公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-28 08:35 UTC

qwc / asiakirjat

Documentation hosting app, that just works. Including auth through LDAP, OAuth2 or built-in and full-text search in all docs. (Mirror from private forgejo instance)

GoAGPL-3.0★ 0 星标⑂ 0 复刻始于 2026年2月在 GitHub 上查看 ↗

qwc/asiakirjat 的健康指数为 100 分中的 47 分,处于「存在风险」区间。 其得分最高的类别是AI Readiness(79/100),最低的是Community & Adoption(24/100)。 最近一次更新在 14 天前。 近期的大部分工作由 1 位贡献者完成。

47
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

47
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Marcel M. Otte个人账户
22 关注者15 个公开仓库始于 2012年2月@Zeiss, mmo.to

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/qwc/asiakirjatv0.8.2-3420 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

74良好 · 占总体的 22%
评分方式
28.8/36推送新近度 — 最近一次推送于 14 天前
6.9/36提交节奏 — 52 周中有 10 周有提交
18/18提交量 — 最近一年 222 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year222
human_commit_share1
days_since_last_push14
active_weeks_last_year10

发布纪律

88优秀
评分方式
16.2/27有发布版本 — 35 个版本标签(无 GitHub 发布版本)
36/36发布时效 — 最近一次发布版本于 20 天前
27/27发布节奏 — 约每 13.7 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count35
latest_release_tagv0.8.2
releases_from_tags
days_since_latest_release20
mean_days_between_releases13.7
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

24危急 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(AGPL-3.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

37存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
0/38.3PR 接受 — 没有已裁定的拉取请求或无数据
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决, PR 接受。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
9.8/25所有者影响力 — qwc 有 22 位关注者
20.8/25既往记录 — 15 个公开仓库,账户约 14 年
所用输入
followers22
owner_typeUser
is_verified
owner_loginqwc
public_repos15
account_age_days5,287
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 20 天前
20/20版本历史 — 34 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/qwc/asiakirjat
ecosystemsgo
any_deprecated
min_days_since_publish20

工程质量

基础的工程与文档实践是否到位?

67中等 · 占总体的 20%

工程实践

62中等
评分方式
0/24CI 工作流
24/24存在测试
16/16Linter 配置 — .golangci.yaml, .golangci.yml
9.6/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

75良好
评分方式
30/30README
0/25文档目录
15/15文档 / 主页站点 — https://git.mmo.to/qwc-open/asiakirjat
10/10仓库描述
10/10主题标签 — 5 个主题标签
10/10Wiki
所用输入
topicsdocumentation, hosting, static, static-docs-hosting, static-documentation-hosting
has_wiki
homepagehttps://git.mmo.to/qwc-open/asiakirjat
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

25危急 · 占总体的 16%

安全态势

25危急
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — 无数据
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — 无数据
0/7.5Vulnerabilities — 31 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate2.5
已排除计分(无数据或不适用):ci_tests, dangerous_workflow, packaging, signed_releases, token_permissions。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

79良好 · 占总体的 0%
评分方式
45/45代理指令 — CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes3,258
评分方式
18/18一条命令的引导启动 — vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile, vendor/github.com/golang-migrate/migrate/v4/Makefile, vendor/github.com/jmoiron/sqlx/Makefile, vendor/github.com/yuin/goldmark/Makefile, vendor/go.etcd.io/bbolt/Makefile, vendor/modernc.org/libc/Makefile, vendor/modernc.org/mathutil/Makefile, vendor/modernc.org/memory/Makefile, vendor/modernc.org/sqlite/Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yaml, .golangci.yml
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 52 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesgo.sum, package-lock.json
has_dockerfile
typed_language
bootstrap_filesvendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile, vendor/github.com/golang-migrate/migrate/v4/Makefile, vendor/github.com/jmoiron/sqlx/Makefile, vendor/github.com/yuin/goldmark/Makefile, vendor/go.etcd.io/bbolt/Makefile, vendor/modernc.org/libc/Makefile, vendor/modernc.org/mathutil/Makefile, vendor/modernc.org/memory/Makefile, vendor/modernc.org/sqlite/Makefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.52
toolchain_manifestsgo.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
54/55可控的文件大小 — 采样的 107 个源文件中有 2 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes309,927
source_files_sampled107
oversized_source_files2

机器可读接口

40存在风险
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto
0/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_filesvendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto

关键数据

0GitHub 星标
1贡献者
222最近 12 个月提交数
14距最近推送天数
35发布版本数
1巴士系数(bus factor)
0开放议题
Go, npm软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 2.5 / 10
2.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-28 08:35 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
不适用Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
不适用Token-PermissionsNo tokens found
0Vulnerabilities31 existing vulnerabilities detected
直接依赖 15
注册表软件包版本约束清单文件
Gogithub.com/blevesearch/bleve/v2v2.5.7go.mod
Gogithub.com/bodgit/sevenzipv1.6.1go.mod
Gogithub.com/go-ldap/ldap/v3v3.4.12go.mod
Gogithub.com/go-sql-driver/mysqlv1.9.3go.mod
Gogithub.com/golang-migrate/migrate/v4v4.19.1go.mod
Gogithub.com/jackc/pgx/v5v5.8.0go.mod
Gogithub.com/jmoiron/sqlxv1.4.0go.mod
Gogithub.com/ledongthuc/pdfv0.0.0-20250511090121-5959a4027728go.mod
Gogithub.com/ulikunitz/xzv0.5.15go.mod
Gogithub.com/yuin/goldmarkv1.7.16go.mod
Gogolang.org/x/cryptov0.47.0go.mod
Gogolang.org/x/netv0.49.0go.mod
Gogolang.org/x/oauth2v0.34.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
Gomodernc.org/sqlitev1.44.3go.mod
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "documentation",
        "hosting",
        "static",
        "static-docs-hosting",
        "static-documentation-hosting"
      ],
      "is_fork": false,
      "size_kb": 46272,
      "has_wiki": true,
      "homepage": "https://git.mmo.to/qwc-open/asiakirjat",
      "languages": {
        "Go": 707880,
        "CSS": 18861,
        "HTML": 73738,
        "Dockerfile": 738,
        "JavaScript": 49647
      },
      "pushed_at": "2026-07-13T12:20:08Z",
      "created_at": "2026-02-04T11:58:04Z",
      "owner_type": "User",
      "updated_at": "2026-07-13T12:20:38Z",
      "description": "Documentation hosting app, that just works. Including auth through LDAP, OAuth2 or built-in and full-text search in all docs. (Mirror from private forgejo instance)",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "main",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://gitea.mmo.to",
      "name": "Marcel M. Otte",
      "type": "User",
      "login": "qwc",
      "company": "@Zeiss, mmo.to",
      "location": "Earth",
      "followers": 22,
      "avatar_url": "https://avatars.githubusercontent.com/u/1408353?v=4",
      "created_at": "2012-02-04T17:02:30Z",
      "is_verified": null,
      "public_repos": 15,
      "account_age_days": 5287
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-07-07T18:01:53Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-06-18T11:32:38Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-06-18T09:01:52Z"
        },
        {
          "tag": "v0.8.0-rc3",
          "kind": "prerelease",
          "published_at": "2026-06-18T09:01:52Z"
        },
        {
          "tag": "v0.8.0-rc2",
          "kind": "prerelease",
          "published_at": "2026-06-18T08:04:49Z"
        },
        {
          "tag": "v0.8.0-rc1",
          "kind": "prerelease",
          "published_at": "2026-06-18T06:04:07Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-05-19T05:26:59Z"
        },
        {
          "tag": "v0.7.0-rc2",
          "kind": "prerelease",
          "published_at": "2026-05-19T05:26:59Z"
        },
        {
          "tag": "v0.7.0-rc1",
          "kind": "prerelease",
          "published_at": "2026-05-18T21:09:24Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-03-06T10:29:51Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-05T08:17:01Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-02-20T07:31:19Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-02-20T06:46:19Z"
        },
        {
          "tag": "v0.5.0-beta-pdf-2",
          "kind": "prerelease",
          "published_at": "2026-02-17T09:49:24Z"
        },
        {
          "tag": "v0.5.0-beta-searchable-pdf",
          "kind": "prerelease",
          "published_at": "2026-02-16T17:29:36Z"
        },
        {
          "tag": "v0.5.0-beta-pdf",
          "kind": "prerelease",
          "published_at": "2026-02-16T17:07:49Z"
        },
        {
          "tag": "v0.5.0-beta+pdfsupport",
          "kind": "prerelease",
          "published_at": "2026-02-16T17:07:49Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-02-16T16:32:02Z"
        },
        {
          "tag": "v0.4.0-test1",
          "kind": "prerelease",
          "published_at": "2026-02-16T16:39:35Z"
        },
        {
          "tag": "v0.3.9",
          "kind": "patch",
          "published_at": "2026-02-10T14:46:19Z"
        },
        {
          "tag": "v0.3.8",
          "kind": "patch",
          "published_at": "2026-02-10T14:34:42Z"
        },
        {
          "tag": "v0.3.7",
          "kind": "patch",
          "published_at": "2026-02-10T13:33:52Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2026-02-10T13:01:40Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2026-02-09T16:40:04Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2026-02-06T13:36:59Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-02-05T14:58:47Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-02-05T09:52:51Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-02-05T06:35:11Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-02-04T18:48:00Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-02-04T13:43:52Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-02-04T13:14:46Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-02-04T10:48:26Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-02-04T08:02:59Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-02-04T07:31:01Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-02-04T07:14:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "fd663cb90fe19a4beea7926e12150eec6b0559c6",
          "body": "…4) from chore/relicense-agpl into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/124",
          "is_bot": false,
          "headline": "Merge pull request 'Relicense from GPL-3.0 to AGPL-3.0-or-later' (#12…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-07-09T20:15:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0b3c451addd94ff031a2a73a017d5da758ecd1d",
          "body": "- Add a License section (AGPL-3.0-or-later) alongside the relicense.\n- Add shipped features that were missing from the list: /latest/ permalink\n  with pinned version, version comparison/diff view, inline PDF viewer.\n- Drop the \"stretch-goal\" framing for full-text search — it's implemented.\n- Add a short Building and Running / configuration section.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Update readme: AGPL license, missing features, run/config notes",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-07-09T16:13:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2d96fdf0548ad1bf185cbab27d7b339c792975f1",
          "body": "Asiakirjat is primarily used as a hosted network service, where GPLv3's\ncopyleft doesn't reach: operators can run modified versions over the\nnetwork without conveying a copy, so they owe nothing back (GPLv3 sec 0).\nAGPLv3 sec 13 closes this by requiring modified versions offered over a\nnetwork to ma\n[…]\npdate the in-app /licenses page to point at AGPL-3.0-or-later\n\nSole copyright holder, so relicensing needs no third-party consent.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Relicense from GPL-3.0 to AGPL-3.0-or-later",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-07-09T16:09:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29a0c9f03cc5fab6e130edcd420ad2f156f1dda0",
          "body": "…22)' (#123) from fix/project-rename-unreachable-docs into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/123",
          "is_bot": false,
          "headline": "Merge pull request 'Migrate deployed docs on project rename (fixes #1…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-07-07T18:01:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b916b832e89ab319ec6a0994261d15f2ba4dff93",
          "body": "Covers the pieces added for the project-rename fix that lacked direct\ntests:\n\n- keyedMutex (locks_test.go): same-key sections are serialized (max\n  concurrency 1), different keys are independent, and unlock releases.\n- handleAdminUpdateProject: renaming a project keeps its deployed docs\n  reachable \n[…]\n the pool makes concurrent access share one\nin-memory DB — a test-harness fix; production uses a shared file/SQL DB.\n\nAI-assisted.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add tests for rename race guard and handler rename path",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-07-07T16:41:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2562e3055975653a8e45cde8c3bffde629686c5d",
          "body": "Doc storage and the search index are keyed on the project slug, so\nrenaming a project (changing its slug) left the deployed files stranded\nat the old-slug path and every doc URL 404'd. Search results pointed at\nthe old slug too.\n\n- docs.Storage.MoveProject relocates a project's directory on rename\n \n[…]\nrectory out from under an in-flight upload.\n- Built-in docs: document rename behavior in the first-project tutorial.\n\nAI-assisted.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Migrate deployed docs on project rename (fixes #122)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-07-07T16:25:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1975bf75ed667754d3fb7d41edc31104bd419a2f",
          "body": "…st/ permalink' (#121) from feature/frontpage-card-latest-link into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/121",
          "is_bot": false,
          "headline": "Merge pull request 'Point frontpage card \"Latest\" button at the /late…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-06-18T11:32:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91a435663f63347b744ace64ce5fa6456b574946",
          "body": "The home-page project cards' Latest button linked to the concrete newest\nversion (/project/{slug}/{tag}/), so a visitor landed on a version-pinned\nURL. Link it to the rolling /project/{slug}/latest/ permalink instead, so\nthe URL someone lands on (and can copy/share) always tracks the newest\nversion.\n[…]\nversion.\n\nAdds a frontpage test asserting the card links to /latest/ and not the\nconcrete tag; notes it in the first-project docs.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Point frontpage card \"Latest\" button at the /latest/ permalink",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T11:27:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9994f423625a93b9c9be826cf20d65f39f8bf3c2",
          "body": "…x/diff-view-on-latest into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/120",
          "is_bot": false,
          "headline": "Merge pull request 'Fix diff view on the /latest/ URL' (#120) from fi…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-06-18T09:01:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d42182771fa0468499e28eeb801ccbb05996609",
          "body": "Guards the overlay regressions that broke the diff view on the /latest/\npermalink. Loads the real static/js/overlay.js into jsdom (no browser\nbinary; Node is already in CI), mocks the versions API and document fetch,\nand drives the compare flow:\n\n- compare from a /latest/ URL must fetch /project/doc\n[…]\n + jsdom only; `npm ci && npm test`. Wired\ninto the CI test job (which already had nodejs; added npm). node_modules is\ngitignored.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add browserless E2E tests for the doc overlay",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T08:58:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84614e9679544d4e656dd05199d04af698612d27",
          "body": "Two issues surfaced using the diff view from a /latest/ URL:\n\n1. The compare handler still computed the in-doc path suffix by stripping\n   the resolved tag (`current`, e.g. v1.5) from window.location.pathname —\n   but the path contains \"latest\", so the target-version fetch URL came out\n   malformed \n[…]\ns on /latest/ (showing the indicator\nvia the correctly-positioned success path); (2) ensures any genuine error\nbar is visible too.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix diff on /latest/: compare suffix + mispositioned error bar",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T08:49:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69ed71f7023f5d9f04099ed416a694f4b68be9eb",
          "body": "…19) from feature/latest-version-permalink into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/119",
          "is_bot": false,
          "headline": "Merge pull request 'Add stable /project/{slug}/latest/ permalink' (#1…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-06-18T08:04:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aeb2eb6a021e7d344f3e87e1b60513721e585c08",
          "body": "Serving the latest version in place means the URL segment (\"latest\")\ndiffers from the resolved concrete tag the overlay reports in data-current\n(e.g. v1.5). The overlay JS computed the in-doc path suffix by stripping\n\"/project/{slug}/{current}\" from window.location.pathname — but the path\nactually c\n[…]\ny; added\na test asserting /latest/ serves data-current=\"v2.0.0\" so the JS always has\na real version to build comparison URLs from.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix overlay version switch/compare on the /latest/ URL",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T08:01:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "54b5875ca6458359a6b2228b7dd8b5661818ad88",
          "body": "Switch the /project/{slug}/latest/ permalink from a 302 redirect to\nserving the resolved version's content directly at the /latest/ URL. The\naddress bar stays /latest/, so relative links inside the docs keep\nresolving under /latest/ and a visitor who lands on the permalink keeps\nbrowsing \"latest\" ra\n[…]\no\n  /latest/ so the served index page's relative links resolve correctly.\n- Docs/tests updated to reflect serve-in-place behavior.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Serve latest in place instead of redirecting",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T07:42:58Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b33b470f812fcf809187551f5cb56add291390d9",
          "body": "There was no shareable URL that always points to a project's newest\nversion — links had to bake in a concrete version tag, so they went stale\non the next upload. Add a rolling permalink that redirects to the current\nlatest:\n\n- GET /project/{slug}/latest and /project/{slug}/latest/{path...} resolve\n \n[…]\nlows the pin.\n- Tests: redirect-to-newest, path preservation, pin precedence, no-versions\n  404, and anonymous-on-private → login.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add stable /project/{slug}/latest/ permalink",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T07:29:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4b1e43d9fbfcf72a78882d1a0511221177cd54d8",
          "body": "…ject created_by' (#118) from feature/editor-manage-own-projects into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/118",
          "is_bot": false,
          "headline": "Merge pull request 'Let editors manage projects they created; add pro…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-06-18T06:04:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbff469f35f6a7650b2e61306ea77e6f4256df61",
          "body": "Editors could create projects (and were auto-granted editor access) but\ncould not edit them or grant access to others — the edit, delete, and\naccess routes were admin-only. Custom projects an editor created were thus\nunusable: nobody could be granted access to them without an admin.\n\nChanges:\n- Migr\n[…]\ngap it exposed — creators having no way to\ngrant access to their own projects — is closed by the per-project access\nchanges above.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Let editors manage projects they created; add project created_by",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-06-18T05:54:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5c323f42395dddcb663ae45b89cad953bc6a90c",
          "body": "…4)' (#117) from fix/private-honors-per-project-grant into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/117",
          "is_bot": false,
          "headline": "Merge pull request 'Honor per-project grants on private projects (M-1…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-19T05:26:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d34da9b0ed58f0f6dba498ac8d79911cf85ef07b",
          "body": "Service.Create auto-grants a non-admin creator editor access on every\nnon-public project they create, but CanView/FilterAccessible for `private`\nonly consulted GlobalAccess — so the grant was dead weight on the default\nvisibility. An editor without an org-wide global grant could create a\nprivate pro\n[…]\n one project without putting them on the org-wide list.\n\nBuilt-in docs updated alongside (visibility model and permission matrix).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Honor per-project grants on private projects (M-14)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-19T05:23:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4ed364ef6baf6c8f248edf4df2a8ca6a09c27c89",
          "body": "…-12 partial)' (#116) from fix/migration-008-mysql-default into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/116",
          "is_bot": false,
          "headline": "Merge pull request 'Align MySQL migration 008 with sqlite/postgres (H…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-19T05:17:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02fb3c660ca6ddbd792960598741ad4a2628ee8d",
          "body": "The `upload_logs.filename` column was declared `TEXT NOT NULL` on\nMySQL but `TEXT NOT NULL DEFAULT ''` on sqlite/postgres. Current code\nalways passes a value, so this is harmless today — but the drift is the\nexact kind of thing the audit's full H-12 fix (multi-dialect migration\nparity test) is meant to catch. Doing the reconcile now; the\ntestcontainers-based parity test is deferred (needs CI Docker).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Align MySQL migration 008 with sqlite/postgres (H-12 partial)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-19T05:06:38Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ef54890f6289491cba8f1925cf5134cc18ff913f",
          "body": "… routes (L-3)' (#115) from feature/security-headers into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/115",
          "is_bot": false,
          "headline": "Merge pull request 'Add baseline security headers; exempt doc-serving…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-19T05:03:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6571625c55bff2442aae6085329d0e36710d6e3e",
          "body": "Sets X-Content-Type-Options, Referrer-Policy, and CSP frame-ancestors on\nresponses for app-owned UI (admin, login, profile, upload, API, project\npages). The doc-serving route is exempt because uploaded HTML may rely\non inline scripts, third-party embeds, or be intentionally framed.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add baseline security headers; exempt doc-serving routes (L-3)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-19T04:23:57Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d5f3c314d8c0c8b234023c6b630d336cc5e499ec",
          "body": "…3)' (#114) from refactor/token-authenticator-deps into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/114",
          "is_bot": false,
          "headline": "Merge pull request 'Construct TokenAuthenticator once on Handler (H-1…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T21:09:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d6df4e0a5b8a8713a6784086374cb33314355cc",
          "body": "Audit finding H-13. handleAPIUploadWithSlug and handleAPICreateProject\neach called auth.NewTokenAuthenticator(h.tokens, h.users) per request\n— cheap but a sign that token auth wasn't a first-class member of the\nhandler. Any new token-auth call site would have re-constructed it the\nsame way, and the \n[…]\n call sites. Matches the established pattern for projectService\nand checker (also wired in handler.New from existing Deps fields).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Construct TokenAuthenticator once on Handler (H-13)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T21:01:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7ef086a139270769ddca66249a0b9dbbdc726d55",
          "body": "…ord (M-9)' (#113) from fix/reject-default-admin-password into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/113",
          "is_bot": false,
          "headline": "Merge pull request 'Refuse to start with insecure initial-admin passw…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T20:59:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ba58ef5d4aedcb589ec1831859ddc50c336fff2",
          "body": "Audit finding M-9: config.yaml.example ships with password: \"changeme\"\nand config.Defaults uses \"admin\". A deployment copying either unchanged\nended up with working admin/changeme (or admin/admin) credentials, which\nhas happened in real setups.\n\nensureInitialAdmin now refuses to create the initial a\n[…]\nnsecureInitialAdminPassword for testability;\nmain_test.go covers the banned defaults, empty, just-too-short, and\nacceptable cases.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Refuse to start with insecure initial-admin password (M-9)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T20:51:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d1cbee14a50ac5b9de9e43baa806966ee85532c2",
          "body": "…cleanup (M-12, M-13)' (#112) from fix/background-jobs-lifecycle into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/112",
          "is_bot": false,
          "headline": "Merge pull request 'Track background jobs; wire session + rate-limit …",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T20:48:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0362c8d71752375a6b543b484375340de4748f7f",
          "body": "Audit findings M-12 and M-13: background goroutines and unused cleanup\npaths were both lifecycle gaps that this PR closes together.\n\nM-13 — fire-and-forget goroutines:\n  Three sites started goroutines that the process abandoned on shutdown:\n    - upload.go and api.go: searchIndex.IndexVersion (post-\n[…]\nst.go) cover runJob's WaitGroup behavior,\ncontext cancellation propagation, and idle-Stop being a no-op. All\nverified under -race.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Track background jobs; wire session + rate-limit cleanup (M-12, M-13)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T20:44:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "17198458cf9d9cdea5d5adcfe615380e8646465a",
          "body": "…ility warning, M-4 demotion sweep' (#111) from fix/lifecycle-cleanups into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/111",
          "is_bot": false,
          "headline": "Merge pull request 'Lifecycle cleanups: M-1 mapping revoke, M-3 visib…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T20:38:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "230c2ae33cfb7fed73ed5ebbc17a9ca9d96b08aa",
          "body": "…emotion sweep\n\nThree audit findings under the lifecycle/cascade-gap theme.\n\nM-1 — Group-mapping deletion previously dropped the mapping row but left\nthe project_access rows that were granted via that source untouched.\nUntil the affected user's next login (which would re-run syncProjectAccess\nand re\n[…]\nuntouched.\n\nsetupTestApp gained GroupMappings in Deps (it was missing, which the\nM-1 test surfaced by panicking on the nil store).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Lifecycle cleanups: M-1 mapping revoke, M-3 visibility warning, M-4 d…",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T20:26:47Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "67d77866139c3f7fcdc99e6bc9b21a1de0114f7b",
          "body": "…M-7)' (#110) from feature/oauth2-state-ttl-pkce into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/110",
          "is_bot": false,
          "headline": "Merge pull request 'OAuth2: bound state map with TTL, add PKCE S256 (…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T20:19:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23e7ef5ec7f9f0f7d3e4327537cfbf298f3bdc34",
          "body": "Audit finding M-7. Two issues in the OAuth2 flow:\n\n  1. states map[string]bool grew on every /auth/oauth2 hit and was only\n     pruned when the corresponding callback consumed the state. An\n     unauthenticated attacker spamming the endpoint kept entries forever.\n\n  2. No PKCE (RFC 7636). A public-c\n[…]\nes + age-out + 1 more issuance → sweep leaves only 1\n\nExisting tests updated for the new HandleCallback / ConsumeState\nsignatures.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "OAuth2: bound state map with TTL; add PKCE S256 (M-7)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T19:56:18Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e94fdf225f49f67779710457f063b45126de1ca7",
          "body": "…STs (M-6)' (#109) from feature/csrf-protection into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/109",
          "is_bot": false,
          "headline": "Merge pull request 'Per-session CSRF tokens on state-changing form PO…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T19:50:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3262c98a210e0025500be6e9a09eefc8da3c5257",
          "body": "Audit finding M-6. SameSite=Lax cookies alone protect against cross-site\nform POSTs today, but the audit flagged it as the single point of\nfailure: a future SameSite=None, lenient lax handling on sibling\nsubdomains, or any GET-with-side-effects regression would re-open CSRF.\nAdds defense-in-depth.\n\n\n[…]\nthe expected token from the test\n    handler's secret; bulk-injected into every existing test that sends\n    a state-changing POST\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add per-session CSRF tokens on state-changing form POSTs (M-6)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T19:20:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "912917496208883bbf007d1c0d7d8a2f139af6de",
          "body": "… (H-5, H-6)' (#108) from fix/archive-extraction-limits into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/108",
          "is_bot": false,
          "headline": "Merge pull request 'Cap archive extraction; stream zip/7z to tempfile…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T18:54:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b088c5ea1d350a17f519074a888a1f59c8337318",
          "body": "Audit findings H-5 (decompression bomb / disk DoS) and H-6 (memory\namplification from buffering whole archives in RAM).\n\nH-5 — extraction limits. Each archive entry was capped at maxFileSize\n(100 MB) but there was no aggregate cap and no entry-count cap. A 100 MB\nupload of bz2/xz could expand to mul\n[…]\ntal-byte bomb (11×100MB → rejected mid-stream, well before\n    writing 1.1 GB to disk)\n  - normal small zip still extracts cleanly\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Cap archive extraction; stream zip/7z to tempfile (H-5, H-6)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T18:46:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5467cc4d7c446d2d06c4fa1c6bbfb221ca8c5731",
          "body": "…rom fix/handler-state-race into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/107",
          "is_bot": false,
          "headline": "Merge pull request 'Synchronize Handler shared state (H-10)' (#107) f…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T18:40:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2c3f8acb71022ab7065ce0199d63cd895da46b2",
          "body": "Audit finding H-10. reindexRunning, reindexProgress, latestTagsCache,\nand latestTagsCacheTime lived as bare fields on Handler. They were\nread and written from concurrent HTTP goroutines and from the worker\ngoroutine started in handleAdminReindex — a real data race in production,\nnot a hypothetical o\n[…]\ning tests don't exercise this\nshape and so wouldn't have flagged H-10 either.\n\n`go test -race ./...` clean across the whole suite.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Synchronize Handler shared state with explicit mutex types (H-10)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T18:35:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "57c99d5e0359e2d96c46fc477e3ff7249353efd4",
          "body": "…ped tokens creating projects (H-3)' (#106) from fix/inline-authz-and-token-scope into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/106",
          "is_bot": false,
          "headline": "Merge pull request 'Fix inline authz drift (H-1, H-2) and project-sco…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T18:27:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8e3291f1353512752ef6806b6e9b031f98ebb84",
          "body": "…POST /api/projects\n\nThree small fixes the access.Checker refactor (H-11, PR #105) unblocked.\n\nH-1: handleDeleteVersion had an inline check (admin/editor or per-project\nProjectAccess) that ignored GlobalAccessGrant editor grants. A user with\na global editor grant could upload to a private project vi\n[…]\nAccess\n  - TestAPICreateProjectRejectsProjectScopedToken\n  - TestAPICreateProjectAllowsGlobalToken (sanity: global token still OK)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix H-1/H-2 inline authz copies; H-3 reject project-scoped tokens on …",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T18:07:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "184f78078790ec7a4fd2db8345f24dcf6fbcf847",
          "body": "…om refactor/access-checker into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/105",
          "is_bot": false,
          "headline": "Merge pull request 'Extract internal/access.Checker (H-11)' (#105) fr…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T18:02:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "252797a4b7a438cc1e40eb54d4872be9a4ca9573",
          "body": "Audit finding H-11. The three authorization helpers — canViewProject,\ncanUpload, filterAccessibleProjects — lived as methods on Handler and\ntook *Handler as receiver. Each consulted ProjectAccessStore +\nGlobalAccessStore directly. Three consequences:\n\n  - Tests of the authorization rules needed a fu\n[…]\nrAccessible verifies the batch form returns the same\n    subset CanView would on each project.\n\nNet handler diff: -85 / +12 lines.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Extract internal/access.Checker (H-11)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T17:53:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cb6712c7209b855d28d38fd18ef457bc27cdc9be",
          "body": "…#104) from refactor/projects-service-create into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/104",
          "is_bot": false,
          "headline": "Merge pull request 'Extract internal/projects.Service.Create (H-9)' (…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T17:48:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3b45e1274fc66661b54b76f86a7974526e2dc96",
          "body": "Audit finding H-9. Three project-create paths each duplicated the same\nsequence: slug validation, visibility defaulting and validation,\npublic-visibility-admin-only gate, projects.Create, EnsureProjectDir,\nauto-grant editor access to the creator. They had already drifted in\nsubtle ways: the admin fo\n[…]\nant for admin, slug\nconflict. Full test suite still passes (validates handler paths still\nbehave the same as before the refactor).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Extract internal/projects.Service.Create (H-9)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T17:42:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4fe3260036d606ad872cea6857f26552e962d97a",
          "body": "…4)' (#103) from fix/uploaded-by-on-delete-set-null into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/103",
          "is_bot": false,
          "headline": "Merge pull request 'Make uploaded_by nullable, ON DELETE SET NULL (H-…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T17:35:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5141d0eba02c336b9b28e33db6565ce051d0775b",
          "body": "Audit finding H-4 (High). Before this change, versions.uploaded_by and\nupload_logs.uploaded_by had FK without ON DELETE, NOT NULL. With\nPRAGMA foreign_keys=ON (sqlite) and the equivalent FK enforcement on\npostgres/mysql, deleting any user who had ever uploaded returned an FK\nconstraint error from ha\n[…]\nndler;\nasserts (a) 303 redirect (FK doesn't block); (b) user gone; (c) version\nand upload_log still present with uploaded_by NULL.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make versions/upload_logs uploaded_by nullable, ON DELETE SET NULL (H-4)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T16:19:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ad833464a95b32b09a87356d7b5cb8976ceee64e",
          "body": "… (#102) from fix/sibling-prefix-leak into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/102",
          "is_bot": false,
          "headline": "Merge pull request 'Make ServeDoc prefix check separator-aware (H-8)'…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T16:09:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ec1aebc83ff7cbf1f64f6e3d1fdd77d434b1a56",
          "body": "Audit finding H-8: ServeDoc rejected escape attempts with\nstrings.HasPrefix(absFile, absStorage), which treats \"/data/proj/v1\" as\na valid prefix of its sibling \"/data/proj/v10\". Two version directories\nwhose names share a prefix could leak between each other (the prefix\nmatch without a separator is \n[…]\n from v1 to v10 is rejected. Two sanity tests cover the\nlegitimate root-directory and in-tree cases so the fix doesn't\nover-block.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Make ServeDoc prefix check separator-aware (H-8)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T16:00:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84caeef9f9d18b88445cee39759f1e96bc5d4583",
          "body": "…d proxies (H-7)' (#101) from fix/trusted-proxies-rate-limit into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/101",
          "is_bot": false,
          "headline": "Merge pull request 'Only honor X-Forwarded-For from configured truste…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T15:59:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6b07a7cbfc829cb2ee45d773d8da60a1d64f40a1",
          "body": "withRateLimit blindly used the X-Forwarded-For header as the limiter key\nwhen present, with no proxy allowlist and no chain parsing. An attacker\ncould rotate the header per request and trivially bypass the 10/60s\nlogin rate limit — enabling credential stuffing against built-in users\nand LDAP backend\n[…]\nting XFF is honored when\nthe peer is in the trusted list (the new feature).\n\nBuilt-in config docs and config.yaml.example updated.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Only honor X-Forwarded-For from configured trusted proxies (H-7)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T15:55:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "72f51fbbb161e93b17ad5d58023a0dd7e16c045a",
          "body": "…rojects (C-5)' (#100) from fix/restrict-public-visibility-to-admin into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/100",
          "is_bot": false,
          "headline": "Merge pull request 'Reject non-admin creators for public-visibility p…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T15:49:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "18f1d3e9f02551cadd92a8f67ab017c2c07429cf",
          "body": "Audit finding C-5 (Critical, privilege escalation).\n\nPublic projects bypass all access checks (canViewProject returns true\nunconditionally at search.go:314). Both handleAdminCreateProject and\nhandleAPICreateProject accepted visibility=public from any editor — an\neditor could therefore publish intern\n[…]\ntic editor case post-fix.\n\nDocs updated: first-project tutorial flags public as admin-only; API\nreference notes the 403 condition.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reject non-admin creators for public-visibility projects",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T14:19:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "762127325ca8ad1dc02dafed23aada3f0760c26f",
          "body": "…ct (C-4)' (#99) from fix/api-versions-access-check into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/99",
          "is_bot": false,
          "headline": "Merge pull request 'Gate /api/project/{slug}/versions by canViewProje…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T14:16:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1083b64d7a37d3c4ee517844c4a03b933f6117e9",
          "body": "Audit finding C-4 (Critical). handleAPIVersions did no access check and\nreturned the version list — tags, content types, creation timestamps —\nfor any project regardless of visibility, to any caller (including\nunauthenticated). Contrast handleAPIProjects (already filtered) and\nhandleAPISearch (resul\n[…]\n4. A second test confirms a viewer with a per-project grant on a\ncustom-visibility project still sees the list (no over-blocking).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Gate /api/project/{slug}/versions by canViewProject",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T14:08:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "380e22f797b1eb75b5053ecde7de7491b5953314",
          "body": "… test (C-3 investigation)' (#98) from fix/search-snippet-xss into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/98",
          "is_bot": false,
          "headline": "Merge pull request 'Lock in search snippet escaping with a regression…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T14:05:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d922e3343d936165fe1d00f1f8b77335302ec966",
          "body": "Audit finding C-3 claimed `{{safe .Snippet}}` in search.html could ship\nraw HTML/JS from indexed documents to the browser. Investigation showed\nthis is **not exploitable today**: Bleve's html highlighter (selected at\nindexer.go:381) uses the html FragmentFormatter, which html.EscapeString's\nthe surr\n[…]\nture change swaps in a different highlighter or custom formatter\nthat doesn't escape, this test fails before the regression ships.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add regression test for search snippet HTML escaping",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T14:04:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "da8278c6bf38aa4f326aa39ad1aba96e9f6927fd",
          "body": "…ored XSS (C-2, L-6)' (#97) from fix/pdf-viewer-xss into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/97",
          "is_bot": false,
          "headline": "Merge pull request 'Move PDF viewer wrapper to html/template — fix st…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T14:00:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82b5ad85fd82e3f0fe84e8baf123e4b2ca36b8a9",
          "body": "Audit findings C-2 (Critical, stored XSS) and L-6 (hand-formatted HTML\nfragile to maintain).\n\nservePDFViewer built the wrapper page with fmt.Fprintf, interpolating the\nproject name and version tag directly into HTML. Project names are\nfree-form text set by editors/admins; version tags are now constr\n[…]\nns the </title><script>\npayload, fetches the viewer wrapper, and asserts the raw payload is absent\nand an escaped form is present.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Move PDF viewer wrapper from fmt.Fprintf to html/template (fix XSS)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T13:55:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7cf170002ec2c9819bfc42ffdf36f17ad0e8ed7d",
          "body": "…tion at all boundaries (C-1, M-5, M-8)' (#96) from fix/input-validation-boundaries into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/96",
          "is_bot": false,
          "headline": "Merge pull request 'Validate slugs, version tags, and Content-Disposi…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-05-18T13:51:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78759322ec940a880e56c241b31d856499c66cf6",
          "body": "…Content-Disposition values\n\nThree findings from the local audit, all involving attacker-controlled\nstrings flowing into filesystem paths or response headers without validation:\n\nC-1 (Critical): r.FormValue(\"version\") flowed directly into the project's\nstorage filesystem path via storage.EnsureVersi\n[…]\nhe\n  malicious-input rejection on both the upload and admin-create endpoints.\n\nAudit findings: C-1, M-5, M-8 (workstream item #1).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add internal/validation; reject path-unsafe slugs, version tags, and …",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-05-18T13:47:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9ebe73815cedc1caf542496955bb957e25be18e5",
          "body": "…(#93) from fix/session-delete-expired-timezone into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/93",
          "is_bot": false,
          "headline": "Merge pull request 'Fix DeleteExpired timezone mismatch with SQLite' …",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-03-17T12:57:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3a08d8b9693c6eb53025362f9ae020031928b82",
          "body": "CURRENT_TIMESTAMP is UTC in SQLite, but sessions are stored with\nlocal time. Pass time.Now().UTC() as a parameter instead so the\ncomparison is consistent regardless of server timezone.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix DeleteExpired timezone mismatch with SQLite",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-03-17T12:55:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "712825229320ba015330d1cf6c65ef43d88845d0",
          "body": "… endpoint' (#92) from feature/auto-create-projects into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/92",
          "is_bot": false,
          "headline": "Merge pull request 'Add auto-create projects on upload and API create…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-03-06T10:29:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52fccd36560cc64f93a7f924194f39cef14db23e",
          "body": "- Add projects.auto_create config option (default: false) to allow\n  automatic project creation when uploading to a non-existent slug\n- Add POST /api/projects endpoint for explicit project creation via API\n- Auto-created projects get private visibility and creator gets editor access\n- API auto-creat\n[…]\nts\n- Change default visibility for new projects from custom to private\n- Add slug validation (lowercase alphanumeric with hyphens, 1-128 chars)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add auto-create projects on upload and API create project endpoint",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-03-06T10:25:20Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee768be9bee3135f17ff8d193dc147d304d7556a",
          "body": "… from feature/upload-log-and-pin-version into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/91",
          "is_bot": false,
          "headline": "Merge pull request 'Add upload log and pinnable latest version' (#91)…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-03-05T08:17:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "589f023c679c17b0a4dbe7ba302175dd9eaacb54",
          "body": "… from fix/version-reupload-date into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/90",
          "is_bot": false,
          "headline": "Merge pull request 'Fix version date not updating on re-upload' (#90)…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-03-05T07:54:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dad8e570bc9cfbeb1e0fdcffdd8e573f0e3faed0",
          "body": "Upload log: Records every upload (new and re-upload) with version tag,\ncontent type, filename, and uploader. Displayed as a collapsible section\non the project detail page for editors/admins.\n\nPinnable latest version: Adds \"Pin\" and \"Temp. pin\" buttons to each\nversion. Permanent pins persist across n\n[…]\nr semver sorting for the frontpage and search.\n\nIncludes migration 008, UploadLogStore, handler tests, and store tests.\n\nCloses #88, closes #89\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add upload log and pinnable latest version",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-03-05T07:52:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "47bf45b6b5b6b94aaa297b7af3708f7a77bf6a0a",
          "body": "When overwriting an existing version, set created_at to the current\ntime and include it in the UPDATE query so the version list reflects\nthe actual re-upload date.\n\nCloses #87\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix version date not updating on re-upload",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-03-05T07:29:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9732b1edaee837b1e48ebacdfb7b6762dce6c814",
          "body": "…h results' (#86) from feature/pdf-search-page-jump into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/86",
          "is_bot": false,
          "headline": "Merge pull request 'Index PDF pages individually for page-level searc…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T07:31:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f0d4cdb15510d10fd5d4288916fbbf6e9d7556e",
          "body": "PDF text is now extracted per page instead of as a single blob.\nSearch results for PDFs include the page number and link directly\nto the matching page using #page=N fragments. The PDF viewer\nreads the fragment and passes it to the embedded PDF, and shows\na search hint banner when arriving from a search result.\n\nRequires a search index rebuild after deploying.\n\nCloses #79\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Index PDF pages individually for page-level search results",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-20T07:22:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "499530e8c0b2a61d312b2986cb352b668bed8b81",
          "body": "…) from docs/fill-documentation-gaps into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/84",
          "is_bot": false,
          "headline": "Merge pull request 'Fill documentation gaps for recent features' (#84…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T06:46:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cea63411fc280117426ae199a8405bbf7edb08a",
          "body": "- Add docs-must-stay-current policy to CLAUDE.md\n- Document editor admin panel access (filtered project list, auto-grant)\n- Document auto-slug derivation on project creation\n- Document version deletion\n- Create how-to guide for Global Access management\n- Add Global Access section to roles-permissions reference\n- Document admin table live filtering\n- Clarify project-scoped API token restrictions\n- Add new how-to to docs index\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fill documentation gaps for recent features",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-20T06:43:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "103e6b5a6d375fd220ca9963e68e0936b6ec0612",
          "body": "…feature/pdf-upload-support into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/72",
          "is_bot": false,
          "headline": "Merge pull request 'Add PDF documentation upload support' (#72) from …",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T06:34:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "619c5eee6d2ec3f7e76d502d02fc89739d817a2d",
          "body": "…3) from feature/project-create-form-reorder into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/83",
          "is_bot": false,
          "headline": "Merge pull request 'Reorder project creation form with auto-slug' (#8…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T06:34:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8509313df81090774320d2ee1cdcdd03e70cf32e",
          "body": "Reorganizes the create project card:\n- Row 1: Name + Slug (with auto-generate checkbox)\n- Row 2: Description textarea (resizable)\n- Row 3: Visibility + Create button\n\nWhen \"Auto slug\" is checked (default), the slug is derived from the\nname automatically. Unchecking allows manual editing.\n\nCloses #82\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Reorder project creation form with auto-slug derivation",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-20T06:31:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f312f40e6f808987d989c62d4dbc9c675d4ff5bf",
          "body": "…bles' (#81) from feature/admin-table-filtering into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/81",
          "is_bot": false,
          "headline": "Merge pull request 'Add live filtering to admin projects and users ta…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T06:29:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4069fe5a0b256d509b1b7958ce43a3713ba4afef",
          "body": "Client-side filter inputs above each table that hide non-matching rows\nin real-time, making it easier to find entries in large lists.\n\nCloses #74\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add live filtering to admin projects and users tables",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-20T06:26:29Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "de55f4df64b30b1b94f5f77a4fefbb1b14dbc5e5",
          "body": "… on create' (#80) from fix/editor-project-list-filtering into feature/pdf-upload-support\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/80",
          "is_bot": false,
          "headline": "Merge pull request 'Filter admin project list for editors, auto-grant…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T06:23:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1bd725eb32743b14aae27153f0da7998c0831308",
          "body": "…8) from fix/pdf-viewer-height into feature/pdf-upload-support\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/78",
          "is_bot": false,
          "headline": "Merge pull request 'Fix PDF viewer only filling ~1/6 of viewport' (#7…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-20T06:23:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffacebba434703bf462037ad363a8daa19af9c12",
          "body": "Editors previously saw all projects in the admin panel regardless of\nvisibility. Now non-admin users only see projects they actually have\naccess to (public, private with global grant, or custom with explicit\naccess), using the same filtering logic as the frontpage.\n\nWhen an editor creates a non-public project, they are automatically\ngranted editor-level access so they don't lose visibility of their\nown project.\n\nFixes #77\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Filter admin project list for editors and auto-grant access on create",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-20T06:18:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a38caff9eb63b7aab04cc39c53cdfa11686959d5",
          "body": "The <embed> element is a replaced element that doesn't compute its\nheight from top+bottom constraints like block elements do. Set an\nexplicit height via calc(100vh - overlayHeight) and re-calculate on\nwindow resize so the PDF always fills the space below the overlay.\n\nFixes #76\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix PDF viewer only filling ~1/6 of viewport",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-20T06:13:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "695c8e56f44626476b86e5e9f1772d581f6d19ad",
          "body": "…pport\n\n# Conflicts:\n#\tinternal/docs/builtin/docs/how-to/configure-ldap.md\n#\tinternal/docs/builtin/docs/reference/configuration.md",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into feature/pdf-upload-su…",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-17T09:49:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64cbba1e1d38ec408493e79e2bf303d434558af9",
          "body": "… from feature/ldap-recursive-groups into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/75",
          "is_bot": false,
          "headline": "Merge pull request 'Add opt-in recursive LDAP group resolution' (#75)…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-17T09:47:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05b828f173bed0cf6cbfd2de6d0cce6dd7a37425",
          "body": "Walk up each group's memberOf chain to resolve nested group memberships,\nenabling role assignment via transitive groups (e.g., user in team-a,\nteam-a member of editors → user gets editor role). Controlled by\nrecursive_groups and group_prefix config options.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add opt-in recursive LDAP group resolution",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-17T09:44:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "278cb2f348e3b5280e3204c1220b8cf8e77d9a36",
          "body": "- Fix config field names (host->address, user_base_dn->base_dn, storage default)\n- Rewrite LDAP/OAuth2 config docs to match actual config.go fields\n- Add PDF upload support documentation across all relevant pages\n- Add retention, proxy_strip_path, log_level config documentation\n- Fix editor role: ca\n[…]\ns (not just admin)\n- Add 100 MB upload size limit (was incorrectly \"no hard-coded limit\")\n- Add version diffing and PDF support to feature list\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix built-in documentation gaps and inaccuracies",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-17T07:33:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d8f61cf1a5fe77a45ff5d24eaeadc7123d5f56f8",
          "body": "…rom feature/pdf-search-and-diff-denial into feature/pdf-upload-support\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/73",
          "is_bot": false,
          "headline": "Merge pull request 'Add PDF full-text search and diff denial' (#73) f…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T17:29:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be0145dda56b0716e08d93194cb81346c69c9627",
          "body": "- Extract text from PDFs for Bleve search indexing using pdftotext\n  (poppler-utils) with pure Go fallback (ledongthuc/pdf)\n- Add poppler-utils to Docker runtime image for best extraction quality\n- Re-enable search indexing for PDF uploads (was skipped in #68)\n- Add content_type to versions API so o\n[…]\ns which are PDFs\n- Block diff comparison for PDF versions with clear error message\n  instead of confusing \"Could not find content area\" failure\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add PDF full-text search and graceful diff denial",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T17:27:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "800ad3fab07299e2256bb3443ad1340047624845",
          "body": "Accept .pdf file uploads alongside archives. PDF versions are stored as\na single file and served in an HTML wrapper with the overlay toolbar.\nSearch indexing is skipped for PDF versions (no text extraction yet).\n\n- Add content_type column to versions (migration 007)\n- Detect PDF uploads in web and A\n[…]\nServe PDF in embedded viewer with overlay\n- Show PDF badge in version list, serve raw PDF on download\n- Update upload form to accept .pdf files\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add PDF documentation upload support (#68)",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T17:07:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c1482d07e659a6cc32425b4e9aa73892ef455928",
          "body": "…1) from feature/arm64-release-binary into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/71",
          "is_bot": false,
          "headline": "Merge pull request 'Add arm64 release binary to release workflow' (#7…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T16:47:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15c5f910f741d8ad963c613849dafcb88b3a0858",
          "body": "Build and upload linux/arm64 binary alongside amd64. Also includes\nthe jq fix for release ID extraction (supersedes #70).\n\nCloses #32 (binary portion — multi-arch Docker deferred)\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add arm64 release binary to release workflow",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T16:46:48Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "26e802b2302ee1edd605c69ebbe26ea075820d89",
          "body": "…70) from fix/release-id-extraction into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/70",
          "is_bot": false,
          "headline": "Merge pull request 'Fix release ID extraction in release workflow' (#…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T16:45:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e30d67e77eb15d64417e8a4707d7f05c82100df1",
          "body": "The sed regex was greedy and matched the last \"id\": in the JSON\n(the author's user ID) instead of the release ID. Replaced with\njq for reliable JSON parsing.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix release ID extraction in release workflow",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T16:39:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6173cc82a1bafd1a6f56b59f7f755ef2cc1bcafd",
          "body": "…from feature/diff-navigation-and-persistence into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/69",
          "is_bot": false,
          "headline": "Merge pull request 'Add diff navigation and state persistence' (#69) …",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T16:32:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d154d60eab3538c5205832df87de2d09a8ac64a2",
          "body": "Adds prev/next navigation buttons and keyboard shortcuts (n/p) to jump\nbetween changes in diff mode, with an amber outline highlighting the\ncurrent change. Persists diff state via ?compare= URL parameter so\ndiffs survive page navigation and reloads. Intercepts in-doc link\nclicks during diff mode to carry the compare parameter forward.\n\nCloses #58, closes #59\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add diff navigation and state persistence to document overlay",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T16:26:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "22db13a85bde77b80474015ce247258ba2decbed",
          "body": "…down hint' (#67) from feature/multiline-project-description into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/67",
          "is_bot": false,
          "headline": "Merge pull request 'Use textarea for project description and add mark…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T15:25:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "092a95d7dd42616364b95290870886988a16b4a2",
          "body": "…feature/editor-create-projects into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/66",
          "is_bot": false,
          "headline": "Merge pull request 'Allow editors to create new projects' (#66) from …",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T15:25:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3da6c75571989c26765d05b13178dbf2ca257814",
          "body": "… (#65) from feature/download-version into main\n\nReviewed-on: https://git.mmo.to/qwc-open/asiakirjat/pulls/65",
          "is_bot": false,
          "headline": "Merge pull request 'Add download endpoint for documentation versions'…",
          "author_name": "qwc",
          "author_login": null,
          "committed_at": "2026-02-16T15:25:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08c4956c3b8f30be4027e90e6cc1ed26374df5ea",
          "body": "Changes the create project form description field from a single-line\ninput to a multiline textarea, matching the edit form. Adds a markdown\nhint to both forms. The frontpage card CSS already truncates long\ndescriptions to 2 lines via line-clamp.\n\nCloses #64\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Use textarea for project description and add markdown hint",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T15:20:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "85327364e73d27e6d018a7b1f2a521ce3546944a",
          "body": "Adds requireEditorOrAdmin middleware and applies it to the project list\nand create routes. The admin projects page conditionally hides admin-only\nfeatures (edit, delete, reindex, deploy, admin nav) for editor users.\nEditors see a \"Manage Projects\" link in the navbar.\n\nCloses #63\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Allow editors to create new projects",
          "author_name": "Marcel M. Otte",
          "author_login": null,
          "committed_at": "2026-02-16T15:19:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 35,
      "commits_last_year": 222,
      "latest_release_at": "2026-07-07T18:01:53Z",
      "latest_release_tag": "v0.8.2",
      "releases_from_tags": true,
      "days_since_last_push": 14,
      "active_weeks_last_year": 10,
      "days_since_latest_release": 20,
      "mean_days_between_releases": 13.7
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 42,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/qwc/asiakirjat",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/qwc/asiakirjat",
          "is_deprecated": false,
          "latest_version": "v0.8.2",
          "repository_url": "https://github.com/qwc/asiakirjat",
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-07T18:01:53Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 20
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile",
        "vendor/github.com/golang-migrate/migrate/v4/Makefile",
        "vendor/github.com/jmoiron/sqlx/Makefile",
        "vendor/github.com/yuin/goldmark/Makefile",
        "vendor/go.etcd.io/bbolt/Makefile",
        "vendor/modernc.org/libc/Makefile",
        "vendor/modernc.org/mathutil/Makefile",
        "vendor/modernc.org/memory/Makefile",
        "vendor/modernc.org/sqlite/Makefile"
      ],
      "api_schema_files": [
        "vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 309927,
      "source_files_sampled": 107,
      "oversized_source_files": 2,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 3258
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/blevesearch/bleve/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.5.7"
        },
        {
          "name": "github.com/bodgit/sevenzip",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.1"
        },
        {
          "name": "github.com/go-ldap/ldap/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.4.12"
        },
        {
          "name": "github.com/go-sql-driver/mysql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.9.3"
        },
        {
          "name": "github.com/golang-migrate/migrate/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.19.1"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.8.0"
        },
        {
          "name": "github.com/jmoiron/sqlx",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/ledongthuc/pdf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20250511090121-5959a4027728"
        },
        {
          "name": "github.com/ulikunitz/xz",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.15"
        },
        {
          "name": "github.com/yuin/goldmark",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.7.16"
        },
        {
          "name": "golang.org/x/crypto",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.47.0"
        },
        {
          "name": "golang.org/x/net",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.34.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.3"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "qwc",
          "commits": 26,
          "avatar_url": "https://avatars.githubusercontent.com/u/1408353?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": false,
      "linter_configs": [
        ".golangci.yaml",
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "31 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "fd663cb90fe19a4beea7926e12150eec6b0559c6",
        "ran_at": "2026-07-28T08:35:16Z",
        "aggregate_score": 2.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/qwc/asiakirjat",
    "host": "github.com",
    "name": "asiakirjat",
    "owner": "qwc"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 47,
      "inputs": {
        "security": 25,
        "vitality": 74,
        "community": 24,
        "governance": 37,
        "engineering": 67
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "commits_last_year": 222,
              "human_commit_share": 1,
              "days_since_last_push": 14,
              "active_weeks_last_year": 10
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 14 days ago",
                "points": 28.8,
                "status": "partial",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 14
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "10/52 weeks with commits",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 10
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "222 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 222
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 35,
              "latest_release_tag": "v0.8.2",
              "releases_from_tags": true,
              "days_since_latest_release": 20,
              "mean_days_between_releases": 13.7
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "35 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 35
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 20 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~13.7 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 13.7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 24,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 37,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "followers": 22,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "qwc",
              "public_repos": 15,
              "account_age_days": 5287
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "22 followers of qwc",
                "points": 9.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 22,
                      "login": "qwc"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "15 public repos, account ~14 yr old",
                "points": 20.8,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 15
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/qwc/asiakirjat"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 20
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 20 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 20
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 67,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml, .golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "documentation",
                "hosting",
                "static",
                "static-docs-hosting",
                "static-documentation-hosting"
              ],
              "has_wiki": true,
              "homepage": "https://git.mmo.to/qwc-open/asiakirjat",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://git.mmo.to/qwc-open/asiakirjat",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "5 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 25,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 25,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 2.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "31 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 79,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 3258
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile",
                "vendor/github.com/golang-migrate/migrate/v4/Makefile",
                "vendor/github.com/jmoiron/sqlx/Makefile",
                "vendor/github.com/yuin/goldmark/Makefile",
                "vendor/go.etcd.io/bbolt/Makefile",
                "vendor/modernc.org/libc/Makefile",
                "vendor/modernc.org/mathutil/Makefile",
                "vendor/modernc.org/memory/Makefile",
                "vendor/modernc.org/sqlite/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.52,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile, vendor/github.com/golang-migrate/migrate/v4/Makefile, vendor/github.com/jmoiron/sqlx/Makefile, vendor/github.com/yuin/goldmark/Makefile, vendor/go.etcd.io/bbolt/Makefile, vendor/modernc.org/libc/Makefile, vendor/modernc.org/mathutil/Makefile, vendor/modernc.org/memory/Makefile, vendor/modernc.org/sqlite/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "vendor/github.com/RoaringBitmap/roaring/v2/roaring64/Makefile, vendor/github.com/golang-migrate/migrate/v4/Makefile, vendor/github.com/jmoiron/sqlx/Makefile, vendor/github.com/yuin/goldmark/Makefile, vendor/go.etcd.io/bbolt/Makefile, vendor/modernc.org/libc/Makefile, vendor/modernc.org/mathutil/Makefile, vendor/modernc.org/memory/Makefile, vendor/modernc.org/sqlite/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml, .golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "52 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 52,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 309927,
              "source_files_sampled": 107,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/107 source files over 60KB",
                "points": 54,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 107,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": false,
              "api_schema_files": [
                "vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "vendor/github.com/blevesearch/bleve/v2/index/upsidedown/upsidedown.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-28T08:35:33.078399Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/q/qwc/asiakirjat.svg",
  "full_name": "qwc/asiakirjat",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.