公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 10:19 UTC

shiblon / entroq

Competing-consumer fault-tolerant task queues. Written in Go. Pronounced Entro-Queue.

GoApache-2.0★ 24 星标⑂ 6 复刻始于 2018年5月在 GitHub 上查看 ↗

shiblon/entroq 的健康指数为 100 分中的 61 分,处于「中等」区间。 其得分最高的类别是Vitality(84/100),最低的是Security(44/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

61
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

61
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Chris Monson个人账户
27 关注者23 个公开仓库始于 2012年9月Abundant Security

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/shiblon/entroqv1.8.0-900 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

84良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
10.4/36提交节奏 — 52 周中有 15 周有提交
18/18提交量 — 最近一年 273 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year273
human_commit_share1
days_since_last_push0
active_weeks_last_year15

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 2 个发布版本
36/36发布时效 — 最近一次发布版本于 0 天前
27/27发布节奏 — 约每 4.8 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count2
latest_release_tagv1.8.0
releases_from_tags
days_since_latest_release0
mean_days_between_releases4.8
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

49存在风险 · 占总体的 18%

流行度与采用

31存在风险
评分方式
22.1/60星标 — 24 个星标
5.8/25复刻 — 6 个复刻
2.7/15关注者 — 4 位关注者
所用输入
forks6
stars24
watchers4
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

70良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

57中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0.2/22.5提交分布 — 头号贡献者编写了 99% 的提交
5.4/13.5贡献者广度 — 4 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled4
top_contributor_share0.99
评分方式
46.8/46.8议题解决 — 100% 的议题已关闭
26.3/38.3PR 接受 — 已裁定的 PR 中 42/61 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs42
open_issues0
closed_issues18
issue_closed_ratio1
closed_unmerged_prs19
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
10.4/25所有者影响力 — shiblon 有 27 位关注者
22.1/25既往记录 — 23 个公开仓库,账户约 13 年
所用输入
followers27
owner_typeUser
is_verified
owner_loginshiblon
public_repos23
account_age_days5,059
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 0 天前
20/20版本历史 — 90 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/shiblon/entroq
ecosystemsgo
any_deprecated
min_days_since_publish0

工程质量

基础的工程与文档实践是否到位?

64中等 · 占总体的 20%

工程实践

50中等
评分方式
0/24CI 工作流
24/24存在测试
16/16Linter 配置 — .golangci.yml
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

85优秀
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
10/10主题标签 — 10 个主题标签
10/10Wiki
所用输入
topicsmessage-queue, task-manager, task-queue, competing-consumers, asynchronous-tasks, golang, postgresql, grpc, taskmaster, workflow-engine
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

44存在风险 · 占总体的 16%

安全态势

38存在风险
评分方式
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
0/10Dangerous-Workflow — 无数据
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — 无数据
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated13
scorecard_versionv5.5.0
checks_inconclusive5
scorecard_aggregate3.8
已排除计分(无数据或不适用):ci_tests, dangerous_workflow, packaging, signed_releases, token_permissions。 其余权重已重新归一化。
评分方式
9.5/35直接依赖不含已知公告 — 1 个受影响:google.golang.org/grpc v1.80.0 (critical 9.1)
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories12
affected_packages3
assessed_packages344
unassessed_packages2
affected_by_severitycritical 1, high 1, unknown 1
direct_affected_packages1
已排除计分(无数据或不适用):间接依赖不含已知公告。 其余权重已重新归一化。 已将 344 个已解析依赖与 OSV 比对。 有 2 项无法评估——没有已解析的版本、生态系统不受支持,或超出所报告的软件包清单。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

81良好 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md, cmd/eqk8s/AGENTS.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, cmd/eqk8s/AGENTS.md
agent_instruction_max_bytes3,260
评分方式
18/18一条命令的引导启动 — Makefile, cmd/eqk8s/Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yml
11/11静态类型检查 — clients/js/tsconfig.json
10/10可复现环境 — devcontainer, Dockerfile, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesgo.sum, mix.lock, package-lock.json
has_dockerfile
typed_language
bootstrap_filesMakefile, cmd/eqk8s/Makefile
has_devcontainer
has_linter_config
typecheck_configsclients/js/tsconfig.json
agent_commit_share0
toolchain_manifestsclients/elixir/mix.exs, go.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.8/55可控的文件大小 — 采样的 228 个源文件中有 1 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes102,925
source_files_sampled228
oversized_source_files1
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — api/entroq.proto, api/openapi.yaml
0/20MCP 服务器
40/40可运行示例 — example, examples, samples
所用输入
example_dirsexample, examples, samples
has_mcp_signal
api_schema_filesapi/entroq.proto, api/openapi.yaml

关键数据

24GitHub 星标
4贡献者
273最近 12 个月提交数
0距最近推送天数
2发布版本数
1巴士系数(bus factor)
0开放议题
Go软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

Star 与 Fork 历史 0 ★ / 6 ⇿
0Star
6Fork

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

123456612020-032023-052026-07

每个点涵盖 6 天。

OpenSSF Scorecard 3.8 / 10
3.8综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 10:18 UTC

9Binary-Artifactsbinaries present in source code
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
不适用Dangerous-Workflowno workflows found
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
不适用Token-PermissionsNo tokens found
3Vulnerabilities7 existing vulnerabilities detected
直接依赖 31
注册表软件包版本约束清单文件
Goconnectrpc.com/connectv1.19.1go.mod
Goconnectrpc.com/vanguardv0.4.0go.mod
Gogithub.com/golang-jwt/jwt/v5v5.3.1go.mod
Gogithub.com/golang/protobufv1.5.4go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/lib/pqv1.12.1go.mod
Gogithub.com/open-policy-agent/opav1.4.0go.mod
Gogithub.com/prometheus/client_golangv1.23.2go.mod
Gogithub.com/shiblon/stuffediov0.8.1go.mod
Gogithub.com/spf13/cobrav1.10.0go.mod
Gogithub.com/spf13/viperv1.21.0go.mod
Gogithub.com/testcontainers/testcontainers-gov0.41.0go.mod
Gogithub.com/testcontainers/testcontainers-go/modules/postgresv0.41.0go.mod
Gogo.opentelemetry.io/otelv1.43.0go.mod
Gogo.opentelemetry.io/otel/exporters/prometheusv0.65.0go.mod
Gogo.opentelemetry.io/otel/metricv1.43.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.43.0go.mod
Gogolang.org/x/syncv0.22.0go.mod
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260223185530-2f722ef697dcgo.mod
Gogoogle.golang.org/grpcv1.80.0go.mod
Gogoogle.golang.org/protobufv1.36.11go.mod
Gogopkg.in/yaml.v2v2.4.0go.mod
Gogithub.com/coder/websocketv1.8.15go.mod
Gogithub.com/google/btreev1.1.3go.mod
Gogithub.com/onsi/ginkgo/v2v2.28.3go.mod
Gogithub.com/onsi/gomegav1.40.0go.mod
Gogithub.com/redis/go-redis/v9v9.18.0go.mod
Gok8s.io/apiv0.35.0go.mod
Gok8s.io/apimachineryv0.35.0go.mod
Gok8s.io/client-gov0.35.0go.mod
Gosigs.k8s.io/controller-runtimev0.23.3go.mod
全部依赖 346

来自 GitHub 依赖图的完整解析依赖集合:31 个直接依赖与 315 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Goconnectrpc.com/connectv1.19.1直接
Goconnectrpc.com/vanguardv0.4.0直接
Gogithub.com/coder/websocketv1.8.15直接
Gogithub.com/golang-jwt/jwt/v5v5.3.1直接
Gogithub.com/golang/protobufv1.5.4直接
Gogithub.com/google/btreev1.1.3直接
Gogithub.com/google/go-cmpv0.7.0直接
Gogithub.com/lib/pqv1.12.1直接
Gogithub.com/onsi/ginkgo/v2v2.28.3直接
Gogithub.com/onsi/gomegav1.40.0直接
Gogithub.com/open-policy-agent/opav1.4.0直接
Gogithub.com/prometheus/client_golangv1.23.2直接
Gogithub.com/redis/go-redis/v9v9.18.0直接
Gogithub.com/shiblon/stuffediov0.8.1直接
Gogithub.com/spf13/cobrav1.10.0直接
Gogithub.com/spf13/viperv1.21.0直接
Gogithub.com/testcontainers/testcontainers-gov0.41.0直接
Gogithub.com/testcontainers/testcontainers-go/modules/postgresv0.41.0直接
Gogo.opentelemetry.io/otelv1.43.0直接
Gogo.opentelemetry.io/otel/exporters/prometheusv0.65.0直接
Gogo.opentelemetry.io/otel/metricv1.43.0直接
Gogo.opentelemetry.io/otel/sdk/metricv1.43.0直接
Gogolang.org/x/syncv0.22.0直接
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260223185530-2f722ef697dc直接
Gogoogle.golang.org/grpcv1.80.0直接
Gogoogle.golang.org/protobufv1.36.11直接
Gogopkg.in/yaml.v2v2.4.0直接
Gok8s.io/apiv0.35.0直接
Gok8s.io/apimachineryv0.35.0直接
Gok8s.io/client-gov0.35.0直接
Gosigs.k8s.io/controller-runtimev0.23.3直接
Gocel.dev/exprv0.25.1间接
Godario.cat/mergov1.0.2间接
Gogithub.com/agnivade/levenshteinv1.2.1间接
Gogithub.com/antlr4-go/antlr/v4v4.13.0间接
Gogithub.com/azure/go-ansitermv0.0.0-20250102033503-faa5f7b0171c间接
Gogithub.com/beorn7/perksv1.0.1间接
Gogithub.com/blang/semver/v4v4.0.0间接
Gogithub.com/cenkalti/backoff/v4v4.3.0间接
Gogithub.com/cespare/xxhash/v2v2.3.0间接
Gogithub.com/containerd/errdefsv1.0.0间接
Gogithub.com/containerd/errdefs/pkgv0.3.0间接
Gogithub.com/containerd/logv0.1.0间接
Gogithub.com/containerd/platformsv0.2.1间接
Gogithub.com/cpuguy83/dockercfgv0.3.2间接
Gogithub.com/davecgh/go-spewv1.1.1间接
Gogithub.com/dgryski/go-rendezvousv0.0.0-20200823014737-9f7001d12a5f间接
Gogithub.com/distribution/referencev0.6.0间接
Gogithub.com/docker/dockerv28.5.2+incompatible间接
Gogithub.com/docker/go-connectionsv0.6.0间接
Gogithub.com/docker/go-unitsv0.5.0间接
Gogithub.com/ebitengine/puregov0.10.0间接
Gogithub.com/emicklei/go-restful/v3v3.12.2间接
Gogithub.com/evanphx/json-patch/v5v5.9.11间接
Gogithub.com/felixge/httpsnoopv1.0.4间接
Gogithub.com/fsnotify/fsnotifyv1.9.0间接
Gogithub.com/fxamacker/cbor/v2v2.9.0间接
Gogithub.com/go-ini/iniv1.67.0间接
Gogithub.com/go-logr/logrv1.4.3间接
Gogithub.com/go-logr/stdrv1.2.2间接
Gogithub.com/go-logr/zaprv1.3.0间接
Gogithub.com/go-ole/go-olev1.2.6间接
Gogithub.com/go-openapi/jsonpointerv0.21.0间接
Gogithub.com/go-openapi/jsonreferencev0.20.2间接
Gogithub.com/go-openapi/swagv0.23.0间接
Gogithub.com/go-task/slim-sprig/v3v3.0.0间接
Gogithub.com/go-viper/mapstructure/v2v2.4.0间接
Gogithub.com/gobwas/globv0.2.3间接
Gogithub.com/google/cel-gov0.26.0间接
Gogithub.com/google/gnostic-modelsv0.7.0间接
Gogithub.com/google/pprofv0.0.0-20260402051712-545e8a4df936间接
Gogithub.com/google/uuidv1.6.0间接
Gogithub.com/gorilla/muxv1.8.1间接
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.28.0间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/josharian/internv1.0.0间接
Gogithub.com/json-iterator/gov1.1.12间接
Gogithub.com/klauspost/compressv1.18.2间接
Gogithub.com/lufia/plan9statsv0.0.0-20211012122336-39d0f177ccd0间接
Gogithub.com/magiconair/propertiesv1.8.10间接
Gogithub.com/mailru/easyjsonv0.7.7间接
Gogithub.com/masterminds/semver/v3v3.4.0间接
Gogithub.com/microsoft/go-winiov0.6.2间接
Gogithub.com/moby/docker-image-specv1.3.1间接
Gogithub.com/moby/go-archivev0.2.0间接
Gogithub.com/moby/patternmatcherv0.6.0间接
Gogithub.com/moby/sys/sequentialv0.6.0间接
Gogithub.com/moby/sys/userv0.4.0间接
Gogithub.com/moby/sys/usernsv0.1.0间接
Gogithub.com/moby/termv0.5.2间接
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1dd间接
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31ee间接
Gogithub.com/morikuni/aecv1.0.0间接
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822间接
Gogithub.com/opencontainers/go-digestv1.0.0间接
Gogithub.com/opencontainers/image-specv1.1.1间接
Gogithub.com/pelletier/go-toml/v2v2.2.4间接
Gogithub.com/pkg/errorsv0.9.1间接
Gogithub.com/pmezard/go-difflibv1.0.0间接
Gogithub.com/power-devops/perfstatv0.0.0-20240221224432-82ca36839d55间接
Gogithub.com/prometheus/client_modelv0.6.2间接
Gogithub.com/prometheus/commonv0.67.5间接
Gogithub.com/prometheus/otlptranslatorv1.0.0间接
Gogithub.com/prometheus/procfsv0.20.1间接
Gogithub.com/rcrowley/go-metricsv0.0.0-20200313005456-10cdbea86bc0间接
Gogithub.com/sagikazarmark/locaferov0.11.0间接
Gogithub.com/shirou/gopsutil/v4v4.26.2间接
Gogithub.com/sirupsen/logrusv1.9.3间接
Gogithub.com/sourcegraph/concv0.3.1-0.20240121214520-5f936abd7ae8间接
Gogithub.com/spf13/aferov1.15.0间接
Gogithub.com/spf13/castv1.10.0间接
Gogithub.com/spf13/pflagv1.0.10间接
Gogithub.com/stoewer/go-strcasev1.3.0间接
Gogithub.com/stretchr/testifyv1.11.1间接
Gogithub.com/subosito/gotenvv1.6.0间接
Gogithub.com/tchap/go-patricia/v2v2.3.2间接
Gogithub.com/tklauser/go-sysconfv0.3.16间接
Gogithub.com/tklauser/numcpusv0.11.0间接
Gogithub.com/x448/float16v0.8.4间接
Gogithub.com/xeipuuv/gojsonpointerv0.0.0-20190905194746-02993c407bfb间接
Gogithub.com/xeipuuv/gojsonreferencev0.0.0-20180127040603-bd5ef7bd5415间接
Gogithub.com/yashtewari/glob-intersectionv0.2.0间接
Gogithub.com/yusufpapurcu/wmiv1.2.4间接
Gogo.opentelemetry.io/auto/sdkv1.2.1间接
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.61.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.41.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.35.0间接
Gogo.opentelemetry.io/otel/sdkv1.43.0间接
Gogo.opentelemetry.io/otel/tracev1.43.0间接
Gogo.opentelemetry.io/proto/otlpv1.9.0间接
Gogo.uber.org/atomicv1.11.0间接
Gogo.uber.org/multierrv1.11.0间接
Gogo.uber.org/zapv1.27.0间接
Gogo.yaml.in/yaml/v2v2.4.4间接
Gogo.yaml.in/yaml/v3v3.0.4间接
Gogolang.org/x/cryptov0.54.0间接
Gogolang.org/x/expv0.0.0-20240719175910-8a7402abbf56间接
Gogolang.org/x/modv0.37.0间接
Gogolang.org/x/netv0.57.0间接
Gogolang.org/x/oauth2v0.35.0间接
Gogolang.org/x/sysv0.47.0间接
Gogolang.org/x/termv0.45.0间接
Gogolang.org/x/textv0.40.0间接
Gogolang.org/x/timev0.11.0间接
Gogolang.org/x/toolsv0.47.0间接
Gogomodules.xyz/jsonpatch/v2v2.4.0间接
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260223185530-2f722ef697dc间接
Gogopkg.in/evanphx/json-patch.v4v4.13.0间接
Gogopkg.in/inf.v0v0.9.1间接
Gogopkg.in/yaml.v3v3.0.1间接
Gok8s.io/apiextensions-apiserverv0.35.0间接
Gok8s.io/apiserverv0.35.0间接
Gok8s.io/component-basev0.35.0间接
Gok8s.io/klog/v2v2.130.1间接
Gok8s.io/kube-openapiv0.0.0-20250910181357-589584f1c912间接
Gok8s.io/utilsv0.0.0-20251002143259-bc988d571ff4间接
Gosigs.k8s.io/apiserver-network-proxy/konnectivity-clientv0.31.2间接
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730间接
Gosigs.k8s.io/randfillv1.0.0间接
Gosigs.k8s.io/structured-merge-diff/v6v6.3.2-0.20260122202528-d9cc6641c482间接
Gosigs.k8s.io/yamlv1.6.0间接
npm@babel/helper-string-parser7.27.1间接
npm@babel/helper-validator-identifier7.28.5间接
npm@babel/parser7.29.2间接
npm@babel/types7.29.0间接
npm@bcoe/v8-coverage1.0.2间接
npm@emnapi/core1.10.0间接
npm@emnapi/runtime1.10.0间接
npm@emnapi/wasi-threads1.2.1间接
npm@esbuild/aix-ppc640.28.1间接
npm@esbuild/android-arm0.28.1间接
npm@esbuild/android-arm640.28.1间接
npm@esbuild/android-x640.28.1间接
npm@esbuild/darwin-arm640.28.1间接
npm@esbuild/darwin-x640.28.1间接
npm@esbuild/freebsd-arm640.28.1间接
npm@esbuild/freebsd-x640.28.1间接
npm@esbuild/linux-arm0.28.1间接
npm@esbuild/linux-arm640.28.1间接
npm@esbuild/linux-ia320.28.1间接
npm@esbuild/linux-loong640.28.1间接
npm@esbuild/linux-mips64el0.28.1间接
npm@esbuild/linux-ppc640.28.1间接
npm@esbuild/linux-riscv640.28.1间接
npm@esbuild/linux-s390x0.28.1间接
npm@esbuild/linux-x640.28.1间接
npm@esbuild/netbsd-arm640.28.1间接
npm@esbuild/netbsd-x640.28.1间接
npm@esbuild/openbsd-arm640.28.1间接
npm@esbuild/openbsd-x640.28.1间接
npm@esbuild/openharmony-arm640.28.1间接
npm@esbuild/sunos-x640.28.1间接
npm@esbuild/win32-arm640.28.1间接
npm@esbuild/win32-ia320.28.1间接
npm@esbuild/win32-x640.28.1间接
npm@jridgewell/gen-mapping0.3.13间接
npm@jridgewell/resolve-uri3.1.2间接
npm@jridgewell/sourcemap-codec1.5.5间接
npm@jridgewell/trace-mapping0.3.31间接
npm@napi-rs/wasm-runtime1.1.5间接
npm@oxc-project/types0.133.0间接
npm@rolldown/binding-android-arm641.0.3间接
npm@rolldown/binding-darwin-arm641.0.3间接
npm@rolldown/binding-darwin-x641.0.3间接
npm@rolldown/binding-freebsd-x641.0.3间接
npm@rolldown/binding-linux-arm-gnueabihf1.0.3间接
npm@rolldown/binding-linux-arm64-gnu1.0.3间接
npm@rolldown/binding-linux-arm64-musl1.0.3间接
npm@rolldown/binding-linux-ppc64-gnu1.0.3间接
npm@rolldown/binding-linux-s390x-gnu1.0.3间接
npm@rolldown/binding-linux-x64-gnu1.0.3间接
npm@rolldown/binding-linux-x64-musl1.0.3间接
npm@rolldown/binding-openharmony-arm641.0.3间接
npm@rolldown/binding-wasm32-wasi1.0.3间接
npm@rolldown/binding-win32-arm64-msvc1.0.3间接
npm@rolldown/binding-win32-x64-msvc1.0.3间接
npm@rolldown/pluginutils1.0.1间接
npm@rollup/rollup-android-arm-eabi4.60.1间接
npm@rollup/rollup-android-arm644.60.1间接
npm@rollup/rollup-darwin-arm644.60.1间接
npm@rollup/rollup-darwin-x644.60.1间接
npm@rollup/rollup-freebsd-arm644.60.1间接
npm@rollup/rollup-freebsd-x644.60.1间接
npm@rollup/rollup-linux-arm-gnueabihf4.60.1间接
npm@rollup/rollup-linux-arm-musleabihf4.60.1间接
npm@rollup/rollup-linux-arm64-gnu4.60.1间接
npm@rollup/rollup-linux-arm64-musl4.60.1间接
npm@rollup/rollup-linux-loong64-gnu4.60.1间接
npm@rollup/rollup-linux-loong64-musl4.60.1间接
npm@rollup/rollup-linux-ppc64-gnu4.60.1间接
npm@rollup/rollup-linux-ppc64-musl4.60.1间接
npm@rollup/rollup-linux-riscv64-gnu4.60.1间接
npm@rollup/rollup-linux-riscv64-musl4.60.1间接
npm@rollup/rollup-linux-s390x-gnu4.60.1间接
npm@rollup/rollup-linux-x64-gnu4.60.1间接
npm@rollup/rollup-linux-x64-musl4.60.1间接
npm@rollup/rollup-openbsd-x644.60.1间接
npm@rollup/rollup-openharmony-arm644.60.1间接
npm@rollup/rollup-win32-arm64-msvc4.60.1间接
npm@rollup/rollup-win32-ia32-msvc4.60.1间接
npm@rollup/rollup-win32-x64-gnu4.60.1间接
npm@rollup/rollup-win32-x64-msvc4.60.1间接
npm@standard-schema/spec1.1.0间接
npm@tybys/wasm-util0.10.2间接
npm@types/chai5.2.3间接
npm@types/deep-eql4.0.2间接
npm@types/estree1.0.8间接
npm@types/node25.5.2间接
npm@vitest/coverage-v84.1.4间接
npm@vitest/expect4.1.4间接
npm@vitest/mocker4.1.4间接
npm@vitest/pretty-format4.1.4间接
npm@vitest/runner4.1.4间接
npm@vitest/snapshot4.1.4间接
npm@vitest/spy4.1.4间接
npm@vitest/utils4.1.4间接
npmacorn8.16.0间接
npmany-promise1.3.0间接
npmassertion-error2.0.1间接
npmast-v8-to-istanbul1.0.0间接
npmbundle-require5.1.0间接
npmcac6.7.14间接
npmchai6.2.2间接
npmchokidar4.0.3间接
npmcommander4.1.1间接
npmconfbox0.1.8间接
npmconsola3.4.2间接
npmconvert-source-map2.0.0间接
npmdebug4.4.3间接
npmdetect-libc2.1.2间接
npmes-module-lexer2.0.0间接
npmesbuild0.28.1间接
npmestree-walker3.0.3间接
npmexpect-type1.3.0间接
npmfdir6.5.0间接
npmfix-dts-default-cjs-exports1.0.1间接
npmfsevents2.3.3间接
npmhas-flag4.0.0间接
npmhtml-escaper2.0.2间接
npmistanbul-lib-coverage3.2.2间接
npmistanbul-lib-report3.0.1间接
npmistanbul-reports3.2.0间接
npmjoycon3.1.1间接
npmjs-tokens10.0.0间接
npmlightningcss1.32.0间接
npmlightningcss-android-arm641.32.0间接
npmlightningcss-darwin-arm641.32.0间接
npmlightningcss-darwin-x641.32.0间接
npmlightningcss-freebsd-x641.32.0间接
npmlightningcss-linux-arm-gnueabihf1.32.0间接
npmlightningcss-linux-arm64-gnu1.32.0间接
npmlightningcss-linux-arm64-musl1.32.0间接
npmlightningcss-linux-x64-gnu1.32.0间接
npmlightningcss-linux-x64-musl1.32.0间接
npmlightningcss-win32-arm64-msvc1.32.0间接
npmlightningcss-win32-x64-msvc1.32.0间接
npmlilconfig3.1.3间接
npmlines-and-columns1.2.4间接
npmload-tsconfig0.2.5间接
npmmagic-string0.30.21间接
npmmagicast0.5.2间接
npmmake-dir4.0.0间接
npmmlly1.8.2间接
npmms2.1.3间接
npmmz2.7.0间接
npmnanoid3.3.12间接
npmobject-assign4.1.1间接
npmobug2.1.1间接
npmpathe2.0.3间接
npmpicocolors1.1.1间接
npmpicomatch4.0.4间接
npmpirates4.0.7间接
npmpkg-types1.3.1间接
npmpostcss8.5.15间接
npmpostcss-load-config6.0.1间接
npmreaddirp4.1.2间接
npmresolve-from5.0.0间接
npmrolldown1.0.3间接
npmrollup4.60.1间接
npmsemver7.7.4间接
npmsiginfo2.0.0间接
npmsource-map0.7.6间接
npmsource-map-js1.2.1间接
npmstackback0.0.2间接
npmstd-env4.0.0间接
npmsucrase3.35.1间接
npmsupports-color7.2.0间接
npmthenify3.3.1间接
npmthenify-all1.6.0间接
npmtinybench2.9.0间接
npmtinyexec0.3.2间接
npmtinyexec1.1.1间接
npmtinyglobby0.2.17间接
npmtinyrainbow3.1.0间接
npmtree-kill1.2.2间接
npmts-interface-checker0.1.13间接
npmtslib2.8.1间接
npmtsup8.5.1间接
npmtypescript5.9.3间接
npmufo1.6.3间接
npmundici-types7.18.2间接
npmvite8.0.16间接
npmvitest4.1.4间接
npmwhy-is-node-running2.3.0间接
PyPIpsycopg间接
PyPIsetuptools间接
依赖安全公告 3

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 344 个包,其中也包含从不交付的开发与测试版本固定:3 个存在已知公告,1 个为直接依赖。 有 2 个无法评估——没有已解析的版本、生态系统不受支持,或不在所列包清单之内。

软件包版本关系严重程度公告数修复版本
google.golang.org/grpcv1.80.0直接严重11.82.1
github.com/docker/dockerv28.5.2+incompatible间接1029.3.1
golang.org/x/cryptov0.54.0间接未知1

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "message-queue",
        "task-manager",
        "task-queue",
        "competing-consumers",
        "asynchronous-tasks",
        "golang",
        "postgresql",
        "grpc",
        "taskmaster",
        "workflow-engine"
      ],
      "is_fork": false,
      "size_kb": 47162,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1103178,
        "Shell": 16464,
        "Elixir": 58564,
        "Python": 125149,
        "PLpgSQL": 115530,
        "Makefile": 14527,
        "Dockerfile": 5980,
        "TypeScript": 51586,
        "Go Template": 3466,
        "Open Policy Agent": 38851
      },
      "pushed_at": "2026-07-21T15:54:29Z",
      "created_at": "2018-05-22T19:13:53Z",
      "owner_type": "User",
      "updated_at": "2026-07-21T15:55:51Z",
      "description": "Competing-consumer fault-tolerant task queues. Written in Go. Pronounced Entro-Queue.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "develop",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://highentropy.com/",
      "name": "Chris Monson",
      "type": "User",
      "login": "shiblon",
      "company": "Abundant Security",
      "location": "Maryland, USA",
      "followers": 27,
      "avatar_url": "https://avatars.githubusercontent.com/u/2344944?v=4",
      "created_at": "2012-09-14T07:05:55Z",
      "is_verified": null,
      "public_repos": 23,
      "account_age_days": 5059
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.8.0",
          "kind": "minor",
          "published_at": "2026-07-21T15:57:48Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2026-07-16T19:34:19Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d0eeae542542713b32220b41bf5d136792b93f94",
          "body": null,
          "is_bot": false,
          "headline": "feat: add document GC and worker controls",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-21T15:53:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ae04a5885f9630367cbc8788d0585cd801c7317",
          "body": "The Sender package doc described an abandoned path-based scheme (\"the first\npath segment names the target queue\"), but the handler derives the queue from\nthe Host header via queueFromHost and forwards the full request path unchanged\nin the envelope. Rewrite the comment to describe the actual host-to-queue\nderivation (domain-suffix strip, dotted labels to segments, namespace prefix)\nand to state that path dispatch is the upstream router's job. Doc-only; no\nbehavior or schema change.",
          "is_bot": false,
          "headline": "docs(async): correct the Sender queue-routing comment to match the code",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T21:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96b66f841849bf55d40c7a7123789270bd8c862a",
          "body": "Security release: the queue is part of a task's modify key, so a caller\ncannot misdeclare a queue to dodge OPA authorization. Also fixes an\nopahttp fail-closed panic on undefined OPA decisions, secures the eqlink\nsidecar's EntroQ connection (TLS + token), flips eqpg LISTEN on by\ndefault, rationalizes the schema version to 1.7.1, and adds work-gateway\nexamples plus docs. See CHANGELOG.md [1.7.1].",
          "is_bot": false,
          "headline": "merge: v1.7.1 release into develop",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T17:37:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "87623168b568d952532f108dfd0bf4003475832d",
          "body": "…est absent\n\nA test audit found several packages that hard-fail on a bare `go test ./...`\nrather than skipping: eqpg and eqredis call log.Fatalf in TestMain when the\nPostgres/Redis testcontainer cannot start, and the eqk8s controller envtest\nsuite calls testEnv.Start() with ErrorIfCRDPathMissing, al\n[…]\nachine without Docker/envtest and unblocks\nwiring up repository-root CI later (currently there is none; the only workflows\nlive under cmd/eqk8s/.github and are not read by GitHub Actions at the root).",
          "is_bot": false,
          "headline": "test(backend,eqk8s): skip integration suites cleanly when Docker/envt…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T17:20:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df5cfc169005425b5f654b918a296758e0525657",
          "body": "The OPA HTTP client dereferenced result.Result without a nil check. OPA\nanswers an undefined decision with \"200 {}\" -- e.g. a misconfigured\n--opa_path or a rule that never sets a value -- leaving Result nil and\npanicking on !e.Allow. A misconfigured policy path thus crashed the\nauthorize path instea\n[…]\nend-to-end enforcement tests in eqsvcgrpc (a denying authorizer must\nblock Modify with PermissionDenied; an allowing one lets it through),\nclosing the seam the modifyAuthz builder tests left untested.",
          "is_bot": false,
          "headline": "fix(authz/opahttp): fail closed on undefined decisions and non-OK status",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:55:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e69cc93a3da67fe7bc29448fc3d09dbc6919c724",
          "body": "Give the eqmem/eqpg/eqredis `serve` commands Long descriptions (backend, the\ngRPC/HTTP ports, eqmem's journal, eqpg's schema requirement). Reword the eqpg\n--heartbeat help to say what it does -- trigger notifications for newly-available\ntasks -- rather than the confusing \"designates a cluster Leader\", and clarify the\neqmem --journal_max_* \"0\" meaning (uses the built-in default).",
          "is_bot": false,
          "headline": "docs(cmd): add serve Long help and clarify a few flag strings",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:29:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "780d4476c6c807b57c1a6a6f314bb000a907ead8",
          "body": "Like the just-fixed send/recv, `eqlink run` opened EntroQ with WithInsecure()\nplus inline token creds -- applying the bearer token but no TLS, and ignoring\n--cert/--key/--ca (a token over plaintext). Route it through localEQ, which\napplies TLS + token + claimant + token reload. All three single-instance sidecar\ncommands now share the one secure path that handoff already used.",
          "is_bot": false,
          "headline": "fix(eqlink): run honors --cert/--key/--ca for the EntroQ connection",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:26:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "08ccd6c0c941bfcf3af5add1d67eeff54f0a29d3",
          "body": "The schema version rationalization updated the Go SchemaVersion const and both\nschema.sql copies but missed the Python client's SCHEMA_VERSION constant, which\nTestSchemaFilesInSync checks against the schema stamp -- so it stayed at 1.8.0\nand the test failed. Set it to 1.7.1. Also drop the redundant drift test I had\nadded: TestSchemaFilesInSync already asserts the Go-const-vs-stamp lockstep (and\nmore), so point the SchemaVersion doc at it instead.",
          "is_bot": false,
          "headline": "fix(eqpg): sync the Python client SCHEMA_VERSION to 1.7.1",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:23:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42bc4ac06d74788111894d9a2af196b4e87332ca",
          "body": "The example was written against the pre-1.x schema (entroq_modify,\nentroq_try_claim_one, bytea/base64 values, a per-row notify trigger) and failed\nend to end. Rewrite it against the current schema-qualified functions\n(entroq.modify with JSONB op arrays, entroq.try_claim over a queue array,\nentroq.ta\n[…]\n note that a delete/change must name the task's queue (part of the modify\nkey). Verified end to end against a PostgreSQL 16 container, including that a\nwrong queue is rejected with a dependency error.",
          "is_bot": false,
          "headline": "docs(examples): rewrite the psql worker example for the current schema",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:16:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f06c2a23248e257021ac6874bc1d18c795056bc1",
          "body": "…false)\n\nThe persistent PostgreSQL LISTEN connection gives prompt claim wakeups via\nNOTIFY; it was off by default, so out of the box claims fell back to polling.\nTurn it on by default. Multiple replicas each holding a LISTEN connection is\nfine (NOTIFY wakes all listeners; SKIP LOCKED arbitrates the claim), and\n--no_listen still disables it for deployments that prefer polling.",
          "is_bot": false,
          "headline": "feat(eqpg): enable LISTEN/NOTIFY by default (--no_listen defaults to …",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e118cd6882c4c232b4be2ce2099143e1a09f28c",
          "body": "`eqlink send` and `eqlink recv` opened the EntroQ connection with\neqgrpc.WithInsecure() only, silently ignoring the root TLS and bearer-token\nflags -- so a deployment passing --cert/--ca got a plaintext, unauthenticated\nconnection to EntroQ. Route both through localEQ (the secure path handoff\nalready uses), which applies TLS and the token file. (`eqlink run` has the same\ngap -- it applies the token but no TLS; flagged for a follow-up.)",
          "is_bot": false,
          "headline": "fix(eqlink): send and recv honor --cert/--key/--ca/--authz-token-file",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T16:16:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad2afd1adb89b788b0bad32ca5eda9c62e653baf",
          "body": "The Technical Protocol Details → Tasks section is what a client author reads;\nspell out that a task's modify identity is (id, version, queue) and a mismatch\nis rejected, matching the godoc and mesh-policy note.",
          "is_bot": false,
          "headline": "docs: state the queue-in-identity rule in the README Tasks section",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T15:51:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a99956145bbfc7aa98557a7a9f62b856d012660",
          "body": "Add a short section tying the CRD authorization model to its enforcement: the\nbackend binds every modify to the task's actual queue, so a caller cannot reach\na task outside its granted queues by misdeclaring where the task lives.",
          "is_bot": false,
          "headline": "docs(mesh-policy): explain why queue authorization is unbypassable",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T15:50:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "321cc47c048a33c9266a70cd6382dcf4d7297a07",
          "body": "… untrack binary\n\ngreetings-demo: `eqc ins ... '{}'` silently ignored the positional value (ins\ntakes -v/--val), so it inserted an empty task; use `-v '{}'`. dynamic_config:\nadd the missing README and stop tracking (and gitignore) the built binary that\nhad been committed.",
          "is_bot": false,
          "headline": "docs(examples): fix greetings ins value flag; dynamic_config README +…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T15:49:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b3d2130933f80bba473d9aa54b914b052b12d290",
          "body": "viper.BindPFlag looked up \"svcaddr\", which is not a flag here, so Lookup returned\nnil and the binding was a silent no-op -- the eqaddr env/config binding never\nworked. Bind the flag that actually exists. (Also tidies the placeholder\ncopyright header.)",
          "is_bot": false,
          "headline": "fix(eqprocworker): bind the eqaddr flag, not a nonexistent svcaddr",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T15:49:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4459a57cc64be9c05dabb9f25783b616919ed6de",
          "body": "…le refs\n\nA task is identified for modification by (id, version, queue): a change, delete,\nor depend must name the queue the task currently occupies, and the backend never\nsubstitutes it -- a mismatch fails the whole modify with a DependencyError. This\nis what makes queue-scoped authorization unbypa\n[…]\nnk root help's phantom GC subcommand and conn.go's stale\n\"(send/recv/run/gc)\"; the entroq package godoc's cmd/eqpgsvc/eqmemsvc ->\ncmd/eqpg/eqmem; and a placeholder \"NAME HERE\" copyright header in eqc.",
          "is_bot": false,
          "headline": "docs: document that the queue is part of a task's modify key; fix sta…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T15:49:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9aab68069b54373d0862cbe859876ceaf79b3d3",
          "body": "Split the Python example so the worker's business logic lives in one shared\nhandler.py and the two transports sit beside it: pipe_worker.py (spawns\neqlink work, reconnect keyed on process exit code 75) and the new ws_worker.py\n(dials a running eqlink work --addr, reconnect keyed on WebSocket close code\n1013). Same handler, two transports -- the clearest way to show how to write a\ngateway client. The README covers running both.",
          "is_bot": false,
          "headline": "docs(examples): add a WebSocket work-gateway client; share the handler",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T15:44:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce2e11eb35f854546366f59f57f6b17d102a381a",
          "body": "From a docs audit against the current commands/packages: update the\nCross-Instance Task Handoff section from the removed `eqlink pull` to\n`eqlink handoff --from/--to` (with the real flags and diagram); add an \"Any\nlanguage (work gateway)\" subsection pointing at `eqlink work`,\ndocs/workgateway-protocol.md, and examples/workgateway; and add the missing\nRedis backend to the Backends list.",
          "is_bot": false,
          "headline": "docs: fix stale README (handoff command, work gateway, Redis backend)",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T14:08:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1255eedb0ca27a505075e1183a6817f2289852a",
          "body": "…guard\n\nAdd the [1.7.1] changelog entry: breaking + security, with the queue-integrity\nauthz fix headlined, the eqpg collation migration and maintenance-window note,\nthe \"service wire unchanged\" reassurance, and the 1.7.0-skip rationale.\n\nAdd a user-facing Versioning section to the README (minors ma\n[…]\nmaVersion major.minor must equal the\ntag\" to \"SchemaVersion must not be ahead of the tag\", so the schema version may\nlag the module across schema-unchanged releases, and correct CONTRIBUTING to\nmatch.",
          "is_bot": false,
          "headline": "docs: 1.7.1 changelog, versioning note, and loosen the schema-vs-tag …",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T14:05:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b85820595be2958b63f8840526381158bc50d60",
          "body": "…utrun module\n\nSchemaVersion had been bumped speculatively to \"1.8.0\" for two planned but never\nreleased module versions, leaving the schema ahead of the module (still at\n1.6.3) -- an impossible state. Set it to 1.7.1, the version that actually ships\nthe change, restoring the invariant that the sche\n[…]\n), and fix UpgradeSchema's now-untrue \"additive only\" wording. Add a test\nguarding the version against drifting between the Go const and schema.sql, and\nkeep the experimental Python pg schema in sync.",
          "is_bot": false,
          "headline": "fix(eqpg): rationalize the schema version to 1.7.1; schema must not o…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-16T12:33:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f352cdf12a823d05ec52513bef03dfa23c9d85bc",
          "body": "A resident worker that spawns `eqlink work`, speaks the newline-delimited JSON\nprotocol over the pipe, and survives a restarting or relocating EntroQ backend\nvia a reconnect loop keyed on the gateway's exit code (75 = transient reconnect,\nanything else = stop). It demonstrates the monolith recipe; the crash-only\nalternative is noted in the code and README. stdlib only, deliberately tiny --\nthe point is the shape of a correct client.",
          "is_bot": false,
          "headline": "docs(examples): add a minimal Python work-gateway client",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T19:51:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e9be36ec6850584f0e2d0cd0a8ec5fa00b39e91",
          "body": "The language-agnostic worker gateway grows a shared exit taxonomy (ok /\ntransient / caller / gateway) surfaced three ways -- a one-way error side\nchannel, a pipe exit code (sysexits), and a WebSocket close code -- plus a\nsupervision loop that rides out a restarting or relocating EntroQ backend\n(boun\n[…]\novering the wire contract, the\nproto-payload rule, the ack shorthand, and the crash-only vs resident-reconnect\nclient recipes; and an integration test driving the ride-out through a gated\ngRPC dialer.",
          "is_bot": false,
          "headline": "merge: work gateway protocol v2 into develop",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T18:13:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b220f3558c917684bc38859ccf392f8bf5f6a634",
          "body": "Drive the gateway against a real eqgrpc client whose in-process, eqmem-backed\nbackend can be made unreachable and reachable again through a gated niladic\ndialer, so a genuine codes.Unavailable travels the eqgrpc error boundary into\nentroq.IsUnavailable and the supervision loop classifies it as trans\n[…]\nTransient exit\nafter the fatal timeout.\n\nExtend the test session helper to accept Bridge options and to dispatch messages\nby type (recvAny), for draining transient error reports until a phase message.",
          "is_bot": false,
          "headline": "test(workgateway): integration-test the EntroQ reconnect ride-out",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T18:07:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4fc63276623fc1efb4f05273c62d8d72ece42aa",
          "body": "…Socket\n\nThread entroqTimeout through Handler and Serve so WebSocket-served bridges honor\nthe same --entroq-timeout as the pipe gateway, rather than always using the\ndefault.",
          "is_bot": false,
          "headline": "feat(workgateway,eqlink): expose the EntroQ ride-out timeout over Web…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T17:56:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9097ebc8b5302db103465db4f06378386b46cb5",
          "body": "Document the wire protocol, the proto-payload contract, the ack shorthand, the\nerror/exit/close-code taxonomy, the EntroQ ride-out, and the two client-side\ndisconnect recipes (crash-only and resident reconnect) so a client-library author\nhas one reference instead of reconstructing it from the code.",
          "is_bot": false,
          "headline": "docs: add the work gateway protocol v2 note",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T17:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d33be89908d279513b7d87747fbdbe8cd586a90",
          "body": "work: add --entroq-timeout for the backend ride-out, and exit with the gateway's\nclass code (0 clean, 75 transient, 78 caller, 70 gateway) so a supervisor can\ntell a retryable backend blip from a caller fault. Refresh the command help for\nthe error channel, exit codes, and the ride-out.",
          "is_bot": false,
          "headline": "feat(eqlink): map the gateway exit class to a process exit code",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T17:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "72484a2d978c0e0a5a1011c69e11ad82c4094df7",
          "body": "…Q ride-out\n\nSupervise the worker loop instead of running it once: classify why it stops into\na small shared vocabulary (ok / transient / caller / gateway) and surface that\nclass three ways -- an out-of-band, reply-free \"error\" message mid-session, a\nprocess exit code over a pipe (sysexits: 0/75/78/\n[…]\n A dropped client connection is now a clean stop\n(the client owns its own lifecycle), tracked by a single connLost bit so the\nclassification is independent of how the error was wrapped on the way out.",
          "is_bot": false,
          "headline": "feat(workgateway): protocol v2 -- error channel, exit taxonomy, Entro…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T17:44:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a7550d1ede613186e84639c208c9b8be1c992d2b",
          "body": "Add entroq.UnavailableError and IsUnavailable, and translate gRPC\ncodes.Unavailable to it at the eqgrpc backend's error boundary, alongside the\nexisting Canceled/DeadlineExceeded/dependency translations. This lets a caller\ntell a routine backend blip -- the server restarting or being relocated -- from a\ngenuine failure without inspecting transport specifics, which is what the work\ngateway needs to ride out a restarting EntroQ.",
          "is_bot": false,
          "headline": "feat(entroq): classify a temporarily-unavailable backend",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T17:44:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3871905a03b055c9cf3e806d8123aa1eb04523be",
          "body": "The success phase runs under the worker's OnSuccess hook, which is best-effort:\nit logs a non-fatal error and continues. That meant a client dropping its\nconnection during the success phase did not stop the worker; it looped back and\nclaimed the next task it could no longer deliver, bumping that tas\n[…]\n so a dead\nconnection stops the worker, matching every other phase, which already exits on\na transport drop. Update the test to assert the worker stops on its own rather\nthan masking it with a cancel.",
          "is_bot": false,
          "headline": "fix(workgateway): stop the worker when the connection drops mid-success",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T15:15:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d7db15a14975f59492d938c364f3d09a91068fed",
          "body": "Adds the failure-mode coverage the work gateway was missing: a client dropping\nits connection mid-task (over both the pipe and WebSocket transports) with\nat-least-once reclaim after the lease expires, drops during the takeDocs and\nsuccess phases, wrong message types, and malformed input.",
          "is_bot": false,
          "headline": "merge: workgateway transport-failure tests into develop",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T15:06:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a58baf620b246a4c43de70860311b6147608bd74",
          "body": "Add the failure-mode coverage the package was missing. The happy paths and the\nfull outcome vocabulary were well tested, but nothing exercised a worker dropping\nits connection -- the very scenario the gateway exists to survive.\n\nNew cases: a client that drops mid-task (before replying, during takeDo\n[…]\ny durable) commit, confirming the exactly-once boundary.\n\nThe test session helper learns to close the client pipe ends so the bridge's\nnext Send/Recv fails exactly as it would on a dropped connection.",
          "is_bot": false,
          "headline": "test(workgateway): cover transport failure and at-least-once reclaim",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T14:33:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf1dc2ecbf923459e2d5cebd3666d06e82760685",
          "body": "…nto develop\n\nClears the actionable Dependabot advisories: bump golang.org/x/crypto v0.50->0.54\nand golang.org/x/net v0.53->0.57 (14 alerts), and pin esbuild >=0.28.1 in the JS\nclient (1 alert). Also fixes a pre-existing broken import in the eqk8s e2e tests\n(wrong path to test/utils) that had been blocking go mod tidy; the docker/docker\nalerts are transitive test-only and were dismissed.",
          "is_bot": false,
          "headline": "merge: dependency bumps (x/crypto, x/net, esbuild) + e2e import fix i…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T14:27:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c4a932c02562b1be1d1447f78ca891b2336dcf7",
          "body": "Bump x/crypto v0.50.0 -> v0.54.0 and x/net v0.53.0 -> v0.57.0 to clear the\nDependabot advisories (14 alerts total, all patched at or below these versions);\ngo get pulled the usual transitive golang.org/x/* updates alongside.\n\nRunning go mod tidy afterward (now possible thanks to the e2e import fix) also\ncorrected several directly-imported dependencies that were mislabeled //\nindirect: coder/websocket, redis/go-redis, onsi/ginkgo, onsi/gomega,\ncontroller-runtime, and k8s.io/*.",
          "is_bot": false,
          "headline": "chore(deps): bump golang.org/x/crypto and golang.org/x/net",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:36:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d54877a00db946e2a3d389ea233ada1310d64b5a",
          "body": "The e2e suite imported github.com/shiblon/entroq/test/utils, but that package\nlives at github.com/shiblon/entroq/cmd/eqk8s/test/utils: a kubebuilder scaffold\nwhose import path was never adjusted for eqk8s living in a subdirectory. The\nfiles are //go:build e2e gated, so normal builds and tests were unaffected and\nnobody noticed, but the dangling import made `go mod tidy` fail to resolve it.\nFix the path in both e2e files.",
          "is_bot": false,
          "headline": "fix(eqk8s): correct the e2e test import path for test/utils",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:36:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "747a250d7ab6f3978f5dfff2a50ec8c5f331c85c",
          "body": "esbuild is a transitive build-time dependency (via tsup) flagged by a\nlow-severity, dev-scope advisory (GHSA-g7r4-m6w7-qqqr, patched in 0.28.1). Pin it\nwith an npm override; the lockfile moves to 0.28.1, npm audit reports no\nvulnerabilities, and the client still builds cleanly (tsup) under it. Not shipped\nto consumers, which receive only dist/.",
          "is_bot": false,
          "headline": "chore(deps): pin esbuild >=0.28.1 in the JS client",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:32:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c686f9aa22913ed838806e70a7799af1afbd4ca8",
          "body": "…e) into develop\n\nThree follow-ups after the work-gateway refactor: eqmem now panics on pure-logic\ninvariants (keeping log.Fatalf for post-mutation persistence hazards); eqsvcgrpc's\nredundant doc-only dependency renderer folds into the shared pbconv one; and a\nmodule-wide gopls modernize sweep over non-generated code.",
          "is_bot": false,
          "headline": "merge: post-workgateway cleanups (eqmem panics, pbconv fold, moderniz…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:21:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "989528dbd34ee9ad1828d684cbeb61e2ddea1ecd",
          "body": "Mechanical modernization pass (gopls modernize) over non-generated code:\nrange-over-int loops, min/max builtins, slices.Sort/Contains/Backward,\nstrings.FieldsSeq, an atomic.Int64 counter, and WaitGroup.Go, plus interface{}\n-> any. No behavior change. Generated files are left untouched.",
          "is_bot": false,
          "headline": "refactor: apply gopls modernize across the module",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:15:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c2eb83d431c47bedb2244816ea0fbb8cf969ae0",
          "body": "…enderer\n\nBoth Modify and ClaimDocs turned a DependencyError into gRPC status details, but\nModify used pbconv.DependencyErrorDetails while ClaimDocs kept a redundant,\ndoc-only docClaimDepDetails. Replace both with one depDetails helper over the\nshared pbconv renderer; it adapts the transport-neutral\n[…]\nagnostic. Behavior is unchanged: a ClaimDocs error only\npopulates doc dependencies, which the shared renderer already covers.\n\nAlso drop a stale \"protoFromDoc\" comment left above the deleted function.",
          "is_bot": false,
          "headline": "refactor(eqsvcgrpc): fold docClaimDepDetails into the shared pbconv r…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:11:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4528c7abc5f81ac5c3df0a2a7d38635a7d8391cb",
          "body": "…stence\n\nThe impossible-state checks (a task missing from the heap after a claim, the\nqueue/namespace storage and lock structures out of step) are programmer errors,\nso panic instead of log.Fatalf: a panic carries a stack trace to the bug and\nruns deferred cleanup, where os.Exit does neither.\n\nThe p\n[…]\ntation already succeeded) deliberately stay log.Fatalf: recovering\nfrom those would continue running with an un-journaled mutation, a durability\nhazard, so an unrecoverable exit is the safer response.",
          "is_bot": false,
          "headline": "refactor(eqmem): panic on pure-logic invariants, keep Fatal for persi…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T13:09:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "54b42ca91cd07313cab6b1ce6a1bc16bece91fe8",
          "body": "Brings in the language-agnostic worker gateway (eqlink work / workgateway): a\nworker in any language drives the EntroQ worker loop over a small JSON protocol\nwhose payloads are the protojson of the api protobufs, so it hand-models nothing.\n\nSupporting work landed on the way: Result.OnDependency (rep\n[…]\ng\nWithDependencyHandler), DependencyError.Implicates for task-scoped failure\nchecks, and the pbconv package that centralizes the proto<->entroq conversion\nshared by eqgrpc, eqsvcgrpc, and the gateway.",
          "is_bot": false,
          "headline": "merge: eqlink work gateway on a shared proto contract into develop",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T12:52:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "997ad73e46a9a56f4d4356dda237dd668b46f102",
          "body": "Reshape the worker-gateway protocol around phases of work. Rename the cleanup\nphase to success and add a mutually-exclusive dependency phase; both are\npost-commit, opt-in, and named by the outcome that fires them (the pre-commit\ntakeDocs/work phases are named by action). The gateway sends only the p\n[…]\non of that task in the modification wins over it.\n\nConstruct the Bridge with functional options (NewBridge(conn, WithConfig,\nWithLease)) instead of positional config, matching the codebase convention.",
          "is_bot": false,
          "headline": "feat(workgateway): opt-in post-commit phases and an ack shorthand",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-15T12:44:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e7d4503982023eee3d752ff9774afc342408acd",
          "body": "These helpers Fatal on programmer errors -- a value that cannot be marshaled, a\nmalformed token, a WaitGroup-style misuse -- conditions that cannot happen with\ncorrect code. log.Fatal is the wrong tool from a library: it os.Exit()s the\nentire process, skips deferred cleanup, and discards the stack t\n[…]\n misuse).\n- procworker: the marshal helpers.\n\neqmem's internal-invariant Fatals are deliberately left for a per-site pass:\nsome guard post-mutation persistence, where a hard exit is the safer failure.",
          "is_bot": false,
          "headline": "refactor: log.Panicf for Must-style programmer-error helpers",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-14T17:28:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "24dbdd4c776e8bb217cfe1ba26b6c6276d4911ab",
          "body": "Complete the wire<->domain boundary: the task/doc/id conversions that were split\nacross eqgrpc (proto->domain, for reading responses) and eqsvcgrpc (domain->proto,\nfor building responses) now live in pbconv as one symmetric set -- TaskToProto/\nTaskFromProto, DocToProto/DocFromProto, TaskDataToProto,\n[…]\nllowing it;\nMustDocFromProto is the loud (log.Panicf) variant for callers converting\nwire-origin content that cannot realistically fail. TaskIDFromProto sheds a\nvestigial error it could never produce.",
          "is_bot": false,
          "headline": "refactor(pbconv): move task/doc/id conversions into pbconv",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-14T17:25:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b607d10ec19b93095ab639a852f5c7920d070f15",
          "body": "The proto ModifyRequest -> entroq modify translation, the DependencyError ->\nproto detail rendering, and the millisecond and JSON<->structpb helpers were\nduplicated between the gRPC client (eqgrpc) and service (eqsvcgrpc), and the work\ngateway was about to hand-roll a fourth copy. Move the single co\n[…]\nromProto,\n  DependencyErrorDetails, plus unit tests.\n- eqsvcgrpc: Modify uses ModifyArgsFromProto + DependencyErrorDetails; local\n  helpers deleted.\n- eqgrpc: shares the helpers; local copies deleted.",
          "is_bot": false,
          "headline": "refactor(pbconv): extract the proto<->entroq conversion into one package",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-14T16:32:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be9538093137233c8e8b5d38432e4d5343a70c48",
          "body": "…checks\n\nA worker reacting to a failed commit (see worker.Result.OnDependency) needs to\ntell \"my claimed task moved out from under me, or was scooped\" from \"some other\ntask or doc failed while my task is still validly claimed\" -- the latter being\nwhen an optimistic Move/Retry can still land on the t\n[…]\n answers\nexactly that, scanning the task-level failure sets (changes, deletes, depends,\nclaims, and insert collisions). It is task-scoped: a doc that happens to share\nthe id never implicates the task.",
          "is_bot": false,
          "headline": "feat(entroq): add DependencyError.Implicates for task-scoped failure …",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-14T15:47:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3359599735067f01fee5b6f8b2db32b7888934c3",
          "body": "OnDependency previously wrapped any handler return as a generic error, so a\nMove meant to quarantine and a Fatal meant to stop were indistinguishable and\nboth just killed the worker. Return the handler's sentinel unwrapped and route\nit, like a work-phase sentinel, through handleSentinelErrors: Retry\n[…]\nled\n  disposition modify. Run's doc spells out the sentinel/dependency/cancel/unknown\n  disposition ladder.\n- eqtest: WorkerDependencyMove exercises the Move-to-error-queue path across all\n  backends.",
          "is_bot": false,
          "headline": "feat(worker): honor Retry/Move/Fatal from OnDependency; exit on unknown",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-14T15:36:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3977ba20a619a9b16f69d94fc268929f92cfb78f",
          "body": "…ency\n\nWithDependencyHandler was a worker-level run option, but it only ever made\nsense for the DoModify path: it lived in runOne and fired after\ndoModifyHandler.Finish had fully unwound, so a dependency failure was handled\nin a different scope from its own commit and asymmetrically from OnSuccess.\n\n[…]\nch\n  drove the hook via DoWork/Finish, a combination that no longer has one.\n- backends: drop the now-dangling test registrations.\n- examples/dynamic_config: chain OnDependency on the returned Result.",
          "is_bot": false,
          "headline": "refactor(worker)!: replace WithDependencyHandler with Result.OnDepend…",
          "author_name": "Chris Monson",
          "author_login": null,
          "committed_at": "2026-07-14T14:32:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55d7df4dbd1a451022741963c43600883673cfda",
          "body": "…rotocol",
          "is_bot": false,
          "headline": "merge: develop (fluent API + worker/backend fixes) into eqlink-work-p…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-14T01:52:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54154b1145b3d5306d0476a4bdd1a08cb9cf8373",
          "body": "modifyImpl called queueDeps.Merge(foundDeps) unconditionally, so every\nsuccessful modify (both nil) still allocated empty slices and ten dedup maps\njust to compute a nil error -- avoidable GC pressure on eqmem's hot path.\nGuard the call to run only when a queue-integrity or found-based failure\nactually exists. No behavior change; the error path (which reports every\nfailure class) is unaffected.",
          "is_bot": false,
          "headline": "perf(eqmem): skip DependencyError.Merge on the modify success path",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-14T01:27:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "755654445e4b46268d11da91a7269aa4a1e1df2f",
          "body": "…o develop",
          "is_bot": false,
          "headline": "merge: modify-queue-integrity (queue-as-modify-key authz + fixes) int…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T22:21:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95cd3df45a2fad8533522333efa22ae8ef0e04ca",
          "body": "The lost-claim delivery race is two-generals: the client cannot be\nguaranteed to learn that a claim committed server-side. 1a2dcea tried to\nengineer around it with a server empty-on-poll-window return plus a client\nre-issue loop, and that machinery conflated the proto PollMs field -- the\nclient sent\n[…]\nCTimeout helper, reworks the\nretry-loop test into a blocking-claim test, and keeps the slow-delivery\nregression test (it still guards that a committed claim reaches the caller\nunder delayed delivery).",
          "is_bot": false,
          "headline": "fix(eqgrpc): make Claim a single blocking RPC; drop the retry loop",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T22:19:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9da867e2ab235db72d9423102c145456f0c1210d",
          "body": "EnsureModifyKeys (Go) rejects empty queue/namespace writes, but the schema\nhas no non-empty CHECK, so a client talking to Postgres directly (an\nunsupported path) would not get that guard. Record the gap in schema.sql,\nnext to where a CHECK would go, so reviving direct-pg support has a\nbreadcrumb. Synced to the Python client.",
          "is_bot": false,
          "headline": "docs(eqpg): note the empty-queue guard is Go-only (direct-pg parity)",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T21:10:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ca2fc1292b2d4ada0bbb29e069b5cb9425acfd3",
          "body": "… place\n\nThe gRPC service authorized a doc change with OldId.ns != NewData.ns as a\nmove (Delete source + Insert destination), but (*Doc).Change applies it\nin-place in the source namespace -- an authz-vs-effect divergence flagged in\nreview. Docs do not move between namespaces, so:\n\n- Modify rejects a\n[…]\njectsWrongQueue), closing the doc-side coverage gap: a doc\ndelete/depend/change naming the wrong namespace fails as a DependencyError on\nevery backend, since the found map is keyed by (namespace, id).",
          "is_bot": false,
          "headline": "fix(eqsvcgrpc): reject cross-namespace doc changes; authorize docs in…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T19:48:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ede5d560510b729963b25860f10b9eef373f605a",
          "body": "eqmem's queue-integrity check (ensureModQueues) returned early on a\nqueue/namespace mismatch, so mod.DependencyError never ran and the returned\nerror omitted every other failure class -- most importantly insert\ncollisions, which a caller's skip-colliding retry logic depends on. That\nviolated the Bac\n[…]\nc ID),\ndocument the completeness requirement as Backend.Modify rule 3, and add the\ncross-backend eqtest ModifyReportsAllFailureClasses (red on eqmem before\nthis change; already green on eqpg/eqredis).",
          "is_bot": false,
          "headline": "fix(eqmem): report all modify failure classes in one DependencyError",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T19:37:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9f27771f24e755f2a5a202286d20ebf3d665c3bb",
          "body": "Surfaced by the TestReadinessTicker_LocalOnly flake:\n\n- eqtest.StartService opened a gRPC service (hence a backend) but returned\n  only the *grpc.Server, so callers stopped the server yet never closed the\n  service. The backend's readiness/GC loops are rooted at\n  context.Background(), so an unclose\n[…]\nr kept advancing the single global notify_ready_queues watermark and\nstole the \"task became ready\" window from a later NoListen client whose only\nwakeup is its own ticker's scan, timing out its claim.",
          "is_bot": false,
          "headline": "fix(eqpg,eqtest): stop leaking the test service's backend loops",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T19:05:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0842ca2684edddb19aa5c2f395885ab475f28f8c",
          "body": "An empty queue or namespace is never a valid write target. A task insert,\na task change destination, and a doc insert have no prior record to look\nup, so an empty key would be silently written to \"\". EnsureModifyKeys\nrejects those at each backend's Modify entry (eqmem, eqpg, eqredis), which\nalso cov\n[…]\nestination means no move\" ergonomic stays at the gRPC service,\nwhere authorization is decided; eqredis's redundant inline copy is removed.\nAdds EmptyWriteTargetRejected, run against all four backends.",
          "is_bot": false,
          "headline": "feat(entroq): reject writes to an empty queue or namespace",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T16:32:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d8bd30e7257673d46b355b7bb4ebbe6965dc3017",
          "body": "Journals written before the queue-as-modify-key requirement (and claim\nchanges generally) recorded ops without a FromQueue/Queue, which the\nintegrity check now rejects. On replay only -- the trusted re-application\nof our own committed record -- modPrep backfills the missing queue from\nstored state b\n[…]\nkipping the claimant check and the queue backfill.\n\nAlso clarify that IDs are arbitrary <=64-char strings, not UUIDs: reframe\nthe schema comment (UUIDs are opt-in) and fix an \"all some backends\" typo.",
          "is_bot": false,
          "headline": "fix(eqmem): replay old journals that omit an op's queue",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-13T15:41:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bfb70295f82fff6651908595081d752df26d91ac",
          "body": "…efore upgrade\n\nThe /work handler built the Config and upgraded the connection before Bridge.Run\nenforced its required-queues and required-work invariants, so a misconfigured\nworker saw a successful WebSocket upgrade followed by an immediate close. Validate\nthe registration up front and return a plain 400 for a missing queue or work=1,\nmatching what Bridge.Run enforces once connected.",
          "is_bot": false,
          "headline": "fix(workgateway): reject a WS work connection missing queue or work b…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T05:19:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b3a093d5cdfa3e0b4bdb7738712a1513f269f52",
          "body": "…ply types\n\nTwo review-fix items surfaced before the gateway lands:\n\n- docDelete and docDepend now require a namespace, the doc twin of a task\n  delete/depend requiring a queue. A doc op that omits its authorization key is\n  rejected rather than passed through.\n- Each phase validates the received me\n[…]\nAn out-of-sequence or\n  malformed reply now fails with a clear protocol error instead of being silently\n  decoded into a zero-valued struct. Clients already set Type, so this is\n  backward compatible.",
          "is_bot": false,
          "headline": "fix(workgateway): require namespace on doc delete/depend; validate re…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T05:18:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e25c7aeff037559db9560798defdffb42a908e98",
          "body": "Fixes surfaced by reviewing the branch prior to merging to develop:\n\n- eqmem journal replay (critical): mustTryClaimOne journaled a claim change with\n  FromQueue unset, so replay was rejected by the queue-as-modify-key check and a\n  journaled backend could not recover on restart. Record the task's c\n[…]\nivergence, doc cross-namespace change authz/effect, ensureModQueues\nDependencyError shape, lone empty-queue insert no-op) touch modify/authz semantics\nand are left for review rather than changed here.",
          "is_bot": false,
          "headline": "fix(entroq): address code-review findings before the develop merge",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T05:05:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "935ef8aeef0957fc2c968b5ec1ba7d3d4cd42908",
          "body": "Queue prefix matching built `queue LIKE 'prefix%'` with the raw prefix, so a\nqueue name containing a SQL LIKE metacharacter (_ % \\) was matched as a wildcard\nand over-matched. Two copies had the bug: the Go backend's inline QueueStats\nquery and the entroq.queues() stored function (which the pg-nativ\n[…]\nst.QueuePrefixMatchLiteral, run by\neqmem/eqredis/eqpg) asserting a prefix containing an underscore matches\nliterally, not as a wildcard. eqmem/eqredis already compared by byte prefix;\neqpg now agrees.",
          "is_bot": false,
          "headline": "fix(eqpg): escape LIKE metacharacters in queue prefix matching, in SQL",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T04:40:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6831e69c2e8c378fd183ba5f42353666758d399f",
          "body": "Runs the MapReduce workload over the gRPC transport against a real Postgres\nbackend under a short claim retry interval, repeated for load. Exercises both the\nlost-claim delivery fix and the doc-key byte-order (COLLATE \"C\") fix end-to-end in\nthe most common deployment environment: a stalled claim would hang the pipeline,\nand locale-collated doc key ranges would hide the shard docs and end the map\nphase prematurely. Skipped in -short.",
          "is_bot": false,
          "headline": "test(eqpg): MapReduce over gRPC + Postgres load test",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T04:21:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d09716135a897745502ed738172fe70754326cb",
          "body": "…tch other backends\n\nDoc key range queries on Postgres compared key_primary/key_secondary under the\ndatabase's default (locale) collation, disagreeing with eqmem, eqredis, and Go's\nbyte-order string comparison for keys containing punctuation. \"shard/0\" is <\n\"shard0\" by byte ('/'=0x2F < '0'=0x30) but\n[…]\n-sync` and its SCHEMA_VERSION is\nbumped in lock-step.\n\nAdds a cross-backend regression test (eqtest.DocKeyRangeByteOrder) run by\neqmem/eqredis/eqpg, pinning byte-order doc key ranges on every backend.",
          "is_bot": false,
          "headline": "fix(eqpg): byte-order (COLLATE \"C\") key/queue/id columns so ranges ma…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T04:18:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8424b7af7b9f58a2be67ee25652b19134dde1d3",
          "body": "Exercises the lost-claim fix under realistic load: many workers claim and delete\na task pool over the gRPC transport against a real Postgres backend, with a short\nclaim retry interval, in the environment where the delivery race historically\ncaused ~30s stalls. Asserts the pool drains completely, since a lost or stranded\nclaim would fall short of the total within the deadline. Skipped in -short mode.",
          "is_bot": false,
          "headline": "test(eqpg): claim contention load test over gRPC + Postgres",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T03:36:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fb7914bcd2ea96a78241bef9d8d7a035a2c5089",
          "body": "Multi-queue and multi-namespace locking must take locks in a consistent order to\navoid dining-philosophers deadlock. That ordering was enforced by modPrep\nsorting its output and trusting callers to pass it through unchanged, an\ninvariant living far from the lock acquisition that a future caller coul\n[…]\nueue\nclaim path passes a one-element slice (no real cost); the multi-queue modify\npath does the same one sort as before, relocated. Every caller owns the slice it\npasses, so the in-place sort is safe.",
          "is_bot": false,
          "headline": "refactor(eqmem): sort lock order inside lockQueues/lockNamespaces",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T03:20:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a2dcea7d851e9ce3359c34cdfd5a57655f0c6fe",
          "body": "A blocking Claim over gRPC could commit a claim server-side and then lose it in\ndelivery, stranding the task for its full claim duration (~30s by default). The\nclient bounded each attempt with a hard context deadline equal to\nclaimRetryInterval; when a claim was granted just as that deadline fired, \n[…]\nil-task\nbehavior.\n\nAdds a deterministic regression test: a server interceptor delays a granted\nclaim's delivery past the retry interval. Red before the client fix (hangs to\nthe deadline), green after.",
          "is_bot": false,
          "headline": "fix(eqgrpc): don't lose a committed claim to the client's retry cancel",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-12T03:20:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c00a0e5f0c121614ebac277a511a6a744d7d05e",
          "body": "The exact-match loops in eqmem.matchesQuery and eqredis.matchesQueuesQuery are\nplain membership checks; slices.Contains (stdlib since go1.21) states that\ndirectly and drops the loop plus its trailing \"return false\". Behavior-preserving.",
          "is_bot": false,
          "headline": "chore(modernize): use slices.Contains for queue-name exact matching",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T22:08:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7989b6b88758a978d8e5eee88a4f7fd665982584",
          "body": "eqlink is a ~23MB build artifact that was accidentally committed. Remove it from\nthe tree and ignore it (matching the existing /eqc entry). Purging it from git\nhistory is a separate maintenance step.",
          "is_bot": false,
          "headline": "chore: drop committed eqlink binary and ignore it",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T21:55:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5d1b9b1106c1028bafd052d939d76ce6203ab02",
          "body": "Queues are EntroQ's authorization boundary. eqmem already bound each task\noperation to (id, version, queue) in 9265e53; this completes the same guarantee\nin eqpg and eqredis, so a caller cannot delete, depend on, or relocate a task by\n(id, version) alone while naming a queue it does not live in.\n\n- \n[…]\nched, while a legitimate move still succeeds.\n\nBREAKING CHANGE: a delete/depend/change must name the task's current queue; a\nbare (id, version) op with an empty queue now fails with a DependencyError.",
          "is_bot": false,
          "headline": "fix(eqpg,eqredis): make the queue part of the modify key (cross-backend)",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T21:54:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "023157263b13657e4da19788b687ebc115ca27ba",
          "body": "…identifier\n\nOperations on an existing task or doc are now methods on the value you hold, and\nonly creation stays a top-level function. Removed the top-level Deleting,\nDependingOn, and Changing (and the doc variants DeletingDoc, DeletingDocID,\nDependingOnDoc, DependingOnDocID, CreatingIn, InsertingD\n[…]\nts a decoy task so it isolates\n\"id not found\" from \"queue not found\").\n\nBREAKING CHANGE: external callers of the removed top-level constructors must\nswitch to the fluent methods or NewTaskID/NewDocID.",
          "is_bot": false,
          "headline": "refactor(entroq): fluent-only modify API; Put for docs; queue on the …",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T21:53:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11ef883bced584329cfec06ad4d79014212517e4",
          "body": "…tract\n\nAn arrival time cannot carry Go's zero value across the wire or a direct-pg\nclient (it round-trips into a year-1 timestamp), so \"unset, arrive now\" must be\nexpressed as a value every representation preserves: far in the past. This makes\nthat a uniform backend contract rather than a per-backe\n[…]\nthDocArrivalTime so an explicit time survives the reset.\n- eqtest.TaskChangeFarPastArrivalNormalized runs on all four backends: a\n  far-past arrival comes back capped to now and immediately claimable.",
          "is_bot": false,
          "headline": "fix(entroq): normalize far-past arrival times to now as a backend con…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T16:34:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f5d6abd4f622574854a3d0801c380b69a912e190",
          "body": "The policy matched a request target against grants with\nstartswith(want.exact, can.prefix), and startswith(\"\", \"\") is true, so a caller\nholding a wildcard (empty-prefix) grant could have an operation on an unnamed\nqueue or namespace authorized. There is nothing to hold a grant on, so such a\nrequest \n[…]\nery generated chart file (Rego and CRDs) with\na \"GENERATED FILE. DO NOT EDIT\" banner, so a copied file is not mistaken for an\neditable source. Those copies are gitignored and rebuilt from the sources.",
          "is_bot": false,
          "headline": "fix(authz/opa): deny requests that name an empty queue or namespace",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T15:48:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5fb0aaf5bc1491b39d54ee2238a11eecd68e4139",
          "body": "…gets\n\nmodifyAuthz previously authorized only task queue operations. The document\noperations (DocInserts/DocChanges/DocDeletes/DocDepends) reached the backend\nunauthorized, and Docs/ClaimDocs were not gated at all, so with an authorizer\nconfigured a caller could touch document namespaces it had no r\n[…]\n follow-up that also touches the authz policy/CRD). Time stays open.\n\nAdds eqsvcgrpc_test.go covering op-type completeness, empty-target denial, the\nmove requirement, and empty-destination-as-no-move.",
          "is_bot": false,
          "headline": "fix(eqsvcgrpc): authorize doc operations and fail closed on empty tar…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T15:37:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53b445952772385c7909a557830b18ac810f0258",
          "body": "Queues are EntroQ's authorization boundary, so 9265e53 made the queue part of\nthe modify key in eqmem: a change must name the task's current queue. The gRPC\nservice, though, built each change by setting the task's Queue to the wire's\ndestination (NewData.Queue) and handing it to Changing, which alwa\n[…]\ncMultiOp in\nthe eqgrpc suite failed on the move case until this fix.\n\nAt handling is intentionally unchanged; capping far-past arrival times to\n\"now\" uniformly across backends is a separate follow-up.",
          "is_bot": false,
          "headline": "fix(eqsvcgrpc): carry the true FromQueue through the gRPC change path",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T15:22:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9265e53c3fc760b580c61ded2d37a789870aa760",
          "body": "Queues are EntroQ's authorization boundary, but Modify authorizes the queue\nthe caller names while eqmem located the task by (id, version) and, for\nchanges, always re-derived the real queue from qByID. So a caller who knew a\ntask's id+version could delete or relocate it out of a queue it had no righ\n[…]\ns current\nqueue; a bare (id, version) op with no queue, or a wrong queue, now fails with\na DependencyError. The Task-based helpers (task.Delete/task.Change) already\ncarry the queue and are unaffected.",
          "is_bot": false,
          "headline": "fix(eqmem): reject modify ops whose queue does not match the task",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-11T00:24:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7746f650c3d2717e1c671c70ab55a87dce7a88c1",
          "body": "…n-absent deltas\n\nThe wire protocol has no \"leave this field alone\" marker, so a change should\nexpress the full desired state: the client echoes what it received, edits any\nfield, and the task or doc becomes exactly that, a cleared field included.\n\nThe prior shape layered redundant delta fields (tas\n[…]\nthe source from Task.Queue). Server-managed\nmetadata (created/modified) rides along untouched. Tests cover setting a value\nvia the echoed task, deferring via its At, and the doc-change content update.",
          "is_bot": false,
          "headline": "fix(workgateway): a change carries full desired state, not preserve-o…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-10T18:42:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a1537394f11afac73eceb17929f055b57e0794c",
          "body": "Give docs the same four operations tasks already have (insert, change, delete,\ndepend), so a wire worker's modification vocabulary matches an in-process\nDoModify worker's exactly.\n\n  - docInserts map to InsertingDoc (namespace and key required, id optional).\n  - docChanges carry the full base Doc th\n[…]\ns are fixed up to the renewed value by the existing Finish\nlogic, so a client may echo the version it saw. Doc CLAIMS were already handled\nby the takeDocs phase; this closes the last modification gap.",
          "is_bot": false,
          "headline": "feat(workgateway): add doc modifications for DoModify parity",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-10T14:39:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0321cbffbf48816dbc652d9f5c1f45632b0855af",
          "body": "Complete task-level modification support by adding changes alongside inserts,\ndeletes, and depends, so a wire worker can express the full protocol.\n\nA change carries the FULL base task (the client echoes the task it received in\ndoWork) plus deltas, rather than a bare ref. Carrying the whole task is \n[…]\nnsistent end to end: the entroq.Task a client receives in\ndoWork is the same shape it echoes back to change. Doc modifications remain the\none reserved follow-up (doc claims already work via takeDocs).",
          "is_bot": false,
          "headline": "feat(workgateway): support task changes in the wire modification",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-10T14:31:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74f9d6ba0e3089bbf68b669951b7d44ef969bbde",
          "body": "…ire message\n\nRegistration (queues, max-attempts, and which phases the worker implements) is\nconnection-scoped and fixed for a session, so it belongs in the connection\npreamble each transport already has, not in an in-band handshake. Flags-at-spawn\nare to a pipe process what URL params/headers are t\n[…]\n=1&...).\n  - Work is now a declared capability like the others. Run fails loudly on a\n    registration with no queues or no work handler rather than silently churning\n    tasks a worker cannot act on.",
          "is_bot": false,
          "headline": "feat(workgateway,eqlink): register out-of-band via flags/URL, not a w…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-10T14:27:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6cfac2868079b33ee455eb21e51dc5ad2dbd952",
          "body": "…ocol\n\nGrow the eqlink work gateway from a work-only skeleton into the full\nlifecycle protocol described in the Worker-Gateway proposal, so a worker\nin any language is a thin JSON client while eqlink runs the hard loop.\n\nProtocol (protocol.go, the single source of truth for the wire):\n\n  - The clien\n[…]\nnly\n\"work\"/\"result-with-implicit-delete\" skeleton is replaced by the register +\ntakeDocs/doWork/cleanup/done protocol, and Bridge.DoWork is replaced by\nBridge.Run. This component is unreleased (v0.x).",
          "is_bot": false,
          "headline": "feat(workgateway,eqlink)!: full register/take-work-clean gateway prot…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-10T01:19:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddb93dd598518aeda897868df2311eb2ccc78d00",
          "body": "…nish\n\nHandlers no longer receive an EntroQ client in the work phases. TakeDocs\nand DoWork get no client at all, and Finish now takes a narrow\nworker.Modifier (Modify only) instead of the full *entroq.EntroQ. This\nmakes the safe capability explicit: only the post-renewal Finish may\ncommit, so a hand\n[…]\nandler.Finish and WithFinish now take a worker.Modifier\ninstead of *entroq.EntroQ; DoModifyRun returns *worker.Result instead of\n[]entroq.ModifyArg; worker.NoWork and the DoFinishRun type are removed.",
          "is_bot": false,
          "headline": "feat(worker)!: Result + OnSuccess for DoModify; Modifier client in Fi…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-09T23:05:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d6cebb749659af174bf3993a402dbfdc2b81ac7",
          "body": "Extract a context-aware Conn seam (Send/Recv one JSON message) so the Bridge is\ntransport-agnostic: stdio is PipeConn, WebSocket is WSConn (coder/websocket +\nwsjson). `eqlink work --addr` serves /work?queue=..., running one worker.Run\nper connection over a WSConn Bridge; without --addr it stays stdi\n[…]\non drop detection (keepalive ping) still to come. go.mod lists\ncoder/websocket as indirect because a repo-wide 'go mod tidy' is blocked by a\npre-existing unrelated broken import in cmd/eqk8s/test/e2e.",
          "is_bot": false,
          "headline": "wip(eqlink): WebSocket transport for the work gateway",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-08T19:29:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "243ee013c224c8ba97535ab477f0e50011727421",
          "body": "Walking skeleton of the eqlink work gateway. A stdio transport claims tasks and\ndrives a language-agnostic worker over newline-delimited JSON: per task it sends\n{\"type\":\"work\",\"task\":<entroq.Task>} to stdout and reads one\n{\"type\":\"result\",\"outcome\":\"ok|retry|move|fatal\"} from stdin. \"ok\"\nconsumes th\n[…]\native modifications land, WebSocket transport still to come.\nAlso routes eqlink command errors to stderr so stdout carries only the protocol.\nNo version bump; ships with the eqlink work release later.",
          "is_bot": false,
          "headline": "wip(eqlink): worker gateway skeleton (eqlink work over stdio)",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-08T19:00:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a57c1afc554fdc4ba011cd087c9ed78a60ea0a6",
          "body": "Replace the RetryError/MoveError/FatalError sentinels with concrete error types\ndetected via AsRetry/AsMove/AsFatal (mirroring entroq.AsDependency). RetryError\ngains fluent per-failure overrides: After(d) for the retry delay (in place of\nWithBaseRetryDelay) and OrMoveTo(q) for the quarantine queue o\n[…]\nor API (no external consumers); migrates all\nin-tree callers and updates conformance expectations, whose messages no longer\ncarry the old sentinel-text suffix. No schema change; version bump deferred.",
          "is_bot": false,
          "headline": "feat(worker)!: structured Retry/Move/Fatal errors with fluent options",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-08T16:26:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a88a2d7263e23bd19bfabdabfb55beefd2aa6b4",
          "body": null,
          "is_bot": false,
          "headline": "chore: prepare release v1.6.3",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-08T14:48:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "837fe88519dfb4d1248593b6b04e403bb538c82a",
          "body": "… into handoff\n\nThe worker that moves tasks between EntroQ instances is direction-neutral: it\nclaims from a source and delivers to a destination, exactly once. Rename the\npackage pullworker -> handoffworker to name the operation rather than one\nvantage (pullHandler -> handoffHandler), and replace th\n[…]\n-> defaultGraveyard (the public surface stays\nWorker/Run/options) and factors localEQ into a reusable openEntroq. Zero\nexternal consumers and unchanged eqlink service behavior, so it rides as a patch.",
          "is_bot": false,
          "headline": "refactor(eqlink): rename pullworker to handoffworker; unify push/pull…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-08T14:48:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5ebd3d3ceade184b26e9eaa88860826012d74b5c",
          "body": "…tate\n\nmakeHandler now runs once per task inside runOne instead of once per Run, so\nper-task handler state is fresh by construction and can no longer leak across\nthe Run loop. The previous behavior isolated concurrent Run calls but not\nindividual tasks, an accidental footgun: variable sharing betwee\n[…]\ntopped and could\nnot retry cleanly. It drops the caller-side insertion-order guard in favor of the\norder contract already pinned by eqtest, and renames the exported TombstoneQueue\nto DefaultGraveyard.",
          "is_bot": false,
          "headline": "fix(worker): construct a fresh handler per task, isolating per-task s…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-08T13:49:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6c7a0a0db93928c58e964663e636188e55e8e7e6",
          "body": "Records the versions actually shipped to PyPI (0.12.2) and npm (0.11.1)\ncarrying the Apache-2.0 license fix. No metadata change; the corrective\nlicense work is already in 3b0506d.",
          "is_bot": false,
          "headline": "chore(release): sync client versions to published (py 0.12.2, js 0.11.1)",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-07T02:21:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b0506d4eea1b4232ebf73378c08338298b06dbb",
          "body": "The Python, JS, and Elixir clients declared MIT in their package\nmanifests while the repository is licensed Apache-2.0 (see LICENSE).\nA conflicting license claim misinforms downstream users, so align all\nthree published packages with the repo license and bundle the license\ntext into each client dir so it ships in the built artifacts.",
          "is_bot": false,
          "headline": "fix(clients): correct license metadata to Apache-2.0",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-07T01:55:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d85f4f863bf6d09ef6b74a35d59e2285c866a42b",
          "body": "python -m build appends to dist/ and twine upload dist/* globs everything,\nso prior versions' artifacts linger and get re-uploaded, aborting on PyPI's\nimmutable-version rule. Clear dist/ at the start of the in-container build\n(root removes its own prior output, which also drops the root-owned-leftover\nannoyance) and add --skip-existing so a retry after a partial upload is\nidempotent.",
          "is_bot": false,
          "headline": "chore(release): clean dist/ before build in publish-py.sh",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T22:01:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b85436b976dffe94109bcfe9b0c9e47eb8df544",
          "body": null,
          "is_bot": false,
          "headline": "chore: prepare release v1.6.1",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T21:54:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1fb50a713b1ec4b91cface4291006400b24e433c",
          "body": "The experimental direct-PostgreSQL client formatted claim and doc-claim\nTTLs as bare-milliseconds interval literals, which Postgres rejects once\nthe integer exceeds int32 (~24.8 days) with SQLSTATE 22015. It is the same\nclass of bug just fixed in the Go eqpg backend, only at a higher threshold\nbecau\n[…]\nle seconds plus\na milliseconds remainder so no interval field overflows, and use it in\ntry_claim and claim_docs. Add test_claim_long_duration (claim for ~30\ndays): red before this change, green after.",
          "is_bot": false,
          "headline": "fix(py/pg): format claim durations to avoid Postgres interval overflow",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T21:31:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc5abf801ed9a739426a0578365144d0715395cf",
          "body": "…es intervals\n\neqpg passed claim and doc-claim durations, and the readiness watermark,\nto Postgres as interval literals spelled entirely in microseconds. The\ninterval parser rejects any single field integer above int32, so a claim\nlonger than ~35.8 minutes (INT32_MAX microseconds) failed with SQLSTA\n[…]\nnotify_ready_queues.\n\nAdd the ClaimLongDuration conformance vector (claim for an hour, assert\nthe lease extends into the future): red on eqpg before this change, green\non eqmem and eqredis throughout.",
          "is_bot": false,
          "headline": "fix(eqpg): format claim durations so long TTLs do not overflow Postgr…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T21:21:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b51d47aff1c2b7e5e95dc2e90e67e677b28fe1aa",
          "body": "Tasks applied Limit before the claimant filter, so a claimant listing\ncould return fewer than Limit matches, even zero, while matching tasks\nsat behind a wall of tasks claimed by other workers. Rework Tasks into\nthree paths:\n\n  - by-ID: fetch the hashes, filter, then cap the results.\n  - no-claimant\n[…]\nment the Claimant/Limit contract on TasksQuery, which no test or\nfield comment previously pinned down. Includes an opt-in listing\nbenchmark alongside the contention benchmark (ENTROQ_REDIS_LISTING=1).",
          "is_bot": false,
          "headline": "fix(eqredis): honor min(Limit,#matching) in claimant-filtered Tasks",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T21:08:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a63ee639443c62eaae4839dab3072852b187c96",
          "body": "Collapse the claim path from ~4 round-trips (ZRANGEBYSCORE, WATCH,\nHGETALL, MULTI/EXEC) to a single EVALSHA. Redis's single thread\nserializes concurrent claimers, removing the optimistic-retry loop the\nGo version needed.\n\nAnti-starvation is preserved: the script still picks uniformly among\nthe lowes\n[…]\ndeterministic; the winner is tracked by lexical ID with a two-sided\nband, which catches lowest- or highest-ID determinism that an\ninsertion-order check would miss. Passes for eqmem, eqpg, and eqredis.",
          "is_bot": false,
          "headline": "feat(eqredis): atomic Lua TryClaim, replacing WATCH/MULTI retries",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T20:17:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ecee17e322e81587ed60fb220e0eeea182b27b38",
          "body": "…l.pg\n\nThe direct-Postgres client is a full backend reimplemented in Python (it calls\nthe same stored procedures as the Go eqpg backend), which makes it a\nmaintenance-sensitive surface. Move it under a new entroq.experimental namespace\nwhose contract is explicit: no stability guarantee, may change o\n[…]\ns unchanged and remains the stable, supported path.\n\nVerified: schemas byte-identical; go build/vet + TestSchemaFilesInSync pass;\nPython 0.12.0 wheel builds, twine check clean, full suite (48) passes.",
          "is_bot": false,
          "headline": "refactor(py): move the direct-PostgreSQL client to entroq.experimenta…",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T18:27:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd3438b95339cc754787dc4964592cba359c5a32",
          "body": "entroq 0.11.0 is now on npm as well as PyPI; add the npm install to the README.\nRecord in RELEASE.md that both client publishes run non-interactively, so PyPI\nneeds an account-scoped token for a first publish and npm needs an Automation\n(or 2FA-bypass granular) token -- the plain publish token fails with E403.",
          "is_bot": false,
          "headline": "docs: JS client on npm; record publish-token requirements",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T15:51:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ce38d75ec3f51acee9ed3f35297c1bfd75afc7c",
          "body": "npm warned and auto-corrected repository.url on publish; set it explicitly so\nthe publish is warning-clean.",
          "is_bot": false,
          "headline": "chore(js): normalize repository.url to git+https form",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-06T15:45:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec1be5d92ce32923c5baa4713c2a3f484343611b",
          "body": "entroq 0.11.0 is now on PyPI; make pip install entroq the primary install (with\nthe [pg] extra for the direct-PostgreSQL backend), and keep the git+subdirectory\nform for unreleased versions.",
          "is_bot": false,
          "headline": "docs: install the Python client from PyPI",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-04T21:12:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fb2f911ac3a3b6b34001c8b7dab4da88994b22d7",
          "body": "pyproject declared readme = \"README.md\" but the file was missing, so the built\npackage had no long_description (twine check warned) and the PyPI page would be\nblank. Add a concise client README (install, the JSON vs direct-PostgreSQL\nflavors, a worker quick-start) ahead of the first PyPI publish.",
          "is_bot": false,
          "headline": "docs(py): add package README for the PyPI project page",
          "author_name": "Chris Monson",
          "author_login": "shiblon",
          "committed_at": "2026-07-04T17:02:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 2,
      "commits_last_year": 273,
      "latest_release_at": "2026-07-21T15:57:48Z",
      "latest_release_tag": "v1.8.0",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 15,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 4.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 57,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/shiblon/entroq",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/shiblon/entroq",
          "is_deprecated": false,
          "latest_version": "v1.8.0",
          "repository_url": "https://github.com/shiblon/entroq",
          "versions_count": 90,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-21T15:53:33Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 6,
      "stars": 24,
      "watchers": 4,
      "fork_history": {
        "days": [
          {
            "date": "2020-03-16",
            "count": 1
          },
          {
            "date": "2022-03-07",
            "count": 1
          },
          {
            "date": "2022-10-24",
            "count": 1
          },
          {
            "date": "2023-03-12",
            "count": 1
          },
          {
            "date": "2026-06-15",
            "count": 1
          },
          {
            "date": "2026-07-09",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 6,
        "total_forks": 6
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "example",
        "examples",
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "cmd/eqk8s/Makefile"
      ],
      "api_schema_files": [
        "api/entroq.proto",
        "api/openapi.yaml"
      ],
      "has_devcontainer": true,
      "typecheck_configs": [
        "clients/js/tsconfig.json"
      ],
      "toolchain_manifests": [
        "clients/elixir/mix.exs",
        "go.mod"
      ],
      "largest_source_bytes": 102925,
      "source_files_sampled": 228,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        "AGENTS.md",
        "cmd/eqk8s/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 3260
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.80.0",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          },
          {
            "name": "github.com/docker/docker",
            "direct": false,
            "version": "v28.5.2+incompatible",
            "severity": "high",
            "ecosystem": "go",
            "cvss_score": 8.8,
            "advisory_ids": [
              "GHSA-pxq6-2prw-chj9",
              "GHSA-rg2x-37c3-w2rh",
              "GHSA-vp62-88p7-qqf5",
              "GHSA-x744-4wpc-v9h2",
              "GHSA-x86f-5xw2-fm2r",
              "GO-2026-4883",
              "GO-2026-4887",
              "GO-2026-5617",
              "GO-2026-5668",
              "GO-2026-5746"
            ],
            "fixed_version": "29.3.1",
            "advisory_count": 10,
            "oldest_advisory_days": 116
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 1,
          "unknown": 1,
          "critical": 1
        },
        "advisory_count": 12,
        "affected_count": 3,
        "assessed_count": 344,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 2,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "connectrpc.com/connect",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.19.1"
        },
        {
          "name": "connectrpc.com/vanguard",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.4.0"
        },
        {
          "name": "github.com/golang-jwt/jwt/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.3.1"
        },
        {
          "name": "github.com/golang/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.4"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/lib/pq",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.12.1"
        },
        {
          "name": "github.com/open-policy-agent/opa",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.4.0"
        },
        {
          "name": "github.com/prometheus/client_golang",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.23.2"
        },
        {
          "name": "github.com/shiblon/stuffedio",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.8.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.0"
        },
        {
          "name": "github.com/spf13/viper",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.21.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.41.0"
        },
        {
          "name": "github.com/testcontainers/testcontainers-go/modules/postgres",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.41.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/prometheus",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.65.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.43.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        },
        {
          "name": "google.golang.org/genproto/googleapis/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260223185530-2f722ef697dc"
        },
        {
          "name": "google.golang.org/grpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.80.0"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.11"
        },
        {
          "name": "gopkg.in/yaml.v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.4.0"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.15"
        },
        {
          "name": "github.com/google/btree",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.3"
        },
        {
          "name": "github.com/onsi/ginkgo/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.28.3"
        },
        {
          "name": "github.com/onsi/gomega",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.40.0"
        },
        {
          "name": "github.com/redis/go-redis/v9",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v9.18.0"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.35.0"
        },
        {
          "name": "sigs.k8s.io/controller-runtime",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.23.3"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "connectrpc.com/connect",
            "direct": true,
            "version": "v1.19.1",
            "ecosystem": "go"
          },
          {
            "name": "connectrpc.com/vanguard",
            "direct": true,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coder/websocket",
            "direct": true,
            "version": "v1.8.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": true,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang/protobuf",
            "direct": true,
            "version": "v1.5.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/btree",
            "direct": true,
            "version": "v1.1.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lib/pq",
            "direct": true,
            "version": "v1.12.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/onsi/ginkgo/v2",
            "direct": true,
            "version": "v2.28.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/onsi/gomega",
            "direct": true,
            "version": "v1.40.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/open-policy-agent/opa",
            "direct": true,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": true,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/redis/go-redis/v9",
            "direct": true,
            "version": "v9.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shiblon/stuffedio",
            "direct": true,
            "version": "v0.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/viper",
            "direct": true,
            "version": "v1.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go",
            "direct": true,
            "version": "v0.41.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/testcontainers/testcontainers-go/modules/postgres",
            "direct": true,
            "version": "v0.41.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": true,
            "version": "v0.65.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": true,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": true,
            "version": "v0.0.0-20260223185530-2f722ef697dc",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": true,
            "version": "v1.80.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.11",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": true,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/controller-runtime",
            "direct": true,
            "version": "v0.23.3",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.1",
            "ecosystem": "go"
          },
          {
            "name": "dario.cat/mergo",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/agnivade/levenshtein",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr4-go/antlr/v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/go-ansiterm",
            "direct": false,
            "version": "v0.0.0-20250102033503-faa5f7b0171c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blang/semver/v4",
            "direct": false,
            "version": "v4.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v4",
            "direct": false,
            "version": "v4.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs/pkg",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/log",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/platforms",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cpuguy83/dockercfg",
            "direct": false,
            "version": "v0.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dgryski/go-rendezvous",
            "direct": false,
            "version": "v0.0.0-20200823014737-9f7001d12a5f",
            "ecosystem": "go"
          },
          {
            "name": "github.com/distribution/reference",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/docker",
            "direct": false,
            "version": "v28.5.2+incompatible",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-connections",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-units",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ebitengine/purego",
            "direct": false,
            "version": "v0.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.12.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/evanphx/json-patch/v5",
            "direct": false,
            "version": "v5.9.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fsnotify/fsnotify",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ini/ini",
            "direct": false,
            "version": "v1.67.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/zapr",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-ole/go-ole",
            "direct": false,
            "version": "v1.2.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.21.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.20.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.23.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-task/slim-sprig/v3",
            "direct": false,
            "version": "v3.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobwas/glob",
            "direct": false,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/cel-go",
            "direct": false,
            "version": "v0.26.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/pprof",
            "direct": false,
            "version": "v0.0.0-20260402051712-545e8a4df936",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gorilla/mux",
            "direct": false,
            "version": "v1.8.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.28.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/josharian/intern",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lufia/plan9stats",
            "direct": false,
            "version": "v0.0.0-20211012122336-39d0f177ccd0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/magiconair/properties",
            "direct": false,
            "version": "v1.8.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mailru/easyjson",
            "direct": false,
            "version": "v0.7.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/masterminds/semver/v3",
            "direct": false,
            "version": "v3.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/docker-image-spec",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/go-archive",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/patternmatcher",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/sequential",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/user",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/sys/userns",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/term",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/morikuni/aec",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/go-digest",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/image-spec",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pelletier/go-toml/v2",
            "direct": false,
            "version": "v2.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/power-devops/perfstat",
            "direct": false,
            "version": "v0.0.0-20240221224432-82ca36839d55",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": false,
            "version": "v0.67.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rcrowley/go-metrics",
            "direct": false,
            "version": "v0.0.0-20200313005456-10cdbea86bc0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sagikazarmark/locafero",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/shirou/gopsutil/v4",
            "direct": false,
            "version": "v4.26.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sirupsen/logrus",
            "direct": false,
            "version": "v1.9.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/sourcegraph/conc",
            "direct": false,
            "version": "v0.3.1-0.20240121214520-5f936abd7ae8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/afero",
            "direct": false,
            "version": "v1.15.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stoewer/go-strcase",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": false,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/subosito/gotenv",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tchap/go-patricia/v2",
            "direct": false,
            "version": "v2.3.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/go-sysconf",
            "direct": false,
            "version": "v0.3.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tklauser/numcpus",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xeipuuv/gojsonpointer",
            "direct": false,
            "version": "v0.0.0-20190905194746-02993c407bfb",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xeipuuv/gojsonreference",
            "direct": false,
            "version": "v0.0.0-20180127040603-bd5ef7bd5415",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yashtewari/glob-intersection",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yusufpapurcu/wmi",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": false,
            "version": "v0.61.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.41.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": false,
            "version": "v1.35.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": false,
            "version": "v1.43.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": false,
            "version": "v1.27.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.4",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20240719175910-8a7402abbf56",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.57.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": false,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.11.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "gomodules.xyz/jsonpatch/v2",
            "direct": false,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260223185530-2f722ef697dc",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiserver",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/component-base",
            "direct": false,
            "version": "v0.35.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": false,
            "version": "v2.130.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20250910181357-589584f1c912",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": false,
            "version": "v0.0.0-20251002143259-bc988d571ff4",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/apiserver-network-proxy/konnectivity-client",
            "direct": false,
            "version": "v0.31.2",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.2-0.20260122202528-d9cc6641c482",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.28.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/core",
            "direct": false,
            "version": "1.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/wasi-threads",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/wasm-runtime",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@oxc-project/types",
            "direct": false,
            "version": "0.133.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-android-arm64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-arm64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-darwin-x64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-freebsd-x64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-arm64-musl",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-gnu",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-linux-x64-musl",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-openharmony-arm64",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-wasm32-wasi",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/binding-win32-x64-msvc",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/pluginutils",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm-eabi",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-arm64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-x64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-arm64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-x64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-gnueabihf",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-musleabihf",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-musl",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-musl",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-musl",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-musl",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-s390x-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-musl",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openbsd-x64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openharmony-arm64",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-arm64-msvc",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-ia32-msvc",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-gnu",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-msvc",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "@standard-schema/spec",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tybys/wasm-util",
            "direct": false,
            "version": "0.10.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "any-promise",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "bundle-require",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "cac",
            "direct": false,
            "version": "6.7.14",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "chokidar",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "confbox",
            "direct": false,
            "version": "0.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "consola",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "fix-dts-default-cjs-exports",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "joycon",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-android-arm64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-arm64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-x64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-freebsd-x64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-gnu",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-musl",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-gnu",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-musl",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-arm64-msvc",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-x64-msvc",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lilconfig",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "load-tsconfig",
            "direct": false,
            "version": "0.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "mlly",
            "direct": false,
            "version": "1.8.2",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mz",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "obug",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pirates",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pkg-types",
            "direct": false,
            "version": "1.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.15",
            "ecosystem": "npm"
          },
          {
            "name": "postcss-load-config",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "readdirp",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "rolldown",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "rollup",
            "direct": false,
            "version": "4.60.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "sucrase",
            "direct": false,
            "version": "3.35.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "thenify",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "thenify-all",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "tree-kill",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ts-interface-checker",
            "direct": false,
            "version": "0.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tsup",
            "direct": false,
            "version": "8.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "ufo",
            "direct": false,
            "version": "1.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "8.0.16",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "4.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "psycopg",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "setuptools",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 346,
        "direct_count": 31,
        "indirect_count": 315
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 42,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 18,
        "closed_unmerged_prs": 19
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "shiblon",
          "commits": 712,
          "avatar_url": "https://avatars.githubusercontent.com/u/2344944?v=4"
        },
        {
          "type": "User",
          "login": "deardooley",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/785202?v=4"
        },
        {
          "type": "User",
          "login": "zahmadsaleem",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/11913101?v=4"
        },
        {
          "type": "User",
          "login": "ButchIstook",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/54079471?v=4"
        }
      ],
      "contributors_sampled": 4,
      "top_contributor_share": 0.99
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "mix.lock",
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d0eeae542542713b32220b41bf5d136792b93f94",
        "ran_at": "2026-07-22T10:18:53Z",
        "aggregate_score": 3.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": null,
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-04T16:35:48Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/shiblon/entroq",
    "host": "github.com",
    "name": "entroq",
    "owner": "shiblon"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 61,
      "inputs": {
        "security": 44,
        "vitality": 84,
        "community": 49,
        "governance": 57,
        "engineering": 64
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "commits_last_year": 273,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 15
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "15/52 weeks with commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 15
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "273 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 273
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 2,
              "latest_release_tag": "v1.8.0",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 4.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "2 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~4.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 4.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 49,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 31,
            "inputs": {
              "forks": 6,
              "stars": 24,
              "watchers": 4,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "24 stars",
                "points": 22.1,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 24
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "6 forks",
                "points": 5.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "4 watchers",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 57,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 18,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 4,
              "top_contributor_share": 0.99
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.2,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "4 contributors",
                "points": 5.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "merged_prs": 42,
              "open_issues": 0,
              "closed_issues": 18,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 19
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 46.8,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "42/61 decided PRs merged",
                "points": 26.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 42,
                      "decided": 61
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 53,
            "inputs": {
              "followers": 27,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "shiblon",
              "public_repos": 23,
              "account_age_days": 5059
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "27 followers of shiblon",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 27,
                      "login": "shiblon"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "23 public repos, account ~13 yr old",
                "points": 22.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 23
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/shiblon/entroq"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "90 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 90
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 64,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 50,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "message-queue",
                "task-manager",
                "task-queue",
                "competing-consumers",
                "asynchronous-tasks",
                "golang",
                "postgresql",
                "grpc",
                "taskmaster",
                "workflow-engine"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 44,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Signed-Releases, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "signed_releases",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 38,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 13,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 5,
              "scorecard_aggregate": 3.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 344 resolved dependencies against OSV; 2 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 344
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 2
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "source": "osv",
              "advisories": 12,
              "affected_packages": 3,
              "assessed_packages": 344,
              "unassessed_packages": 2,
              "affected_by_severity": "critical 1, high 1, unknown 1",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: google.golang.org/grpc v1.80.0 (critical 9.1)",
                "points": 9.5,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "google.golang.org/grpc v1.80.0 (critical 9.1)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 344,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 5
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 81,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "cmd/eqk8s/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 3260
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, cmd/eqk8s/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, cmd/eqk8s/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "mix.lock",
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "cmd/eqk8s/Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "clients/js/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "clients/elixir/mix.exs",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, cmd/eqk8s/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, cmd/eqk8s/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "clients/js/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "clients/js/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 102925,
              "source_files_sampled": 228,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/228 source files over 60KB",
                "points": 54.8,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 228,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "example",
                "examples",
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "api/entroq.proto",
                "api/openapi.yaml"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "api/entroq.proto, api/openapi.yaml",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "api/entroq.proto, api/openapi.yaml"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "example, examples, samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "example, examples, samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T10:19:05.554729Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/shiblon/entroq.svg",
  "full_name": "shiblon/entroq",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.