.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/exaring/otelpgx",
            "direct": true,
            "version": "v0.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": true,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgx/v5",
            "direct": true,
            "version": "v5.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lmittmann/tint",
            "direct": true,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/moby/api",
            "direct": true,
            "version": "v1.55.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nats.go",
            "direct": true,
            "version": "v1.52.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nicksnyder/go-i18n/v2",
            "direct": true,
            "version": "v2.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ory/keto/proto",
            "direct": true,
            "version": "v0.13.0-alpha.0.0.20260420082854-eb334a7a5cf0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/panjf2000/ants/v2",
            "direct": true,
            "version": "v2.12.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pitabwire/natspubsub",
            "direct": true,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pitabwire/util",
            "direct": true,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/v9",
            "direct": true,
            "version": "v9.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rs/xid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spiffe/go-spiffe/v2",
            "direct": true,
            "version": "v2.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/nats",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/postgres",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/valkey",
            "direct": true,
            "version": "v0.43.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/valkey-io/valkey-go",
            "direct": true,
            "version": "v1.0.76",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/bridges/otelslog",
            "direct": true,
            "version": "v0.19.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/exporters/autoexport",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/autoprop",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/log",
            "direct": true,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/log",
            "direct": true,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "gocloud.dev",
            "direct": true,
            "version": "v0.46.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": true,
            "version": "v0.57.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/api",
            "direct": true,
            "version": "v0.290.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.82.1",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/driver/postgres",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "gorm.io/gorm",
            "direct": true,
            "version": "v1.31.2",
            "ecosystem": "go"
          },
          {
            "name": "buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go",
            "direct": false,
            "version": "v1.36.11-20260709200747-435963d16310.1",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.2",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/auth",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/auth/oauth2adapt",
            "direct": false,
            "version": "v0.2.8",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/compute/metadata",
            "direct": false,
            "version": "v0.9.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/iam",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/pubsub",
            "direct": false,
            "version": "v1.51.0",
            "ecosystem": "go"
          },
          {
            "name": "cloud.google.com/go/pubsub/v2",
            "direct": false,
            "version": "v2.6.1",
            "ecosystem": "go"
          },
          {
            "name": "dario.cat/mergo",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr4-go/antlr/v4",
            "direct": false,
            "version": "v4.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/go-ansiterm",
            "direct": false,
            "version": "v0.0.0-20250102033503-faa5f7b0171c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs/pkg",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/log",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/platforms",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cpuguy83/dockercfg",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/distribution/reference",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-connections",
            "direct": false,
            "version": "v0.8.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-units",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ebitengine/purego",
            "direct": false,
            "version": "v0.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ole/go-ole",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/cel-go",
            "direct": false,
            "version": "v0.30.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/s2a-go",
            "direct": false,
            "version": "v0.1.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/wire",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googleapis/enterprise-certificate-proxy",
            "direct": false,
            "version": "v0.3.19",
            "ecosystem": "go"
          },
          {
            "name": "github.com/googleapis/gax-go/v2",
            "direct": false,
            "version": "v2.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgpassfile",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgservicefile",
            "direct": false,
            "version": "v0.0.0-20240606120523-5a60cdf6a761",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/puddle/v2",
            "direct": false,
            "version": "v2.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/inflection",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jinzhu/now",
            "direct": false,
            "version": "v1.1.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.19.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lufia/plan9stats",
            "direct": false,
            "version": "v0.0.0-20260627054121-477a66015f15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/magiconair/properties",
            "direct": false,
            "version": "v1.18.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mdelapenya/tlscert",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/docker-image-spec",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/go-archive",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/moby/client",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/patternmatcher",
            "direct": false,
            "version": "v0.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/sequential",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/user",
            "direct": false,
            "version": "v0.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/userns",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/term",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nkeys",
            "direct": false,
            "version": "v0.4.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/nats-io/nuid",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/go-digest",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/image-spec",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/power-devops/perfstat",
            "direct": false,
            "version": "v0.0.0-20240221224432-82ca36839d55",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.24.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.70.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.21.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shirou/gopsutil/v4",
            "direct": false,
            "version": "v4.26.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.9.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/go-sysconf",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/numcpus",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yusufpapurcu/wmi",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/bridges/prometheus",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/aws",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/b3",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/jaeger",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/propagators/ot",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": false,
            "version": "v0.66.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdoutlog",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdoutmetric",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.5",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20260718201538-764159d718ef",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/xerrors",
            "direct": false,
            "version": "v0.0.0-20240903120638-7835f813f4da",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto",
            "direct": false,
            "version": "v0.0.0-20260724162435-b2f20204f0df",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": false,
            "version": "v0.0.0-20260724162435-b2f20204f0df",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260724162435-b2f20204f0df",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 149,
        "direct_count": 47,
        "indirect_count": 102
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 663,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 5,
        "closed_unmerged_prs": 18
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "pitabwire",
          "commits": 1127,
          "avatar_url": "https://avatars.githubusercontent.com/u/4368681?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "changelog.yml",
        "dependabot-auto-merge.yml",
        "docs.yml",
        "draft_release.yml",
        "gemini-cli.yml",
        "gemini-pr-review.yml",
        "golangci-lint.yml",
        "publish-release.yml",
        "run_tests.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/23 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 1,
            "reason": "dependency not pinned by hash detected -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2e77d14b44836599674ac7cb8f05b57826a62664",
        "ran_at": "2026-07-28T22:07:57Z",
        "aggregate_score": 5.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T13:25:20Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-26T18:27:36Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/pitabwire/frame",
    "host": "github.com",
    "name": "frame",
    "owner": "pitabwire"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 71,
      "inputs": {
        "security": 62,
        "vitality": 98,
        "community": 38,
        "governance": 57,
        "engineering": 96
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 98,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "commits_last_year": 664,
              "human_commit_share": 0.87,
              "days_since_last_push": 1,
              "active_weeks_last_year": 48
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "48/52 weeks with commits",
                "points": 33.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 48
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "664 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 664
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v2.1.2",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 0.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 38,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "forks": 2,
              "stars": 5,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "5 stars",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "merged_prs": 663,
              "open_issues": 0,
              "closed_issues": 5,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 18
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "663/681 decided PRs merged",
                "points": 37.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 663,
                      "decided": 681
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/23 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "followers": 8,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "pitabwire",
              "public_repos": 30,
              "account_age_days": 4830
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "8 followers of pitabwire",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 8,
                      "login": "pitabwire"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "30 public repos, account ~13 yr old",
                "points": 22.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 30
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/pitabwire/frame/v2"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 1
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "21 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 96,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "9 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "go",
                "golang",
                "boilerplate",
                "gocloud",
                "microservice",
                "postgresql",
                "message-queue"
              ],
              "has_wiki": true,
              "homepage": "https://pitabwire.github.io/frame/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://pitabwire.github.io/frame/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 52,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 5.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "8 out of 8 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/23 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 0.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 149 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 149
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 149,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 149,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 71,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.989,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "86 of 87 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 86,
                      "sampled": 87
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 1",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 96081,
              "source_files_sampled": 297,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/297 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 297,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "frametests/rpcservice/ping/v1/ping.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "frametests/rpcservice/ping/v1/ping.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "frametests/rpcservice/ping/v1/ping.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T22:08:12.267371Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/pitabwire/frame.svg",
  "full_name": "pitabwire/frame",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.