原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"openssl",
"c",
"ruby",
"tls",
"hacktoberfest"
],
"is_fork": false,
"size_kb": 6045,
"has_wiki": true,
"homepage": null,
"languages": {
"C": 810129,
"Ruby": 509903,
"Go Template": 341
},
"pushed_at": "2026-07-13T10:10:22Z",
"created_at": "2014-10-27T02:12:48Z",
"owner_type": "Organization",
"updated_at": "2026-07-13T11:55:26Z",
"description": "Provides SSL, TLS and general purpose cryptography.",
"is_archived": false,
"is_disabled": false,
"license_spdx": null,
"default_branch": "master",
"license_spdx_raw": "NOASSERTION",
"primary_language": "C",
"significant_languages": [
"C",
"Ruby"
]
},
"owner": {
"blog": "https://www.ruby-lang.org/",
"name": "The Ruby Programming Language",
"type": "Organization",
"login": "ruby",
"company": null,
"location": "Japan",
"followers": 2077,
"avatar_url": "https://avatars.githubusercontent.com/u/210414?v=4",
"created_at": "2010-02-25T03:48:00Z",
"is_verified": null,
"public_repos": 190,
"account_age_days": 5990
},
"license": {
"state": "custom",
"spdx_id": null,
"raw_spdx": "NOASSERTION",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v4.0.2",
"kind": "patch",
"published_at": "2026-05-13T17:40:09Z"
},
{
"tag": "v3.3.3",
"kind": "patch",
"published_at": "2026-05-13T17:39:05Z"
},
{
"tag": "v3.2.4",
"kind": "patch",
"published_at": "2026-05-13T17:38:55Z"
},
{
"tag": "v4.0.1",
"kind": "patch",
"published_at": "2026-02-16T17:01:20Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2025-12-15T09:57:57Z"
},
{
"tag": "v3.3.2",
"kind": "patch",
"published_at": "2025-10-27T06:43:56Z"
},
{
"tag": "v3.2.3",
"kind": "patch",
"published_at": "2025-10-27T06:43:53Z"
},
{
"tag": "v3.1.3",
"kind": "patch",
"published_at": "2025-10-27T06:43:38Z"
},
{
"tag": "v3.3.1",
"kind": "patch",
"published_at": "2025-10-06T08:06:42Z"
},
{
"tag": "v3.2.2",
"kind": "patch",
"published_at": "2025-10-06T08:06:53Z"
},
{
"tag": "v3.1.2",
"kind": "patch",
"published_at": "2025-10-06T08:07:30Z"
},
{
"tag": "v3.3.0",
"kind": "minor",
"published_at": "2024-12-21T17:38:06Z"
},
{
"tag": "v3.2.1",
"kind": "patch",
"published_at": "2024-12-18T13:13:02Z"
},
{
"tag": "v3.1.1",
"kind": "patch",
"published_at": "2024-12-18T13:12:49Z"
},
{
"tag": "v3.0.3",
"kind": "patch",
"published_at": "2024-12-18T13:12:34Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2023-09-21T20:02:51Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2022-12-23T00:56:48Z"
},
{
"tag": "v3.0.2",
"kind": "patch",
"published_at": "2022-12-23T00:56:32Z"
},
{
"tag": "v2.2.3",
"kind": "patch",
"published_at": "2022-12-23T00:56:08Z"
}
],
"recent_commits": [
{
"oid": "27c59a4cc8a652004184182f734de0161ba08b41",
"body": "…urity/harden-runner-2.20.0\n\nbuild(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0",
"is_bot": false,
"headline": "Merge pull request #1084 from ruby/dependabot/github_actions/step-sec…",
"author_name": "Olle Jonsson",
"author_login": "olleolleolle",
"committed_at": "2026-07-13T10:10:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f79dd7a969dbeee8b79cd5afa5b3cd8e5f217a70",
"body": "Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.4 to 2.20.0.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/9af89fc71515a100421586dfdb3dc9c984fbf411...bf7454d0\n[…]\n-name: step-security/harden-runner\n dependency-version: 2.20.0\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump step-security/harden-runner from 2.19.4 to 2.20.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-13T09:30:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2a8a82967eb74d5cce32902589bab19aa3e5abb2",
"body": "pkey: add OpenSSL::PKey::PKey#get_param",
"is_bot": false,
"headline": "Merge pull request #1078 from rhenium/ky/pkey-get-params",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-10T11:25:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7103c050c4cf6026e9927f178f8552a06b2bae9a",
"body": "ssl: use uint64_t for SSL options",
"is_bot": false,
"headline": "Merge pull request #1073 from rhenium/ky/ssl-options-uint64_t",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-10T11:23:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fbddeb74b0b54cf8fb3cd23bda1082d81958aa55",
"body": "Expose EVP_PKEY_get_params(), added in OpenSSL 3.0, for retrieving\nvarious parameters from an EVP_PKEY object.",
"is_bot": false,
"headline": "pkey: add OpenSSL::PKey::PKey#get_param",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-10T11:02:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "680370b5ee0b4a42f4405a6f3015798eb1a51278",
"body": "Allocate OpenSSL objects in #initialize{,_copy}",
"is_bot": false,
"headline": "Merge pull request #1046 from rhenium/ky/alloc-in-initialize",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:48:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f9026106a30f40662dbb25e3e69c60a410d5d3a3",
"body": null,
"is_bot": false,
"headline": "ns_spki: allocate OpenSSL objects in #initialize{,_copy}",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:41:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6bb2810f594d74b0adb510f57aa1cc9ff9edab21",
"body": null,
"is_bot": false,
"headline": "pkcs7: allocate OpenSSL objects in #initialize{,_copy}",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:41:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4cbe86fd1e0b93aad8254580539e8612927298a5",
"body": null,
"is_bot": false,
"headline": "ts: allocate OpenSSL objects in #initialize{,_copy}",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:41:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c70b060c3d1df532cd95a3dee2512ae4414f883d",
"body": null,
"is_bot": false,
"headline": "x509*: allocate OpenSSL objects in #initialize{,_copy}",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:41:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1472feb74e2773388f1b2a2fab57b907c0cf6fc3",
"body": null,
"is_bot": false,
"headline": "pkcs12: allocate OpenSSL objects in #initialize{,_copy}",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:41:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5f104287930a00f99c3e1842018f9a04e305e8e5",
"body": "Allocate the underlying OpenSSL object in #initialize{,_copy} instead\nof .allocate. Allocating an empty OpenSSL object in .allocate is\nwasteful because #initialize{,_copy} cannot always reuse an existing\nobject and have to allocate a new one.\n\nSome ruby/openssl classes already follow this approach, such as\nOpenSSL::PKey::PKey. Let's standardize on it.\n\nAlso expand New*() and Set*() macros, which are only used once or twice\nand are not very helpful for readability in my opinion.",
"is_bot": false,
"headline": "ocsp: allocate OpenSSL objects in #initialize{,_copy}",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:29:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24f72a8350ed6084d1fe0a03315bec8944d1b160",
"body": "Simplify the code and raise exceptions with a consistent error message.\n\nThis unifies the exception type raised when #initialize is called twice\nto TypeError. This should not affect valid usage of these classes.",
"is_bot": false,
"headline": "pkey, ssl, cipher, hpke: use ossl_want_uninitialized()",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:27:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02872d3c8f00c680884f869f5ae9733ff87353c1",
"body": null,
"is_bot": false,
"headline": "ossl.c: add helper function ossl_want_uninitialized()",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:27:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f62cc13cfa02236460ddd740e8b07f276cc74628",
"body": "Allocate the wrapper object before attempting to load the provider.\n\nAlso, expand macros NewProvider() and SetProvider(), which are only\nused once and are unlikely to be reused in the future.",
"is_bot": false,
"headline": "provider: fix potential memory leak in .load",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T17:25:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "99d442e2bc131c8e922f873feecf03a53e421afa",
"body": "Implement dcompact",
"is_bot": false,
"headline": "Merge pull request #1079 from rhenium/ky/dcompact",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T10:40:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98acd95e86f7952fc40d73d19fe3400b305e0201",
"body": "We can implement this now that we require Ruby 2.7 or later.\n\nThe return value of OpenSSL's *_set_ex_data() functions is not checked\nsince replacing an existing index should not fail.",
"is_bot": false,
"headline": "Implement dcompact",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-07-05T09:22:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fe1b71b1cf233ca178fb1e2e9617840cb39f00a",
"body": "…cache-6\n\nbuild(deps): bump actions/cache from 5 to 6",
"is_bot": false,
"headline": "Merge pull request #1076 from ruby/dependabot/github_actions/actions/…",
"author_name": "Olle Jonsson",
"author_login": "olleolleolle",
"committed_at": "2026-06-29T09:34:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce767ae2883fbb3918c9c89f264e09d06f4ff249",
"body": "Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/cache\n dependency-version: '6'\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/cache from 5 to 6",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T09:28:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb7e784e5e633c421e9954ea85caf45245d700fb",
"body": "Fix unused-but-set-global warnings in clang-23",
"is_bot": false,
"headline": "Merge pull request #1074 from nobu/unused-variables",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-25T09:00:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "44bb2aa07005dd3b4f6a8710771f7ab096ca7aa3",
"body": null,
"is_bot": false,
"headline": "Fix unused-but-set-global warnings in clang-23",
"author_name": "Nobuyoshi Nakada",
"author_login": "nobu",
"committed_at": "2026-06-25T08:27:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8adbb9adbc298d22574a5306b1561c955526caf0",
"body": null,
"is_bot": false,
"headline": "ssl: sync SSL_OP constants with OpenSSL 4.0",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T16:14:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "743daa7ac9827e2c68bce4ac72311e65e33107e0",
"body": "OpenSSL 3.0 changed the type of SSL options to uint64_t. Since OpenSSL\n3.2 began using the 33rd bit, treating it as unsigned long is no longer\nsufficient.",
"is_bot": false,
"headline": "ssl: use uint64_t for SSL options",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T16:14:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "567be80127ee4b6f4c33817915827f79560d0d73",
"body": null,
"is_bot": false,
"headline": "ossl.h: add UINT64T2NUM(x)",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T14:15:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b353e40c58785b933a692c94a56d7d5fd184b196",
"body": "x509store: add X509::Store{,Context}#flags and #clear_flags",
"is_bot": false,
"headline": "Merge pull request #1067 from rhenium/ky/x509store-flags-warn-add",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T13:50:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d47beddd95114254e13726e3a9d0b8543cc4d2f2",
"body": "ssl: let SSLServer accept frozen SSLContext",
"is_bot": false,
"headline": "Merge pull request #1072 from rhenium/ky/ssl-sslserver-missing-sidctx",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T13:35:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "51de9c303e70892285a55ccff8d0b49377a78e03",
"body": "Do not raise FrozenError in SSLServer.new when\nSSLContext#session_id_context cannot be updated. session_id_context is\nonly necessary for session resumption, so its absence is not critical.\n\nFixes https://github.com/ruby/openssl/pull/742",
"is_bot": false,
"headline": "ssl: let SSLServer accept frozen SSLContext",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T11:13:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a457bfdf4822a1770b2f336314f1a23d38160c37",
"body": "pkey: expand OSSL_3_const macro",
"is_bot": false,
"headline": "Merge pull request #1071 from rhenium/ky/pkey-legacy-constify",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T11:06:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ce050d77403c0e2b43caaf1249b6675f5d244838",
"body": "OSSL_3_const was useful when supporting OpenSSL 1.0.2-3.x at the same\ntime. Since support for OpenSSL < 1.1.1 has been dropped, most uses can\nsimply be replaced with plain const.",
"is_bot": false,
"headline": "pkey: expand OSSL_3_const macro",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T10:00:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "21c0ef5a5832f37f66777a7f4ec9f871ddab4bf1",
"body": ".github/workflows/test.yml: enable -Werror for AWS-LC checks",
"is_bot": false,
"headline": "Merge pull request #1070 from rhenium/ky/ci-update-20260624",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T09:59:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "59d654e25a9e31cdcd4d1519bf7cbba0bc85b857",
"body": null,
"is_bot": false,
"headline": ".github/workflows/test.yml: update OpenSSL versions",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T09:48:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec8f5e97934637e115ac3cbd231e1f29cc7e6213",
"body": "Except for known warnings. We want to let the check fail on\n-Wimplicit-function-declaration, for example.\n\nAlso, use the \"env\" directive in the \"rake compile\" step instead of\n$GITHUB_ENV to simplify.",
"is_bot": false,
"headline": ".github/workflows/test.yml: enable -Werror for AWS-LC checks",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T09:48:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9627df57cecd0dc3b2bea5caf0d3a70a06711585",
"body": "Add DHKEM support and test cases",
"is_bot": false,
"headline": "Merge pull request #1069 from sylph01/test-dhkem",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-24T09:45:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dfc45d31d0535d73c5d2ab66aaaf6c97fc846d60",
"body": null,
"is_bot": false,
"headline": "Add DHKEM test cases",
"author_name": "Ryo Kajiwara",
"author_login": "sylph01",
"committed_at": "2026-06-24T09:37:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9394001f9aa53d4bd45d0f7d1ffcf5129b498fe2",
"body": "Bump minimum jruby-openssl to 0.15.4 for CVE-2025-46551",
"is_bot": false,
"headline": "Merge pull request #1022 from ruby/bumpup-jruby-openssl",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-22T17:41:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ffbe73aaa831176777c7f52e90670ee6d5c82eb",
"body": "\"~> 0.14\" is equivalent to \">= 0.14, < 1\". Since the openssl gem is an\nempty stub on JRuby, there is no good reason to specify version bounds\non jruby-openssl.\n\n[ky: commit message]\n\nCo-authored-by: Kazuki Yamaguchi <k@rhe.jp>",
"is_bot": false,
"headline": "Remove version constraint for jruby-openssl",
"author_name": "Hiroshi SHIBATA",
"author_login": "hsbt",
"committed_at": "2026-06-22T17:37:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f68ac058713f884b1908afc5ebec3f775b42fd2",
"body": "x509crl: add OpenSSL::X509::CRL#by_serial",
"is_bot": false,
"headline": "Merge pull request #1065 from jarthod/x509crl-by-serial",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-22T17:23:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "83f4a0db329324d331de1f8767e7b521a77512de",
"body": "…le cert",
"is_bot": false,
"headline": "x509crl: add OpenSSL::X509::CRL#by_serial for faster lookup of a sing…",
"author_name": "Adrien Rey-Jarthon",
"author_login": "jarthod",
"committed_at": "2026-06-22T17:18:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09dafdb0b5eccd0e2b37f03c82f5d6eceb159c9d",
"body": "…checkout-7\n\nbuild(deps): bump actions/checkout from 6 to 7",
"is_bot": false,
"headline": "Merge pull request #1068 from ruby/dependabot/github_actions/actions/…",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-22T17:18:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ed7e7bb6dcddc7c8634f9d3ca9424c3ed7f9e81c",
"body": "Add EVP_PKEY KEM operations",
"is_bot": false,
"headline": "Merge pull request #1062 from bdewater-thatch/pkey-kem-api",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-22T17:17:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eaa6b3122280ff2caf4ac5ea8e17e89632dca64a",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n dependency-version: '7'\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump actions/checkout from 6 to 7",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T09:26:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bd89c50577cfaee6a2c39e5e597ad2d2371153e7",
"body": "Add Hybrid Public Key Encryption (HPKE) API Support",
"is_bot": false,
"headline": "Merge pull request #1061 from sylph01/hpke",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-21T11:59:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b80681cde3c2c1c5254ddcbfbade5ec9ca22d4b",
"body": null,
"is_bot": false,
"headline": "Add Hybrid Public Key Encryption (HPKE) API Support",
"author_name": "Ryo Kajiwara",
"author_login": "sylph01",
"committed_at": "2026-06-21T10:58:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a245620e2eee001b809742326f5e25d551a1c89e",
"body": "OpenSSL::X509::Store{,Context}#flags= does not clear existing flags.\nInstead, it ORs new flags to the current set. This is contrary to\nnormal convention and likely unintentional, but changing the behavior\nwould not be acceptable for compatibility reasons.\n\nAdd #flags to get the current flags to allo\n[…]\nr_flags to remove existing flags. The underlying OpenSSL\nC APIs appear to have been added in a patch release of OpenSSL 0.9.8.\n\nWarn in #flags= if the argument is not a superset of the existing flags.",
"is_bot": false,
"headline": "x509store: add X509::Store{,Context}#flags and #clear_flags",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-06-21T10:44:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "501d2b227c5170437bdc3d8e10ce3aae0169976f",
"body": "Constify pkey pointers",
"is_bot": false,
"headline": "Merge pull request #1066 from nobu/constify",
"author_name": "Nobuyoshi Nakada",
"author_login": "nobu",
"committed_at": "2026-06-21T03:04:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d74f60deaadb03d0185ea1de3a75c3cf03bd0e3",
"body": null,
"is_bot": false,
"headline": "Constify pkey pointers",
"author_name": "Nobuyoshi Nakada",
"author_login": "nobu",
"committed_at": "2026-06-21T02:53:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f2ec03dda1bc20faaefbb5bd9d2ff96b488feef2",
"body": null,
"is_bot": false,
"headline": "Add EVP_PKEY KEM operations",
"author_name": "Bart de Water",
"author_login": "bdewater-thatch",
"committed_at": "2026-06-16T20:28:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7cdca78f5ee19576113d6d600fd22650f0e37c4",
"body": "asn1: limit nesting depth in OpenSSL::ASN1.decode",
"is_bot": false,
"headline": "Merge pull request #1060 from rhenium/ky/asn1-decode-limit-recursion",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-30T09:02:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fc753239cc2d15a4ecfbdbcb9328398c0b6d55c6",
"body": "Feeding a deeply nested constructed encoding to OpenSSL::ASN1.decode,\n.decode_all, or .traverse can cause unbounded recursion and result in\nSystemStackError.\n\nAdd an explicit nesting depth limit of 200 levels and raise\nOpenSSL::ASN1::ASN1Error if it is exceeded. This limit is arbitrary and\ncurrently not configurable, but should be sufficient for any practical\nuse cases.\n\nFixes https://hackerone.com/reports/3662125",
"is_bot": false,
"headline": "asn1: limit nesting depth in OpenSSL::ASN1.decode",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-30T08:52:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9cdfb77b343c7d7c4e2c05321cb68ffc1f3c4226",
"body": "Fix test_ts.rb in FIPS.",
"is_bot": false,
"headline": "Merge pull request #1056 from junaruga/wip/fips-test-ts",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-30T08:46:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f1303124422e272ee980979ec6187e76aac3d3f3",
"body": "Replace RSA keys for intermediate_key and ee_key with RSA 4096-bit keys\nrsa-1.pem and rsa-2.pem. At least RSA 2048-bit keys are required for signing\nand encryption in FIPS.\n\nSP 800-131A Rev. 2\n* 3. Digital Signatures\n* 6. Key Agreement and Key Transport Using RSA\nhttps://nvlpubs.nist.gov/nistpubs/Sp\n[…]\nsl/fixtures/pkey/rsa-1.pem -text -noout | head -1\nPrivate-Key: (4096 bit, 2 primes)\n\n$ openssl rsa -in test/openssl/fixtures/pkey/rsa-2.pem -text -noout | head -1\nPrivate-Key: (4096 bit, 2 primes)\n```",
"is_bot": false,
"headline": "Fix test_ts.rb in FIPS.",
"author_name": "Jun Aruga",
"author_login": "junaruga",
"committed_at": "2026-05-29T16:27:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ba53fad9f5029825e81087dfb0d206c62ae1115f",
"body": "kdf: document incompatibility with timeout",
"is_bot": false,
"headline": "Merge pull request #1024 from rhenium/ky/kdf-document-interrupt",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T13:07:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "58c0b81a59c01508a570e3b694e2bf13bc7dac9c",
"body": "OpenSSL::KDF.pbkdf2_hmac and .scrypt are currently not interrupted by\nTimeout.timeout because they make a single, slow OpenSSL function call\nduring which Ruby-level interrupts cannot be handled. Add advice against\nusing parameters from untrusted inputs.",
"is_bot": false,
"headline": "kdf: document incompatibility with timeout",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T13:06:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "567723485473ecd06aec701b2f0cef75b293cb79",
"body": "ts: refactor decoding DER",
"is_bot": false,
"headline": "Merge pull request #1045 from rhenium/ky/ts-d2i-avoid-reuse",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:45:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "831c13b0bbdcbd1a20ea787cd7f94c9b173025c9",
"body": "pkcs7: avoid using strcmp() with Ruby strings",
"is_bot": false,
"headline": "Merge pull request #1059 from rhenium/ky/string-nul-terminator",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:38:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3f1a7a377ccaf68bb929593826c2fd0d983241e7",
"body": "Also, avoid using the \"reuse\" behavior of d2i_*{,_bio}() functions.",
"is_bot": false,
"headline": "pkcs12: add missing error check for d2i_PKCS12_bio()",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:35:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "01e560258130653353201c7e70a4d8a476a6bf46",
"body": "The man page discourages using this behavior because it may leave the\nobject in an inconsistent state on error paths. This fixes a potential\nmemory leak reported at <https://github.com/ruby/openssl/issues/1011>.",
"is_bot": false,
"headline": "ts: do not use the \"reuse\" behavior of d2i_*{,_bio}() functions",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:34:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b35e1a8109b6ab0bcbf534bc1c912b1055e08d9",
"body": "We should not rely on the NUL terminator of Ruby strings. Use memcmp().",
"is_bot": false,
"headline": "pkcs7: avoid using strcmp() with Ruby strings",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:32:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3b00e98df887eb09df14c414b1409d038eedb0f8",
"body": "Fix test_kdf.rb in FIPS.",
"is_bot": false,
"headline": "Merge pull request #1054 from junaruga/wip/fips-test-kdf",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:24:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a87a21c51241dfcaebe9844797b5595c5f59843c",
"body": "…es-ractor-safe\n\nMake OpenSSL::Digest classes Ractor-safe",
"is_bot": false,
"headline": "Merge pull request #1053 from etiennebarrie/make-openssl-digest-class…",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-29T08:22:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "502bc6c378d823465681ec66efd7fb7ef3d70220",
"body": "Use class_eval with a string so the initialize instance method, and the\ndigest and hexdigest class methods are not defined via define_method\nwith a Proc (which is not Ractor-safe).",
"is_bot": false,
"headline": "Make OpenSSL::Digest classes Ractor-safe",
"author_name": "Étienne Barrié",
"author_login": "etiennebarrie",
"committed_at": "2026-05-26T16:35:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "450721cc5d541e0c5f2cadb6d40026422d28f61f",
"body": "* PBKDF2 salt >= 16 bytes (128 bits) and iterations >= 1000 are required in\n FIPS.\n SP 800-132: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf\n * 5.1 The Salt (S)\n https://github.com/openssl/openssl/blob/71943544885ff364a10bcc5ffc62d0e651c9a021/providers/implemen\n[…]\n 6070 test is good enough.\n* Remove test_hkdf_rfc5869_test_case_4 in favor of the new\n test_hkdf_rfc5869_test_case_5.\n* We want to avoid conditional tests that don't work in FIPS as much as possible.",
"is_bot": false,
"headline": "Fix test_kdf.rb in FIPS.",
"author_name": "Jun Aruga",
"author_login": "junaruga",
"committed_at": "2026-05-25T18:08:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff3a822eec2035b1fca2fab1fc62e6bffb1eae9c",
"body": "…urity/harden-runner-2.19.4\n\nbuild(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4",
"is_bot": false,
"headline": "Merge pull request #1058 from ruby/dependabot/github_actions/step-sec…",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-25T14:42:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b359d75dff37c58f84cb3fe45072ae14509cac80",
"body": "Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.3 to 2.19.4.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/ab7a9404c0f3da075243ca237b5fac12c98deaa5...9af89fc7\n[…]\n-name: step-security/harden-runner\n dependency-version: 2.19.4\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump step-security/harden-runner from 2.19.3 to 2.19.4",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-25T14:40:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "26e304b93f7bdf07a60f4eaca95b9701f3b9d6db",
"body": "…mental\n\nRakefile: suppress \"experimental\" warnings in rake test",
"is_bot": false,
"headline": "Merge pull request #1057 from rhenium/ky/test-suppress-warning-experi…",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-22T11:26:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "03ed2081f98e784a38ead2bb6f3529c78633b8e7",
"body": null,
"is_bot": false,
"headline": "Rakefile: suppress \"experimental\" warning category in rake test",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-22T11:19:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0593fe0232fe3b26e3864def4be3dd04a050c216",
"body": "Document syswrite_nonblock opts and symbol return",
"is_bot": false,
"headline": "Merge pull request #1055 from zonuexe/fix-call-seq",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-22T10:37:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6339db4386f67766782ba8d84eb9b4b8fa47d8bc",
"body": null,
"is_bot": false,
"headline": "Document syswrite_nonblock opts and symbol return value",
"author_name": "USAMI Kenta",
"author_login": "zonuexe",
"committed_at": "2026-05-21T11:19:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ccdfc6eb0564ec27ef73ba4d06b371108cfb7ac",
"body": "…urity/harden-runner-2.19.3\n\nbuild(deps): bump step-security/harden-runner from 2.19.1 to 2.19.3",
"is_bot": false,
"headline": "Merge pull request #1052 from ruby/dependabot/github_actions/step-sec…",
"author_name": "Olle Jonsson",
"author_login": "olleolleolle",
"committed_at": "2026-05-19T06:34:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2d63160f16afe3f441cd42dc2f954a96bde7d5d7",
"body": "Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.1 to 2.19.3.\n- [Release notes](https://github.com/step-security/harden-runner/releases)\n- [Commits](https://github.com/step-security/harden-runner/compare/a5ad31d6a139d249332a2605b85202e8c0b78450...ab7a9404\n[…]\n-name: step-security/harden-runner\n dependency-version: 2.19.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "build(deps): bump step-security/harden-runner from 2.19.1 to 2.19.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-18T17:40:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b61ff5afeef1d492a326a9623fc26f394250f061",
"body": "OpenSSL 4.0 support has been backported to the 3.2, 3.3, and 4.0\nbranches.",
"is_bot": false,
"headline": "README.md: update compatibility table",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T17:22:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "318be774d71ad66cdc1188a7a0fa498dfebbe85d",
"body": "* maint-4.0:\n Ruby/OpenSSL 4.0.2\n Ruby/OpenSSL 3.3.3\n Ruby/OpenSSL 3.2.4",
"is_bot": false,
"headline": "Merge branch 'maint-4.0'",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:30:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6e410b804f4c6a52c146fe651941bafdbb332754",
"body": null,
"is_bot": false,
"headline": "Ruby/OpenSSL 4.0.2",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:30:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d6d068e434ae3198db72d1f9f5ca05c72438552",
"body": "* maint-3.3:\n Ruby/OpenSSL 3.3.3\n Ruby/OpenSSL 3.2.4",
"is_bot": false,
"headline": "Merge branch 'maint-3.3' into maint-4.0",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:28:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9720a7644cbb46735460993b2091ce4a08c10890",
"body": null,
"is_bot": false,
"headline": "Ruby/OpenSSL 3.3.3",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:28:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6062da04945e1b211f96501d9523b79fcc28cd98",
"body": "* maint-3.2:\n Ruby/OpenSSL 3.2.4",
"is_bot": false,
"headline": "Merge branch 'maint-3.2' into maint-3.3",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:27:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d1fb31bf24676ffc177f881fb3c31e87f3f6ee42",
"body": null,
"is_bot": false,
"headline": "Ruby/OpenSSL 3.2.4",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:25:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4989395f5e38ef445a5204bcb739bddaf97dcd4b",
"body": "* maint-4.0:\n test_pkey_rsa.rb: Fix test_private_encoding_encrypted in OpenSSL 4.0 FIPS\n Add const qualifiers for OpenSSL 4.0 compatibility\n const correct ossl_bin2hex()\n Backport changes for opaque ASN1_STRING in OpenSSL 4\n ssl: fix test_tmp_dh and test_tmp_dh_callback with OpenSSL 4.0\n pkey/\n[…]\nempty_rsa with OpenSSL >= 3\n pkey: handle EVP_PKEY_KEYMGMT return by EVP_PKEY_id()\n pkey: use EVP_PKEY_new_raw_{private,public}_key_ex() if available\n ossl.h: include <openssl/provider.h> in ossl.h",
"is_bot": false,
"headline": "Merge branch 'maint-4.0'",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T15:23:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4bae03bf73eea7cdc2ae0c8c20ea032827e56f3b",
"body": "* maint-3.3:\n test_pkey_rsa.rb: Fix test_private_encoding_encrypted in OpenSSL 4.0 FIPS\n Add const qualifiers for OpenSSL 4.0 compatibility\n const correct ossl_bin2hex()\n Backport changes for opaque ASN1_STRING in OpenSSL 4\n ssl: fix test_tmp_dh and test_tmp_dh_callback with OpenSSL 4.0\n pkey/\n[…]\nempty_rsa with OpenSSL >= 3\n pkey: handle EVP_PKEY_KEYMGMT return by EVP_PKEY_id()\n pkey: use EVP_PKEY_new_raw_{private,public}_key_ex() if available\n ossl.h: include <openssl/provider.h> in ossl.h",
"is_bot": false,
"headline": "Merge branch 'maint-3.3' into maint-4.0",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T11:13:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b7f2b7e426d11afa49f37e01d30dc02ed3577cbb",
"body": "…FIPS\n\n[ This is a backport to the 3.3 branch. ]\n\nOpenSSL 4.0.0 added a check for Password-Based Key Derivation Function 2\n(PBKDF2) to require the minimal password length 8 in FIPS by the following\ncommit.\nhttps://github.com/openssl/openssl/commit/71ed0fc8b3cdb33cd06059416686f8972ede0248\n\nThis commi\n[…]\nce, asn1\n 468: assert_equal 2, asn1.value.size\nError: OpenSSL::PKey::PKeyError: i2d_PKCS8PrivateKey_bio: encrypt error\n```\n\n(cherry picked from commit 69f8cd1af184d312a9ecba950b63cb2ef3d41d36)",
"is_bot": false,
"headline": "test_pkey_rsa.rb: Fix test_private_encoding_encrypted in OpenSSL 4.0 …",
"author_name": "Jun Aruga",
"author_login": "junaruga",
"committed_at": "2026-05-13T11:11:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1c29d5560b1b7342328f8d910580ab6de154d38e",
"body": "* maint-3.2:\n Add const qualifiers for OpenSSL 4.0 compatibility\n const correct ossl_bin2hex()\n Backport changes for opaque ASN1_STRING in OpenSSL 4\n ssl: fix test_tmp_dh and test_tmp_dh_callback with OpenSSL 4.0\n pkey/rsa: skip test_verify_empty_rsa with OpenSSL >= 3\n pkey: handle EVP_PKEY_KEYMGMT return by EVP_PKEY_id()\n pkey: use EVP_PKEY_new_raw_{private,public}_key_ex() if available\n ossl.h: include <openssl/provider.h> in ossl.h",
"is_bot": false,
"headline": "Merge branch 'maint-3.2' into maint-3.3",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T10:58:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c37f74fdd42fd263c3369f9075b0fa2cd43dc076",
"body": "Backport OpenSSL 4.0 support",
"is_bot": false,
"headline": "Merge pull request #1051 from rhenium/ky/openssl-4.0-backport",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T10:50:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e79cfad1fe957ed8f431463b33812dabd2b1facf",
"body": "* maint-4.0:\n .github/workflows/test.yml: synchronize with master\n Remove test_ed25519_not_approved_on_fips.\n test_s_generate_parameters: Consider a DSA error in FIPS.\n Revert \"Always respect the openssl prefix chosen by truffle/openssl-prefix on TruffleRuby\"",
"is_bot": false,
"headline": "Merge branch 'maint-4.0'",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T10:28:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ef34d7147bab1d80e0fbd578dd2d75abb544b4b",
"body": "* maint-3.3:\n .github/workflows/test.yml: synchronize with master\n Remove test_ed25519_not_approved_on_fips.\n test_s_generate_parameters: Consider a DSA error in FIPS.\n Revert \"Always respect the openssl prefix chosen by truffle/openssl-prefix on TruffleRuby\"",
"is_bot": false,
"headline": "Merge branch 'maint-3.3' into maint-4.0",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T10:26:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ebe64932af885cda21086ef7de2774e740146b8f",
"body": "* maint-3.2:\n .github/workflows/test.yml: synchronize with master\n Remove test_ed25519_not_approved_on_fips.\n test_s_generate_parameters: Consider a DSA error in FIPS.\n Revert \"Always respect the openssl prefix chosen by truffle/openssl-prefix on TruffleRuby\"",
"is_bot": false,
"headline": "Merge branch 'maint-3.2' into maint-3.3",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T10:22:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "17c2fc01baf178bfbd893b6eddf9b803cd485004",
"body": "[ This is a backport to the 3.2 branch. ]\n\nOpenSSL's master branch is changing functions to return const pointers\nwhere the returned objects are not meant to be modified by the caller.\n\nUpdate ossl_*_new() to take const pointers accordingly. Unfortunately,\n*_dup() in older versions of OpenSSL and in LibreSSL/AWS-LC take\nnon-const pointers, so const casts are required.\n\n(cherry picked from commit 34c49e6c6cda548bf9b1da8a099ec3d39efdb2c2)",
"is_bot": false,
"headline": "Add const qualifiers for OpenSSL 4.0 compatibility",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T09:59:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8311041fa46e6752a44326436b9df91a0bfa0435",
"body": "[ This is a backport to the 3.2 branch. ]\n\nThis helper only reads from its in parameter. Making that const\navoids a couple of casts in an upcoming change.\n\n(cherry picked from commit 970d5764e3b349f152003e3b482d2382b7b3dcef)",
"is_bot": false,
"headline": "const correct ossl_bin2hex()",
"author_name": "Theo Buehler",
"author_login": "botovq",
"committed_at": "2026-05-13T05:46:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2fdc1e3c088cb079a1176153a845269be7f4132b",
"body": "[ This is a backport to the 3.2 branch. ]\n\nBackport the following commits from master:\n\n a41cf28babe8 Convert ossl_x509ext.c to opaque ASN1_STRING\n 8945f379b3c6 Convert ossl_ts.c to opaque ASN1_STRING\n 0941ebbda527 Convert ossl_ns_spki.c to opaque ASN1_STRING\n ba3d1cc5c268 Convert some o\n[…]\n does not exist in OpenSSL 1.0.2.\n - asn1time_to_time() in ossl_asn1.c is manually converted. It had\n been rewritten in master, but older branches need to be converted\n to use those accessors.",
"is_bot": false,
"headline": "Backport changes for opaque ASN1_STRING in OpenSSL 4",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T05:45:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8d9e6f936547657082c59130eede3557c4055d64",
"body": "[ This is a backport to the 3.2 branch. ]\n\nOpenSSL master added support for RFC 7919 groups in TLS 1.2. They are\npreferred over SSLContext#tmp_dh= or #tmp_dh_callback= values if the\nclient advertises them in the supported_groups extension.\n\n(cherry picked from commit 3e01c802c9cf96ab386c5d57f42ecebc053d6b08)",
"is_bot": false,
"headline": "ssl: fix test_tmp_dh and test_tmp_dh_callback with OpenSSL 4.0",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T05:45:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "00daa318b1a2a28e02db1452046f7321d7907d26",
"body": "[ This is a backport to the 3.2 branch. ]\n\nThis test case seems to fail with OpenSSL 4.0.0. Let's disable it for\nnow. It is an impossible state with our master branch as of commit\naffd569f78b0 (pkey: disallow {DH,DSA,EC,RSA}.new without arguments with\nOpenSSL 3.0, 2025-01-30) and the test is disabled there, too.",
"is_bot": false,
"headline": "pkey/rsa: skip test_verify_empty_rsa with OpenSSL >= 3",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T05:45:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c5476686d74ac1d488e70d7180af6ea601e900e1",
"body": "[ This is a backport to the 3.2 branch. ]\n\nFor algorithms implemented solely in an OpenSSL 3 provider, without an\nassociated EVP_PKEY_METHOD, EVP_PKEY_id() returns a special value\nEVP_PKEY_KEYMGMT.\n\nLet OpenSSL::PKey::PKey#oid raise an exception as necessary.\nUpdate PKey#inspect to include the string returned by\nEVP_PKEY_get0_type_name(), if available.\n\n(cherry picked from commit bd3e32270ed8f2c57735035d9451c6118154df28)",
"is_bot": false,
"headline": "pkey: handle EVP_PKEY_KEYMGMT return by EVP_PKEY_id()",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T05:45:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1dfaeee0721d547f657c2f635b93a8f58df1b861",
"body": "[ This is a backport to the 3.2 branch. ]\n\nAlgorithms implemented only in OpenSSL 3 providers may not have a\ncorresponding NID. The *_ex() variants have been added in OpenSSL 3.0\nto handle such algorithms, by taking algorithm names as a string.\n\n(cherry picked from commit e730e457cc00d240d9cafc60ba6a21793a420cc9)",
"is_bot": false,
"headline": "pkey: use EVP_PKEY_new_raw_{private,public}_key_ex() if available",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T05:45:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f8a36695cc4f0df9c038b47d9fc697aaf0126b7",
"body": "[ This is a backport to the 3.2 branch. ]\n\nMove the #include from ossl_provider.c to ossl.h. As OpenSSL 3 provider\nfunctions will be used in multiple source files, having it in the\ncommon header file is convenient.\n\n(cherry picked from commit f831bb66bcccca4b79a9e61bbf0e6d9ff2d3590d)",
"is_bot": false,
"headline": "ossl.h: include <openssl/provider.h> in ossl.h",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-13T05:45:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "87bf6f2aaef9bba5efc0c0d57a0c6af00cd9f137",
"body": "Fix CI in 3.2 branch",
"is_bot": false,
"headline": "Merge pull request #1049 from rhenium/ky/maint-3.2-ci-backport",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-12T19:13:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee351a5783938fd1b3ee06f943029bef8d667e40",
"body": ".github/workflows/test.yml: enable rake test_fips with OpenSSL 4.0",
"is_bot": false,
"headline": "Merge pull request #1050 from rhenium/ky/ci-openssl-4.0-fips",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-12T19:04:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7245db4acc52a3d65479df31374acf86e722f76d",
"body": "[ This is a backport to the 3.2 branch. ]\n\nExcluding the AWS-LC stuff. This includes the following commits:\n\n 83259e6c4bf1 CI: Upgrade OpenSSL versions\n fe4319cf3587 .github/workflows/test.yml: stop using ubuntu-20.04 runner image\n b198fddffa16 .github/workflows/test.yml: update test-openss\n[…]\n versions and LibreSSL comments\n 373a3ea5fd31 build(deps): bump step-security/harden-runner from 2.19.0 to 2.19.1\n 5321f9665465 .github/workflows/test.yml: enable rake test_fips with OpenSSL 4.0",
"is_bot": false,
"headline": ".github/workflows/test.yml: synchronize with master",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-12T19:02:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "48d8a83c4732bc1a0a834dc10289a1ab9f0ddd3e",
"body": "[ This is a backport to the 3.2 branch. ]\n\nThis commit fixes the following failure on OpenSSL master FIPS case.\n\n```\n1) Failure: test_ed25519_not_approved_on_fips(OpenSSL::TestPKey): OpenSSL::PKey::PKeyError expected but nothing was raised.\n/home/runner/work/openssl/openssl/vendor/bundle/ruby/3.0.0/\n[…]\nithub.com/openssl/openssl/discussions/22054\n[2] https://github.com/openssl/openssl/commit/5f04124aab4a477d4e58149d8f04871ff7e5ea4b\n\n(cherry picked from commit d43904b83457d16fa150f9bbb4586999821396a1)",
"is_bot": false,
"headline": "Remove test_ed25519_not_approved_on_fips.",
"author_name": "Jun Aruga",
"author_login": "junaruga",
"committed_at": "2026-05-12T19:02:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0ed83c7e49297eef71409dd4088958c562200d83",
"body": "[ This is a backport to the 3.2 branch. ]\n\nDSA kengen is not FIPS-approved. The `EVP_PKEY_paramgen` in the\n`OpenSSL::PKey.generate_parameters(\"DSA\")` raises a DSA error in FIPS by the\nfollowing commit. Split the test for DSA.\n\nhttps://github.com/openssl/openssl/commit/49a35f0#diff-605396c063194975af8ce31399d42690ab18186b422fb5012101cc9132660fe1R611-R614\n(cherry picked from commit 5ca6eb4ecabc3cfbc18969b5cd502980e6b523b8)",
"is_bot": false,
"headline": "test_s_generate_parameters: Consider a DSA error in FIPS.",
"author_name": "Jun Aruga",
"author_login": "junaruga",
"committed_at": "2026-05-12T19:01:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5321f9665465c27630570e9bf1b6c72604027b19",
"body": null,
"is_bot": false,
"headline": ".github/workflows/test.yml: enable rake test_fips with OpenSSL 4.0",
"author_name": "Kazuki Yamaguchi",
"author_login": "rhenium",
"committed_at": "2026-05-12T18:59:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9baa3a1356a361a0b4609f5dadbaef18f4a14947",
"body": "…urity/harden-runner-2.19.1\n\nbuild(deps): bump step-security/harden-runner from 2.19.0 to 2.19.1",
"is_bot": false,
"headline": "Merge pull request #1047 from ruby/dependabot/github_actions/step-sec…",
"author_name": "Olle Jonsson",
"author_login": "olleolleolle",
"committed_at": "2026-05-04T11:34:44Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 19,
"commits_last_year": 316,
"latest_release_at": "2026-05-13T17:40:09Z",
"latest_release_tag": "v4.0.2",
"releases_from_tags": false,
"days_since_last_push": 8,
"active_weeks_last_year": 45,
"days_since_latest_release": 69,
"mean_days_between_releases": 24.4
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "openssl",
"exists": true,
"license": "Ruby",
"keywords": [],
"ecosystem": "rubygems",
"matches_repo": true,
"registry_url": "https://rubygems.org/gems/openssl",
"is_deprecated": false,
"latest_version": "4.0.2",
"repository_url": "https://github.com/ruby/openssl",
"versions_count": 55,
"total_downloads": 89743078,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": "2016-08-29T05:29:06.459000Z",
"latest_published_at": "2026-05-13T15:34:08.875000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 69
}
]
},
"popularity": {
"forks": 196,
"stars": 275,
"watchers": 49,
"fork_history": {
"days": [
{
"date": "2014-10-29",
"count": 1
},
{
"date": "2014-12-17",
"count": 1
},
{
"date": "2015-02-26",
"count": 1
},
{
"date": "2015-03-27",
"count": 1
},
{
"date": "2015-06-08",
"count": 1
},
{
"date": "2015-07-22",
"count": 1
},
{
"date": "2015-08-13",
"count": 1
},
{
"date": "2015-08-25",
"count": 1
},
{
"date": "2015-08-30",
"count": 1
},
{
"date": "2015-10-23",
"count": 1
},
{
"date": "2015-11-15",
"count": 1
},
{
"date": "2015-12-07",
"count": 1
},
{
"date": "2016-02-08",
"count": 1
},
{
"date": "2016-03-04",
"count": 1
},
{
"date": "2016-04-01",
"count": 1
},
{
"date": "2016-04-13",
"count": 1
},
{
"date": "2016-05-29",
"count": 1
},
{
"date": "2016-05-31",
"count": 1
},
{
"date": "2016-08-01",
"count": 1
},
{
"date": "2016-08-18",
"count": 1
},
{
"date": "2016-08-29",
"count": 1
},
{
"date": "2016-10-11",
"count": 1
},
{
"date": "2016-11-10",
"count": 1
},
{
"date": "2016-12-09",
"count": 1
},
{
"date": "2017-02-18",
"count": 1
},
{
"date": "2017-02-19",
"count": 1
},
{
"date": "2017-03-14",
"count": 1
},
{
"date": "2017-05-15",
"count": 1
},
{
"date": "2017-06-09",
"count": 1
},
{
"date": "2017-07-12",
"count": 1
},
{
"date": "2017-07-26",
"count": 1
},
{
"date": "2017-08-22",
"count": 1
},
{
"date": "2017-08-25",
"count": 1
},
{
"date": "2017-08-27",
"count": 1
},
{
"date": "2017-08-31",
"count": 1
},
{
"date": "2017-09-11",
"count": 1
},
{
"date": "2017-10-14",
"count": 1
},
{
"date": "2017-10-25",
"count": 1
},
{
"date": "2017-10-29",
"count": 1
},
{
"date": "2017-12-27",
"count": 1
},
{
"date": "2018-01-16",
"count": 1
},
{
"date": "2018-02-23",
"count": 1
},
{
"date": "2018-03-25",
"count": 1
},
{
"date": "2018-04-19",
"count": 1
},
{
"date": "2018-07-13",
"count": 1
},
{
"date": "2018-08-24",
"count": 1
},
{
"date": "2018-09-09",
"count": 1
},
{
"date": "2018-09-13",
"count": 1
},
{
"date": "2018-09-19",
"count": 1
},
{
"date": "2018-09-26",
"count": 1
},
{
"date": "2018-11-10",
"count": 1
},
{
"date": "2018-11-12",
"count": 1
},
{
"date": "2019-01-11",
"count": 1
},
{
"date": "2019-01-21",
"count": 1
},
{
"date": "2019-01-25",
"count": 1
},
{
"date": "2019-02-05",
"count": 1
},
{
"date": "2019-02-12",
"count": 1
},
{
"date": "2019-03-05",
"count": 1
},
{
"date": "2019-03-16",
"count": 1
},
{
"date": "2019-03-25",
"count": 1
},
{
"date": "2019-04-10",
"count": 1
},
{
"date": "2019-04-29",
"count": 2
},
{
"date": "2019-05-14",
"count": 1
},
{
"date": "2019-05-28",
"count": 1
},
{
"date": "2019-06-01",
"count": 1
},
{
"date": "2019-06-10",
"count": 1
},
{
"date": "2019-06-17",
"count": 1
},
{
"date": "2019-07-27",
"count": 1
},
{
"date": "2019-07-30",
"count": 1
},
{
"date": "2019-08-18",
"count": 1
},
{
"date": "2019-08-31",
"count": 1
},
{
"date": "2019-11-19",
"count": 1
},
{
"date": "2019-11-21",
"count": 1
},
{
"date": "2019-12-05",
"count": 1
},
{
"date": "2019-12-13",
"count": 1
},
{
"date": "2019-12-19",
"count": 1
},
{
"date": "2020-02-08",
"count": 1
},
{
"date": "2020-02-19",
"count": 1
},
{
"date": "2020-02-28",
"count": 1
},
{
"date": "2020-03-19",
"count": 1
},
{
"date": "2020-03-30",
"count": 1
},
{
"date": "2020-04-19",
"count": 1
},
{
"date": "2020-06-29",
"count": 1
},
{
"date": "2020-07-23",
"count": 1
},
{
"date": "2020-07-29",
"count": 1
},
{
"date": "2020-07-31",
"count": 1
},
{
"date": "2020-08-06",
"count": 1
},
{
"date": "2020-10-12",
"count": 1
},
{
"date": "2021-02-10",
"count": 1
},
{
"date": "2021-02-14",
"count": 1
},
{
"date": "2021-03-15",
"count": 1
},
{
"date": "2021-03-18",
"count": 1
},
{
"date": "2021-03-22",
"count": 1
},
{
"date": "2021-03-24",
"count": 1
},
{
"date": "2021-03-30",
"count": 1
},
{
"date": "2021-04-04",
"count": 1
},
{
"date": "2021-04-07",
"count": 1
},
{
"date": "2021-04-25",
"count": 1
},
{
"date": "2021-06-15",
"count": 1
},
{
"date": "2021-06-26",
"count": 1
},
{
"date": "2021-09-04",
"count": 1
},
{
"date": "2021-10-12",
"count": 1
},
{
"date": "2021-10-13",
"count": 2
},
{
"date": "2022-01-04",
"count": 2
},
{
"date": "2022-01-08",
"count": 1
},
{
"date": "2022-02-01",
"count": 1
},
{
"date": "2022-03-02",
"count": 1
},
{
"date": "2022-04-12",
"count": 1
},
{
"date": "2022-04-21",
"count": 3
},
{
"date": "2022-05-19",
"count": 1
},
{
"date": "2022-06-26",
"count": 1
},
{
"date": "2022-07-23",
"count": 1
},
{
"date": "2022-08-23",
"count": 1
},
{
"date": "2022-08-25",
"count": 1
},
{
"date": "2022-09-21",
"count": 1
},
{
"date": "2022-10-01",
"count": 1
},
{
"date": "2022-10-16",
"count": 1
},
{
"date": "2022-10-18",
"count": 1
},
{
"date": "2022-11-03",
"count": 1
},
{
"date": "2022-11-19",
"count": 1
},
{
"date": "2022-12-26",
"count": 1
},
{
"date": "2022-12-30",
"count": 1
},
{
"date": "2023-02-08",
"count": 1
},
{
"date": "2023-02-09",
"count": 1
},
{
"date": "2023-02-28",
"count": 1
},
{
"date": "2023-04-01",
"count": 1
},
{
"date": "2023-05-24",
"count": 1
},
{
"date": "2023-05-26",
"count": 1
},
{
"date": "2023-06-04",
"count": 1
},
{
"date": "2023-07-17",
"count": 1
},
{
"date": "2023-08-31",
"count": 1
},
{
"date": "2023-10-12",
"count": 1
},
{
"date": "2023-12-12",
"count": 1
},
{
"date": "2023-12-17",
"count": 1
},
{
"date": "2024-01-05",
"count": 1
},
{
"date": "2024-01-13",
"count": 1
},
{
"date": "2024-02-13",
"count": 1
},
{
"date": "2024-03-12",
"count": 1
},
{
"date": "2024-03-20",
"count": 1
},
{
"date": "2024-04-30",
"count": 1
},
{
"date": "2024-05-21",
"count": 1
},
{
"date": "2024-05-28",
"count": 1
},
{
"date": "2024-06-02",
"count": 1
},
{
"date": "2024-06-09",
"count": 1
},
{
"date": "2024-06-17",
"count": 1
},
{
"date": "2024-06-30",
"count": 1
},
{
"date": "2024-09-13",
"count": 1
},
{
"date": "2024-10-08",
"count": 1
},
{
"date": "2024-10-10",
"count": 1
},
{
"date": "2024-10-26",
"count": 1
},
{
"date": "2024-10-30",
"count": 1
},
{
"date": "2024-12-02",
"count": 1
},
{
"date": "2024-12-10",
"count": 2
},
{
"date": "2024-12-21",
"count": 1
},
{
"date": "2025-01-14",
"count": 1
},
{
"date": "2025-02-28",
"count": 1
},
{
"date": "2025-04-16",
"count": 1
},
{
"date": "2025-05-13",
"count": 1
},
{
"date": "2025-06-02",
"count": 1
},
{
"date": "2025-06-16",
"count": 1
},
{
"date": "2025-08-12",
"count": 1
},
{
"date": "2025-09-04",
"count": 1
},
{
"date": "2025-09-15",
"count": 1
},
{
"date": "2025-09-21",
"count": 1
},
{
"date": "2025-10-06",
"count": 1
},
{
"date": "2025-10-21",
"count": 2
},
{
"date": "2025-11-11",
"count": 1
},
{
"date": "2025-11-17",
"count": 1
},
{
"date": "2025-12-04",
"count": 1
},
{
"date": "2025-12-05",
"count": 1
},
{
"date": "2025-12-24",
"count": 1
},
{
"date": "2026-01-02",
"count": 1
},
{
"date": "2026-01-19",
"count": 1
},
{
"date": "2026-01-22",
"count": 1
},
{
"date": "2026-02-24",
"count": 1
},
{
"date": "2026-03-14",
"count": 1
},
{
"date": "2026-04-10",
"count": 1
},
{
"date": "2026-05-11",
"count": 1
},
{
"date": "2026-05-19",
"count": 1
},
{
"date": "2026-05-21",
"count": 1
},
{
"date": "2026-05-29",
"count": 1
},
{
"date": "2026-06-10",
"count": 1
},
{
"date": "2026-06-16",
"count": 1
},
{
"date": "2026-06-20",
"count": 1
},
{
"date": "2026-06-22",
"count": 1
}
],
"complete": true,
"collected": 192,
"total_forks": 196
},
"star_history": {
"days": [
{
"date": "2014-12-19",
"count": 1
},
{
"date": "2014-12-29",
"count": 1
},
{
"date": "2015-01-06",
"count": 1
},
{
"date": "2015-01-11",
"count": 3
},
{
"date": "2015-03-07",
"count": 1
},
{
"date": "2015-03-24",
"count": 1
},
{
"date": "2015-03-25",
"count": 2
},
{
"date": "2015-06-12",
"count": 1
},
{
"date": "2015-08-09",
"count": 1
},
{
"date": "2015-08-10",
"count": 1
},
{
"date": "2015-10-30",
"count": 1
},
{
"date": "2015-11-04",
"count": 1
},
{
"date": "2016-01-23",
"count": 1
},
{
"date": "2016-01-24",
"count": 1
},
{
"date": "2016-02-02",
"count": 1
},
{
"date": "2016-02-20",
"count": 1
},
{
"date": "2016-03-14",
"count": 1
},
{
"date": "2016-04-14",
"count": 1
},
{
"date": "2016-05-04",
"count": 1
},
{
"date": "2016-05-13",
"count": 1
},
{
"date": "2016-06-08",
"count": 1
},
{
"date": "2016-08-19",
"count": 1
},
{
"date": "2016-08-26",
"count": 1
},
{
"date": "2016-09-21",
"count": 1
},
{
"date": "2016-09-23",
"count": 2
},
{
"date": "2016-10-09",
"count": 1
},
{
"date": "2016-11-03",
"count": 1
},
{
"date": "2016-11-16",
"count": 1
},
{
"date": "2016-11-25",
"count": 1
},
{
"date": "2016-11-29",
"count": 1
},
{
"date": "2016-12-26",
"count": 1
},
{
"date": "2016-12-31",
"count": 1
},
{
"date": "2017-01-05",
"count": 1
},
{
"date": "2017-01-08",
"count": 1
},
{
"date": "2017-01-27",
"count": 1
},
{
"date": "2017-02-03",
"count": 1
},
{
"date": "2017-02-12",
"count": 1
},
{
"date": "2017-02-13",
"count": 1
},
{
"date": "2017-02-20",
"count": 1
},
{
"date": "2017-03-02",
"count": 1
},
{
"date": "2017-03-09",
"count": 1
},
{
"date": "2017-03-16",
"count": 1
},
{
"date": "2017-03-20",
"count": 1
},
{
"date": "2017-03-22",
"count": 1
},
{
"date": "2017-03-27",
"count": 1
},
{
"date": "2017-05-01",
"count": 1
},
{
"date": "2017-05-03",
"count": 1
},
{
"date": "2017-05-10",
"count": 1
},
{
"date": "2017-05-20",
"count": 1
},
{
"date": "2017-05-25",
"count": 1
},
{
"date": "2017-06-14",
"count": 1
},
{
"date": "2017-07-14",
"count": 1
},
{
"date": "2017-08-11",
"count": 1
},
{
"date": "2017-08-16",
"count": 1
},
{
"date": "2017-08-17",
"count": 3
},
{
"date": "2017-09-15",
"count": 1
},
{
"date": "2017-09-18",
"count": 1
},
{
"date": "2017-10-06",
"count": 1
},
{
"date": "2017-11-03",
"count": 1
},
{
"date": "2017-11-09",
"count": 1
},
{
"date": "2017-11-18",
"count": 1
},
{
"date": "2017-11-20",
"count": 2
},
{
"date": "2017-12-20",
"count": 1
},
{
"date": "2017-12-26",
"count": 1
},
{
"date": "2018-01-16",
"count": 2
},
{
"date": "2018-01-31",
"count": 1
},
{
"date": "2018-02-14",
"count": 1
},
{
"date": "2018-03-19",
"count": 1
},
{
"date": "2018-04-23",
"count": 1
},
{
"date": "2018-04-26",
"count": 1
},
{
"date": "2018-04-27",
"count": 1
},
{
"date": "2018-05-03",
"count": 1
},
{
"date": "2018-05-06",
"count": 1
},
{
"date": "2018-05-09",
"count": 1
},
{
"date": "2018-05-20",
"count": 1
},
{
"date": "2018-06-13",
"count": 1
},
{
"date": "2018-07-09",
"count": 1
},
{
"date": "2018-08-29",
"count": 2
},
{
"date": "2018-09-24",
"count": 1
},
{
"date": "2018-10-30",
"count": 1
},
{
"date": "2018-10-31",
"count": 1
},
{
"date": "2018-11-05",
"count": 1
},
{
"date": "2018-11-10",
"count": 1
},
{
"date": "2018-11-12",
"count": 2
},
{
"date": "2018-11-26",
"count": 1
},
{
"date": "2018-11-30",
"count": 1
},
{
"date": "2018-12-14",
"count": 1
},
{
"date": "2018-12-27",
"count": 1
},
{
"date": "2018-12-28",
"count": 1
},
{
"date": "2019-01-03",
"count": 1
},
{
"date": "2019-01-10",
"count": 1
},
{
"date": "2019-02-11",
"count": 1
},
{
"date": "2019-02-12",
"count": 2
},
{
"date": "2019-02-13",
"count": 1
},
{
"date": "2019-02-15",
"count": 1
},
{
"date": "2019-02-20",
"count": 1
},
{
"date": "2019-03-08",
"count": 1
},
{
"date": "2019-04-09",
"count": 1
},
{
"date": "2019-04-26",
"count": 1
},
{
"date": "2019-05-05",
"count": 1
},
{
"date": "2019-05-16",
"count": 1
},
{
"date": "2019-05-20",
"count": 1
},
{
"date": "2019-05-22",
"count": 1
},
{
"date": "2019-05-25",
"count": 1
},
{
"date": "2019-05-28",
"count": 1
},
{
"date": "2019-06-01",
"count": 1
},
{
"date": "2019-07-18",
"count": 1
},
{
"date": "2019-07-26",
"count": 1
},
{
"date": "2019-08-28",
"count": 1
},
{
"date": "2019-08-31",
"count": 1
},
{
"date": "2019-09-14",
"count": 1
},
{
"date": "2019-10-16",
"count": 1
},
{
"date": "2019-10-27",
"count": 1
},
{
"date": "2019-11-19",
"count": 1
},
{
"date": "2019-11-25",
"count": 1
},
{
"date": "2019-11-29",
"count": 1
},
{
"date": "2019-12-13",
"count": 1
},
{
"date": "2020-01-02",
"count": 1
},
{
"date": "2020-01-04",
"count": 1
},
{
"date": "2020-01-08",
"count": 1
},
{
"date": "2020-02-09",
"count": 2
},
{
"date": "2020-02-20",
"count": 1
},
{
"date": "2020-03-25",
"count": 1
},
{
"date": "2020-04-13",
"count": 1
},
{
"date": "2020-04-17",
"count": 1
},
{
"date": "2020-04-24",
"count": 1
},
{
"date": "2020-05-01",
"count": 1
},
{
"date": "2020-05-13",
"count": 1
},
{
"date": "2020-07-13",
"count": 2
},
{
"date": "2020-08-06",
"count": 1
},
{
"date": "2020-08-16",
"count": 1
},
{
"date": "2020-08-20",
"count": 1
},
{
"date": "2020-10-16",
"count": 1
},
{
"date": "2020-11-13",
"count": 1
},
{
"date": "2020-12-10",
"count": 1
},
{
"date": "2020-12-13",
"count": 1
},
{
"date": "2020-12-23",
"count": 1
},
{
"date": "2021-01-24",
"count": 1
},
{
"date": "2021-02-02",
"count": 1
},
{
"date": "2021-02-04",
"count": 1
},
{
"date": "2021-02-26",
"count": 1
},
{
"date": "2021-03-09",
"count": 1
},
{
"date": "2021-03-30",
"count": 1
},
{
"date": "2021-04-05",
"count": 1
},
{
"date": "2021-04-22",
"count": 1
},
{
"date": "2021-05-06",
"count": 1
},
{
"date": "2021-05-12",
"count": 1
},
{
"date": "2021-05-27",
"count": 1
},
{
"date": "2021-06-15",
"count": 1
},
{
"date": "2021-09-11",
"count": 1
},
{
"date": "2021-09-21",
"count": 1
},
{
"date": "2021-10-09",
"count": 1
},
{
"date": "2021-10-12",
"count": 2
},
{
"date": "2021-10-13",
"count": 1
},
{
"date": "2021-10-14",
"count": 2
},
{
"date": "2021-10-17",
"count": 1
},
{
"date": "2021-10-21",
"count": 1
},
{
"date": "2021-10-24",
"count": 1
},
{
"date": "2021-10-30",
"count": 1
},
{
"date": "2021-11-05",
"count": 1
},
{
"date": "2022-01-14",
"count": 1
},
{
"date": "2022-01-18",
"count": 1
},
{
"date": "2022-02-02",
"count": 1
},
{
"date": "2022-03-03",
"count": 1
},
{
"date": "2022-03-08",
"count": 1
},
{
"date": "2022-03-10",
"count": 1
},
{
"date": "2022-03-27",
"count": 1
},
{
"date": "2022-04-03",
"count": 1
},
{
"date": "2022-05-02",
"count": 1
},
{
"date": "2022-05-07",
"count": 1
},
{
"date": "2022-05-09",
"count": 1
},
{
"date": "2022-06-28",
"count": 1
},
{
"date": "2022-06-29",
"count": 1
},
{
"date": "2022-07-22",
"count": 1
},
{
"date": "2022-08-04",
"count": 1
},
{
"date": "2022-09-09",
"count": 1
},
{
"date": "2022-09-13",
"count": 1
},
{
"date": "2022-10-02",
"count": 1
},
{
"date": "2022-11-02",
"count": 1
},
{
"date": "2022-11-11",
"count": 1
},
{
"date": "2022-11-12",
"count": 1
},
{
"date": "2022-11-18",
"count": 1
},
{
"date": "2022-11-23",
"count": 1
},
{
"date": "2022-12-13",
"count": 1
},
{
"date": "2023-02-20",
"count": 2
},
{
"date": "2023-02-22",
"count": 1
},
{
"date": "2023-03-24",
"count": 1
},
{
"date": "2023-05-04",
"count": 1
},
{
"date": "2023-05-20",
"count": 1
},
{
"date": "2023-06-04",
"count": 1
},
{
"date": "2023-07-13",
"count": 1
},
{
"date": "2023-08-17",
"count": 1
},
{
"date": "2023-08-21",
"count": 1
},
{
"date": "2023-09-10",
"count": 1
},
{
"date": "2023-09-28",
"count": 1
},
{
"date": "2023-09-30",
"count": 1
},
{
"date": "2023-11-10",
"count": 1
},
{
"date": "2023-12-18",
"count": 1
},
{
"date": "2024-01-02",
"count": 1
},
{
"date": "2024-01-13",
"count": 1
},
{
"date": "2024-01-25",
"count": 1
},
{
"date": "2024-02-08",
"count": 1
},
{
"date": "2024-02-17",
"count": 1
},
{
"date": "2024-03-06",
"count": 1
},
{
"date": "2024-03-11",
"count": 1
},
{
"date": "2024-03-13",
"count": 1
},
{
"date": "2024-03-30",
"count": 1
},
{
"date": "2024-04-16",
"count": 1
},
{
"date": "2024-05-12",
"count": 1
},
{
"date": "2024-06-05",
"count": 1
},
{
"date": "2024-06-07",
"count": 1
},
{
"date": "2024-07-02",
"count": 1
},
{
"date": "2024-07-12",
"count": 1
},
{
"date": "2024-07-24",
"count": 1
},
{
"date": "2024-09-08",
"count": 1
},
{
"date": "2024-09-26",
"count": 1
},
{
"date": "2024-10-11",
"count": 1
},
{
"date": "2024-12-13",
"count": 1
},
{
"date": "2025-02-02",
"count": 1
},
{
"date": "2025-02-03",
"count": 1
},
{
"date": "2025-02-13",
"count": 1
},
{
"date": "2025-03-19",
"count": 1
},
{
"date": "2025-04-03",
"count": 1
},
{
"date": "2025-04-04",
"count": 1
},
{
"date": "2025-05-29",
"count": 1
},
{
"date": "2025-06-26",
"count": 1
},
{
"date": "2025-07-23",
"count": 1
},
{
"date": "2025-08-01",
"count": 1
},
{
"date": "2025-08-28",
"count": 1
},
{
"date": "2025-09-19",
"count": 1
},
{
"date": "2025-10-04",
"count": 1
},
{
"date": "2025-10-15",
"count": 1
},
{
"date": "2025-10-29",
"count": 1
},
{
"date": "2025-11-02",
"count": 1
},
{
"date": "2025-11-10",
"count": 1
},
{
"date": "2025-11-26",
"count": 1
},
{
"date": "2026-01-02",
"count": 1
},
{
"date": "2026-01-09",
"count": 1
},
{
"date": "2026-01-26",
"count": 1
},
{
"date": "2026-02-08",
"count": 1
},
{
"date": "2026-03-06",
"count": 1
},
{
"date": "2026-05-23",
"count": 2
},
{
"date": "2026-05-24",
"count": 1
},
{
"date": "2026-05-25",
"count": 7
},
{
"date": "2026-05-26",
"count": 1
},
{
"date": "2026-05-30",
"count": 1
},
{
"date": "2026-06-03",
"count": 1
},
{
"date": "2026-06-19",
"count": 1
},
{
"date": "2026-06-22",
"count": 1
},
{
"date": "2026-06-23",
"count": 1
},
{
"date": "2026-07-09",
"count": 1
},
{
"date": "2026-07-12",
"count": 1
}
],
"complete": true,
"collected": 275,
"total_stars": 275
},
"open_issues_and_prs": 80
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"sample"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 102468,
"source_files_sampled": 117,
"oversized_source_files": 3,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"Gemfile"
],
"advisories": {
"error": "No resolved dependencies carried a version and a supported ecosystem",
"scope": "repository_graph",
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 7,
"direct_affected_count": 0
},
"ecosystems": [
"rubygems"
],
"dependencies": [
{
"name": "rake",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
},
{
"name": "rake-compiler",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
},
{
"name": "test-unit",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": "~> 3.0"
},
{
"name": "test-unit-ruby-core",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
},
{
"name": "prime",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
},
{
"name": "rdoc",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
},
{
"name": "power_assert",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": "< 3"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "prime",
"direct": true,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rake",
"direct": true,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rake-compiler",
"direct": true,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "rdoc",
"direct": true,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "test-unit",
"direct": true,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "test-unit-ruby-core",
"direct": true,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "jruby-openssl",
"direct": false,
"version": null,
"ecosystem": "rubygems"
}
],
"collected": true,
"truncated": false,
"total_count": 7,
"direct_count": 6,
"indirect_count": 1
}
},
"maintainership": {
"issues": {
"open_prs": 35,
"merged_prs": 604,
"open_issues": 45,
"closed_ratio": 0.871,
"closed_issues": 305,
"closed_unmerged_prs": 91
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "rhenium",
"commits": 1463,
"avatar_url": "https://avatars.githubusercontent.com/u/1033740?v=4"
},
{
"type": "User",
"login": "junaruga",
"commits": 118,
"avatar_url": "https://avatars.githubusercontent.com/u/121989?v=4"
},
{
"type": "User",
"login": "hsbt",
"commits": 98,
"avatar_url": "https://avatars.githubusercontent.com/u/12301?v=4"
},
{
"type": "User",
"login": "nobu",
"commits": 81,
"avatar_url": "https://avatars.githubusercontent.com/u/16700?v=4"
},
{
"type": "User",
"login": "ioquatix",
"commits": 51,
"avatar_url": "https://avatars.githubusercontent.com/u/30030?v=4"
},
{
"type": "User",
"login": "thekuwayama",
"commits": 28,
"avatar_url": "https://avatars.githubusercontent.com/u/42881635?v=4"
},
{
"type": "User",
"login": "jeremyevans",
"commits": 25,
"avatar_url": "https://avatars.githubusercontent.com/u/3846?v=4"
},
{
"type": "User",
"login": "btoews",
"commits": 23,
"avatar_url": "https://avatars.githubusercontent.com/u/1144197?v=4"
},
{
"type": "User",
"login": "bdewater",
"commits": 22,
"avatar_url": "https://avatars.githubusercontent.com/u/496367?v=4"
},
{
"type": "User",
"login": "samuel40791765",
"commits": 17,
"avatar_url": "https://avatars.githubusercontent.com/u/11924508?v=4"
}
],
"contributors_sampled": 99,
"top_contributor_share": 0.68
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"github-pages.yml",
"push_gem.yml",
"sync-ruby.yml",
"test.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 9,
"reason": "10 out of 11 merged PRs checked by a CI test -- score normalized to 9",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 1,
"reason": "Found 1/9 approved changesets -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 62 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 9,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "27c59a4cc8a652004184182f734de0161ba08b41",
"ran_at": "2026-07-21T23:17:13Z",
"aggregate_score": 4.8,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-20T09:29:52Z",
"oldest_open_prs": [
{
"number": 171,
"created_at": "2017-11-18T23:57:47Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 366,
"created_at": "2020-05-10T00:51:32Z",
"last_comment_at": "2020-07-01T10:20:19Z",
"last_comment_author": "eregon"
},
{
"number": 401,
"created_at": "2020-08-28T00:41:03Z",
"last_comment_at": "2020-08-28T00:44:22Z",
"last_comment_author": "p-mongo"
},
{
"number": 421,
"created_at": "2021-03-15T01:22:59Z",
"last_comment_at": "2021-04-14T19:27:44Z",
"last_comment_author": "rxbynerd"
},
{
"number": 432,
"created_at": "2021-03-31T00:45:55Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 434,
"created_at": "2021-04-02T07:34:15Z",
"last_comment_at": "2021-04-15T06:58:03Z",
"last_comment_author": "rhenium"
},
{
"number": 435,
"created_at": "2021-04-04T00:55:21Z",
"last_comment_at": "2021-04-15T06:13:39Z",
"last_comment_author": "rickmark"
},
{
"number": 503,
"created_at": "2022-03-16T12:42:15Z",
"last_comment_at": "2022-03-21T11:21:50Z",
"last_comment_author": "casperisfine"
},
{
"number": 555,
"created_at": "2022-10-19T15:48:42Z",
"last_comment_at": "2026-07-11T13:33:12Z",
"last_comment_author": "bdewater"
},
{
"number": 691,
"created_at": "2023-10-29T03:05:54Z",
"last_comment_at": "2023-11-06T18:46:56Z",
"last_comment_author": "rhenium"
},
{
"number": 735,
"created_at": "2024-03-27T12:50:06Z",
"last_comment_at": "2024-03-27T15:44:04Z",
"last_comment_author": "rhenium"
},
{
"number": 736,
"created_at": "2024-03-27T15:38:11Z",
"last_comment_at": "2026-01-23T18:36:16Z",
"last_comment_author": "rhenium"
},
{
"number": 777,
"created_at": "2024-07-12T15:42:57Z",
"last_comment_at": "2025-12-04T17:29:11Z",
"last_comment_author": "rhenium"
},
{
"number": 803,
"created_at": "2024-10-05T15:15:25Z",
"last_comment_at": "2024-10-29T17:22:41Z",
"last_comment_author": "rhenium"
},
{
"number": 807,
"created_at": "2024-10-19T15:55:28Z",
"last_comment_at": "2024-11-13T16:21:18Z",
"last_comment_author": "rhenium"
},
{
"number": 816,
"created_at": "2024-11-12T18:26:23Z",
"last_comment_at": "2025-03-30T14:03:18Z",
"last_comment_author": "rhenium"
},
{
"number": 883,
"created_at": "2025-04-30T09:45:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 891,
"created_at": "2025-05-21T10:53:56Z",
"last_comment_at": "2025-07-04T10:23:31Z",
"last_comment_author": "rhenium"
},
{
"number": 906,
"created_at": "2025-07-04T10:11:04Z",
"last_comment_at": "2026-04-14T16:57:14Z",
"last_comment_author": "BenMorganMY"
},
{
"number": 915,
"created_at": "2025-07-26T17:13:30Z",
"last_comment_at": null,
"last_comment_author": null
}
],
"last_merged_pr_at": "2026-07-13T10:10:21Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 5,
"created_at": "2015-02-03T22:16:40Z",
"last_comment_at": "2020-09-07T14:12:47Z",
"last_comment_author": "nickshatilo"
},
{
"number": 20,
"created_at": "2015-08-05T21:37:55Z",
"last_comment_at": "2023-10-11T17:08:35Z",
"last_comment_author": "yweiy10"
},
{
"number": 30,
"created_at": "2015-10-12T18:28:43Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 63,
"created_at": "2016-07-11T16:02:56Z",
"last_comment_at": "2025-08-11T22:46:45Z",
"last_comment_author": "snyff"
},
{
"number": 163,
"created_at": "2017-10-24T18:41:50Z",
"last_comment_at": "2017-10-28T06:18:43Z",
"last_comment_author": "rhenium"
},
{
"number": 195,
"created_at": "2018-04-25T11:51:46Z",
"last_comment_at": "2025-11-26T13:34:22Z",
"last_comment_author": "rhenium"
},
{
"number": 196,
"created_at": "2018-04-25T11:53:26Z",
"last_comment_at": "2019-11-04T02:10:08Z",
"last_comment_author": "ioquatix"
},
{
"number": 197,
"created_at": "2018-04-25T12:02:31Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 295,
"created_at": "2019-11-21T20:30:45Z",
"last_comment_at": "2020-08-27T22:08:21Z",
"last_comment_author": "p-mongo"
},
{
"number": 395,
"created_at": "2020-08-20T16:35:06Z",
"last_comment_at": "2020-08-30T20:11:51Z",
"last_comment_author": "p-mongo"
},
{
"number": 408,
"created_at": "2020-11-16T23:10:14Z",
"last_comment_at": "2022-03-17T09:57:22Z",
"last_comment_author": "djberg96"
},
{
"number": 425,
"created_at": "2021-03-30T20:57:07Z",
"last_comment_at": "2021-04-04T13:24:21Z",
"last_comment_author": "rhenium"
},
{
"number": 426,
"created_at": "2021-03-30T21:04:03Z",
"last_comment_at": "2023-08-31T17:05:34Z",
"last_comment_author": "rhenium"
},
{
"number": 427,
"created_at": "2021-03-30T21:11:22Z",
"last_comment_at": "2021-04-02T07:40:06Z",
"last_comment_author": "rickmark"
},
{
"number": 433,
"created_at": "2021-04-02T05:35:09Z",
"last_comment_at": "2021-04-04T13:45:27Z",
"last_comment_author": "rhenium"
},
{
"number": 451,
"created_at": "2021-07-21T16:21:50Z",
"last_comment_at": "2023-06-07T23:03:52Z",
"last_comment_author": "mcr"
},
{
"number": 474,
"created_at": "2021-11-10T10:56:26Z",
"last_comment_at": "2023-04-15T09:09:58Z",
"last_comment_author": "gettalong"
},
{
"number": 475,
"created_at": "2021-11-16T00:15:43Z",
"last_comment_at": "2024-09-20T16:55:21Z",
"last_comment_author": "nevans"
},
{
"number": 490,
"created_at": "2022-01-05T17:21:21Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 498,
"created_at": "2022-02-25T19:01:15Z",
"last_comment_at": "2022-12-30T12:00:22Z",
"last_comment_author": "DimaD"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/ruby/openssl",
"host": "github.com",
"name": "openssl",
"owner": "ruby"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"security": 48,
"vitality": 89,
"community": 75,
"governance": 70,
"engineering": 64
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 89,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 88,
"inputs": {
"commits_last_year": 316,
"human_commit_share": 0.95,
"days_since_last_push": 8,
"active_weeks_last_year": 45
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 8 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 8
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "45/52 weeks with commits",
"points": 31.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 45
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "316 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 316
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 19,
"latest_release_tag": "v4.0.2",
"releases_from_tags": false,
"days_since_latest_release": 69,
"mean_days_between_releases": 24.4
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "19 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 19
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 69 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 69
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~24.4 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 24.4
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 8,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 8 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 8
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "good",
"name": "Community & Adoption",
"value": 75,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "moderate",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"forks": 196,
"stars": 275,
"watchers": 49,
"growth_state": "organic",
"growth_factor_pct": 100
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "275 stars",
"points": 39.5,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 275
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "196 forks",
"points": 19.1,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 196
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "49 watchers",
"points": 9.3,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 49
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "license file present, not a recognized license",
"points": 16.9,
"status": "partial",
"details": [
{
"code": "license_custom",
"params": {}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "excellent",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"packages": [
"openssl"
],
"dependents": null,
"ecosystems": "rubygems",
"total_downloads": 89743078,
"monthly_downloads": null
},
"components": [
{
"key": "total_downloads",
"name": "Total downloads",
"detail": "89,743,078 downloads all-time across rubygems",
"points": 80,
"status": "met",
"details": [
{
"code": "downloads_total",
"params": {
"count": 89743078,
"ecosystems": "rubygems"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "good",
"name": "Sustainability & Governance",
"value": 70,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 99,
"top_contributor_share": 0.68
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 68% of commits",
"points": 7.2,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 68
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "99 contributors",
"points": 13.5,
"status": "met",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 99
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 62 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"merged_prs": 604,
"open_issues": 45,
"closed_issues": 305,
"issue_closed_ratio": 0.871,
"closed_unmerged_prs": 91
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "87% of issues closed",
"points": 40.7,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 87
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "604/695 decided PRs merged",
"points": 33.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 604,
"decided": 695
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 1/9 approved changesets -- score normalized to 1",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 79,
"inputs": {
"followers": 2077,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "ruby",
"public_repos": 190,
"account_age_days": 5990
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "2,077 followers of ruby",
"points": 23.9,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 2077,
"login": "ruby"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "190 public repos, account ~16 yr old",
"points": 25,
"status": "met",
"details": [
{
"code": "public_repos",
"params": {
"count": 190
}
},
{
"code": "account_age_years",
"params": {
"years": 16
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"openssl"
],
"ecosystems": "rubygems",
"any_deprecated": false,
"min_days_since_publish": 69
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on rubygems",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "rubygems"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 69 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 69
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "55 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 55
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 64,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "10 out of 11 merged PRs checked by a CI test -- score normalized to 9",
"points": 18,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"topics": [
"openssl",
"c",
"ruby",
"tls",
"hacktoberfest"
],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "5 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 5
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "at_risk",
"name": "Security",
"value": 48,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "at_risk",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 48,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 4.8
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "10 out of 11 merged PRs checked by a CI test -- score normalized to 9",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 1/9 approved changesets -- score normalized to 1",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 62 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 25
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 49,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 39,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.737,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "70 of 95 human commits state their intent (structured subject or explanatory body)",
"points": 39.3,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 70,
"sampled": 95
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "at_risk",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 41,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.05
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "C (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "C"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "5 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 5,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 99,
"inputs": {
"primary_language": "C",
"largest_source_bytes": 102468,
"source_files_sampled": 117,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "C (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "C"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/117 source files over 60KB",
"points": 53.6,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 117,
"oversized": 3
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"sample"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "sample",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "sample"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"No resolved dependencies carried a version and a supported ecosystem"
],
"report_type": "repository",
"generated_at": "2026-07-21T23:17:38.511347Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/r/ruby/openssl.svg",
"full_name": "ruby/openssl",
"license_state": "custom",
"license_spdx": null
}