公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 02:12 UTC

tektoncd / pipelines-as-code

Pipelines-as-Code for Tekton

GoApache-2.0★ 203 星标⑂ 135 复刻始于 2021年4月在 GitHub 上查看 ↗

tektoncd/pipelines-as-code 的健康指数为 100 分中的 79 分,处于「良好」区间。 其得分最高的类别是Engineering Quality(96/100),最低的是Security(62/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

79
总分 / 100
良好

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

79
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Tekton组织
1,421 关注者24 个公开仓库始于 2019年2月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/openshift-pipelines/pipelines-as-code指向其他仓库——不计分v0.49.0-11315 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

95优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
35.3/36提交节奏 — 52 周中有 51 周有提交
18/18提交量 — 最近一年 575 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year575
human_commit_share0.9
days_since_last_push0
active_weeks_last_year51

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 100 个发布版本
36/36发布时效 — 最近一次发布版本于 4 天前
27/27发布节奏 — 约每 5.8 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count100
latest_release_tagv0.48.1
releases_from_tags
days_since_latest_release4
mean_days_between_releases5.8

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

75良好 · 占总体的 18%
评分方式
37.4/60星标 — 203 个星标
17.7/25复刻 — 135 个复刻
5/15关注者 — 9 位关注者
所用输入
forks135
stars203
watchers9
growth_stateorganic
growth_factor_pct100

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

65中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
5/22.5提交分布 — 头号贡献者编写了 78% 的提交
13.5/13.5贡献者广度 — 59 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 33 contributing companies or organizations
所用输入
bus_factor1
contributors_sampled59
top_contributor_share0.776
评分方式
41.1/46.8议题解决 — 88% 的议题已关闭
34/38.3PR 接受 — 已裁定的 PR 中 2,014/2,266 已合并
12/15OpenSSF Scorecard:Code-Review — Found 17/20 approved changesets -- score normalized to 8
所用输入
merged_prs2,014
open_issues70
closed_issues515
issue_closed_ratio0.88
closed_unmerged_prs252
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
22.7/25所有者影响力 — tektoncd 有 1,421 位关注者
22.2/25既往记录 — 24 个公开仓库,账户约 7 年
所用输入
followers1,421
owner_typeOrganization
is_verified
owner_logintektoncd
public_repos24
account_age_days2,715

工程质量

基础的工程与文档实践是否到位?

96优秀 · 占总体的 20%

工程实践

94优秀
评分方式
24/24CI 工作流 — 3 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yaml, .golangci.yml, .pylintrc
9.6/9.6Pre-commit 钩子
6.4/6.4.editorconfig
14/20OpenSSF Scorecard:CI-Tests — 18 out of 24 merged PRs checked by a CI test -- score normalized to 7
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

100优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://pipelinesascode.com
10/10仓库描述
10/10主题标签 — 11 个主题标签
10/10Wiki
所用输入
topicstekton-pipelines, tekton, github, pipeline, kubernetes, continuous-delivery, pipelines-as-code, gitlab, ci, bitbucket, gitops
has_wiki
homepagehttps://pipelinesascode.com
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

62中等 · 占总体的 16%

安全态势

56中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
1.8/2.5CI-Tests — 18 out of 24 merged PRs checked by a CI test -- score normalized to 7
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
6/7.5Code-Review — Found 17/20 approved changesets -- score normalized to 8
2.5/2.5Contributors — project has 33 contributing companies or organizations
0/10Dangerous-Workflow — dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
6/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate5.7
已排除计分(无数据或不适用):packaging。 其余权重已重新归一化。
评分方式
26.6/35直接依赖不含已知公告 — 1 个受影响:github.com/tektoncd/pipeline v1.14.0 (unknown)
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
37.2/40没有长期未处理的公告 — 1 个携带公告的软件包超过 90 天未处理;最早一条发布于 700 天前
所用输入
sourceosv
advisories4
affected_packages3
assessed_packages156
unassessed_packages7
affected_by_severitycritical 1, unknown 2
direct_affected_packages1
已排除计分(无数据或不适用):间接依赖不含已知公告。 其余权重已重新归一化。 已将 156 个已解析依赖与 OSV 比对。 有 7 项无法评估——没有已解析的版本、生态系统不受支持,或超出所报告的软件包清单。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

96优秀 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md
15/15机器可读文档(llms.txt) — 存在 llms.txt
40/40可读的提交历史 — 90 次人类提交中有 90 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md
agent_instruction_max_bytes12,245
评分方式
18/18一条命令的引导启动 — Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yaml, .golangci.yml, .pylintrc
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 26 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 10 次为自动依赖更新
7/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.26
toolchain_manifestsdocs/go.mod, go.mod
dependency_bot_commit_share0.1
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.7/55可控的文件大小 — 采样的 518 个源文件中有 3 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes92,818
source_files_sampled518
oversized_source_files3
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto
0/20MCP 服务器
40/40可运行示例 — samples
所用输入
example_dirssamples
has_mcp_signal
api_schema_filesvendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto

关键数据

203GitHub 星标
59贡献者
575最近 12 个月提交数
0距最近推送天数
100发布版本数
1巴士系数(bus factor)
70开放议题
Go软件包生态系统数

数据采集警告

  • go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring

更多细节

Star 与 Fork 历史 203 ★ / 135 ⇿
203Star
135Fork
100发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

0408012016020024020312962021-042023-112026-07
主版本 0次版本 34修订 66

每个点涵盖 5 天。

OpenSSF Scorecard 5.7 / 10
5.7综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 02:12 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
7CI-Tests18 out of 24 merged PRs checked by a CI test -- score normalized to 7
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
8Code-ReviewFound 17/20 approved changesets -- score normalized to 8
10Contributorsproject has 33 contributing companies or organizations
0Dangerous-Workflowdangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
8Token-Permissionsdetected GitHub workflow tokens with excessive permissions
6Vulnerabilities4 existing vulnerabilities detected
直接依赖 54
注册表软件包版本约束清单文件
Gocodeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3v3.0.0go.mod
Gogithub.com/AlecAivazis/survey/v2v2.3.7go.mod
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.18.0go.mod
Gogithub.com/chzyer/readlinev1.5.1go.mod
Gogithub.com/cloudevents/sdk-go/v2v2.16.2go.mod
Gogithub.com/fvbommel/sortorderv1.1.0go.mod
Gogithub.com/gobwas/globv0.2.3go.mod
Gogithub.com/google/cel-gov0.29.2go.mod
Gogithub.com/google/go-cmpv0.7.0go.mod
Gogithub.com/google/go-github/scrapev0.0.0-20260403152401-96a365122246go.mod
Gogithub.com/google/go-github/v84v84.0.0go.mod
Gogithub.com/google/go-github/v85v85.0.0go.mod
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16bgo.mod
Gogithub.com/jenkins-x/go-scmv1.15.31go.mod
Gogithub.com/jonboulle/clockworkv0.5.0go.mod
Gogithub.com/juju/ansitermv1.0.0go.mod
Gogithub.com/ktrysmt/go-bitbucketv0.10.0go.mod
Gogithub.com/mattn/go-colorablev0.1.15go.mod
Gogithub.com/mattn/go-isattyv0.0.23go.mod
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957dgo.mod
Gogithub.com/mitchellh/mapstructurev1.5.0go.mod
Gogithub.com/pkg/errorsv0.9.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/stretchr/testifyv1.11.1go.mod
Gogithub.com/tektoncd/pipelinev1.14.0go.mod
Gogitlab.com/gitlab-org/api/client-gov1.46.0go.mod
Gogo.opentelemetry.io/otelv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0go.mod
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0go.mod
Gogo.opentelemetry.io/otel/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdkv1.44.0go.mod
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0go.mod
Gogo.opentelemetry.io/otel/tracev1.44.0go.mod
Gogo.uber.org/zapv1.28.0go.mod
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/syncv0.22.0go.mod
Gogolang.org/x/textv0.40.0go.mod
Gogopkg.in/yaml.v2v2.4.0go.mod
Gogotest.tools/v3v3.5.2go.mod
Gok8s.io/apiv0.36.2go.mod
Gok8s.io/apimachineryv0.36.2go.mod
Gok8s.io/client-gov0.36.2go.mod
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5go.mod
Goknative.dev/eventingv0.49.2go.mod
Goknative.dev/pkgv0.0.0-20260622140654-39ebae2ee2dcgo.mod
Gosigs.k8s.io/yamlv1.6.0go.mod
Gogithub.com/golang-jwt/jwt/v4v4.5.2go.mod
Gogithub.com/prometheus/client_modelv0.6.2go.mod
Gogithub.com/prometheus/commonv0.69.0go.mod
Gogolang.org/x/termv0.45.0go.mod
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaago.mod
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996afgo.mod
Gok8s.io/klog/v2v2.140.0go.mod
全部依赖 163

来自 GitHub 依赖图的完整解析依赖集合:54 个直接依赖与 109 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gocodeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3v3.0.0直接
Gogithub.com/alecaivazis/survey/v2v2.3.7直接
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.18.0直接
Gogithub.com/chzyer/readlinev1.5.1直接
Gogithub.com/cloudevents/sdk-go/v2v2.16.2直接
Gogithub.com/fvbommel/sortorderv1.1.0直接
Gogithub.com/gobwas/globv0.2.3直接
Gogithub.com/golang-jwt/jwt/v4v4.5.2直接
Gogithub.com/google/cel-gov0.29.2直接
Gogithub.com/google/go-cmpv0.7.0直接
Gogithub.com/google/go-github/scrapev0.0.0-20260403152401-96a365122246直接
Gogithub.com/google/go-github/v84v84.0.0直接
Gogithub.com/google/go-github/v85v85.0.0直接
Gogithub.com/hako/durafmtv0.0.0-20210608085754-5c1018a4e16b直接
Gogithub.com/jenkins-x/go-scmv1.15.31直接
Gogithub.com/jonboulle/clockworkv0.5.0直接
Gogithub.com/juju/ansitermv1.0.0直接
Gogithub.com/ktrysmt/go-bitbucketv0.10.0直接
Gogithub.com/mattn/go-colorablev0.1.15直接
Gogithub.com/mattn/go-isattyv0.0.23直接
Gogithub.com/mgutz/ansiv0.0.0-20200706080929-d51e80ef957d直接
Gogithub.com/mitchellh/mapstructurev1.5.0直接
Gogithub.com/pkg/errorsv0.9.1直接
Gogithub.com/prometheus/client_modelv0.6.2直接
Gogithub.com/prometheus/commonv0.69.0直接
Gogithub.com/spf13/cobrav1.10.2直接
Gogithub.com/stretchr/testifyv1.11.1直接
Gogithub.com/tektoncd/pipelinev1.14.0直接
Gogitlab.com/gitlab-org/api/client-gov1.46.0直接
Gogo.opentelemetry.io/otelv1.44.0直接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpcv1.44.0直接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttpv1.44.0直接
Gogo.opentelemetry.io/otel/metricv1.44.0直接
Gogo.opentelemetry.io/otel/sdkv1.44.0直接
Gogo.opentelemetry.io/otel/sdk/metricv1.44.0直接
Gogo.opentelemetry.io/otel/tracev1.44.0直接
Gogo.uber.org/zapv1.28.0直接
Gogolang.org/x/expv0.0.0-20260312153236-7ab1446f8b90直接
Gogolang.org/x/oauth2v0.36.0直接
Gogolang.org/x/syncv0.22.0直接
Gogolang.org/x/termv0.45.0直接
Gogolang.org/x/textv0.40.0直接
Gogoogle.golang.org/genproto/googleapis/apiv0.0.0-20260526163538-3dc84a4a5aaa直接
Gogoogle.golang.org/protobufv1.36.12-0.20260120151049-f2248ac996af直接
Gogopkg.in/yaml.v2v2.4.0直接
Gogotest.tools/v3v3.5.2直接
Gok8s.io/apiv0.36.2直接
Gok8s.io/apimachineryv0.36.2直接
Gok8s.io/client-gov0.36.2直接
Gok8s.io/klog/v2v2.140.0直接
Gok8s.io/utilsv0.0.0-20260319190234-28399d86e0b5直接
Goknative.dev/eventingv0.49.2直接
Goknative.dev/pkgv0.0.0-20260622140654-39ebae2ee2dc直接
Gosigs.k8s.io/yamlv1.6.0直接
Gocel.dev/exprv0.25.1间接
Gogithub.com/42wim/httpsigv1.2.4间接
Gogithub.com/andybalholm/cascadiav1.3.3间接
Gogithub.com/antlr/antlr4/runtime/go/antlrv1.4.10间接
Gogithub.com/antlr4-go/antlr/v4v4.13.1间接
Gogithub.com/beorn7/perksv1.0.1间接
Gogithub.com/blang/semver/v4v4.0.0间接
Gogithub.com/blendle/zapdriverv1.3.1间接
Gogithub.com/cenkalti/backoff/v5v5.0.3间接
Gogithub.com/cert-manager/cert-managerv1.20.1间接
Gogithub.com/cespare/xxhash/v2v2.3.0间接
Gogithub.com/cloudevents/sdk-go/observability/opentelemetry/v2v2.16.2间接
Gogithub.com/cloudevents/sdk-go/sql/v2v2.16.2间接
Gogithub.com/coreos/go-oidc/v3v3.18.0间接
Gogithub.com/davecgh/go-spewv1.1.2-0.20180830191138-d8f796af33cc间接
Gogithub.com/davidmz/go-pageantv1.0.2间接
Gogithub.com/emicklei/go-restful/v3v3.13.0间接
Gogithub.com/evanphx/json-patch/v5v5.9.11间接
Gogithub.com/felixge/httpsnoopv1.0.4间接
Gogithub.com/fxamacker/cbor/v2v2.9.1间接
Gogithub.com/go-fed/httpsigv1.1.1-0.20201223112313-55836744818e间接
Gogithub.com/go-jose/go-jose/v3v3.0.5间接
Gogithub.com/go-jose/go-jose/v4v4.1.4间接
Gogithub.com/go-logr/logrv1.4.3间接
Gogithub.com/go-logr/stdrv1.2.2间接
Gogithub.com/go-logr/zaprv1.3.0间接
Gogithub.com/go-openapi/errorsv0.22.7间接
Gogithub.com/go-openapi/jsonpointerv0.22.5间接
Gogithub.com/go-openapi/jsonreferencev0.21.5间接
Gogithub.com/go-openapi/strfmtv0.26.1间接
Gogithub.com/go-openapi/swagv0.25.5间接
Gogithub.com/go-openapi/swag/cmdutilsv0.25.5间接
Gogithub.com/go-openapi/swag/convv0.25.5间接
Gogithub.com/go-openapi/swag/fileutilsv0.25.5间接
Gogithub.com/go-openapi/swag/jsonnamev0.25.5间接
Gogithub.com/go-openapi/swag/jsonutilsv0.25.5间接
Gogithub.com/go-openapi/swag/loadingv0.25.5间接
Gogithub.com/go-openapi/swag/manglingv0.25.5间接
Gogithub.com/go-openapi/swag/netutilsv0.25.5间接
Gogithub.com/go-openapi/swag/stringutilsv0.25.5间接
Gogithub.com/go-openapi/swag/typeutilsv0.25.5间接
Gogithub.com/go-openapi/swag/yamlutilsv0.25.5间接
Gogithub.com/go-viper/mapstructure/v2v2.5.0间接
Gogithub.com/google/gnostic-modelsv0.7.1间接
Gogithub.com/google/go-querystringv1.2.0间接
Gogithub.com/google/uuidv1.6.0间接
Gogithub.com/grpc-ecosystem/grpc-gateway/v2v2.29.0间接
Gogithub.com/hashicorp/go-cleanhttpv0.5.2间接
Gogithub.com/hashicorp/go-retryablehttpv0.7.8间接
Gogithub.com/hashicorp/go-versionv1.9.0间接
Gogithub.com/hashicorp/golang-lruv1.0.2间接
Gogithub.com/imfing/hextrav0.12.0间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/json-iterator/gov1.1.12间接
Gogithub.com/kballard/go-shellquotev0.0.0-20180428030007-95032a82bc51间接
Gogithub.com/kelseyhightower/envconfigv1.4.0间接
Gogithub.com/lunixbochs/vtcleanv1.0.0间接
Gogithub.com/modern-go/concurrentv0.0.0-20180306012644-bacd9c7ef1dd间接
Gogithub.com/modern-go/reflect2v1.0.3-0.20250322232337-35a7c28c31ee间接
Gogithub.com/munnerz/goautonegv0.0.0-20191010083416-a7dc8b61c822间接
Gogithub.com/oklog/ulid/v2v2.1.1间接
Gogithub.com/pmezard/go-difflibv1.0.1-0.20181226105442-5d4384ee4fb2间接
Gogithub.com/prometheus/client_golangv1.23.2间接
Gogithub.com/prometheus/otlptranslatorv1.0.0间接
Gogithub.com/prometheus/procfsv0.20.1间接
Gogithub.com/puerkitobio/goqueryv1.12.0间接
Gogithub.com/rickb777/datev1.22.0间接
Gogithub.com/rickb777/pluralv1.4.10间接
Gogithub.com/robfig/cron/v3v3.0.1间接
Gogithub.com/spf13/pflagv1.0.10间接
Gogithub.com/x448/float16v0.8.4间接
Gogithub.com/xlzd/gotpv0.1.0间接
Gogo.opentelemetry.io/auto/sdkv1.2.1间接
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0间接
Gogo.opentelemetry.io/contrib/instrumentation/runtimev0.69.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpcv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttpv1.44.0间接
Gogo.opentelemetry.io/otel/exporters/otlp/otlptracev1.44.0间接
Gogo.opentelemetry.io/otel/exporters/prometheusv0.66.0间接
Gogo.opentelemetry.io/otel/exporters/stdout/stdouttracev1.44.0间接
Gogo.opentelemetry.io/proto/otlpv1.10.0间接
Gogo.uber.org/atomicv1.11.0间接
Gogo.uber.org/automaxprocsv1.6.0间接
Gogo.uber.org/multierrv1.11.0间接
Gogo.yaml.in/yaml/v2v2.4.4间接
Gogo.yaml.in/yaml/v3v3.0.4间接
Gogolang.org/x/cryptov0.53.0间接
Gogolang.org/x/netv0.56.0间接
Gogolang.org/x/sysv0.47.0间接
Gogolang.org/x/timev0.15.0间接
Gogomodules.xyz/jsonpatch/v2v2.5.0间接
Gogoogle.golang.org/genproto/googleapis/rpcv0.0.0-20260526163538-3dc84a4a5aaa间接
Gogoogle.golang.org/grpcv1.81.1间接
Gogopkg.in/evanphx/json-patch.v4v4.13.0间接
Gogopkg.in/inf.v0v0.9.1间接
Gogopkg.in/yaml.v3v3.0.1间接
Gok8s.io/apiextensions-apiserverv0.36.2间接
Gok8s.io/kube-openapiv0.0.0-20260330154417-16be699c7b31间接
Gosigs.k8s.io/gateway-apiv1.5.1间接
Gosigs.k8s.io/jsonv0.0.0-20250730193827-2d320260d730间接
Gosigs.k8s.io/randfillv1.0.0间接
Gosigs.k8s.io/structured-merge-diff/v6v6.3.2间接
npm@axe-core/playwright^4.10.1间接
npm@playwright/test^1.49.1间接
npm@tailwindcss/postcss^4.1.18间接
npmpostcss-cli^11.0.1间接
npmprettier^3.8.0间接
npmprettier-plugin-go-template^0.0.15间接
npmtailwindcss^4.1.18间接
依赖安全公告 3

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 156 个包,其中也包含从不交付的开发与测试版本固定:3 个存在已知公告,1 个为直接依赖。 有 7 个无法评估——没有已解析的版本、生态系统不受支持,或不在所列包清单之内。

软件包版本关系严重程度公告数修复版本
google.golang.org/grpcv1.81.1间接严重11.82.1
github.com/tektoncd/pipelinev1.14.0直接未知2
golang.org/x/cryptov0.53.0间接未知1

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "tekton-pipelines",
        "tekton",
        "github",
        "pipeline",
        "kubernetes",
        "continuous-delivery",
        "pipelines-as-code",
        "gitlab",
        "ci",
        "bitbucket",
        "gitops"
      ],
      "is_fork": false,
      "size_kb": 78996,
      "has_wiki": true,
      "homepage": "https://pipelinesascode.com",
      "languages": {
        "Go": 3487952,
        "Shell": 88231,
        "Python": 31194,
        "Makefile": 9406,
        "Go Template": 11587
      },
      "pushed_at": "2026-07-21T10:21:44Z",
      "created_at": "2021-04-06T13:26:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-21T10:21:49Z",
      "description": "Pipelines-as-Code for Tekton",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://tekton.dev",
      "name": "Tekton",
      "type": "Organization",
      "login": "tektoncd",
      "company": null,
      "location": null,
      "followers": 1421,
      "avatar_url": "https://avatars.githubusercontent.com/u/47602533?v=4",
      "created_at": "2019-02-13T14:53:43Z",
      "is_verified": null,
      "public_repos": 24,
      "account_age_days": 2715
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.48.1",
          "kind": "patch",
          "published_at": "2026-07-17T13:48:26Z"
        },
        {
          "tag": "v0.42.3",
          "kind": "patch",
          "published_at": "2026-07-17T13:39:45Z"
        },
        {
          "tag": "v0.49.0",
          "kind": "minor",
          "published_at": "2026-07-06T12:59:38Z"
        },
        {
          "tag": "v0.42.2",
          "kind": "patch",
          "published_at": "2026-06-15T07:19:37Z"
        },
        {
          "tag": "v0.37.8",
          "kind": "patch",
          "published_at": "2026-06-12T13:43:39Z"
        },
        {
          "tag": "v0.39.7",
          "kind": "patch",
          "published_at": "2026-06-09T18:31:33Z"
        },
        {
          "tag": "v0.42.1",
          "kind": "patch",
          "published_at": "2026-06-08T16:18:26Z"
        },
        {
          "tag": "v0.39.6",
          "kind": "patch",
          "published_at": "2026-06-08T14:41:54Z"
        },
        {
          "tag": "v0.48.0",
          "kind": "minor",
          "published_at": "2026-06-04T16:28:32Z"
        },
        {
          "tag": "v0.47.0",
          "kind": "minor",
          "published_at": "2026-05-26T08:24:42Z"
        },
        {
          "tag": "v0.46.0",
          "kind": "minor",
          "published_at": "2026-05-06T11:27:46Z"
        },
        {
          "tag": "v0.45.0",
          "kind": "minor",
          "published_at": "2026-04-08T08:38:24Z"
        },
        {
          "tag": "v0.44.0",
          "kind": "minor",
          "published_at": "2026-03-31T18:49:00Z"
        },
        {
          "tag": "v0.43.0",
          "kind": "minor",
          "published_at": "2026-03-12T10:28:22Z"
        },
        {
          "tag": "v0.42.0",
          "kind": "minor",
          "published_at": "2026-02-23T14:42:23Z"
        },
        {
          "tag": "v0.37.7",
          "kind": "patch",
          "published_at": "2026-02-23T14:00:10Z"
        },
        {
          "tag": "v0.39.5",
          "kind": "patch",
          "published_at": "2026-02-19T18:57:07Z"
        },
        {
          "tag": "v0.37.6",
          "kind": "patch",
          "published_at": "2026-02-19T14:43:04Z"
        },
        {
          "tag": "v0.37.5",
          "kind": "patch",
          "published_at": "2026-01-29T15:13:18Z"
        },
        {
          "tag": "v0.39.4",
          "kind": "patch",
          "published_at": "2026-01-29T15:14:58Z"
        },
        {
          "tag": "v0.41.1",
          "kind": "patch",
          "published_at": "2026-01-29T10:33:18Z"
        },
        {
          "tag": "v0.41.0",
          "kind": "minor",
          "published_at": "2026-01-20T14:11:55Z"
        },
        {
          "tag": "v0.40.0",
          "kind": "minor",
          "published_at": "2025-12-19T06:49:11Z"
        },
        {
          "tag": "v0.39.3",
          "kind": "patch",
          "published_at": "2025-12-15T17:36:46Z"
        },
        {
          "tag": "v0.37.4",
          "kind": "patch",
          "published_at": "2025-12-15T09:42:51Z"
        },
        {
          "tag": "v0.35.4",
          "kind": "patch",
          "published_at": "2025-12-04T04:41:54Z"
        },
        {
          "tag": "v0.39.2",
          "kind": "patch",
          "published_at": "2025-11-19T11:02:58Z"
        },
        {
          "tag": "v0.37.3",
          "kind": "patch",
          "published_at": "2025-11-18T08:39:26Z"
        },
        {
          "tag": "v0.39.1",
          "kind": "patch",
          "published_at": "2025-11-18T07:41:53Z"
        },
        {
          "tag": "v0.37.2",
          "kind": "patch",
          "published_at": "2025-11-10T04:40:32Z"
        },
        {
          "tag": "v0.39.0",
          "kind": "minor",
          "published_at": "2025-11-04T17:28:24Z"
        },
        {
          "tag": "v0.37.1",
          "kind": "patch",
          "published_at": "2025-10-01T09:30:13Z"
        },
        {
          "tag": "v0.38.0",
          "kind": "minor",
          "published_at": "2025-09-26T06:21:33Z"
        },
        {
          "tag": "v0.37.0",
          "kind": "minor",
          "published_at": "2025-08-12T11:40:15Z"
        },
        {
          "tag": "v0.35.3",
          "kind": "patch",
          "published_at": "2025-07-16T18:29:05Z"
        },
        {
          "tag": "v0.35.2",
          "kind": "patch",
          "published_at": "2025-07-04T16:53:16Z"
        },
        {
          "tag": "v0.36.0",
          "kind": "minor",
          "published_at": "2025-06-26T15:30:13Z"
        },
        {
          "tag": "v0.35.1",
          "kind": "patch",
          "published_at": "2025-06-04T13:07:41Z"
        },
        {
          "tag": "v0.35.0",
          "kind": "minor",
          "published_at": "2025-05-26T15:19:51Z"
        },
        {
          "tag": "v0.34.0",
          "kind": "minor",
          "published_at": "2025-05-06T13:43:40Z"
        },
        {
          "tag": "v0.33.2",
          "kind": "patch",
          "published_at": "2025-05-02T08:04:29Z"
        },
        {
          "tag": "v0.33.1",
          "kind": "patch",
          "published_at": "2025-04-16T10:34:37Z"
        },
        {
          "tag": "v0.33.0",
          "kind": "minor",
          "published_at": "2025-02-14T14:28:54Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2025-01-21T10:35:04Z"
        },
        {
          "tag": "v0.28.2",
          "kind": "patch",
          "published_at": "2025-01-07T13:23:58Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2025-01-07T13:23:36Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2024-12-17T10:56:53Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2024-11-27T11:51:15Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2024-11-08T16:55:33Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2024-10-31T16:23:11Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2024-09-19T17:40:55Z"
        },
        {
          "tag": "v0.27.2",
          "kind": "patch",
          "published_at": "2024-07-05T11:31:26Z"
        },
        {
          "tag": "v0.27.1",
          "kind": "patch",
          "published_at": "2024-06-10T15:39:31Z"
        },
        {
          "tag": "v0.24.7",
          "kind": "patch",
          "published_at": "2024-05-30T09:57:00Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2024-05-06T15:20:57Z"
        },
        {
          "tag": "v0.24.6",
          "kind": "patch",
          "published_at": "2024-05-06T14:39:36Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2024-04-18T11:57:55Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2024-03-25T15:21:09Z"
        },
        {
          "tag": "v0.24.5",
          "kind": "patch",
          "published_at": "2024-03-22T14:37:32Z"
        },
        {
          "tag": "v0.24.4",
          "kind": "patch",
          "published_at": "2024-03-21T14:02:29Z"
        },
        {
          "tag": "v0.24.3",
          "kind": "patch",
          "published_at": "2024-03-19T16:23:42Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2024-03-12T13:01:33Z"
        },
        {
          "tag": "v0.24.1",
          "kind": "patch",
          "published_at": "2024-02-14T16:31:12Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2024-02-05T14:01:16Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2024-01-09T09:51:56Z"
        },
        {
          "tag": "v0.22.6",
          "kind": "patch",
          "published_at": "2024-01-02T12:13:30Z"
        },
        {
          "tag": "v0.22.5",
          "kind": "patch",
          "published_at": "2023-12-15T14:02:13Z"
        },
        {
          "tag": "v0.22.4",
          "kind": "patch",
          "published_at": "2023-11-23T10:10:32Z"
        },
        {
          "tag": "v0.22.3",
          "kind": "patch",
          "published_at": "2023-11-21T12:25:21Z"
        },
        {
          "tag": "v0.22.2",
          "kind": "patch",
          "published_at": "2023-11-16T08:22:54Z"
        },
        {
          "tag": "v0.22.1",
          "kind": "patch",
          "published_at": "2023-11-13T10:57:32Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2023-11-10T09:05:21Z"
        },
        {
          "tag": "v0.21.5",
          "kind": "patch",
          "published_at": "2023-10-31T14:38:00Z"
        },
        {
          "tag": "v0.21.4",
          "kind": "patch",
          "published_at": "2023-10-20T07:48:16Z"
        },
        {
          "tag": "v0.17.7",
          "kind": "patch",
          "published_at": "2023-10-20T07:28:36Z"
        },
        {
          "tag": "v0.19.6",
          "kind": "patch",
          "published_at": "2023-10-20T09:04:23Z"
        },
        {
          "tag": "v0.17.6",
          "kind": "patch",
          "published_at": "2023-10-18T15:19:51Z"
        },
        {
          "tag": "v0.19.5",
          "kind": "patch",
          "published_at": "2023-10-18T14:48:27Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2023-10-17T11:10:03Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2023-10-10T12:49:07Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2023-09-26T11:34:53Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2023-09-13T18:01:46Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2023-08-25T06:56:16Z"
        },
        {
          "tag": "v0.19.4",
          "kind": "patch",
          "published_at": "2023-08-04T08:37:21Z"
        },
        {
          "tag": "v0.19.3",
          "kind": "patch",
          "published_at": "2023-08-01T15:58:54Z"
        },
        {
          "tag": "v0.17.5",
          "kind": "patch",
          "published_at": "2023-08-01T14:00:28Z"
        },
        {
          "tag": "v0.17.4",
          "kind": "patch",
          "published_at": "2023-06-09T12:03:37Z"
        },
        {
          "tag": "v0.19.2",
          "kind": "patch",
          "published_at": "2023-06-08T14:05:48Z"
        },
        {
          "tag": "v0.19.1",
          "kind": "patch",
          "published_at": "2023-05-24T15:19:57Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2023-05-04T09:10:44Z"
        },
        {
          "tag": "v0.15.6",
          "kind": "patch",
          "published_at": "2023-04-19T09:46:58Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2023-04-18T13:34:40Z"
        },
        {
          "tag": "v0.17.3",
          "kind": "patch",
          "published_at": "2023-04-18T11:26:19Z"
        },
        {
          "tag": "v0.17.2",
          "kind": "patch",
          "published_at": "2023-03-30T12:31:01Z"
        },
        {
          "tag": "v0.17.1",
          "kind": "patch",
          "published_at": "2023-03-08T15:15:55Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2023-03-02T14:50:12Z"
        },
        {
          "tag": "v0.15.5",
          "kind": "patch",
          "published_at": "2023-02-06T11:46:56Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2023-02-06T10:59:31Z"
        },
        {
          "tag": "v0.15.4",
          "kind": "patch",
          "published_at": "2023-02-06T11:01:40Z"
        },
        {
          "tag": "v0.15.3",
          "kind": "patch",
          "published_at": "2023-01-19T11:50:50Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
          "body": "Corrected the default container image path for the controller in the\nmulti-controller documentation to point to the correct GitHub Container\nRegistry repository.\n\nFixes #2559\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Update controller image path in multi-controller docs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-21T10:21:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4dfe8e76d8674cb78bc70bd5b84201f05799323",
          "body": "When updating a Bitbucket Cloud token via update-token, also\nprompt for the Atlassian account email and update\ngit_provider.user on the Repository CR. Without this, tokens\nrotated via the CLI leave a stale username that causes 401\nerrors on all provider API calls.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cli): set BB Cloud email in update-token",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-21T07:54:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "558561804964b529a161aea871788868687b0378",
          "body": "this deletes the gemini config from PaC repo\nbecause gemini code review is decommisioned and\nit is no longer needed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: delete gemini config from repo",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-20T18:43:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0feb33f9f5b2ead03cc2d510df497577b6ebee14",
          "body": "Replace testify/assert with gotest.tools/v3/assert in\ninfo_test.go and task_status_test.go to match the project's\nstandard assertion library and eliminate mixed usage.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "test: use gotest.tools/v3/assert consistently",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-20T12:09:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9f1fe585601252cf88ded8a2487dde0cb25fdb3",
          "body": "Tekton Hub has been shut down and is no longer supported in\nOSP 1.24. Remove all TektonHub-specific code, configuration,\ntests, and documentation, leaving only Artifact Hub integration.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(hub): remove Tekton Hub support",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-20T12:09:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6e3f736a86b0e89103b84dfda95e5999075a0c72",
          "body": "Added logic to extract and display error messages from waiting container\nstates, which occur when secrets or other configuration issues prevent\npod creation. This allows users to see the actual error (e.g., \"secret\nnot found\") in the pipeline failure output instead of just a generic\nreason code. Als\n[…]\ns to include container creation and pod creation errors.\n\nFixes #2751\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12208\nCo-Authored-By: Gemini\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: capture container creation error messages in logs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-20T10:08:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad947f41d3d277edd7b761a030d5911dc3cc72c5",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-go](https://github.com/actions/setup-go).\n\n\nUpdates `actions/setup-go` from 6.5.0 to 7.0.0\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356f\n[…]\n\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump actions/setup-go in the github-actions group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:25:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d121ae3e51f0ffdcdcd3391a674b6877a7af0ec",
          "body": "Bumps the go-dependencies group with 1 update: [github.com/mattn/go-isatty](https://github.com/mattn/go-isatty).\n\n\nUpdates `github.com/mattn/go-isatty` from 0.0.22 to 0.0.23\n- [Commits](https://github.com/mattn/go-isatty/compare/v0.0.22...v0.0.23)\n\n---\nupdated-dependencies:\n- dependency-name: github\n[…]\n dependency-version: 0.0.23\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n  dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump github.com/mattn/go-isatty in the go-dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:18:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e25db4412aa0a70b220da6dc1e2a268b386c7131",
          "body": "Enabled verbose JSON logging with connection timeouts and retries for\ngosmee clients to make end-to-end test failures easier to debug.\nIsolated Gitea and GitHub Enterprise webhook client logs into their\nown directories and files to prevent them from overwriting or\nappending to shared main logs. Upda\n[…]\non script to\ngather these new logs, capture internal Kubernetes gosmee deployment\ndetails when available, and redact the newly added webhook URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: Improve gosmee client debugging for end-to-end tests",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:11:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a054817abb339b0eef99e76aab00ed42bd571d89",
          "body": "Updated the AI code reviewer prompt to provide more detailed guidance on\nreview standards. Enhanced instructions to clarify what constitutes\nactionable findings versus nits, added explicit severity level\ndefinitions for consistent issue categorization, and improved guidance\non when and how to provid\n[…]\nuggestions. These changes aim to\nproduce more focused and useful pull request reviews by setting clearer\nexpectations for the reviewer's behavior.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: refine paco code review prompt",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:07:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f314275a165afc0641f3e6cef98bbecf0e51134",
          "body": "Extend Paco's structured review response with a difficulty rating, a\nshort explanation, and a security-sensitivity flag. Explain the rating\ncriteria in the model prompt so scores account for change size,\ncomplexity, risk, and blast radius while keeping summary-only runs\nconsistent with full reviews.\n[…]\nthe review instructions to suppress subjective formatting,\nnaming, and phrasing nits unless they affect correctness, security, or\nmaintainability.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: score review difficulty and other paco impro",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T10:07:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ad2dcdb267f0d0b5ad99f3366bb4365d277c2fe0",
          "body": "Added an automated code review pipeline powered by AI to analyze pull\nrequest diffs against project-specific guidelines. This was done to help\ndevelopers catch bugs, style violations, and security flaws early by\nposting inline comments and a persistent overview summary directly onto\nGitHub pull requests.\n\nThis using opencode cli backend (but thats an implementation detail) and\nsupport custom review rules via a .tekton/ai/REVIEW.md file.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Introduce Paco AI code review",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-17T08:34:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29c47b6e5245b6f115934cc6e4a889e60909dab1",
          "body": "Remove the Status []RepositoryRunStatus field from the Repository\nCR to eliminate informer cache churn caused by updating the CR on\nevery PipelineRun completion. CLI commands now query PipelineRuns\ndirectly via label selectors instead of reading repo status.\n\n- Delete updateRepoRunStatus reconciler \n[…]\n ShowLastSHA, ShowStatus, ShowLastAge\n- Update deepcopy, test helpers, informer transform, golden files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
          "is_bot": false,
          "headline": "refactor: remove Repository CR pipelinerun_status field",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-16T07:18:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f6a391687b88008a8b4cc264077508b7a1c8181c",
          "body": "Replace IsCollaborator (which returns true for read-only collaborators)\nwith CollaboratorPermission to verify the sender has write or admin\nor owner access before allowing pipeline runs. Also fix\nCreateForkPullRequest to grant access to SecondUserName instead of\nTargetRefName.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(gitea): check write/admin permission instead of collaborator only",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-16T06:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84829463a99d791164a3ef8f7f5dc1cd00fc6766",
          "body": "Adds TestOTelMetrics, a consolidated e2e test for the OC→OTel metrics\nmigration in Pipelines-as-Code (PR #2567). The test scrapes two pods:\n\nController (app.kubernetes.io/name=controller):\n- Asserts http_client_* metrics from knative k8s client OTel instrumentation\n- Asserts go_* runtime metrics\n- C\n[…]\ne metrics\n\nVerified locally with PAC controller and watcher deployed to kind via ko.\n\nRelates to tektoncd/pipelines-as-code#2567\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add e2e test for OpenCensus to OpenTelemetry metrics migration",
          "author_name": "Khurram Baig",
          "author_login": "khrm",
          "committed_at": "2026-07-16T04:12:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "69c4496b1d39ca6d22eff42a499bd7626e40e949",
          "body": "Add missing unit tests for low-coverage packages identified via\ncodecov analysis: params/clients, cli, bootstrap, pipelinerunmetrics,\nwebhook, and llm/llm-context. Also exclude test-helper packages from\ncodecov accounting and add a codecov badge to README.\n\nCoverage improvements:\n- params/clients: 1\n[…]\n: 39.6% -> 81.3%\n- webhook: 47.9% -> 70.9%\n- llm: 46.8% -> 57.9%\n- llm/context: 38.8% -> 77.5%\n\nOverall project statement coverage: 65.6% -> 68.3%\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: raise unit test coverage across packages",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-15T13:47:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5438a1e06ea50062a79fe8fcd52f456a1b974a46",
          "body": "The warning about the old profiling.enable key is migration\nguidance that describes historical state rather than current\nbehavior. Since the old key no longer works, only the current\nruntime-profiling key needs to be documented.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "docs(profiling): remove deprecated key callout",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-15T09:04:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35ee9df55f472c448f203fb60b566fbc27efd06f",
          "body": "The Gitea cancel run test used a hardcoded sleep before sending the\ncancel comment. This caused test failures when the webhook relay took\nlonger than expected to deliver the event, sending the cancel command\nbefore the pipeline run existed. Replaced the sleep with a check that\nwaits for the pipeline run to be created first.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "test: Wait for pipelinerun to be created before cancellation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-15T07:32:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "85b606bb30f6b42d645cd79526dfd5ceba629f88",
          "body": "The apiextensions-apiserver indirect dependency is updated\nfrom v0.35.6 to v0.36.2 along with the corresponding\nk8s.io/apiserver transitive dependency. The vendored files\nreflect upstream changes including a new StorageMigrating\ncondition type and the removal of the deprecated\nprotomessage compatibility shim.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore: bump k8s.io/apiextensions-apiserver to v0.36.2",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-10T08:07:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c6483e2865399ae6794a5a3f57f2fac628bdd93",
          "body": "Bumps the go-dependencies group with 1 update: [k8s.io/client-go](https://github.com/kubernetes/client-go).\n\n\nUpdates `k8s.io/client-go` from 0.35.6 to 0.36.2\n- [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/kubernetes/client-go/compare/v\n[…]\n dependency-version: 0.36.2\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n  dependency-group: go-dependencies\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "ci: bump k8s.io/client-go in the go-dependencies group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-10T08:07:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2e845ef225649de5ab631288562795a1c4037e83",
          "body": "rh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
          "is_bot": false,
          "headline": "refractor: split gitea_test.go into focused files",
          "author_name": "KMI1011",
          "author_login": "KMI1011",
          "committed_at": "2026-07-10T07:32:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85cad747dee15d9847c04cec0d79a4c4fab5789a",
          "body": null,
          "is_bot": false,
          "headline": "fix: bump knative.dev/pkg and semconv to fix otel schema panic",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0fe2198bfa19188481c1a166b368df68055fc1e2",
          "body": "Dependabot generates automated commit messages that often violate line\nlength or body formatting rules. Added a check to bypass commit\nvalidation for dependabot pull requests, allowing these automated\nupdates to proceed without linting failures.",
          "is_bot": false,
          "headline": "ci: skip commit validation on dependabot PRs",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c421e079e553bbf0b3fcdf7291fca29ee66e6b7",
          "body": null,
          "is_bot": false,
          "headline": "ci: ignore go-github and ghinstallation in dependabot",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3b3981bc20b55759649f413d515452f7161b029b",
          "body": "Bumps the go-dependencies group with 15 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [github.com/bradleyfalzon/ghinstallation/v2](https://github.com/bradleyfalzon/ghinstallation) | `2.18.0` | `2.19.0` |\n| [github.com/google/cel-go](https://github.com/google/cel-go) | `0.28.1` | `0.29.2` |\n[…]\nx: pin ghinstallation to v2.18.0\n\nDowngraded ghinstallation from v2.19.0 to v2.18.0 and removed the unused\ngo-github v88 dependency that was pulled in transitively.\n\nfix: pin ghinstallation to v2.18.0",
          "is_bot": true,
          "headline": "ci: bump the go-dependencies group with 15 updates",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-09T16:56:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "717f163e6fd3bfef22bd51108202c1049050bd7e",
          "body": "Added Go module tracking to the Dependabot configuration to keep Go\ndependencies updated. Since we can now group these updates together, we\ncan prevent an excessive number of pull requests.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Readd Go module updates in Dependabot",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-09T12:38:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "912f4e6b3b4147f4143f45e9cedbf2e767f562fd",
          "body": "- Update Go version from 1.26.4 to 1.26.5 in go.mod\n- Addresses crypto/tls Encrypted Client Hello privacy leak\n- CVE-2026-42505 / GO-2026-5856 fixed in go1.26.5\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): CVE-2026-42505 - update Go to 1.26.5",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-09T11:50:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a8413915cd80a6217b6eb3d50018b449082550a",
          "body": "The test waited on the PR head SHA status which is already green from\nthe pull_request run, then slept 5s; a delayed push webhook made\nGetStandardParams fail fatally on its first iteration with zero push\npipelineruns.\n\nWait for both pipelineruns to succeed after the merge and make\nGetStandardParams \n[…]\nhecking helper is patient\nenough to retry while things are still warming up, instead of quitting\nat the first empty result.\n\nAI-assisted-by: Cursor\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(e2e): wait for push pipelinerun in gitea params test",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-08T11:47:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e270e68e403cf5f937f48e6e5ea73ea663818888",
          "body": "The GitLab token auto-rotation feature revoked the old token via the\nself-rotate API before making the first Kubernetes API call that\ncould fail with a permission error. If the subsequent Secret update\nfailed, the old token was already revoked and the new token was\ndiscarded, irrecoverably destroyin\n[…]\n the\nrotation is aborted with a clear error while the old token is still\nvalid, so nothing is lost.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gitlab): verify write access before rotating token",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-08T08:23:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "73cb521a48abeca491396811ac795e5a0039ece2",
          "body": "Document that provider code must use v.Logger instead of\nrun.Clients.Log, since the provider logger carries standard\ncontext variables (provider, repository, event-id). This\nprevents regressions of the pattern fixed in the recent\nprovider logging commits.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore: add provider logginf guidance to AGENTS.md",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-08T05:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b89b22edfa4ae5a6c296b11b8a39e6c01cd7caab",
          "body": "The token auto-rotation logging in the GitLab provider's\nsetClient was still using run.Clients.Log instead of the\nprovider's own logger. This logger lacks the standard context\nvariables (provider, repository, event-id) that v.Logger\ncarries.\n\nFollow-up-to: https://github.com/tektoncd/pipelines-as-code/pull/2827\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(provider): use provider logger in gitlab setClient",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-08T05:52:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "939d30a4365440484d4319046065af596601a37a",
          "body": "The run.CLients.Log logger is created early and does not have the\nstandard context variables. The provider logger is used primarily and\nwhile technically possible because pointers, provider.Logger == nil is\nan illegal state.\n\nAssisted-by: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(provider): always use log using Provider logger",
          "author_name": "Andrew Thorp",
          "author_login": "aThorp96",
          "committed_at": "2026-07-07T13:08:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3e62d212d539ff389a82f4ca257aa9a7655cf042",
          "body": "Complete the refactor started in 39271f36a which removed the wait\nhelpers polling the deprecated Repository CR Status field. Three\nloose ends were left behind and are tied off here.\n\nFix zero-minimum wait semantics. The removed helpers compared with\n\">\" so MinNumberStatus: 0 meant \"wait for one\". Th\n[…]\nross 22\nE2E test files are deleted.\n\nValidated with go test ./test/pkg/wait and a compile of the e2e\ntagged test package.\n\nAssisted-by: Claude Code\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "refactor(e2e): finish Repository.Status removal in waits",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-07T11:16:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39271f36a191962287f27270b75ebc52084c3f84",
          "body": "The Repository CR's Status field is deprecated and will be removed.\nThis refactors E2E test wait helpers to use PipelineRun objects directly\ninstead of polling Repository.Status:\n\n- Remove UntilRepositoryUpdated and UntilRepositoryHasStatusReason\n- Remove FailOnRepoCondition from wait.Opts\n- Modify \n[…]\ninstead\n  of repo.Status fields\n- Migrate all ~40 call sites across 20 test files\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(e2e): remove reliance on Repository.Status in wait functions",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-07T07:39:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1433ee8668857940524d58b6c8510d4d8552d7b8",
          "body": "Add Forgejo to the webhook setup used by `tkn pac create repo` and\n`tkn pac webhook add`. Create the repository webhook and store the\ntoken and webhook secret for runtime use.\n\nHandle repository URLs with `.git` suffixes, trailing slashes,\ninstance subpaths, and SSH forms without blocking manual set\n[…]\noken permission is needed and clarify when the CLI\ncreates the provider secret.\n\nFixes #2755.\n\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>\nSigned-off-by: Katie Mulliken <mulliken@redhat.com>",
          "is_bot": false,
          "headline": "feat(webhook): add Forgejo CLI setup",
          "author_name": "Katie Mulliken",
          "author_login": "SecKatie",
          "committed_at": "2026-07-06T12:02:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0badfa041319b55f201e956df9ecf152923581f",
          "body": "Pipelines-as-Code automatically rotated GitLab access tokens to\nprevent pipeline failures caused by expired credentials. Expiring\ntokens were replaced with new tokens and updated in the corresponding\nKubernetes Secret, reducing manual maintenance. Shared secrets from the\nglobal repository were exclu\n[…]\ns. This behavior is disabled\nby default but could be turned on via repository configuration.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-11153\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Implement automatic GitLab access rotation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-06T11:22:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bd2cc1be180b32ada848ab65d1090d32e6bf1a2",
          "body": "Removed the testrr integration, including the upload script, CI\nenvironment variables, and documentation. The testrr service is no\nlonger used to track test results from Tekton and GitHub Actions.\n\nIt was never really used and created a lot of resources waste, so we are\nremoving it to simplify our CI/CD pipeline and reduce unnecessary\ndependencies.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Remove testrr test reporting from the CI environment",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-06T09:04:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27ac5d7e2567f21b5ae281fa54db0fcc89dd3c80",
          "body": "The reconciler is a shared controller object. It can work on more than one\nPipelineRun at the same time. Some values it used while loading Git provider\ncredentials were stored on that shared object, even though they only belonged\nto the PipelineRun currently being processed.\n\nThat could let one Pipe\n[…]\non. Also copy Repository objects before merging global settings, so\nwe do not modify objects that came from the shared informer cache.\n\nFixes #2824\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(reconciler): avoid shared state",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-03T13:29:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63e8059d17c3fde3e60fd1dc07b48b260d9996a5",
          "body": "Updated the documentation and scaffolding templates to clarify task\nresolution behaviors. Explicitly distinguished annotation-based task\ninlining from native Tekton Hub resolver syntax because combining them\ncaused configuration errors. Replaced outdated git-clone catalog URLs\nwith the correct Artifact Hub links to ensure accurate references.\n\nFixes #2814\nAI-assisted-by: OpenAI ChatGPT\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Clarify task resolution in the pipeline documentation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-03T07:53:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccba1d5ca7a56c0eb66c102420bb553c8581f48b",
          "body": "this commit reverts a github link in docs from using\nmain branch to point to a specific commit to make\npermalink lint happy.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: use commit sha to prevent permalint lint error",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-03T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e30e597f4318d7438df004401802772ff56e6429",
          "body": "Label removal events on GitLab merge requests were incorrectly triggering\npipeline runs. The hasOnlyLabelsChanged check used an OR condition that\nmatched both additions and removals. Changed to compare current vs previous\nlabel count so only label additions are processed.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(gitlab): discard label removal events on merge requests",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-07-03T07:31:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "8a7f21344bdf3ab247c8759fdcbefff42f8a62fc",
          "body": "- Upgrade github.com/tektoncd/pipeline from v1.13.1 to v1.14.0\n- Fixes GHSA-cv4x-93xx-wgfj / CVE-2026-33022: controller panic via long\n  resolver name in TaskRun/PipelineRun (GenerateDeterministicNameFromSpec)\n- Fixes GO-2023-1901: Pipelines do not validate child UIDs\n- Co-upgrade transitive deps pu\n[…]\n,text} minor bumps\n- Ran: go mod tidy && go mod verify && go mod vendor\n\nResolves: SRVKP-11100\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): CVE-2026-33022 - upgrade tektoncd/pipeline v1.13.1 → v1.14.0",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-07-03T05:20:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "03cd060cbf610d5343af4d10e8bbf0e3d66279e6",
          "body": "Added a Go formatting check to the linting process using gofumpt.\nIntegrated this verification step into the local Makefile lint target\nand the automated Tekton CI pipeline to ensure consistent code style\nacross the repository.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Enforce Go code formatting checks in lint pipeline",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-02T13:42:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8966a5331f743fe9e68d2262da1234b2391e4cb",
          "body": "Code was reformatted using fumpt to improve consistency with Go\nformatting standards. This includes adjusting line breaks in function\ncalls and adding parentheses for better readability where function\narguments span multiple lines. chore: reformat files with make fumpt",
          "is_bot": false,
          "headline": "chore: reformat code with fumpt",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-02T08:43:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dfcd60091c46844449e91a38bf38b76bea56c47",
          "body": "Switch Bitbucket Cloud setup away from app-password language and\nmake the CLI collect the Atlassian account email used for API token\nauthentication. Webhook creation now uses that email with the scoped\nAPI token instead of authenticating with the repository owner.\n\nKeep Repository CRD shape unchange\n[…]\nthe CLI auth flow, token rotation prompt, and generated git auth\nsecret behavior.\n\nFixes #2818\nJira https://redhat.atlassian.net/browse/SRVKP-12685\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix: bitbucket API tokens instead of app-passwords",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-01T15:55:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fdee04551602b8af9ef267e121863f045c256e5",
          "body": "Addresses SRVKP-12311 by moving unit coverage publishing to a\ndedicated GitHub Actions workflow. The workflow runs on pull requests,\npushes to main, and manual dispatch, then uploads coverage with the\nunit-tests flag through Codecov OIDC.\n\nRemove the older Tekton Codecov uploader steps that relied o\n[…]\no longer suggests Codecov coverage ownership.\n\nJira: https://redhat.atlassian.net/browse/SRVKP-12311\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "ci: add codecov oidc upload",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-07-01T09:33:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9d51949f5027d41d9e8941ffa651a541acd8188f",
          "body": "Explain that disabling GitLab PipelineRun status comments does not\nhide validation errors from PipelineRuns in the `.tekton/` directory.\nThis keeps the note in normal prose instead of an info callout, so\nthe GitLab guide reads as a continuous troubleshooting section.\n\nSigned-off-by: Estee Cohen <estherco@post.bgu.ac.il>\nCo-authored-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: clarify GitLab comment strategy behavior",
          "author_name": "Estee Cohen",
          "author_login": "EsteeCohen",
          "committed_at": "2026-07-01T09:16:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffc50929a53e9d07fda018ac73bd6f899a31310d",
          "body": null,
          "is_bot": false,
          "headline": "fix(llm): run default AI roles on completed PipelineRuns",
          "author_name": "BoseKarthikeyan",
          "author_login": "BoseKarthikeyan",
          "committed_at": "2026-06-30T09:21:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d2cde6492c70ac4f983f6fede548dd138c5d73b",
          "body": "Knative's config-observability ConfigMap only exposes a flat\ntracing-sampling-rate, so at fractional rates each service in the chain\nrolls independently — PaC can drop a trace while Tekton keeps it, leaving\nexecution spans whose parent_spanID points at nothing. Switching to the\nOTel SDK opens up OTE\n[…]\nonally not honored per Konflux-CI\nADR 0061. otlptracegrpc and otlptracehttp promoted from indirect to direct\ndependencies.\n\nAssisted-by: Claude Code\nSigned-off-by: Josiah England <jengland@redhat.com>",
          "is_bot": false,
          "headline": "fix(tracing): direct OTel SDK setup for chain-coherent sampling",
          "author_name": "Josiah England",
          "author_login": "ci-operator",
          "committed_at": "2026-06-30T05:31:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e1a2f48ed544837c80ea38487d1ed728df82c819",
          "body": "Replace duplicate 404 and non-404 error subtests with a\ntable-driven test to satisfy the dupl linter.\n\nFixes https://github.com/tektoncd/pipelines-as-code/issues/2653\n\nrh-pre-commit.version: 2.4.0\nrh-pre-commit.check-secrets: ENABLED",
          "is_bot": false,
          "headline": "fix: downgrade 404 API responses from error to debug log level",
          "author_name": "KMI1011",
          "author_login": "KMI1011",
          "committed_at": "2026-06-29T14:14:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74939ef42af88d708302559927406a59c7f16bbb",
          "body": "Reduce PR noise by grouping all GitHub Actions dependency updates into a\nsingle consolidated pull request, improving workflow efficiency.",
          "is_bot": false,
          "headline": "chore: Configure Dependabot to group GitHub Actions updates",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-29T08:16:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f045c6cf34367dbc09d0e0da9cdd72f9610b76d",
          "body": "Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fcca\n[…]\ns:\n- dependency-name: actions/cache\n  dependency-version: 6.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/cache from 5.0.5 to 6.1.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:41:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa462865bb55ec617868b0f23451bc03ebcd0452",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\n- dependency-name: actions/setup-go\n  dependency-version: 6.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:41:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a781dbea31c5b894d6419b95df9fd2eb6f2cb1d",
          "body": "Bumps [ko-build/setup-ko](https://github.com/ko-build/setup-ko) from 0.9 to 0.10.\n- [Release notes](https://github.com/ko-build/setup-ko/releases)\n- [Commits](https://github.com/ko-build/setup-ko/compare/d006021bd0c28d1ce33a07e7943d48b079944c8d...61b4d1d396f5b2e7d6bb6fefdce3dc38d1a13445)\n\n---\nupdate\n[…]\ndependency-name: ko-build/setup-ko\n  dependency-version: '0.10'\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump ko-build/setup-ko from 0.9 to 0.10",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-29T06:40:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82843027ab11abb03ce42f4603361cc3718e9ee9",
          "body": "Cache ListOrgTeams API responses per organization to avoid\nredundant API calls when checking policy for the same org\nacross multiple allowed teams evaluations.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "feat(forgejo): cache org teams in policy check",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-26T13:57:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "181a27faf760794cb3104995f0dcc88c12cb6be9",
          "body": "this allows e2e workflow run on any changes in hack/\ndirectory as there are all the script used across\nworkflow file.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore(ci): allow e2e workflow run hack/* changes",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-26T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e8ac13de68283c7aade7524100f9ba0f980f6569",
          "body": "Use per-resource kubectl get with --- separators when collecting\npipelineruns, repositories, and configmaps in CI log artifacts so\neach resource is a distinct YAML document.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): separate collected resources with YAML document markers",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-26T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fb79c78fc4bb95b6aafeac654f2ab76cebcdf1e",
          "body": "Add table-driven unit tests for pkg/provider/gitea/parse_payload.go:\n\n- TestParsePayloadPullRequest covers the opened, synchronized, label_updated\n  and closed actions (event type, trigger target and label extraction).\n- TestParsePayloadPush covers the head_commit path and the before-SHA fallback.\n-\n[…]\noad helper builds the request and calls ParsePayload, and\nprPayload builds pull_request webhook bodies.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Kshitiz Jain <kshitizj@gmail.com>",
          "is_bot": false,
          "headline": "test(gitea): add unit tests for parse_payload",
          "author_name": "Kshitiz Jain",
          "author_login": "kshitizj03",
          "committed_at": "2026-06-25T09:21:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fff1dac7fad8183449d7521d3a6c0e797b06efe6",
          "body": "Tekton workspaces are shallow detached-HEAD clones; remote tracking\nrefs like origin/main are not available after git fetch -a --tags.\nUsing {{revision}} (the triggering commit SHA) matches the pattern\nalready used in .tekton/release-pipeline.yaml.",
          "is_bot": false,
          "headline": "fix: use revision instead of origin/main for nightly branch checkout",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-23T13:51:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f765bcb26a4da9fd5cd13137179450683953f56",
          "body": "actions/checkout v7 now refuses to fetch fork pull request code in\npull_request_target workflows by default to prevent pwn request\nattacks. Add allow-unsafe-pr-checkout: true to the e2e workflow\ncheckout step that needs to build and test fork PR code with\nrepository secrets.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): allow checkout of fork PR code in pull_request_target workflow",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-23T11:27:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6554d32b4a9b867c0d3ecc9b902e2b5b358ce38c",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b43\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-23T08:09:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20a29a92b595e6e1c7794d1f9d0771b9554eb14f",
          "body": "Value.Emit() is deprecated in the updated OpenTelemetry SDK;\nreplace with Value.String() to resolve linter warning.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(tracing): use String instead of deprecated Emit",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-23T07:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d39d0d9b0924b8133e16d99d3e5997e1ef058b5",
          "body": "- Update github.com/tektoncd/pipeline from v1.11.1 to v1.13.1\n- Co-upgrades: cel-go v0.28.1, go-scm v1.15.22, otel v1.44.0,\n  zap v1.28.0, k8s.io/* v0.35.5, grpc v1.81.1\n\nCVE-2026-33022 (GHSA-cv4x-93xx-wgfj, CVSS 6.5 Medium):\nTekton Pipelines controller panic via long resolver name in\nGenerateDeterm\n[…]\nIs (pkg/apis, pkg/client) and does not run the\nTekton controller binary.\n\nResolves: SRVKP-9042\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(deps): bump tektoncd/pipeline to v1.13.1",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-23T07:10:31Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2ad17d4501ebcc8021b929c13ae397fcff5c8554",
          "body": "Updated the Homebrew installation documentation to include instructions\nfor trusting the tap to support newer Homebrew versions. Added steps\nto handle macOS Gatekeeper blocking the binary on first run, and\ndefined corresponding caveats in the release configuration.\n\nCo-authored-by: Claude <noreply@anthropic.com>\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "docs: Update homebrew installation instructions for tap trust",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-22T11:19:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3dcf4ae3040e688935b84886bb4d6bbd9f6498a5",
          "body": "this commits adds a reason in log message that why the\nPipelineRun is cancelled so to make it clear to users.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "refactor: enhance log message for cancel-in-progress",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-19T15:22:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c38b0283fe109f5d9dcdfc9a215e07788e112a6c",
          "body": "Addresses Go stdlib vulnerabilities that require upgrading the compiler\ntoolchain from Go 1.25.11 to Go 1.26.4.\n\nCVEs fixed:\n- CVE-2026-27137 (GO-2026-4599): Incorrect email constraints in crypto/x509\n- CVE-2026-27138 (GO-2026-4600): Panic in name constraint checking in crypto/x509\n- CVE-2026-25679 \n[…]\n these fixes require Go 1.26.x.\nNo dependency changes: go.sum unchanged, go mod verify passes.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(security): upgrade Go from 1.25.11 to 1.26.4 to fix 23 stdlib CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-18T13:37:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c0fabcc29f8a87bf2cb7169d2914b8321bbe684",
          "body": "Replaced the local HTTP-based git-clone stepaction with the official\nTekton Hub resolver across Tekton workflows. Removed the redundant\nlocal stepaction definition file to keep configuration centralized.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: Use git-clone artifacthub stepactions",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-17T11:37:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aeb85ab653e95a4ddac059a2909cc41468097d36",
          "body": "Preserves the error chain for errors.Is/errors.As callers.\n\nCo-Authored-By: Claude <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: use %w instead of %s for error wrapping in DetectPacInstallation",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-17T11:37:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cc818de1b009f8c117952eb651a783143c56e605",
          "body": "Add notes to the configmap and docs clarifying that\ncustom-console-url-pr-details, custom-console-url-namespace,\nand custom-console-url-pr-tasklog must all be configured when\ncustom-console-url is set. Also document console URL precedence\norder and add the missing custom-console-url-namespace example.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(consoleui): document required custom console settings",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-17T05:22:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "52fd4ae9ff914eb88fda2013ec33f611b1726f15",
          "body": "Upgrade golang.org/x/crypto from v0.50.0 to v0.52.0 to address the\nfollowing vulnerabilities in the SSH package:\n\n- CVE-2026-42508 (GO-2026-5021): auth bypass via unenforced @revoked status in ssh/knownhosts\n- CVE-2026-39833 (GO-2026-5005): key constraints not enforced in ssh/agent\n- CVE-2026-39832 \n[…]\n3.0\n- golang.org/x/text: v0.36.0 → v0.37.0\n\nAll fixed in v0.52.0 (minimum safe patch version).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade golang.org/x/crypto v0.50.0 → v0.52.0 to fix 13 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-17T03:54:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3180f7ca1db2856ddcc1f1e968c414d0cb89a812",
          "body": "this commit fixes the linting issues after a new\nvale release changes the rule I guess.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(ci): linting issue after new release",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-16T12:59:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6035f789cdf72090f5b6a58e3dece394323c3bf",
          "body": "Upgrade go directive in go.mod from go1.25.7 to go1.25.11 to address\nthe following Go standard library vulnerabilities:\n\n- CVE-2026-42507 (GO-2026-5039): arbitrary inputs in errors without escaping in net/textproto\n- CVE-2026-42504 (GO-2026-5038): quadratic complexity in mime.WordDecoder.DecodeHeade\n[…]\not escaped in html/template\n\nAll fixed in go1.25.11 (minimum safe patch in the go1.25.x line).\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade Go stdlib to go1.25.11 to fix 16 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-16T11:04:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f06dcf55cf3d3f83af65ac8fc9733448b545a4f5",
          "body": "Upgrade golang.org/x/net from v0.53.0 to v0.55.0 to address the\nfollowing vulnerabilities in golang.org/x/net:\n\n- CVE-2026-39821 (GO-2026-5026): failure to reject ASCII-only Punycode-encoded labels\n- CVE-2026-42506 (GO-2026-5025): incorrect handling of namespaced elements in foreign content\n- CVE-20\n[…]\n/text: v0.36.0 → v0.37.0\n\nNote: A separate PR upgrades x/crypto to v0.52.0 to fix 13 SSH CVEs.\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(cve): upgrade golang.org/x/net v0.53.0 → v0.55.0 to fix 6 CVEs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-16T11:03:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cbd582d0eef060094da1bbac907a1d6764b210df",
          "body": "… in the set client",
          "is_bot": false,
          "headline": "feat(bitbucketdatacenter): allow service accounts to not require user…",
          "author_name": "Ruben Rodrigues",
          "author_login": "Ru13en",
          "committed_at": "2026-06-09T18:56:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe709aecfe20b4da430a686463f655b4e1ebefac",
          "body": "gosmee v0.31.1 fixed an inverted TLS flag (InsecureSkipVerify was\nnegated), so the flag now works correctly. Restore it for e2e tests\nthat use self-signed minica certificates and unpin the version to\npick up the security fixes in v0.31.1+.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "fix(ci): restore --insecure-skip-tls-verify and unpin gosmee version",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T15:08:22Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f9c939d7369a9d246ced54404e90642a2d963655",
          "body": "The e2e workflow now installs the minica CA certificate into the system\ntrust store, so gosmee no longer needs to skip TLS verification.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): remove --insecure-skip-tls-verify flag from gosmee client",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T12:01:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ce4774d3f94b07ecc723a920d8312412d730a091",
          "body": "we've seen some failure in E2E test which could\nbe surfaced due to recent gosmee release so using\nv0.31.0 version to see the affect.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: stick gosmee version to v0.31.0",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-09T11:22:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "85f323a53088693acf3e403ff9b6219ce346cc9c",
          "body": "Update release notes format reference to use the new\nTekton Github org name as well as product name,\nreplacing openshift-pipelines and OpenShift references.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(release-notes): update org and branding refs",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-09T08:56:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70faf9f9220253a15f9d71058faeb11097824a78",
          "body": "Gosmee starts before startpaac generates minica certs and before\nupdate-ca-certificates runs. Even after the CA is installed, the\nalready-running gosmee process doesn't pick it up since Go loads\nthe cert pool at startup. This only affects the downstream\nconnection to the PAC controller inside the ephemeral CI cluster,\nnot the upstream SSE connection or any git provider connections.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): skip TLS verification for gosmee client in e2e tests",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-08T12:23:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5bee3b79913be2d55892b4b1dc7306301701e88b",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 6.0.3.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67\n[…]\n- dependency-name: actions/checkout\n  dependency-version: 6.0.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-07T11:12:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "402d5c7eeece881cb082ec68e9e8b61709e39ace",
          "body": "Removed logic that blindly accepted the X-GitHub-Enterprise-Host header\nand now validate that it matches the repository URL in the webhook payload.\nAdded webhook signature verification before token generation to ensure\nthe payload hasn't been tampered with. This prevents an attacker from\nredirecting token requests to their own server by forging the Enterprise\nHost header.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix: prevent GitHub Enterprise header hijacking in app token requests",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-04T15:57:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee5d9b0a55afcd66b09ebce0d9d58d30c050cdb5",
          "body": "Use DeepCopy when reusing cached Pipeline and Task objects across\nPipelineRuns. Without this, inlineTasks mutates the cached\noriginal, contaminating subsequent runs that reference the same\nremote pipeline.\n\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(resolve): deep-copy cached resources before inlining",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-04T15:50:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "001782829e82b83ecb3da903f5a024ca0826b64c",
          "body": "Scope GitHub App installation tokens so they cannot access\nrepositories beyond the triggering one.  Normal webhooks now\nextract the repository ID from the payload and pass it to\nInstallationTokenOptions.  Incoming webhooks lack a payload\nrepo ID, so a new RepositoryNames field lets SetClient scope\nt\n[…]\npe providers and extend SetClient's\nfallback to reissue a scoped token when either field is set.\n\nCo-Authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(github): scope App token to triggering repo",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-04T15:50:44Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bd262aa3b7ad12ea664f9d654351a8766f2c1306",
          "body": "this updates the message about deprecation of secret passing\nin URL query parameters so which would be removed in future\nrelease.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>",
          "is_bot": false,
          "headline": "chore: update incoming webhook legacy params deprecation message",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-06-04T11:39:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c03760fd7181c2b5da1e4ce4356279bf322a7ae",
          "body": "Signed-off-by: Shubham Bhardwaj <shubbhar@redhat.com>",
          "is_bot": false,
          "headline": "fix(security): redact query string from incoming webhook log",
          "author_name": "Shubham Bhardwaj",
          "author_login": "infernus01",
          "committed_at": "2026-06-03T15:42:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "223e39c0ec6d784114d566364a7c6eb99964172a",
          "body": "The notify-slack script looked for e2e-test-output.log which was\nnever produced by gotestsum. Switch to parsing e2e-test-output.json\nusing jq so scheduled run failures are reported to Slack.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): parse JSON test output for Slack notifications",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-06-03T11:45:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "885427460c5323b1267bd10eccbcd59a29baa1bf",
          "body": "The pipelines-as-code-controller ServiceAccount had cluster-wide delete\npermission on secrets that was never used in the codebase. This change\nremoves the unused permission to follow the principle of least privilege.\n\nThe controller only requires 'get' permission on secrets for:\n- Incoming webhook v\n[…]\nate, delete) for managing the\nlifecycle of pac-gitauth-* secrets.\n\nVerification:\n- All unit tests pass (2816 tests)\n- Linting passes\n- Watcher permissions unchanged\n- No functional impact\n\nFixes #2743",
          "is_bot": false,
          "headline": "fix: remove unused secrets/delete permission from controller",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-06-03T06:58:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d0454b7d2cd8ddef53fc8c6b147851b053acff2",
          "body": "Bumps [mxschmitt/action-tmate](https://github.com/mxschmitt/action-tmate) from 3.23 to 3.24.\n- [Release notes](https://github.com/mxschmitt/action-tmate/releases)\n- [Changelog](https://github.com/mxschmitt/action-tmate/blob/master/RELEASE.md)\n- [Commits](https://github.com/mxschmitt/action-tmate/com\n[…]\ndency-name: mxschmitt/action-tmate\n  dependency-version: '3.24'\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump mxschmitt/action-tmate from 3.23 to 3.24",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-01T14:47:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67cfa525176645dee0e19297584436c0526f6183",
          "body": "Replace the obsolete profiling.enable ConfigMap key with\nruntime-profiling (enabled/disabled). Remove the K_METRICS_CONFIG\ncontroller section since the controller now uses ConfigMap-based\nobservability via the eventing adapter. Document that controller\nprofiling requires a pod restart as the adapter\n[…]\nconfig once\nat startup. Add CONFIG_OBSERVABILITY_NAME prerequisite for the\nwebhook.\n\nFixes #2633\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(profiling): update guide for OTel migration",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-29T12:34:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3811249c246b4084b1f2e337069c0ccf412ac516",
          "body": "Update knative/eventing to v0.49.0 which includes the pprof server\nfix (knative/eventing#9008). Also bumps k8s.io to v0.35.4,\nknative/pkg, and golang.org/x dependencies.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "chore(deps): bump knative/eventing to v0.49.0",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-29T12:34:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0bb2f82a9cfac342fe22a948cc7b7c035d9ec4a3",
          "body": "Add configurable TLS settings for the PAC controller via\ndeployment environment variables. This allows the Tekton Operator\nto propagate TLS configuration (min version, cipher suites, curve\npreferences) to the controller without code changes.\n\n- Add pkg/tlsconfig package for parsing TLS configuration\n[…]\n_CURVE_PREFERENCES env vars to the controller deployment\n  with secure defaults matching Tekton Results\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nAssisted-by: Claude Opus 4.6 (via Claude Code)",
          "is_bot": false,
          "headline": "feat: add TLS configuration support",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-28T12:49:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4dac4d6d836a59f2ec81cb3d5f0f132227b9c102",
          "body": "Deprecated the Tekton Hub catalog integration across documentation,\nconfiguration settings, and resource resolution. Added deprecation\nwarnings via logger messages, Kubernetes events on Repository CRs,\nand automated comments on pull requests when resources were resolved\nfrom Tekton Hub catalogs. Thi\n[…]\nnge prepared users for the complete\nremoval of Tekton Hub support in a future release, encouraging them\nto migrate to Artifact Hub or remote URLs.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "feat: Add deprecation warnings for Tekton Hub integration",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-28T12:06:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69fa323d60c2436976059296b33993a03ecd5553",
          "body": "When a version tag (e.g. v0.47.0) is pushed, the container workflow's\ntag sanitization converts dots to dashes producing v0-47-0 images.\nThe release pipeline generates release.yaml referencing v0.47.0\n(with dots), causing a mismatch where manifests point to nonexistent\nimage tags.\n\nAdd a condition for refs/tags/v* that uses the tag name as-is, since\nDocker image tags support dots.\n\nCloses #2741",
          "is_bot": false,
          "headline": "fix(release): preserve dots in image tags for version tag pushes",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-27T08:37:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32820cbb4c98d6b66e40e5445c20e5f85459e678",
          "body": "Enable Gitea/Forgejo provider to resolve remote taskRef URLs using\nthe provider's authenticated API instead of returning \"not\nsupported\". Supports branch, tag, and commit SHA URL formats.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>\nAssisted-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(gitea): implement GetTaskURI for remote task resolution",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-27T08:28:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "529a725ac61ca5c4e0a0e35408e36c16fe238e33",
          "body": "When a merge request originates from a fork the bot cannot access,\npost an informative comment on the MR explaining the issue. Uses\nCreateComment with an update marker to prevent duplicate comments\non reconciler retries.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "fix(gitlab): post MR comment on inaccessible fork",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-25T10:11:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c7b0e06e41e7d3834292bd66e13dee95f195c9d",
          "body": "The watcher observes PipelineRun status but does not own it.\nDisable generated status synchronization so informer cache\ntransforms cannot trigger UpdateStatus calls against the\nPipelineRun /status subresource.\n\nThis avoids forbidden errors on clusters where the watcher\nonly has metadata and spec-level PipelineRun permissions.\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "fix(reconciler): skip watcher status updates",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-20T11:46:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b9a6f1842eb647014055bb183f76fb724f0b3d6",
          "body": "The gomodguard_v2 linter was introduced in v2.12.0 but the CI\nimage was still on v2.10.1, causing lint failures with unknown\nlinter error.\n\nSigned-off-by: Akshay Pant <akpant@redhat.com>",
          "is_bot": false,
          "headline": "ci: update golangci-lint to v2.12.2",
          "author_name": "Akshay Pant",
          "author_login": "theakshaypant",
          "committed_at": "2026-05-20T10:09:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9db1feca2d2b030a3f08ffac7f1710928f5d11f8",
          "body": "Updated gomodguard to gomodguard_v2 for the latest linter\nversion. Also disabled the inline check in govet to reduce\nfalse positives during code analysis.\n\nError was:\n\nlevel=warning msg=\"The linter 'gomodguard' is deprecated (since v2.12.0)\ndue to: new major version. Replaced by gomodguard_v2.\" leve\n[…]\nta) ^\ntest/pkg/configmap/configmap.go:22:11: inline: cannot inline: type\nparameter inference is not yet supported (govet) maps.Copy(newData,\ndata)\n\nSigned-off-by: Chmouel Boudjnah <chmouel@redhat.com>",
          "is_bot": false,
          "headline": "chore: update golangci linter configuration",
          "author_name": "Chmouel Boudjnah",
          "author_login": "chmouel",
          "committed_at": "2026-05-20T03:18:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "445941b2cc745ff67afc9fcc9549a3b66a011b74",
          "body": "Previously, CEL expressions in Pipelines-as-Code only had access to\nthe core CEL operators, which limited users to basic comparisons and\nlogical expressions. Functions like join(), replace(), substring(),\nand other string/list manipulation operations were unavailable,\nforcing users to work around th\n[…]\nparison, since the output is a single\ndynamic file path that varies per test run.\n\nSigned-off-by: Zaki Shaikh <zashaikh@redhat.com>\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(cel): enable string and list extension functions in CEL expressions",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-19T15:07:09Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f841d2d728d228f4008fa0cb336793e5a182cd74",
          "body": "When a pull request is merged in Bitbucket Data Center, the resulting\npush event contains a merge commit that reports no file changes. This\ncaused on-path-change and on-cel-expression filters to silently skip\nPipelineRuns because the changed files list was always empty.\n\nThe fix detects merge commit\n[…]\n for on-path-change annotation surviving a PR merge push\n- Add unit tests for getMergeCommitChanges and merge commit GetFiles path\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bitbucket-datacenter): detect changes on merged PR push",
          "author_name": "Zaki Shaikh",
          "author_login": "zakisk",
          "committed_at": "2026-05-19T10:57:42Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 575,
      "latest_release_at": "2026-07-17T13:48:26Z",
      "latest_release_tag": "v0.48.1",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 51,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 5.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/openshift-pipelines/pipelines-as-code",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": false,
          "registry_url": "https://pkg.go.dev/github.com/openshift-pipelines/pipelines-as-code",
          "is_deprecated": false,
          "latest_version": "v0.49.0",
          "repository_url": "https://github.com/openshift-pipelines/pipelines-as-code",
          "versions_count": 113,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-06T12:02:19Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 15
        }
      ]
    },
    "popularity": {
      "forks": 135,
      "stars": 203,
      "watchers": 9,
      "fork_history": {
        "days": [
          {
            "date": "2021-04-06",
            "count": 1
          },
          {
            "date": "2021-04-22",
            "count": 1
          },
          {
            "date": "2021-05-20",
            "count": 1
          },
          {
            "date": "2021-07-01",
            "count": 1
          },
          {
            "date": "2021-08-12",
            "count": 1
          },
          {
            "date": "2021-08-16",
            "count": 1
          },
          {
            "date": "2021-08-29",
            "count": 1
          },
          {
            "date": "2021-09-14",
            "count": 1
          },
          {
            "date": "2021-10-14",
            "count": 1
          },
          {
            "date": "2021-11-11",
            "count": 1
          },
          {
            "date": "2021-11-15",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 1
          },
          {
            "date": "2021-11-19",
            "count": 1
          },
          {
            "date": "2021-11-24",
            "count": 1
          },
          {
            "date": "2021-11-29",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-01-21",
            "count": 1
          },
          {
            "date": "2022-01-26",
            "count": 1
          },
          {
            "date": "2022-02-07",
            "count": 1
          },
          {
            "date": "2022-02-15",
            "count": 1
          },
          {
            "date": "2022-03-11",
            "count": 1
          },
          {
            "date": "2022-03-24",
            "count": 1
          },
          {
            "date": "2022-03-25",
            "count": 1
          },
          {
            "date": "2022-04-04",
            "count": 2
          },
          {
            "date": "2022-04-07",
            "count": 1
          },
          {
            "date": "2022-04-18",
            "count": 1
          },
          {
            "date": "2022-06-08",
            "count": 1
          },
          {
            "date": "2022-06-09",
            "count": 2
          },
          {
            "date": "2022-07-07",
            "count": 1
          },
          {
            "date": "2022-07-16",
            "count": 1
          },
          {
            "date": "2022-08-17",
            "count": 1
          },
          {
            "date": "2022-08-30",
            "count": 1
          },
          {
            "date": "2022-10-05",
            "count": 1
          },
          {
            "date": "2022-10-16",
            "count": 1
          },
          {
            "date": "2022-11-01",
            "count": 1
          },
          {
            "date": "2022-11-18",
            "count": 1
          },
          {
            "date": "2023-01-06",
            "count": 1
          },
          {
            "date": "2023-01-11",
            "count": 1
          },
          {
            "date": "2023-01-13",
            "count": 1
          },
          {
            "date": "2023-01-19",
            "count": 1
          },
          {
            "date": "2023-02-14",
            "count": 1
          },
          {
            "date": "2023-03-09",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 1
          },
          {
            "date": "2023-03-26",
            "count": 2
          },
          {
            "date": "2023-03-29",
            "count": 2
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-04-26",
            "count": 1
          },
          {
            "date": "2023-05-03",
            "count": 1
          },
          {
            "date": "2023-05-17",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-12",
            "count": 1
          },
          {
            "date": "2023-09-04",
            "count": 1
          },
          {
            "date": "2023-10-15",
            "count": 1
          },
          {
            "date": "2023-10-25",
            "count": 1
          },
          {
            "date": "2023-11-06",
            "count": 1
          },
          {
            "date": "2023-11-16",
            "count": 1
          },
          {
            "date": "2023-12-07",
            "count": 1
          },
          {
            "date": "2023-12-13",
            "count": 1
          },
          {
            "date": "2024-02-04",
            "count": 1
          },
          {
            "date": "2024-03-14",
            "count": 1
          },
          {
            "date": "2024-03-22",
            "count": 2
          },
          {
            "date": "2024-04-08",
            "count": 1
          },
          {
            "date": "2024-06-04",
            "count": 1
          },
          {
            "date": "2024-06-05",
            "count": 1
          },
          {
            "date": "2024-06-20",
            "count": 1
          },
          {
            "date": "2024-06-28",
            "count": 1
          },
          {
            "date": "2024-07-02",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-10-15",
            "count": 1
          },
          {
            "date": "2024-11-26",
            "count": 1
          },
          {
            "date": "2024-11-28",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-03",
            "count": 1
          },
          {
            "date": "2024-12-27",
            "count": 1
          },
          {
            "date": "2025-01-03",
            "count": 1
          },
          {
            "date": "2025-01-18",
            "count": 1
          },
          {
            "date": "2025-01-22",
            "count": 1
          },
          {
            "date": "2025-01-30",
            "count": 2
          },
          {
            "date": "2025-02-06",
            "count": 1
          },
          {
            "date": "2025-02-11",
            "count": 1
          },
          {
            "date": "2025-02-23",
            "count": 1
          },
          {
            "date": "2025-02-28",
            "count": 1
          },
          {
            "date": "2025-03-14",
            "count": 1
          },
          {
            "date": "2025-03-20",
            "count": 1
          },
          {
            "date": "2025-04-15",
            "count": 1
          },
          {
            "date": "2025-05-08",
            "count": 1
          },
          {
            "date": "2025-05-28",
            "count": 1
          },
          {
            "date": "2025-06-05",
            "count": 1
          },
          {
            "date": "2025-06-13",
            "count": 1
          },
          {
            "date": "2025-06-20",
            "count": 1
          },
          {
            "date": "2025-06-30",
            "count": 1
          },
          {
            "date": "2025-07-20",
            "count": 1
          },
          {
            "date": "2025-08-04",
            "count": 1
          },
          {
            "date": "2025-08-10",
            "count": 1
          },
          {
            "date": "2025-09-30",
            "count": 1
          },
          {
            "date": "2025-10-14",
            "count": 1
          },
          {
            "date": "2025-11-21",
            "count": 1
          },
          {
            "date": "2025-12-17",
            "count": 1
          },
          {
            "date": "2026-01-17",
            "count": 1
          },
          {
            "date": "2026-01-28",
            "count": 1
          },
          {
            "date": "2026-02-17",
            "count": 1
          },
          {
            "date": "2026-02-19",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 1
          },
          {
            "date": "2026-03-18",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-24",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-16",
            "count": 1
          },
          {
            "date": "2026-04-20",
            "count": 1
          },
          {
            "date": "2026-05-13",
            "count": 2
          },
          {
            "date": "2026-05-15",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-01",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-08",
            "count": 1
          },
          {
            "date": "2026-06-09",
            "count": 1
          },
          {
            "date": "2026-06-18",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-06-21",
            "count": 1
          },
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 129,
        "total_forks": 135
      },
      "star_history": {
        "days": [
          {
            "date": "2021-05-27",
            "count": 2
          },
          {
            "date": "2021-06-07",
            "count": 1
          },
          {
            "date": "2021-06-25",
            "count": 1
          },
          {
            "date": "2021-06-29",
            "count": 1
          },
          {
            "date": "2021-07-03",
            "count": 1
          },
          {
            "date": "2021-07-04",
            "count": 1
          },
          {
            "date": "2021-07-05",
            "count": 1
          },
          {
            "date": "2021-07-06",
            "count": 2
          },
          {
            "date": "2021-09-01",
            "count": 1
          },
          {
            "date": "2021-09-08",
            "count": 1
          },
          {
            "date": "2021-09-19",
            "count": 1
          },
          {
            "date": "2021-09-21",
            "count": 1
          },
          {
            "date": "2021-10-13",
            "count": 1
          },
          {
            "date": "2021-10-26",
            "count": 1
          },
          {
            "date": "2021-11-17",
            "count": 2
          },
          {
            "date": "2021-11-23",
            "count": 1
          },
          {
            "date": "2021-11-24",
            "count": 1
          },
          {
            "date": "2021-12-09",
            "count": 1
          },
          {
            "date": "2021-12-10",
            "count": 2
          },
          {
            "date": "2021-12-15",
            "count": 1
          },
          {
            "date": "2021-12-20",
            "count": 1
          },
          {
            "date": "2022-01-08",
            "count": 1
          },
          {
            "date": "2022-01-11",
            "count": 1
          },
          {
            "date": "2022-02-08",
            "count": 1
          },
          {
            "date": "2022-03-01",
            "count": 1
          },
          {
            "date": "2022-03-04",
            "count": 1
          },
          {
            "date": "2022-03-08",
            "count": 1
          },
          {
            "date": "2022-03-16",
            "count": 1
          },
          {
            "date": "2022-03-17",
            "count": 1
          },
          {
            "date": "2022-04-01",
            "count": 1
          },
          {
            "date": "2022-04-08",
            "count": 1
          },
          {
            "date": "2022-04-11",
            "count": 1
          },
          {
            "date": "2022-04-12",
            "count": 1
          },
          {
            "date": "2022-04-19",
            "count": 1
          },
          {
            "date": "2022-04-27",
            "count": 1
          },
          {
            "date": "2022-04-29",
            "count": 1
          },
          {
            "date": "2022-05-13",
            "count": 1
          },
          {
            "date": "2022-05-14",
            "count": 1
          },
          {
            "date": "2022-05-17",
            "count": 1
          },
          {
            "date": "2022-05-25",
            "count": 1
          },
          {
            "date": "2022-06-10",
            "count": 1
          },
          {
            "date": "2022-06-14",
            "count": 1
          },
          {
            "date": "2022-06-22",
            "count": 1
          },
          {
            "date": "2022-06-25",
            "count": 1
          },
          {
            "date": "2022-07-14",
            "count": 1
          },
          {
            "date": "2022-07-21",
            "count": 1
          },
          {
            "date": "2022-08-05",
            "count": 1
          },
          {
            "date": "2022-08-07",
            "count": 1
          },
          {
            "date": "2022-08-23",
            "count": 1
          },
          {
            "date": "2022-10-19",
            "count": 1
          },
          {
            "date": "2022-11-05",
            "count": 1
          },
          {
            "date": "2022-12-13",
            "count": 1
          },
          {
            "date": "2022-12-14",
            "count": 1
          },
          {
            "date": "2022-12-29",
            "count": 1
          },
          {
            "date": "2023-01-17",
            "count": 1
          },
          {
            "date": "2023-01-27",
            "count": 2
          },
          {
            "date": "2023-02-03",
            "count": 1
          },
          {
            "date": "2023-02-06",
            "count": 1
          },
          {
            "date": "2023-02-09",
            "count": 1
          },
          {
            "date": "2023-02-16",
            "count": 1
          },
          {
            "date": "2023-03-01",
            "count": 1
          },
          {
            "date": "2023-03-15",
            "count": 1
          },
          {
            "date": "2023-03-25",
            "count": 2
          },
          {
            "date": "2023-03-28",
            "count": 1
          },
          {
            "date": "2023-04-08",
            "count": 1
          },
          {
            "date": "2023-04-11",
            "count": 1
          },
          {
            "date": "2023-04-12",
            "count": 1
          },
          {
            "date": "2023-04-15",
            "count": 1
          },
          {
            "date": "2023-04-21",
            "count": 1
          },
          {
            "date": "2023-04-24",
            "count": 1
          },
          {
            "date": "2023-04-25",
            "count": 1
          },
          {
            "date": "2023-04-30",
            "count": 1
          },
          {
            "date": "2023-05-02",
            "count": 1
          },
          {
            "date": "2023-05-25",
            "count": 1
          },
          {
            "date": "2023-05-31",
            "count": 1
          },
          {
            "date": "2023-06-01",
            "count": 1
          },
          {
            "date": "2023-06-08",
            "count": 1
          },
          {
            "date": "2023-06-20",
            "count": 1
          },
          {
            "date": "2023-06-21",
            "count": 1
          },
          {
            "date": "2023-07-04",
            "count": 1
          },
          {
            "date": "2023-07-08",
            "count": 1
          },
          {
            "date": "2023-07-13",
            "count": 1
          },
          {
            "date": "2023-07-24",
            "count": 1
          },
          {
            "date": "2023-08-28",
            "count": 1
          },
          {
            "date": "2023-09-04",
            "count": 1
          },
          {
            "date": "2023-09-08",
            "count": 1
          },
          {
            "date": "2023-09-20",
            "count": 1
          },
          {
            "date": "2023-09-25",
            "count": 2
          },
          {
            "date": "2023-10-03",
            "count": 1
          },
          {
            "date": "2023-10-30",
            "count": 1
          },
          {
            "date": "2023-11-10",
            "count": 1
          },
          {
            "date": "2023-12-08",
            "count": 1
          },
          {
            "date": "2023-12-19",
            "count": 1
          },
          {
            "date": "2023-12-21",
            "count": 1
          },
          {
            "date": "2023-12-28",
            "count": 1
          },
          {
            "date": "2024-01-02",
            "count": 1
          },
          {
            "date": "2024-01-19",
            "count": 1
          },
          {
            "date": "2024-02-07",
            "count": 2
          },
          {
            "date": "2024-02-20",
            "count": 1
          },
          {
            "date": "2024-02-26",
            "count": 1
          },
          {
            "date": "2024-02-28",
            "count": 1
          },
          {
            "date": "2024-03-11",
            "count": 1
          },
          {
            "date": "2024-03-27",
            "count": 1
          },
          {
            "date": "2024-04-02",
            "count": 1
          },
          {
            "date": "2024-04-09",
            "count": 2
          },
          {
            "date": "2024-04-25",
            "count": 1
          },
          {
            "date": "2024-05-06",
            "count": 1
          },
          {
            "date": "2024-05-08",
            "count": 1
          },
          {
            "date": "2024-06-05",
            "count": 1
          },
          {
            "date": "2024-06-18",
            "count": 1
          },
          {
            "date": "2024-06-19",
            "count": 1
          },
          {
            "date": "2024-06-20",
            "count": 1
          },
          {
            "date": "2024-07-16",
            "count": 1
          },
          {
            "date": "2024-07-21",
            "count": 1
          },
          {
            "date": "2024-08-02",
            "count": 1
          },
          {
            "date": "2024-08-08",
            "count": 1
          },
          {
            "date": "2024-08-13",
            "count": 1
          },
          {
            "date": "2024-09-27",
            "count": 1
          },
          {
            "date": "2024-10-16",
            "count": 1
          },
          {
            "date": "2024-10-20",
            "count": 1
          },
          {
            "date": "2024-10-27",
            "count": 1
          },
          {
            "date": "2024-10-28",
            "count": 1
          },
          {
            "date": "2024-11-10",
            "count": 1
          },
          {
            "date": "2024-11-15",
            "count": 1
          },
          {
            "date": "2024-11-30",
            "count": 1
          },
          {
            "date": "2024-12-25",
            "count": 1
          },
          {
            "date": "2025-01-09",
            "count": 2
          },
          {
            "date": "2025-02-07",
            "count": 1
          },
          {
            "date": "2025-02-12",
            "count": 4
          },
          {
            "date": "2025-02-13",
            "count": 2
          },
          {
            "date": "2025-02-24",
            "count": 1
          },
          {
            "date": "2025-02-26",
            "count": 1
          },
          {
            "date": "2025-03-19",
            "count": 1
          },
          {
            "date": "2025-03-21",
            "count": 1
          },
          {
            "date": "2025-04-23",
            "count": 1
          },
          {
            "date": "2025-05-21",
            "count": 2
          },
          {
            "date": "2025-05-27",
            "count": 1
          },
          {
            "date": "2025-05-30",
            "count": 1
          },
          {
            "date": "2025-06-07",
            "count": 1
          },
          {
            "date": "2025-06-11",
            "count": 4
          },
          {
            "date": "2025-07-01",
            "count": 2
          },
          {
            "date": "2025-07-06",
            "count": 1
          },
          {
            "date": "2025-08-30",
            "count": 1
          },
          {
            "date": "2025-10-10",
            "count": 1
          },
          {
            "date": "2025-10-11",
            "count": 1
          },
          {
            "date": "2025-10-22",
            "count": 1
          },
          {
            "date": "2025-11-07",
            "count": 1
          },
          {
            "date": "2025-11-19",
            "count": 1
          },
          {
            "date": "2025-11-26",
            "count": 1
          },
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-01-30",
            "count": 1
          },
          {
            "date": "2026-02-03",
            "count": 1
          },
          {
            "date": "2026-02-06",
            "count": 1
          },
          {
            "date": "2026-02-08",
            "count": 1
          },
          {
            "date": "2026-02-09",
            "count": 1
          },
          {
            "date": "2026-02-10",
            "count": 1
          },
          {
            "date": "2026-03-16",
            "count": 1
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-04-01",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 2
          },
          {
            "date": "2026-04-08",
            "count": 1
          },
          {
            "date": "2026-04-09",
            "count": 1
          },
          {
            "date": "2026-04-14",
            "count": 1
          },
          {
            "date": "2026-04-19",
            "count": 1
          },
          {
            "date": "2026-04-23",
            "count": 1
          },
          {
            "date": "2026-04-26",
            "count": 1
          },
          {
            "date": "2026-05-02",
            "count": 1
          },
          {
            "date": "2026-05-04",
            "count": 2
          },
          {
            "date": "2026-05-16",
            "count": 1
          },
          {
            "date": "2026-05-30",
            "count": 1
          },
          {
            "date": "2026-06-03",
            "count": 1
          },
          {
            "date": "2026-06-04",
            "count": 1
          },
          {
            "date": "2026-06-05",
            "count": 1
          },
          {
            "date": "2026-06-07",
            "count": 1
          },
          {
            "date": "2026-06-16",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          },
          {
            "date": "2026-06-23",
            "count": 1
          },
          {
            "date": "2026-07-03",
            "count": 2
          },
          {
            "date": "2026-07-07",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 203,
        "total_stars": 203
      },
      "open_issues_and_prs": 80
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "samples"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
        "vendor/github.com/emicklei/go-restful/v3/Makefile",
        "vendor/github.com/felixge/httpsnoop/Makefile",
        "vendor/github.com/hashicorp/go-retryablehttp/Makefile",
        "vendor/github.com/juju/ansiterm/Makefile",
        "vendor/github.com/ktrysmt/go-bitbucket/Makefile",
        "vendor/github.com/munnerz/goautoneg/Makefile",
        "vendor/github.com/pkg/errors/Makefile",
        "vendor/github.com/prometheus/procfs/Makefile",
        "vendor/github.com/spf13/cobra/Makefile",
        "vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
        "vendor/go.opentelemetry.io/otel/Makefile",
        "vendor/go.uber.org/atomic/Makefile",
        "vendor/go.uber.org/multierr/Makefile",
        "vendor/go.uber.org/zap/Makefile",
        "vendor/google.golang.org/grpc/Makefile",
        "vendor/sigs.k8s.io/json/Makefile"
      ],
      "api_schema_files": [
        "vendor/github.com/google/gnostic-models/extensions/extension.proto",
        "vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
        "vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
        "vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
        "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
        "vendor/k8s.io/api/admission/v1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
        "vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
        "vendor/k8s.io/api/apidiscovery/v2/generated.proto",
        "vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
        "vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
        "vendor/k8s.io/api/apps/v1/generated.proto",
        "vendor/k8s.io/api/apps/v1beta1/generated.proto",
        "vendor/k8s.io/api/apps/v1beta2/generated.proto",
        "vendor/k8s.io/api/authentication/v1/generated.proto",
        "vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
        "vendor/k8s.io/api/authentication/v1beta1/generated.proto",
        "vendor/k8s.io/api/authorization/v1/generated.proto",
        "vendor/k8s.io/api/authorization/v1beta1/generated.proto",
        "vendor/k8s.io/api/autoscaling/v1/generated.proto",
        "vendor/k8s.io/api/autoscaling/v2/generated.proto",
        "vendor/k8s.io/api/batch/v1/generated.proto",
        "vendor/k8s.io/api/batch/v1beta1/generated.proto",
        "vendor/k8s.io/api/certificates/v1/generated.proto",
        "vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
        "vendor/k8s.io/api/certificates/v1beta1/generated.proto",
        "vendor/k8s.io/api/coordination/v1/generated.proto",
        "vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
        "vendor/k8s.io/api/coordination/v1beta1/generated.proto",
        "vendor/k8s.io/api/core/v1/generated.proto",
        "vendor/k8s.io/api/discovery/v1/generated.proto",
        "vendor/k8s.io/api/discovery/v1beta1/generated.proto",
        "vendor/k8s.io/api/events/v1/generated.proto",
        "vendor/k8s.io/api/events/v1beta1/generated.proto",
        "vendor/k8s.io/api/extensions/v1beta1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
        "vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
        "vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
        "vendor/k8s.io/api/networking/v1/generated.proto",
        "vendor/k8s.io/api/networking/v1beta1/generated.proto",
        "vendor/k8s.io/api/node/v1/generated.proto",
        "vendor/k8s.io/api/node/v1alpha1/generated.proto",
        "vendor/k8s.io/api/node/v1beta1/generated.proto",
        "vendor/k8s.io/api/policy/v1/generated.proto",
        "vendor/k8s.io/api/policy/v1beta1/generated.proto",
        "vendor/k8s.io/api/rbac/v1/generated.proto",
        "vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
        "vendor/k8s.io/api/rbac/v1beta1/generated.proto",
        "vendor/k8s.io/api/resource/v1/generated.proto",
        "vendor/k8s.io/api/resource/v1alpha3/generated.proto",
        "vendor/k8s.io/api/resource/v1beta1/generated.proto",
        "vendor/k8s.io/api/resource/v1beta2/generated.proto",
        "vendor/k8s.io/api/scheduling/v1/generated.proto",
        "vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
        "vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
        "vendor/k8s.io/api/storage/v1/generated.proto",
        "vendor/k8s.io/api/storage/v1alpha1/generated.proto",
        "vendor/k8s.io/api/storage/v1beta1/generated.proto",
        "vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
        "vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
        "vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "docs/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 92818,
      "source_files_sampled": 518,
      "oversized_source_files": 3,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
        "vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
        "vendor/go.opentelemetry.io/otel/AGENTS.md",
        "vendor/go.opentelemetry.io/otel/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 12245
    },
    "dependencies": {
      "manifests": [
        "docs/go.mod",
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.81.1",
            "severity": "critical",
            "ecosystem": "go",
            "cvss_score": 9.1,
            "advisory_ids": [
              "GHSA-hrxh-6v49-42gf"
            ],
            "fixed_version": "1.82.1",
            "advisory_count": 1,
            "oldest_advisory_days": 0
          },
          {
            "name": "github.com/tektoncd/pipeline",
            "direct": true,
            "version": "v1.14.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2023-1901",
              "GO-2026-4730"
            ],
            "fixed_version": null,
            "advisory_count": 2,
            "oldest_advisory_days": 700
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 2,
          "critical": 1
        },
        "advisory_count": 4,
        "affected_count": 3,
        "assessed_count": 156,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 7,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.0"
        },
        {
          "name": "github.com/AlecAivazis/survey/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.3.7"
        },
        {
          "name": "github.com/bradleyfalzon/ghinstallation/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.18.0"
        },
        {
          "name": "github.com/chzyer/readline",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.1"
        },
        {
          "name": "github.com/cloudevents/sdk-go/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.16.2"
        },
        {
          "name": "github.com/fvbommel/sortorder",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.1.0"
        },
        {
          "name": "github.com/gobwas/glob",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.3"
        },
        {
          "name": "github.com/google/cel-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.29.2"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.7.0"
        },
        {
          "name": "github.com/google/go-github/scrape",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260403152401-96a365122246"
        },
        {
          "name": "github.com/google/go-github/v84",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v84.0.0"
        },
        {
          "name": "github.com/google/go-github/v85",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v85.0.0"
        },
        {
          "name": "github.com/hako/durafmt",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20210608085754-5c1018a4e16b"
        },
        {
          "name": "github.com/jenkins-x/go-scm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.15.31"
        },
        {
          "name": "github.com/jonboulle/clockwork",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.0"
        },
        {
          "name": "github.com/juju/ansiterm",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/ktrysmt/go-bitbucket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.10.0"
        },
        {
          "name": "github.com/mattn/go-colorable",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.1.15"
        },
        {
          "name": "github.com/mattn/go-isatty",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.23"
        },
        {
          "name": "github.com/mgutz/ansi",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20200706080929-d51e80ef957d"
        },
        {
          "name": "github.com/mitchellh/mapstructure",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/pkg/errors",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.9.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/stretchr/testify",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.11.1"
        },
        {
          "name": "github.com/tektoncd/pipeline",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.0"
        },
        {
          "name": "gitlab.com/gitlab-org/api/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.46.0"
        },
        {
          "name": "go.opentelemetry.io/otel",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/sdk/metric",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.opentelemetry.io/otel/trace",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.0"
        },
        {
          "name": "go.uber.org/zap",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.28.0"
        },
        {
          "name": "golang.org/x/exp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260312153236-7ab1446f8b90"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        },
        {
          "name": "golang.org/x/text",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.40.0"
        },
        {
          "name": "gopkg.in/yaml.v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.4.0"
        },
        {
          "name": "gotest.tools/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.5.2"
        },
        {
          "name": "k8s.io/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/apimachinery",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/client-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.2"
        },
        {
          "name": "k8s.io/utils",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260319190234-28399d86e0b5"
        },
        {
          "name": "knative.dev/eventing",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.49.2"
        },
        {
          "name": "knative.dev/pkg",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260622140654-39ebae2ee2dc"
        },
        {
          "name": "sigs.k8s.io/yaml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/golang-jwt/jwt/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.5.2"
        },
        {
          "name": "github.com/prometheus/client_model",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.2"
        },
        {
          "name": "github.com/prometheus/common",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.69.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "google.golang.org/genproto/googleapis/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.0.0-20260526163538-3dc84a4a5aaa"
        },
        {
          "name": "google.golang.org/protobuf",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.36.12-0.20260120151049-f2248ac996af"
        },
        {
          "name": "k8s.io/klog/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.140.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "codeberg.org/mvdkleijn/forgejo-sdk/forgejo/v3",
            "direct": true,
            "version": "v3.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/alecaivazis/survey/v2",
            "direct": true,
            "version": "v2.3.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bradleyfalzon/ghinstallation/v2",
            "direct": true,
            "version": "v2.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/chzyer/readline",
            "direct": true,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/v2",
            "direct": true,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fvbommel/sortorder",
            "direct": true,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gobwas/glob",
            "direct": true,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v4",
            "direct": true,
            "version": "v4.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/cel-go",
            "direct": true,
            "version": "v0.29.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/scrape",
            "direct": true,
            "version": "v0.0.0-20260403152401-96a365122246",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v84",
            "direct": true,
            "version": "v84.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v85",
            "direct": true,
            "version": "v85.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hako/durafmt",
            "direct": true,
            "version": "v0.0.0-20210608085754-5c1018a4e16b",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jenkins-x/go-scm",
            "direct": true,
            "version": "v1.15.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jonboulle/clockwork",
            "direct": true,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/juju/ansiterm",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ktrysmt/go-bitbucket",
            "direct": true,
            "version": "v0.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-colorable",
            "direct": true,
            "version": "v0.1.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": true,
            "version": "v0.0.23",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mgutz/ansi",
            "direct": true,
            "version": "v0.0.0-20200706080929-d51e80ef957d",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/mapstructure",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/errors",
            "direct": true,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_model",
            "direct": true,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/common",
            "direct": true,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/testify",
            "direct": true,
            "version": "v1.11.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tektoncd/pipeline",
            "direct": true,
            "version": "v1.14.0",
            "ecosystem": "go"
          },
          {
            "name": "gitlab.com/gitlab-org/api/client-go",
            "direct": true,
            "version": "v1.46.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/sdk/metric",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": true,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/zap",
            "direct": true,
            "version": "v1.28.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": true,
            "version": "v0.0.0-20260312153236-7ab1446f8b90",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": true,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": true,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/api",
            "direct": true,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/protobuf",
            "direct": true,
            "version": "v1.36.12-0.20260120151049-f2248ac996af",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v2",
            "direct": true,
            "version": "v2.4.0",
            "ecosystem": "go"
          },
          {
            "name": "gotest.tools/v3",
            "direct": true,
            "version": "v3.5.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/api",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apimachinery",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/client-go",
            "direct": true,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/klog/v2",
            "direct": true,
            "version": "v2.140.0",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/utils",
            "direct": true,
            "version": "v0.0.0-20260319190234-28399d86e0b5",
            "ecosystem": "go"
          },
          {
            "name": "knative.dev/eventing",
            "direct": true,
            "version": "v0.49.2",
            "ecosystem": "go"
          },
          {
            "name": "knative.dev/pkg",
            "direct": true,
            "version": "v0.0.0-20260622140654-39ebae2ee2dc",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/yaml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "cel.dev/expr",
            "direct": false,
            "version": "v0.25.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/42wim/httpsig",
            "direct": false,
            "version": "v1.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/andybalholm/cascadia",
            "direct": false,
            "version": "v1.3.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr/antlr4/runtime/go/antlr",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/antlr4-go/antlr/v4",
            "direct": false,
            "version": "v4.13.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/beorn7/perks",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blang/semver/v4",
            "direct": false,
            "version": "v4.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/blendle/zapdriver",
            "direct": false,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cenkalti/backoff/v5",
            "direct": false,
            "version": "v5.0.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cert-manager/cert-manager",
            "direct": false,
            "version": "v1.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/observability/opentelemetry/v2",
            "direct": false,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cloudevents/sdk-go/sql/v2",
            "direct": false,
            "version": "v2.16.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-oidc/v3",
            "direct": false,
            "version": "v3.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davecgh/go-spew",
            "direct": false,
            "version": "v1.1.2-0.20180830191138-d8f796af33cc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/davidmz/go-pageant",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/emicklei/go-restful/v3",
            "direct": false,
            "version": "v3.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/evanphx/json-patch/v5",
            "direct": false,
            "version": "v5.9.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/fxamacker/cbor/v2",
            "direct": false,
            "version": "v2.9.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-fed/httpsig",
            "direct": false,
            "version": "v1.1.1-0.20201223112313-55836744818e",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v3",
            "direct": false,
            "version": "v3.0.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": false,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/zapr",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/errors",
            "direct": false,
            "version": "v0.22.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonpointer",
            "direct": false,
            "version": "v0.22.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/jsonreference",
            "direct": false,
            "version": "v0.21.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/strfmt",
            "direct": false,
            "version": "v0.26.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/cmdutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/conv",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/fileutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonname",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/jsonutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/loading",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/mangling",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/netutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/stringutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/typeutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-openapi/swag/yamlutils",
            "direct": false,
            "version": "v0.25.5",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-viper/mapstructure/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/gnostic-models",
            "direct": false,
            "version": "v0.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/grpc-ecosystem/grpc-gateway/v2",
            "direct": false,
            "version": "v2.29.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-cleanhttp",
            "direct": false,
            "version": "v0.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-retryablehttp",
            "direct": false,
            "version": "v0.7.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/go-version",
            "direct": false,
            "version": "v1.9.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/hashicorp/golang-lru",
            "direct": false,
            "version": "v1.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/imfing/hextra",
            "direct": false,
            "version": "v0.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/json-iterator/go",
            "direct": false,
            "version": "v1.1.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kballard/go-shellquote",
            "direct": false,
            "version": "v0.0.0-20180428030007-95032a82bc51",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kelseyhightower/envconfig",
            "direct": false,
            "version": "v1.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lunixbochs/vtclean",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/concurrent",
            "direct": false,
            "version": "v0.0.0-20180306012644-bacd9c7ef1dd",
            "ecosystem": "go"
          },
          {
            "name": "github.com/modern-go/reflect2",
            "direct": false,
            "version": "v1.0.3-0.20250322232337-35a7c28c31ee",
            "ecosystem": "go"
          },
          {
            "name": "github.com/munnerz/goautoneg",
            "direct": false,
            "version": "v0.0.0-20191010083416-a7dc8b61c822",
            "ecosystem": "go"
          },
          {
            "name": "github.com/oklog/ulid/v2",
            "direct": false,
            "version": "v2.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pmezard/go-difflib",
            "direct": false,
            "version": "v1.0.1-0.20181226105442-5d4384ee4fb2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/client_golang",
            "direct": false,
            "version": "v1.23.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/otlptranslator",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/prometheus/procfs",
            "direct": false,
            "version": "v0.20.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/puerkitobio/goquery",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rickb777/date",
            "direct": false,
            "version": "v1.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rickb777/plural",
            "direct": false,
            "version": "v1.4.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/robfig/cron/v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/x448/float16",
            "direct": false,
            "version": "v0.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xlzd/gotp",
            "direct": false,
            "version": "v0.1.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/runtime",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/otlp/otlptrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/prometheus",
            "direct": false,
            "version": "v0.66.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/exporters/stdout/stdouttrace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/proto/otlp",
            "direct": false,
            "version": "v1.10.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/atomic",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/automaxprocs",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "go.uber.org/multierr",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v2",
            "direct": false,
            "version": "v2.4.4",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/time",
            "direct": false,
            "version": "v0.15.0",
            "ecosystem": "go"
          },
          {
            "name": "gomodules.xyz/jsonpatch/v2",
            "direct": false,
            "version": "v2.5.0",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/genproto/googleapis/rpc",
            "direct": false,
            "version": "v0.0.0-20260526163538-3dc84a4a5aaa",
            "ecosystem": "go"
          },
          {
            "name": "google.golang.org/grpc",
            "direct": false,
            "version": "v1.81.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/evanphx/json-patch.v4",
            "direct": false,
            "version": "v4.13.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/inf.v0",
            "direct": false,
            "version": "v0.9.1",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": false,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/apiextensions-apiserver",
            "direct": false,
            "version": "v0.36.2",
            "ecosystem": "go"
          },
          {
            "name": "k8s.io/kube-openapi",
            "direct": false,
            "version": "v0.0.0-20260330154417-16be699c7b31",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/gateway-api",
            "direct": false,
            "version": "v1.5.1",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/json",
            "direct": false,
            "version": "v0.0.0-20250730193827-2d320260d730",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/randfill",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "sigs.k8s.io/structured-merge-diff/v6",
            "direct": false,
            "version": "v6.3.2",
            "ecosystem": "go"
          },
          {
            "name": "@axe-core/playwright",
            "direct": false,
            "version": "^4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "^1.49.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/postcss",
            "direct": false,
            "version": "^4.1.18",
            "ecosystem": "npm"
          },
          {
            "name": "postcss-cli",
            "direct": false,
            "version": "^11.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "^3.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "prettier-plugin-go-template",
            "direct": false,
            "version": "^0.0.15",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "^4.1.18",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 163,
        "direct_count": 54,
        "indirect_count": 109
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 10,
        "merged_prs": 2014,
        "open_issues": 70,
        "closed_ratio": 0.88,
        "closed_issues": 515,
        "closed_unmerged_prs": 252
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "chmouel",
          "commits": 2290,
          "avatar_url": "https://avatars.githubusercontent.com/u/98980?v=4"
        },
        {
          "type": "User",
          "login": "zakisk",
          "commits": 223,
          "avatar_url": "https://avatars.githubusercontent.com/u/49492007?v=4"
        },
        {
          "type": "User",
          "login": "savitaashture",
          "commits": 107,
          "avatar_url": "https://avatars.githubusercontent.com/u/9441662?v=4"
        },
        {
          "type": "User",
          "login": "theakshaypant",
          "commits": 84,
          "avatar_url": "https://avatars.githubusercontent.com/u/16561942?v=4"
        },
        {
          "type": "User",
          "login": "piyush-garg",
          "commits": 31,
          "avatar_url": "https://avatars.githubusercontent.com/u/19270240?v=4"
        },
        {
          "type": "User",
          "login": "aThorp96",
          "commits": 24,
          "avatar_url": "https://avatars.githubusercontent.com/u/28596783?v=4"
        },
        {
          "type": "User",
          "login": "sm43",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/55777192?v=4"
        },
        {
          "type": "User",
          "login": "PuneetPunamiya",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/32545638?v=4"
        },
        {
          "type": "User",
          "login": "vdemeester",
          "commits": 15,
          "avatar_url": "https://avatars.githubusercontent.com/u/6508?v=4"
        },
        {
          "type": "User",
          "login": "infernus01",
          "commits": 13,
          "avatar_url": "https://avatars.githubusercontent.com/u/89133323?v=4"
        }
      ],
      "contributors_sampled": 59,
      "top_contributor_share": 0.776
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "codecov.yaml",
        "container.yaml",
        "e2e.yaml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yaml",
        ".golangci.yml",
        ".pylintrc"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": true
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 7,
            "reason": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 8,
            "reason": "Found 17/20 approved changesets -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 33 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 0,
            "reason": "dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 8,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "fb05bedea50a30bb39d5cdd3b3179b187e39e9a5",
        "ran_at": "2026-07-22T02:12:12Z",
        "aggregate_score": 5.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T13:36:38Z",
      "oldest_open_prs": [
        {
          "number": 2655,
          "created_at": "2026-04-08T09:02:29Z",
          "last_comment_at": "2026-07-16T11:44:33Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2848,
          "created_at": "2026-07-10T19:24:17Z",
          "last_comment_at": "2026-07-21T07:29:37Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2854,
          "created_at": "2026-07-15T12:23:38Z",
          "last_comment_at": "2026-07-15T18:09:09Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2856,
          "created_at": "2026-07-16T08:41:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2859,
          "created_at": "2026-07-16T11:10:41Z",
          "last_comment_at": "2026-07-21T06:28:58Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2867,
          "created_at": "2026-07-21T11:07:16Z",
          "last_comment_at": "2026-07-21T11:07:40Z",
          "last_comment_author": "pipelines-as-code"
        },
        {
          "number": 2868,
          "created_at": "2026-07-21T11:09:17Z",
          "last_comment_at": "2026-07-21T11:47:47Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2869,
          "created_at": "2026-07-21T12:56:50Z",
          "last_comment_at": "2026-07-21T13:02:50Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 2870,
          "created_at": "2026-07-21T13:02:08Z",
          "last_comment_at": "2026-07-21T13:14:09Z",
          "last_comment_author": "codecov"
        },
        {
          "number": 2871,
          "created_at": "2026-07-21T13:30:25Z",
          "last_comment_at": "2026-07-21T13:33:08Z",
          "last_comment_author": "codecov"
        }
      ],
      "last_merged_pr_at": "2026-07-21T10:21:44Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 508,
          "created_at": "2022-04-01T13:59:38Z",
          "last_comment_at": "2026-02-26T11:40:23Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 724,
          "created_at": "2022-06-09T08:42:43Z",
          "last_comment_at": "2025-10-15T09:37:31Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 732,
          "created_at": "2022-06-20T06:56:49Z",
          "last_comment_at": "2026-02-26T11:40:05Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 780,
          "created_at": "2022-08-01T15:57:45Z",
          "last_comment_at": "2026-02-26T11:39:49Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 790,
          "created_at": "2022-08-09T12:42:02Z",
          "last_comment_at": "2026-02-26T11:40:07Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 828,
          "created_at": "2022-09-09T12:32:05Z",
          "last_comment_at": "2026-02-26T11:40:31Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 924,
          "created_at": "2022-10-17T13:23:32Z",
          "last_comment_at": "2026-02-26T11:40:19Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 933,
          "created_at": "2022-10-20T10:25:52Z",
          "last_comment_at": "2026-02-26T11:40:43Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 934,
          "created_at": "2022-10-20T10:29:41Z",
          "last_comment_at": "2026-02-26T11:40:18Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 998,
          "created_at": "2022-11-21T07:04:20Z",
          "last_comment_at": "2026-02-26T11:40:36Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1049,
          "created_at": "2022-12-05T12:02:37Z",
          "last_comment_at": "2026-02-26T15:23:46Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1070,
          "created_at": "2022-12-12T15:15:51Z",
          "last_comment_at": "2026-02-26T11:51:25Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1098,
          "created_at": "2023-01-05T11:28:07Z",
          "last_comment_at": "2026-02-26T11:40:08Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1112,
          "created_at": "2023-01-19T11:18:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1152,
          "created_at": "2023-02-14T11:04:32Z",
          "last_comment_at": "2026-02-26T11:51:20Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1227,
          "created_at": "2023-04-12T07:07:13Z",
          "last_comment_at": "2026-02-26T11:41:47Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1235,
          "created_at": "2023-04-13T14:52:59Z",
          "last_comment_at": "2026-02-26T13:50:34Z",
          "last_comment_author": "tekton-pac-bot"
        },
        {
          "number": 1237,
          "created_at": "2023-04-17T09:46:26Z",
          "last_comment_at": "2026-02-26T11:40:55Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1246,
          "created_at": "2023-04-22T12:57:18Z",
          "last_comment_at": "2026-02-26T11:42:27Z",
          "last_comment_author": "chmouel"
        },
        {
          "number": 1291,
          "created_at": "2023-05-18T07:12:16Z",
          "last_comment_at": "2026-03-06T10:32:53Z",
          "last_comment_author": "mikem-of"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/tektoncd/pipelines-as-code",
    "host": "github.com",
    "name": "pipelines-as-code",
    "owner": "tektoncd"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "good",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 79,
      "inputs": {
        "security": 62,
        "vitality": 95,
        "community": 75,
        "governance": 65,
        "engineering": 96
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 95,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "commits_last_year": 575,
              "human_commit_share": 0.9,
              "days_since_last_push": 0,
              "active_weeks_last_year": 51
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "51/52 weeks with commits",
                "points": 35.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 51
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "575 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 575
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "v0.48.1",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 5.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~5.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 5.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 0,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 0 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 75,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "forks": 135,
              "stars": 203,
              "watchers": 9,
              "growth_state": "organic",
              "growth_factor_pct": 100
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "203 stars",
                "points": 37.4,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 203
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "135 forks",
                "points": 17.7,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 135
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "9 watchers",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 65,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 59,
              "top_contributor_share": 0.776
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 78% of commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 78
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "59 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 59
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 87,
            "inputs": {
              "merged_prs": 2014,
              "open_issues": 70,
              "closed_issues": 515,
              "issue_closed_ratio": 0.88,
              "closed_unmerged_prs": 252
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "88% of issues closed",
                "points": 41.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 88
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2014/2266 decided PRs merged",
                "points": 34,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2014,
                      "decided": 2266
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 17/20 approved changesets -- score normalized to 8",
                "points": 12,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "followers": 1421,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "tektoncd",
              "public_repos": 24,
              "account_age_days": 2715
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1,421 followers of tektoncd",
                "points": 22.7,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1421,
                      "login": "tektoncd"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "24 public repos, account ~7 yr old",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 24
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 7
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 96,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": true
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yaml, .golangci.yml, .pylintrc",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml, .pylintrc"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 9.6,
                "status": "met",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
                "points": 14,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "topics": [
                "tekton-pipelines",
                "tekton",
                "github",
                "pipeline",
                "kubernetes",
                "continuous-delivery",
                "pipelines-as-code",
                "gitlab",
                "ci",
                "bitbucket",
                "gitops"
              ],
              "has_wiki": true,
              "homepage": "https://pipelinesascode.com",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://pipelinesascode.com",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "11 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 5.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "18 out of 24 merged PRs checked by a CI test -- score normalized to 7",
                "points": 1.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 17/20 approved changesets -- score normalized to 8",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 33 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "dangerous workflow patterns detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 156 resolved dependencies against OSV; 7 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 156
                }
              },
              {
                "code": "advisories_unassessed",
                "params": {
                  "count": 7
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 85,
            "inputs": {
              "source": "osv",
              "advisories": 4,
              "affected_packages": 3,
              "assessed_packages": 156,
              "unassessed_packages": 7,
              "affected_by_severity": "critical 1, unknown 2",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: github.com/tektoncd/pipeline v1.14.0 (unknown)",
                "points": 26.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "github.com/tektoncd/pipeline v1.14.0 (unknown)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "1 advisory-carrying package(s) unaddressed past 90 days; oldest published 700 days ago",
                "points": 37.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_stale",
                    "params": {
                      "days": 90,
                      "count": 1,
                      "oldest": 700
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 156,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 17
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 96,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md",
                "vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md",
                "vendor/go.opentelemetry.io/otel/AGENTS.md",
                "vendor/go.opentelemetry.io/otel/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 12245
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, vendor/github.com/ktrysmt/go-bitbucket/CLAUDE.md, vendor/gitlab.com/gitlab-org/api/client-go/AGENTS.md, vendor/go.opentelemetry.io/otel/AGENTS.md, vendor/go.opentelemetry.io/otel/CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "90 of 90 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 90,
                      "sampled": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 97,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile",
                "vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile",
                "vendor/github.com/emicklei/go-restful/v3/Makefile",
                "vendor/github.com/felixge/httpsnoop/Makefile",
                "vendor/github.com/hashicorp/go-retryablehttp/Makefile",
                "vendor/github.com/juju/ansiterm/Makefile",
                "vendor/github.com/ktrysmt/go-bitbucket/Makefile",
                "vendor/github.com/munnerz/goautoneg/Makefile",
                "vendor/github.com/pkg/errors/Makefile",
                "vendor/github.com/prometheus/procfs/Makefile",
                "vendor/github.com/spf13/cobra/Makefile",
                "vendor/gitlab.com/gitlab-org/api/client-go/Makefile",
                "vendor/go.opentelemetry.io/otel/Makefile",
                "vendor/go.uber.org/atomic/Makefile",
                "vendor/go.uber.org/multierr/Makefile",
                "vendor/go.uber.org/zap/Makefile",
                "vendor/google.golang.org/grpc/Makefile",
                "vendor/sigs.k8s.io/json/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0.26,
              "toolchain_manifests": [
                "docs/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.1
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, vendor/github.com/cloudevents/sdk-go/sql/v2/Makefile, vendor/github.com/emicklei/go-restful/v3/Makefile, vendor/github.com/felixge/httpsnoop/Makefile, vendor/github.com/hashicorp/go-retryablehttp/Makefile, vendor/github.com/juju/ansiterm/Makefile, vendor/github.com/ktrysmt/go-bitbucket/Makefile, vendor/github.com/munnerz/goautoneg/Makefile, vendor/github.com/pkg/errors/Makefile, vendor/github.com/prometheus/procfs/Makefile, vendor/github.com/spf13/cobra/Makefile, vendor/gitlab.com/gitlab-org/api/client-go/Makefile, vendor/go.opentelemetry.io/otel/Makefile, vendor/go.uber.org/atomic/Makefile, vendor/go.uber.org/multierr/Makefile, vendor/go.uber.org/zap/Makefile, vendor/google.golang.org/grpc/Makefile, vendor/sigs.k8s.io/json/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yaml, .golangci.yml, .pylintrc",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yaml, .golangci.yml, .pylintrc"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "26 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 26,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "10 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 10,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 92818,
              "source_files_sampled": 518,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/518 source files over 60KB",
                "points": 54.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 518,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "vendor/github.com/google/gnostic-models/extensions/extension.proto",
                "vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto",
                "vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto",
                "vendor/github.com/google/gnostic-models/openapiv3/annotations.proto",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json",
                "vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json",
                "vendor/k8s.io/api/admission/v1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto",
                "vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto",
                "vendor/k8s.io/api/apidiscovery/v2/generated.proto",
                "vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto",
                "vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto",
                "vendor/k8s.io/api/apps/v1/generated.proto",
                "vendor/k8s.io/api/apps/v1beta1/generated.proto",
                "vendor/k8s.io/api/apps/v1beta2/generated.proto",
                "vendor/k8s.io/api/authentication/v1/generated.proto",
                "vendor/k8s.io/api/authentication/v1alpha1/generated.proto",
                "vendor/k8s.io/api/authentication/v1beta1/generated.proto",
                "vendor/k8s.io/api/authorization/v1/generated.proto",
                "vendor/k8s.io/api/authorization/v1beta1/generated.proto",
                "vendor/k8s.io/api/autoscaling/v1/generated.proto",
                "vendor/k8s.io/api/autoscaling/v2/generated.proto",
                "vendor/k8s.io/api/batch/v1/generated.proto",
                "vendor/k8s.io/api/batch/v1beta1/generated.proto",
                "vendor/k8s.io/api/certificates/v1/generated.proto",
                "vendor/k8s.io/api/certificates/v1alpha1/generated.proto",
                "vendor/k8s.io/api/certificates/v1beta1/generated.proto",
                "vendor/k8s.io/api/coordination/v1/generated.proto",
                "vendor/k8s.io/api/coordination/v1alpha2/generated.proto",
                "vendor/k8s.io/api/coordination/v1beta1/generated.proto",
                "vendor/k8s.io/api/core/v1/generated.proto",
                "vendor/k8s.io/api/discovery/v1/generated.proto",
                "vendor/k8s.io/api/discovery/v1beta1/generated.proto",
                "vendor/k8s.io/api/events/v1/generated.proto",
                "vendor/k8s.io/api/events/v1beta1/generated.proto",
                "vendor/k8s.io/api/extensions/v1beta1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto",
                "vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto",
                "vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto",
                "vendor/k8s.io/api/networking/v1/generated.proto",
                "vendor/k8s.io/api/networking/v1beta1/generated.proto",
                "vendor/k8s.io/api/node/v1/generated.proto",
                "vendor/k8s.io/api/node/v1alpha1/generated.proto",
                "vendor/k8s.io/api/node/v1beta1/generated.proto",
                "vendor/k8s.io/api/policy/v1/generated.proto",
                "vendor/k8s.io/api/policy/v1beta1/generated.proto",
                "vendor/k8s.io/api/rbac/v1/generated.proto",
                "vendor/k8s.io/api/rbac/v1alpha1/generated.proto",
                "vendor/k8s.io/api/rbac/v1beta1/generated.proto",
                "vendor/k8s.io/api/resource/v1/generated.proto",
                "vendor/k8s.io/api/resource/v1alpha3/generated.proto",
                "vendor/k8s.io/api/resource/v1beta1/generated.proto",
                "vendor/k8s.io/api/resource/v1beta2/generated.proto",
                "vendor/k8s.io/api/scheduling/v1/generated.proto",
                "vendor/k8s.io/api/scheduling/v1alpha2/generated.proto",
                "vendor/k8s.io/api/scheduling/v1beta1/generated.proto",
                "vendor/k8s.io/api/storage/v1/generated.proto",
                "vendor/k8s.io/api/storage/v1alpha1/generated.proto",
                "vendor/k8s.io/api/storage/v1beta1/generated.proto",
                "vendor/k8s.io/api/storagemigration/v1beta1/generated.proto",
                "vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/runtime/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto",
                "vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "vendor/github.com/google/gnostic-models/extensions/extension.proto, vendor/github.com/google/gnostic-models/openapiv2/OpenAPIv2.proto, vendor/github.com/google/gnostic-models/openapiv3/OpenAPIv3.proto, vendor/github.com/google/gnostic-models/openapiv3/annotations.proto, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1alpha1/swagger.json, vendor/github.com/tektoncd/pipeline/pkg/apis/pipeline/v1beta1/swagger.json, vendor/k8s.io/api/admission/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1/generated.proto, vendor/k8s.io/api/admissionregistration/v1alpha1/generated.proto, vendor/k8s.io/api/admissionregistration/v1beta1/generated.proto, vendor/k8s.io/api/apidiscovery/v2/generated.proto, vendor/k8s.io/api/apidiscovery/v2beta1/generated.proto, vendor/k8s.io/api/apiserverinternal/v1alpha1/generated.proto, vendor/k8s.io/api/apps/v1/generated.proto, vendor/k8s.io/api/apps/v1beta1/generated.proto, vendor/k8s.io/api/apps/v1beta2/generated.proto, vendor/k8s.io/api/authentication/v1/generated.proto, vendor/k8s.io/api/authentication/v1alpha1/generated.proto, vendor/k8s.io/api/authentication/v1beta1/generated.proto, vendor/k8s.io/api/authorization/v1/generated.proto, vendor/k8s.io/api/authorization/v1beta1/generated.proto, vendor/k8s.io/api/autoscaling/v1/generated.proto, vendor/k8s.io/api/autoscaling/v2/generated.proto, vendor/k8s.io/api/batch/v1/generated.proto, vendor/k8s.io/api/batch/v1beta1/generated.proto, vendor/k8s.io/api/certificates/v1/generated.proto, vendor/k8s.io/api/certificates/v1alpha1/generated.proto, vendor/k8s.io/api/certificates/v1beta1/generated.proto, vendor/k8s.io/api/coordination/v1/generated.proto, vendor/k8s.io/api/coordination/v1alpha2/generated.proto, vendor/k8s.io/api/coordination/v1beta1/generated.proto, vendor/k8s.io/api/core/v1/generated.proto, vendor/k8s.io/api/discovery/v1/generated.proto, vendor/k8s.io/api/discovery/v1beta1/generated.proto, vendor/k8s.io/api/events/v1/generated.proto, vendor/k8s.io/api/events/v1beta1/generated.proto, vendor/k8s.io/api/extensions/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta1/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta2/generated.proto, vendor/k8s.io/api/flowcontrol/v1beta3/generated.proto, vendor/k8s.io/api/imagepolicy/v1alpha1/generated.proto, vendor/k8s.io/api/networking/v1/generated.proto, vendor/k8s.io/api/networking/v1beta1/generated.proto, vendor/k8s.io/api/node/v1/generated.proto, vendor/k8s.io/api/node/v1alpha1/generated.proto, vendor/k8s.io/api/node/v1beta1/generated.proto, vendor/k8s.io/api/policy/v1/generated.proto, vendor/k8s.io/api/policy/v1beta1/generated.proto, vendor/k8s.io/api/rbac/v1/generated.proto, vendor/k8s.io/api/rbac/v1alpha1/generated.proto, vendor/k8s.io/api/rbac/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1/generated.proto, vendor/k8s.io/api/resource/v1alpha3/generated.proto, vendor/k8s.io/api/resource/v1beta1/generated.proto, vendor/k8s.io/api/resource/v1beta2/generated.proto, vendor/k8s.io/api/scheduling/v1/generated.proto, vendor/k8s.io/api/scheduling/v1alpha2/generated.proto, vendor/k8s.io/api/scheduling/v1beta1/generated.proto, vendor/k8s.io/api/storage/v1/generated.proto, vendor/k8s.io/api/storage/v1alpha1/generated.proto, vendor/k8s.io/api/storage/v1beta1/generated.proto, vendor/k8s.io/api/storagemigration/v1beta1/generated.proto, vendor/k8s.io/apiextensions-apiserver/pkg/apis/apiextensions/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/api/resource/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1/generated.proto, vendor/k8s.io/apimachinery/pkg/apis/meta/v1beta1/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/generated.proto, vendor/k8s.io/apimachinery/pkg/runtime/schema/generated.proto, vendor/k8s.io/apimachinery/pkg/util/intstr/generated.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "go package 'github.com/openshift-pipelines/pipelines-as-code' points at a different repository (https://github.com/openshift-pipelines/pipelines-as-code); excluded from ecosystem scoring"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T02:12:45.089451Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tektoncd/pipelines-as-code.svg",
  "full_name": "tektoncd/pipelines-as-code",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.