原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 903,
"has_wiki": false,
"homepage": "https://developers.tremendous.com",
"languages": {
"Ruby": 2526293,
"Shell": 4337
},
"pushed_at": "2026-07-23T14:28:45Z",
"created_at": "2018-06-06T19:04:25Z",
"owner_type": "Organization",
"updated_at": "2026-07-23T14:26:20Z",
"description": "Ruby client for Tremendous API",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Ruby",
"significant_languages": [
"Ruby"
]
},
"owner": {
"blog": "https://www.tremendous.com",
"name": "Tremendous",
"type": "Organization",
"login": "tremendous-rewards",
"company": null,
"location": "United States of America",
"followers": 16,
"avatar_url": "https://avatars.githubusercontent.com/u/56234492?v=4",
"created_at": "2019-10-06T19:36:38Z",
"is_verified": null,
"public_repos": 20,
"account_age_days": 2481
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "tremendous_ruby/v5.28.0",
"kind": "other",
"published_at": "2026-07-23T14:28:46Z"
},
{
"tag": "tremendous_ruby/v5.27.0",
"kind": "other",
"published_at": "2026-07-03T13:43:38Z"
},
{
"tag": "tremendous_ruby/v5.26.0",
"kind": "other",
"published_at": "2026-06-10T13:28:57Z"
},
{
"tag": "tremendous_ruby/v5.25.0",
"kind": "other",
"published_at": "2026-05-12T16:43:11Z"
},
{
"tag": "tremendous_ruby/v5.24.0",
"kind": "other",
"published_at": "2026-05-01T15:56:35Z"
},
{
"tag": "tremendous_ruby/v5.23.0",
"kind": "other",
"published_at": "2026-04-22T18:42:30Z"
},
{
"tag": "tremendous_ruby/v5.22.0",
"kind": "other",
"published_at": "2026-04-22T13:53:40Z"
},
{
"tag": "tremendous_ruby/v5.21.0",
"kind": "other",
"published_at": "2026-04-17T12:59:56Z"
},
{
"tag": "tremendous_ruby/v5.20.0",
"kind": "other",
"published_at": "2026-04-16T18:42:17Z"
},
{
"tag": "tremendous_ruby/v5.19.0",
"kind": "other",
"published_at": "2026-04-15T18:30:03Z"
},
{
"tag": "tremendous_ruby/v5.18.1",
"kind": "other",
"published_at": "2026-04-14T18:38:32Z"
},
{
"tag": "tremendous_ruby/v5.18.0",
"kind": "other",
"published_at": "2026-03-24T13:24:47Z"
},
{
"tag": "tremendous_ruby/v5.17.0",
"kind": "other",
"published_at": "2026-02-27T14:40:56Z"
},
{
"tag": "tremendous_ruby/v5.16.0",
"kind": "other",
"published_at": "2026-02-25T17:17:35Z"
},
{
"tag": "tremendous_ruby/v5.15.0",
"kind": "other",
"published_at": "2026-02-07T00:58:39Z"
},
{
"tag": "tremendous_ruby/v5.14.0",
"kind": "other",
"published_at": "2026-01-28T16:03:52Z"
},
{
"tag": "tremendous_ruby/v5.13.0",
"kind": "other",
"published_at": "2025-10-21T13:51:14Z"
},
{
"tag": "tremendous_ruby/v5.12.0",
"kind": "other",
"published_at": "2025-08-07T19:15:38Z"
},
{
"tag": "tremendous_ruby/v5.11.0",
"kind": "other",
"published_at": "2025-07-28T14:30:09Z"
},
{
"tag": "tremendous_ruby/v5.10.0",
"kind": "other",
"published_at": "2025-06-09T13:05:30Z"
},
{
"tag": "tremendous_ruby/v5.9.0",
"kind": "other",
"published_at": "2024-12-03T17:57:47Z"
},
{
"tag": "tremendous_ruby/v5.8.0",
"kind": "other",
"published_at": "2024-11-19T14:14:03Z"
},
{
"tag": "tremendous_ruby/v5.7.0",
"kind": "other",
"published_at": "2024-11-04T19:25:22Z"
},
{
"tag": "tremendous_ruby/v5.6.0",
"kind": "other",
"published_at": "2024-09-30T15:14:21Z"
},
{
"tag": "v5.5.0",
"kind": "minor",
"published_at": "2024-09-19T20:58:02Z"
},
{
"tag": "v5.4.0",
"kind": "minor",
"published_at": "2024-09-18T16:03:41Z"
},
{
"tag": "v5.3.0",
"kind": "minor",
"published_at": "2024-08-06T13:40:17Z"
},
{
"tag": "v5.1.0",
"kind": "minor",
"published_at": "2024-05-28T14:09:10Z"
},
{
"tag": "v5.0.1",
"kind": "patch",
"published_at": "2024-04-01T18:21:40Z"
},
{
"tag": "v5.0.0",
"kind": "major",
"published_at": "2024-03-27T16:30:04Z"
},
{
"tag": "v4.3.5",
"kind": "patch",
"published_at": "2024-01-08T12:04:10Z"
},
{
"tag": "v4.3.1",
"kind": "patch",
"published_at": "2022-07-13T08:13:28Z"
},
{
"tag": "v4.3.0",
"kind": "minor",
"published_at": "2021-05-03T22:09:42Z"
},
{
"tag": "v4",
"kind": "other",
"published_at": "2019-06-12T18:42:44Z"
}
],
"recent_commits": [
{
"oid": "8d8458ce66e50defdf4fa9f82369b5b9f056f6b4",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.28.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.27.0...tremendous_ruby/v5.28.0)\n(2026-07-23)\n\n\n### Features\n\n* add `permission` field to create API key request\n([0cca243](https://github.com/tremendous-r\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.28.0 (#155)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-23T14:28:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0cca24321a66957970616787c11e9763d40b1eda",
"body": "feat: add `permission` field to create API key request\nfeat: support `read_only` API keys via `permission` enum\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#156)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-23T14:24:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8681d81b916293f76237328ba1a83534685f68ba",
"body": "feat: add delete member endpoint (DELETE /members/{id})\nfeat: add update member endpoint (PATCH /members/{id})\nfeat: add `state` field to connected org member sessions\ndocs: clarify cancel reward fails with `422` if redeemed\ndocs: update sandbox balance limit from $5k to $100k\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#153)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-21T12:41:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cdcab85635432af91da7c93c61c6e33ec5036696",
"body": "Deserialization assigns attributes through writers that validate enum\nmembership, so whenever the API adds an enum value (product categories,\nfraud reasons, statuses — most releases do), previously released\nversions of this gem start raising `ArgumentError` mid-parse. This is\nthe same systemic issue\n[…]\ns now a runtime dependency matching the\nupstream gemspec.\n\nIncludes an offline spec (`spec/models/enum_tolerance_spec.rb`) that\nparses canned hashes and needs no sandbox credentials.\n\nStacked on #150.",
"is_bot": false,
"headline": "fix: tolerate unknown enum values in API responses (#151)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-07-20T16:35:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "497092d3f23bb792bf3c5bc6a17df333c84f494a",
"body": "…154)\n\nBumps\n[slackapi/slack-github-action](https://github.com/slackapi/slack-github-action)\nfrom 3.0.3 to 3.0.5.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/slackapi/slack-github-action/releases\">slackapi/slack-github-action's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump slackapi/slack-github-action from 3.0.3 to 3.0.5 (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-18T07:02:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c7cca61433dff1c5ee3dddb235969ac4a2844473",
"body": "The generator never deletes files it stops producing, so models removed\nor renamed in the spec linger in the repo after regeneration. Ten model\nfiles checked in today are no longer generated from the current spec;\nnothing requires them from `lib/tremendous.rb`, and the only references\nbetween them a\n[…]\nopy of `main` removes\nexactly these 10 files and touches nothing else.\n\nNote: this touches `bin/generate`, so it will have a small conflict with\n#150 — whichever merges second just keeps both changes.",
"is_bot": false,
"headline": "chore: remove stale generated model files (#152)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-07-17T14:23:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c3282ebe218f33570d3fae861208c7dc85e7b9c4",
"body": "…(#150)\n\nOur `templates/ruby/` overrides were full copies of the upstream\nopenapi-generator templates, each carrying a couple of intentional\nedits. Full copies drift silently: ours were stale against the pinned\n7.12.0 generator and missing upstream fixes we never noticed — the\n`ignore_operation_serv\n[…]\na\ntemplate near one of our customizations, generation fails with a\nconflict to resolve instead of drifting. The upstream fixes we were\nmissing will land in the generated code on the next regeneration.",
"is_bot": false,
"headline": "chore: build generator templates from patches instead of full copies …",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-07-17T13:08:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9ebf1ab5586eab2a0d6248825760780860e05002",
"body": "We ran [zizmor](https://docs.zizmor.sh/) over this repo's GitHub Actions\nworkflows and fixed everything it flagged: the Dependabot auto-merge\ngate now checks the PR author instead of the spoofable `github.actor`,\nworkflows declare least-privilege token permissions, checkouts no longer\npersist creden\n[…]\nd job that packages the\npublished gem.\n\nThere's also a new workflow that runs zizmor on every push and PR,\nuploading SARIF results to GitHub code scanning so future findings show\nup as PR annotations.",
"is_bot": false,
"headline": "chore: fix zizmor findings and add zizmor CI workflow (#149)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-07-03T18:32:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "38826d6f0063707a0146fc83d29e6887a7244e65",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.27.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.26.0...tremendous_ruby/v5.27.0)\n(2026-07-03)\n\n\n### Features\n\n* rename `kyb` to `kyb_prefill` in create\n([5139d89](https://github.com/tremendous-rewards/tr\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.27.0 (#148)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T13:43:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5139d89159f11ef54cca01568328ef4752bcc457",
"body": "feat: rename `kyb` to `kyb_prefill` in create\nconnected organization request\nfeat: add address fields to `kyb_prefill` model\nfix: remove `prefilled_kyb_details` from\nconnected organization responses\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#145)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-07-03T13:36:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3b824368e8642208cb77def5b3327765f012e4d",
"body": "Bumps [ruby/setup-ruby](https://github.com/ruby/setup-ruby) from 1.313.0\nto 1.314.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/ruby/setup-ruby/releases\">ruby/setup-ruby's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.314.0</h2>\n<h2>What's Changed</h2>\n<u\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump ruby/setup-ruby from 1.313.0 to 1.314.0 (#146)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T13:07:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "09db744a8c88d8d37e2e9b8d4dd55b4d3ec368dd",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3\nto 7.0.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/checkout/releases\">actions/checkout's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v7.0.0</h2>\n<h2>What's Changed</h2>\n<ul>\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#147)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-29T13:06:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0f90256426ab430291513a4b1305ce97f6e43b70",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.14.2 to\n2.14.3.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.14.3</h2>\n<h2>Security Note</h2>\n<p>This release \n[…]\ntremendous-rewards/tremendous-ruby/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.14.2 to 2.14.3 (#144)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T16:43:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "48bca662ba919641d81572d5b5c1b7f1341301a7",
"body": "Bumps [ruby/setup-ruby](https://github.com/ruby/setup-ruby) from 1.310.0\nto 1.313.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/ruby/setup-ruby/releases\">ruby/setup-ruby's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.313.0</h2>\n<h2>What's Changed</h2>\n<u\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump ruby/setup-ruby from 1.310.0 to 1.313.0 (#143)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T16:42:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "12bc665574e4656ba39930dbfe5abf582a392c21",
"body": "…to 2.1.0 (#142)\n\nBumps\n[rubygems/configure-rubygems-credentials](https://github.com/rubygems/configure-rubygems-credentials)\nfrom 2.0.0 to 2.1.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/rubygems/configure-rubygems-credentials/releases\">rubygems/con\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump rubygems/configure-rubygems-credentials from 2.0.0 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-22T16:41:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "133526bf31cf260a7e86f57a49e2ad3ab653ece0",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2\nto 6.0.3.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/checkout/releases\">actions/checkout's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v6.0.3</h2>\n<h2>What's Changed</h2>\n<ul>\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#141)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-13T07:02:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "61843a622232e9f3174f69327bb47384e0cbb30b",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.26.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.25.0...tremendous_ruby/v5.26.0)\n(2026-06-09)\n\n\n### Features\n\n* add `Apple Private Relay` fraud review reason\n([cd0f2ae](https://github.com/tremendous-rewa\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.26.0 (#140)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-06-10T13:28:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c1dba3772c3b4cbce2addfbbbf719c5d94828b33",
"body": "Bumps [ruby/setup-ruby](https://github.com/ruby/setup-ruby) from 1.308.0\nto 1.310.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/ruby/setup-ruby/releases\">ruby/setup-ruby's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.310.0</h2>\n<h2>What's Changed</h2>\n<u\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump ruby/setup-ruby from 1.308.0 to 1.310.0 (#139)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-09T19:04:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cd0f2ae6bf4d150afc4c00485465813f7112af87",
"body": "feat: add optional `kyb` to create connected org\nfeat: add `prefilled_kyb_details` to connected org\nfeat: add `wallet` product category enum value\nfeat: add `Apple Private Relay` fraud review reason\nfeat: add `skip_apple_private_relay` to VPN fraud rule\nfeat: add `review_vpn` config to fraud rule request\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#138)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-06-09T18:59:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4289a9d14d00d2bc09498793e0faa81ff4344e98",
"body": "Bumps\n[actions/upload-artifact](https://github.com/actions/upload-artifact)\nfrom 4.6.2 to 7.0.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/upload-artifact/releases\">actions/upload-artifact's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v7.0.1</h2>\n\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 (#134)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-27T18:05:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "479a180e750dc35bdbb6a59157b3f48217c5d570",
"body": "Bumps\n[actions/download-artifact](https://github.com/actions/download-artifact)\nfrom 4.3.0 to 8.0.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/download-artifact/releases\">actions/download-artifact's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v8.0\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/download-artifact from 4.3.0 to 8.0.1 (#133)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-27T18:05:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fefeb5dd524590b00137c26121c3971932b958c2",
"body": "Bumps [ruby/setup-ruby](https://github.com/ruby/setup-ruby) from 1.307.0\nto 1.308.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/ruby/setup-ruby/releases\">ruby/setup-ruby's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.308.0</h2>\n<h2>What's Changed</h2>\n<u\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump ruby/setup-ruby from 1.307.0 to 1.308.0 (#137)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-25T19:05:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d1055c3a088c0a13db33dfe957eb2390e474e99b",
"body": "Given the recent supply chain attacks, this raises Dependabot's minimum\npackage age to seven days before version update PRs are opened.\n\nExisting stricter cooldowns stay in place, so major and minor updates\nthat already waited longer continue to do so.",
"is_bot": false,
"headline": "Increase Dependabot cooldown to 7 days (#136)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-05-21T16:38:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8576cd1a8cc7487e6d447edef526db8038a7f0d1",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.14.1 to\n2.14.2.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.14.2</h2>\n<h2>Security Note</h2>\n<p>This release \n[…]\ntremendous-rewards/tremendous-ruby/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.14.1 to 2.14.2 (#135)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-18T15:12:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "81ee560f8d2c03db4750e9dcc073b72116f4132f",
"body": "Applies workflow hardening best practices across the four CI/CD workflow\nfiles:\n\n- Split `release.yml` into build and publish jobs so `id-token: write`\nis scoped to publish only; build job runs `bundle install` and `bundle\nexec rake build`, uploads the gem as an artifact; publish job downloads\nthe a\n[…]\ns\n- Add `actionlint` job to `test.yml`\n- Add `persist-credentials: false` to the checkout in `update-sdk.yml`\nand narrow permissions to job level\n- Restrict Dependabot auto-merge to patch updates only",
"is_bot": false,
"headline": "chore: harden CI/CD workflows (#131)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-05-12T17:40:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a66743af9bb4e741a19c1a1f5ee6c84dee47a718",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.25.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.24.0...tremendous_ruby/v5.25.0)\n(2026-05-12)\n\n\n### Features\n\n* add `auto_add_product_rule` to campaigns\n([3ca07cc](https://github.com/tremendous-rewards/t\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.25.0 (#132)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-05-12T16:42:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3ca07ccd4ddc0bb6cc25a63a9de21b6e2ab8e2de",
"body": "feat: add `auto_add_product_rule` to campaigns\ndocs: update `LINK` delivery method description\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#129)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-05-12T16:40:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e8013d36394a1fc789ab316a3186387f4e5936a",
"body": "…130)\n\nBumps\n[slackapi/slack-github-action](https://github.com/slackapi/slack-github-action)\nfrom 3.0.2 to 3.0.3.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/slackapi/slack-github-action/releases\">slackapi/slack-github-action's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump slackapi/slack-github-action from 3.0.2 to 3.0.3 (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-09T07:02:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c787c8e9672b012e68c7683c5a2fd8c2a64f0a8c",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.24.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.23.0...tremendous_ruby/v5.24.0)\n(2026-05-01)\n\n\n### Features\n\n* add fraud reason `Allowed country`\n([73423d3](https://github.com/tremendous-rewards/tremend\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.24.0 (#128)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-05-01T15:56:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "73423d37aa5b2cbfd2e1d7ffe3cad8993689d6fa",
"body": "docs: update `currency_code` description to note org default\nfix: remove `USD` default for reward `currency_code`\nfix: rename fraud reason `Over reward dollar limit` to `Over reward\namount limit`\nfeat: add fraud reason `Device on a Tremendous fraud list`\nfeat: add fraud reason `Allowed country`\nfix: make campaign webpage style `message` nullable\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#127)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-05-01T15:45:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d675f61a6adf5a35adfe7adf4116be8a0efd8b7",
"body": "Bumps\n[googleapis/release-please-action](https://github.com/googleapis/release-please-action)\nfrom 4 to 5.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/googleapis/release-please-action/releases\">googleapis/release-please-action's\nreleases</a>.</em></p>\n<\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump googleapis/release-please-action from 4 to 5 (#125)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-29T18:43:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2b90b15e966b363371514d7b8e253bce36fe0bb3",
"body": "…126)\n\nBumps\n[slackapi/slack-github-action](https://github.com/slackapi/slack-github-action)\nfrom 3.0.1 to 3.0.2.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/slackapi/slack-github-action/releases\">slackapi/slack-github-action's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump slackapi/slack-github-action from 3.0.1 to 3.0.2 (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-25T07:02:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b2272507ddc555ea9531b2908663086952c86cf",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.23.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.22.0...tremendous_ruby/v5.23.0)\n(2026-04-22)\n\n\n### Features\n\n* add `external_name`, `external_email`, `role` to connected org\n([a4c5e3d](https://github.co\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.23.0 (#124)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-22T18:42:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a4c5e3d2ecc14c71bf96e3c259eaf88fc0011f57",
"body": "feat: add `external_name`, `external_email`, `role` to connected org\nmember creation\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#123)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-22T18:37:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ace7f06760d34e2e3ae212d612d0d0a05da36c86",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.22.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.21.0...tremendous_ruby/v5.22.0)\n(2026-04-22)\n\n\n### Features\n\n* add `available_amount`, `pending_amount` to funding sources\n([dbcca88](https://github.com/t\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.22.0 (#122)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-22T13:53:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dbcca88d8e737f0d1fed244ef1811b7da071291c",
"body": "feat: add `currency_code` to balance transactions\nfeat: add `currency_code` to order payments and refunds\nfeat: add `currency_code` to topups\nfeat: add `currency_code` to funding source meta\nfeat: add `currency_code` to organizations\nfeat: add `currency_code` to connected organizations\nfeat: add `cu\n[…]\nartially_credited` topup status\nfix: make recipient `name` nullable on rewards\ndocs: denominate amounts in `currency_code` not USD\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#121)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-22T13:23:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "89b05b79c4b39921c24e86896d769298bd9569f5",
"body": "Bumps [rake](https://github.com/ruby/rake) from 13.3.1 to 13.4.2.\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/ruby/rake/commit/503b8ec593c51289c09cc2a69a34af99d6198c6a\"><code>503b8ec</code></a>\nv13.4.2</li>\n<li><a\nhref=\"https://github.com/ruby/rake/commit/46038e780e5982\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump rake from 13.3.1 to 13.4.2 (#120)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-18T07:02:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f153f3c8616576cb5076d1d86504e35596a57b3e",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.21.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.20.0...tremendous_ruby/v5.21.0)\n(2026-04-17)\n\n\n### Features\n\n* add `currency_code` field to invoices\n([90ecd1c](https://github.com/tremendous-rewards/trem\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.21.0 (#119)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-17T12:59:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "90ecd1c615d08f48ba13b2feddc8da716a3fb48c",
"body": "feat: add `currency_code` field to invoices\nfix: deprecate `currency` in favor of `currency_code`\nfix: remove default `USD` value for invoice `currency`\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#118)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-17T12:56:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "12b62451fb47bfa1ac0474af45e1aab97527483f",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.20.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.19.0...tremendous_ruby/v5.20.0)\n(2026-04-16)\n\n\n### Features\n\n* add `currency_code` field to create invoice\n([afb5295](https://github.com/tremendous-reward\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.20.0 (#117)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-16T18:42:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "afb5295a70b70d99955321210423fa017defe88e",
"body": "feat: add `currency_code` field to create invoice\nfix: deprecate `currency` in favor of `currency_code`\nfix: remove default `USD` for invoice `currency`\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#116)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-16T18:29:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "271ba8a4267e72a3c6132515c3ab3e8552ff4082",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.19.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.18.1...tremendous_ruby/v5.19.0)\n(2026-04-15)\n\n\n### Features\n\n* add delete connected organization endpoint\n([183c48b](https://github.com/tremendous-rewards\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.19.0 (#115)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-15T18:29:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "183c48b0800b389e96ea6de2687d8912f00a9929",
"body": "feat: add delete connected organization endpoint\nfeat: add delete connected organization member endpoint\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#114)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-15T18:22:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ee6e8a579bf2e350e4b61a6ac3523c423ccafab5",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.18.1](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.18.0...tremendous_ruby/v5.18.1)\n(2026-04-14)\n\n\n### Bug Fixes\n\n* remove obsolete `EEK`, `LTL`, `LVL`, `ZMK` currencies\n([5bf49db](https://github.com/tremen\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.18.1 (#113)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-14T18:38:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5bf49db07f5685ba3b452226ddac65ee885c37aa",
"body": "fix: replace `BYR` with `BYN` in currency codes\nfix: remove obsolete `EEK`, `LTL`, `LVL`, `ZMK` currencies\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#112)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-04-14T18:36:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df3a5445cc172522f492986aef4c6eab3c203ebd",
"body": "Bumps\n[dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata)\nfrom 2 to 3.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/dependabot/fetch-metadata/releases\">dependabot/fetch-metadata's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v3.0.0</h2>\n\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump dependabot/fetch-metadata from 2 to 3 (#111)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-13T17:36:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4afa7f19447c4a4763a5908e0b79ac9560e8aab4",
"body": null,
"is_bot": false,
"headline": "chore: require MFA when publishing the gem manually",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-04-09T17:42:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9f481d360f0cb8757752cccce579ae4b3fa7f9b",
"body": "…107)\n\nBumps\n[slackapi/slack-github-action](https://github.com/slackapi/slack-github-action)\nfrom 2.1.1 to 3.0.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/slackapi/slack-github-action/releases\">slackapi/slack-github-action's\nreleases</a>.</em></p>\n<b\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump slackapi/slack-github-action from 2.1.1 to 3.0.1 (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-04-02T17:39:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f9a35252dbfba24c28fb2d14de414ca612ce0a1",
"body": null,
"is_bot": false,
"headline": "chore: set dependabot `cooldown` config",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-04-02T17:32:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "69ed055586de8f4f4a3b6dc57d76453bb1169b7d",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.18.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.17.0...tremendous_ruby/v5.18.0)\n(2026-03-20)\n\n\n### Features\n\n* add `international_bank` to product `category` enum\n([23e951b](https://github.com/tremendou\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.18.0 (#110)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-03-24T13:24:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23e951b3b6dbbb4b133927ff9a4686c98d68e4e6",
"body": "feat: add `PENDING SETTLEMENT` to order `status` enum\nfeat: add `international_bank` to product `category` enum\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#109)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-03-20T12:46:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a62974c142a2ecd1af9beea9ee928166de445f11",
"body": "Bumps [json](https://github.com/ruby/json) from 2.18.1 to 2.19.2.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/ruby/json/releases\">json's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.19.2</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>Fix a format string injection \n[…]\ntremendous-rewards/tremendous-ruby/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump json from 2.18.1 to 2.19.2 (#108)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-19T12:51:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a1baa76cfc10e25096db15b50c6bcb22f3e1d219",
"body": "Bumps\n[peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request)\nfrom 7 to 8.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/peter-evans/create-pull-request/releases\">peter-evans/create-pull-request's\nreleases</a>.</em></p>\n<bloc\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump peter-evans/create-pull-request from 7 to 8 (#106)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-03-02T14:58:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "18ec245c673c6b6a1620615c76632f17957f2314",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.17.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.16.0...tremendous_ruby/v5.17.0)\n(2026-02-27)\n\n\n### Features\n\n* rename order `status` enum `CART` to `OPEN`\n([b18981c](https://github.com/tremendous-reward\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.17.0 (#105)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-02-27T14:40:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b18981cdafc817e2eb2cdd5ec2fe462849301ee6",
"body": "feat: rename order `status` enum `CART` to `OPEN`\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "chore: regenerate SDK (#104)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-02-27T14:37:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4ae1417eae342520951802e5c6081dd6828b571",
"body": "The AI prompt in `bin/generate-pr-description` can produce lines longer\nthan 72 characters. GitHub's squash merge wraps commit body lines at ~72\nchars, which causes Release Please to miss `fix:` and `docs:` entries in\nthe changelog (as happened in tremendous-python\n[#75](https://github.com/tremendou\n[…]\n/\n[#76](https://github.com/tremendous-rewards/tremendous-python/pull/76)).\n\nAdding a 70-char-per-line constraint to the prompt so generated\nconventional commit lines stay under the wrapping threshold.",
"is_bot": false,
"headline": "chore: fix PR description line length for Release Please (#103)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-02-25T19:58:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ce9af7695713db1f2ac9311dbdf109e751bc1afa",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.16.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.15.0...tremendous_ruby/v5.16.0)\n(2026-02-25)\n\n\n### Features\n\n* Add `expires_at` to Rewards\n([4967958](https://github.com/tremendous-rewards/tremendous-rub\n[…]\neapis/release-please#release-please).\n\n---------\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>\nCo-authored-by: Lucas Mattioli <lucas.mattioli7@gmail.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.16.0 (#100)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-02-25T17:17:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40bfb99e9ee72b4b2656435340ec5b1c9d826ef0",
"body": "Follow-up for\nhttps://github.com/tremendous-rewards/tremendous-ruby/pull/95: here, we\nare adding a CI step where we will query Claude to create a PR\ndescription when we are automatically generating the SDK\n\nAlso in this PR:\n- We are changing the prefix from `feat: renegerate SDK` to `chore:\nregenera\n[…]\ning `bin/update-sdk` altogether -- I noticed it's simply doing\nwhat `bin/generate` is already doing, so we can simplify it\n\n---------\n\nCo-authored-by: Lucas Mazza <lucasmazza@users.noreply.github.com>",
"is_bot": false,
"headline": "ci: automatically create PR description when regenerating SDK (#102)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-02-25T17:12:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "495b1944cc4583a2fc40c930df8bd39d3e1a7f7d",
"body": null,
"is_bot": false,
"headline": "chore: bump `bundler`",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-02-25T14:04:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02693409d9916041df966fa4498438360f0e54c5",
"body": null,
"is_bot": false,
"headline": "chore: add Ruby 4.0 to the test matrix",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2026-02-25T14:03:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "669caed6260c333c7493074c4a67ebc11e61da94",
"body": "Follow-up for #95: updating the auto-generated PR title to use a\nconventional commit format (`feat: regenerate SDK`).\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "ci: use conventional commit title for auto-generated PR (#101)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-02-24T21:15:13Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4967958bc6c2bec1915f05adfee4a480ec4879e4",
"body": "feat: Add `expires_at` to Rewards\nfix: Remove `BGN` currency code reference\n\nCo-authored-by: Mattioli <5321824+Mattioli@users.noreply.github.com>",
"is_bot": true,
"headline": "feat: regenerate SDK (#99)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-02-24T20:45:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f68ea4d7d0d43e16f4218ac00169ad805c0e17b",
"body": "…API changes (#95)\n\nWhen changes are detected in our API, an automation creates an issue in\nall of our SDKs repositories. Then, we go and generate the SDKs with a\nscript in each SDK repo. To make the process more automatic, this PR is\nreplacing the issue creation with the creation of a PR where\n`bin/generate` has already ran. This way, we cut one step from this\nflow.",
"is_bot": false,
"headline": "Automatically create a PR with `bin/generate` output after detecting …",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-02-24T20:37:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cef2eee69b2fc546a49414d9a567d69edc7b5f47",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.14.0 to\n2.14.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.14.1</h2>\n<h2>Security Note</h2>\n<p>This release \n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.14.0 to 2.14.1 (#98)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-02-09T07:11:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "857ea91d6e34d49e5f82d994ffa9fe2c402acf29",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.15.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.14.0...tremendous_ruby/v5.15.0)\n(2026-02-07)\n\n\n### Features\n\n* add create field endpoint (POST /fields)\n([f4527d0](https://github.com/tremendous-rewards/t\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.15.0 (#97)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-02-07T00:58:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f4527d02cc5a720878c1d9d28c4b1f9b4bb9b8ec",
"body": "feat: add create field endpoint (POST /fields)\nfeat: add data_type enum validation for fields (Checkbox, Currency,\nDate, Dropdown, Email, List, Number, Phone, Text, TextArea)\nfix: type field data as structured object instead of untyped hash\n\nCo-authored-by: Cursor <cursoragent@cursor.com>",
"is_bot": false,
"headline": "feat: regenerate SDK (#96)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-02-07T00:56:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "fe3df63dc975888ff509f8b6222a0b87476aaa4b",
"body": "Adds `workflow_dispatch` trigger to the release workflow so it can be\ntriggered manually from the GitHub Actions UI.",
"is_bot": false,
"headline": "ci: add workflow_dispatch to release workflow (#93)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-01-28T16:56:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "daccfc2a645aa5644ca5e554e37bd653f818ba4f",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.14.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.13.0...tremendous_ruby/v5.14.0)\n(2026-01-28)\n\n\n### Features\n\n* add currency support to invoices (USD, EUR, GBP)\n([698e964](https://github.com/tremendous-r\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.14.0 (#92)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2026-01-28T16:03:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "698e964356f9d90b384bf65c6acb2bdee116b3e8",
"body": "feat: add new Topups API (create, get, list)\nfeat: add currency support to invoices (USD, EUR, GBP)\nfeat: expand fraud review schema with additional fields\nfeat: allow BALANCE keyword in get_funding_source\nfix: update redemption method enum values\nfix: make funding source meta fields nullable",
"is_bot": false,
"headline": "feat: regenerate SDK (#91)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2026-01-28T15:49:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "73776e1e3e3d193fa40630e867ae6fc838f3952f",
"body": "Bumps [uri](https://github.com/ruby/uri) from 1.0.3 to 1.0.4.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a href=\"https://github.com/ruby/uri/releases\">uri's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.0.4</h2>\n<h3>Security fixes</h3>\n<ul>\n<li><a\nhref=\"https://www.ruby-lang.org/en\n[…]\ntremendous-rewards/tremendous-ruby/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump uri from 1.0.3 to 1.0.4 (#90)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-30T21:11:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "88dea1ea19e530be77e86395fe0e3b90693f84cc",
"body": "Bumps\n[faraday-multipart](https://github.com/lostisland/faraday-multipart)\nfrom 1.1.1 to 1.2.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday-multipart/releases\">faraday-multipart's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.2.0</h2>\n<h\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday-multipart from 1.1.1 to 1.2.0 (#89)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-12-29T07:00:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "385b23a36344865ae4520f5714c946bbd5943201",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to\n6.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/checkout/releases\">actions/checkout's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v6.0.0</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>Upd\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 5 to 6 (#88)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-11-24T13:32:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02d1d31526fd67196ba4de2e2eb2584d3da3780a",
"body": "Bumps [rake](https://github.com/ruby/rake) from 13.3.0 to 13.3.1.\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/ruby/rake/commit/f0001c3eeada8220f2976170876c75d21ed0626f\"><code>f0001c3</code></a>\nv13.3.1</li>\n<li><a\nhref=\"https://github.com/ruby/rake/commit/a644c808b98692\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump rake from 13.3.0 to 13.3.1 (#86)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-11-03T07:01:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8a0923f930abdd2f757a31ce03eded79ad7a4b69",
"body": "Bumps [rspec](https://github.com/rspec/rspec) from 3.13.1 to 3.13.2.\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/rspec/rspec/commit/ce5fe4f6521eb957f02e088a1c4c4f778a5c825e\"><code>ce5fe4f</code></a>\nrspec-v3.13.2</li>\n<li><a\nhref=\"https://github.com/rspec/rspec/commit/1\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump rspec from 3.13.1 to 3.13.2 (#85)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-10-27T07:19:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "634787640e6bb7bcaa17b107ba7378e0883666db",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.13.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.12.0...tremendous_ruby/v5.13.0)\n(2025-10-21)\n\n\n### Features\n\n* add `subcategory` enum to Products\n([7d4a3d1](https://github.com/tremendous-rewards/tremend\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.13.0 (#84)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2025-10-21T13:50:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7d4a3d1747d1b5813addd9bc25a7983ea7b392d4",
"body": "feat: add `subcategory` enum to Products\nfeat: remove `pending_confirmation` status from Funding Sources\nfeat: enforce a 50000 limit for the IP/email list on custom fraud rules\n\nCloses #81",
"is_bot": false,
"headline": "feat: regen SDK (#83)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-10-21T13:46:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ab8b5f83152ff7ab5014f2f012cd6fabed78284",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.13.4 to\n2.14.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.14.0</h2>\n<h2>What's Changed</h2>\n<h3>New feature\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.13.4 to 2.14.0 (#82)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-09-29T08:48:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "625ffa348fdfe714b75252b005e5ec14df560e71",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to\n5.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/actions/checkout/releases\">actions/checkout's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v5.0.0</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>Upd\n[…]\n----\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Lucas Mattioli <lucas.mattioli7@gmail.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 4 to 5 (#78)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-08-19T22:13:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "98f3cbf5f0db0c995d7845f6fc105f6f83f9c121",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.12.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.11.0...tremendous_ruby/v5.12.0)\n(2025-08-07)\n\n\n### Features\n\n* add address fields to funding sources meta schema\n([c2c0005](https://github.com/tremendous-\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.12.0 (#77)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2025-08-07T19:15:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c2c0005c1c3149c460f4be12f635f184615e1907",
"body": "feat: add Cash App as product category\ndocs: clarify resend reward API restrictions \nfeat: add address fields to funding sources meta schema",
"is_bot": false,
"headline": "feat: regenerate SDK (#76)",
"author_name": "Lucas Mattioli",
"author_login": "Mattioli",
"committed_at": "2025-08-07T19:13:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7a0ef31c53f6839ecf8cdc8ce17716c5fae0710",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.11.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.10.0...tremendous_ruby/v5.11.0)\n(2025-07-28)\n\n\n### Features\n\n* add credit_limit_cents to funding source for commercial invoicing\n([ad5528a](https://github\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.11.0 (#74)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2025-07-28T14:29:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ad5528aec291806f601a5064aa2af44aa6b9fe8f",
"body": "feat: update limit param in List rewards\nfeat: include invoice data in funding sources schema\nfix: update amount_money to amount in topup api\nfeat: add credit_limit_cents to funding source for commercial invoicing\nchore: update to openapi-generator@v7.12.0\n\nCloses #71",
"is_bot": false,
"headline": "feat: regenerate SDK (#72)",
"author_name": "caioicy",
"author_login": "CaioIcy",
"committed_at": "2025-07-28T14:18:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ffc2553acd380cdadaa73fd0178c7feb0135085",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.13.2 to\n2.13.4.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.13.4</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>Improv\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.13.2 to 2.13.4 (#73)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-07-28T11:07:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "80d40c1d87206baa085f5b01b06dc839334e9cf4",
"body": "Bumps\n[slackapi/slack-github-action](https://github.com/slackapi/slack-github-action)\nfrom 2.1.0 to 2.1.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/slackapi/slack-github-action/releases\">slackapi/slack-github-action's\nreleases</a>.</em></p>\n<blockquo\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump slackapi/slack-github-action from 2.1.0 to 2.1.1 (#70)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-07-14T08:35:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "72c17904594c38f0136c7fcfd5e6856a47677cba",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.13.1 to\n2.13.2.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.13.2</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>CI aga\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.13.1 to 2.13.2 (#69)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-07-07T09:38:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3bfcd735ac688235fefcc90de5ca43ea83ce84e0",
"body": "Bumps\n[faraday-multipart](https://github.com/lostisland/faraday-multipart)\nfrom 1.1.0 to 1.1.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday-multipart/releases\">faraday-multipart's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.1.1</h2>\n<h\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday-multipart from 1.1.0 to 1.1.1 (#68)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-06-23T08:54:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8832a74f0bb1ff39880e0fe888acfcdb4334f7c5",
"body": null,
"is_bot": false,
"headline": "chore: send custom Slack notifications (#67)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-06-09T20:09:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "601cf83e322f38b649388b7c9cfaf3ebc0532167",
"body": ":robot: I have created a release *beep* *boop*\n---\n\n\n##\n[5.10.0](https://github.com/tremendous-rewards/tremendous-ruby/compare/tremendous_ruby/v5.9.0...tremendous_ruby/v5.10.0)\n(2025-06-09)\n\n\n### Features\n\n* add more fields to the Funding Source resource\n([44c0d1d](https://github.com/tremendous-rewa\n[…]\nogleapis/release-please). See\n[documentation](https://github.com/googleapis/release-please#release-please).\n\nCo-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(main): release tremendous_ruby 5.10.0 (#66)",
"author_name": "github-actions[bot]",
"author_login": "github-actions[bot]",
"committed_at": "2025-06-09T13:05:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "44c0d1d0ee3c78354baf4e0b357b8541d044db70",
"body": "feat: add support for the Connected Organization and Connected\nOrganization Member endpoints\n\nfeat: add support for the Cancel Reward endpoint\n\nfeat: update fields regarding disclosures on the Products resource\n\nfix: expect `200` instead of `201` when creating a Report or a Campaign\n\nfeat: add more fields to the Funding Source resource",
"is_bot": false,
"headline": "feat: regen SDK code (#65)",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-06-09T12:57:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7695c0a8b6255be57a704cc67ea63ac85738c1a4",
"body": null,
"is_bot": false,
"headline": "chore: update `CODEOWNERS`",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-06-06T20:06:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b6670cdab81c8894a017603a9374a964610262a2",
"body": null,
"is_bot": false,
"headline": "chore: set test schedule",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-06-06T20:06:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0338a24539afe39b974608004ace6a1cbf8fffd9",
"body": "[//]: # (dependabot-start)\n⚠️ **Dependabot is rebasing this PR** ⚠️ \n\nRebasing might not happen immediately, so don't worry if this takes some\ntime.\n\nNote: if you make any changes to this PR yourself, they will take\nprecedence over the rebase.\n\n---\n\n[//]: # (dependabot-end)\n\nBumps [rake](https://gi\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump rake from 13.2.1 to 13.3.0 (#64)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-06-06T14:16:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0b4f59d69ae1dec2f467a5630ee32356156c62c",
"body": null,
"is_bot": false,
"headline": "chore: bump `bundler`",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-06-06T14:15:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f4608771079d6f71dab865f06da9d274894af30",
"body": null,
"is_bot": false,
"headline": "chore: add Ruby 3.4 to the build matrix",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-06-06T14:14:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b64cf50bd8481fb1eeccf03182a5813204be89c9",
"body": "Bumps [rspec](https://github.com/rspec/rspec) from 3.13.0 to 3.13.1.\n<details>\n<summary>Commits</summary>\n<ul>\n<li><a\nhref=\"https://github.com/rspec/rspec/commit/cd5cab2a4373b03dc730d84c8214b0cca1b7fde2\"><code>cd5cab2</code></a>\nrspec v3.13.1</li>\n<li><a\nhref=\"https://github.com/rspec/rspec/commit/4\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump rspec from 3.13.0 to 3.13.1 (#63)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-06-02T08:19:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6b1c2b760ec6843e25f2978b60d0a318f4bc6492",
"body": null,
"is_bot": false,
"headline": "chore: move dependabot `reviewers` to `CODEOWNERS`",
"author_name": "Lucas Mazza",
"author_login": "lucasmazza",
"committed_at": "2025-05-07T14:56:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d6e71766488fb79155107682e0ad7d0bd85b18ab",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.13.0 to\n2.13.1.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.13.1</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>Logger\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.13.0 to 2.13.1 (#62)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-04-28T11:02:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "51d4759aedc854935608b9f1d4cb5d0b94a30846",
"body": "Bumps [faraday](https://github.com/lostisland/faraday) from 2.12.2 to\n2.13.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday/releases\">faraday's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v2.13.0</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>feat(s\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday from 2.12.2 to 2.13.0 (#61)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-04-14T07:11:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd22733fa3885ff5798b95d339d4db0362e26bda",
"body": "Bumps [uri](https://github.com/ruby/uri) from 1.0.2 to 1.0.3.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a href=\"https://github.com/ruby/uri/releases\">uri's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.0.3</h2>\n<h2>What's Changed</h2>\n<ul>\n<li>Bump step-security/harden-runner from\n[…]\ntremendous-rewards/tremendous-ruby/network/alerts).\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump uri from 1.0.2 to 1.0.3 (#60)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2025-03-06T00:04:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d8ea51bddac5c9560e4348695da76eaeb3edd612",
"body": "Bumps\n[faraday-multipart](https://github.com/lostisland/faraday-multipart)\nfrom 1.0.4 to 1.1.0.\n<details>\n<summary>Release notes</summary>\n<p><em>Sourced from <a\nhref=\"https://github.com/lostisland/faraday-multipart/releases\">faraday-multipart's\nreleases</a>.</em></p>\n<blockquote>\n<h2>v1.1.0</h2>\n<h\n[…]\nnless you reopen the\nPR or upgrade to it yourself)\n\n\n</details>\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump faraday-multipart from 1.0.4 to 1.1.0 (#58)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2024-12-23T07:57:15Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 34,
"commits_last_year": 81,
"latest_release_at": "2026-07-23T14:28:46Z",
"latest_release_tag": "tremendous_ruby/v5.28.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 28,
"days_since_latest_release": 0,
"mean_days_between_releases": 11
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 50,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "tremendous_ruby",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "rubygems",
"matches_repo": true,
"registry_url": "https://rubygems.org/gems/tremendous_ruby",
"is_deprecated": false,
"latest_version": "5.28.0",
"repository_url": "https://github.com/tremendous-rewards/tremendous-ruby",
"versions_count": 44,
"total_downloads": 257457,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": "2019-04-27T00:06:29.193000Z",
"latest_published_at": "2026-07-23T14:29:25.986000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 19,
"stars": 9,
"watchers": 8,
"fork_history": {
"days": [
{
"date": "2018-10-29",
"count": 1
},
{
"date": "2019-09-11",
"count": 1
},
{
"date": "2020-03-03",
"count": 1
},
{
"date": "2020-03-06",
"count": 1
},
{
"date": "2020-04-14",
"count": 1
},
{
"date": "2020-05-27",
"count": 1
},
{
"date": "2021-01-07",
"count": 1
},
{
"date": "2021-12-23",
"count": 1
},
{
"date": "2022-01-06",
"count": 1
},
{
"date": "2022-06-13",
"count": 1
},
{
"date": "2022-06-22",
"count": 1
},
{
"date": "2023-02-06",
"count": 1
},
{
"date": "2023-02-23",
"count": 1
},
{
"date": "2023-09-19",
"count": 1
}
],
"complete": true,
"collected": 14,
"total_forks": 19
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 261410,
"source_files_sampled": 255,
"oversized_source_files": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"Gemfile"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 16,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 3,
"direct_affected_count": 0
},
"ecosystems": [
"rubygems"
],
"dependencies": [
{
"name": "rake",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
},
{
"name": "rspec",
"manifest": "Gemfile",
"ecosystem": "rubygems",
"version_constraint": null
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "rake",
"direct": true,
"version": "13.4.2",
"ecosystem": "rubygems"
},
{
"name": "rspec",
"direct": true,
"version": "3.13.2",
"ecosystem": "rubygems"
},
{
"name": "diff-lcs",
"direct": false,
"version": "1.6.2",
"ecosystem": "rubygems"
},
{
"name": "faraday",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "faraday",
"direct": false,
"version": "2.14.3",
"ecosystem": "rubygems"
},
{
"name": "faraday-multipart",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "faraday-multipart",
"direct": false,
"version": "1.2.0",
"ecosystem": "rubygems"
},
{
"name": "faraday-net_http",
"direct": false,
"version": "3.4.4",
"ecosystem": "rubygems"
},
{
"name": "json",
"direct": false,
"version": "2.19.9",
"ecosystem": "rubygems"
},
{
"name": "logger",
"direct": false,
"version": "1.7.0",
"ecosystem": "rubygems"
},
{
"name": "marcel",
"direct": false,
"version": null,
"ecosystem": "rubygems"
},
{
"name": "marcel",
"direct": false,
"version": "1.2.1",
"ecosystem": "rubygems"
},
{
"name": "multipart-post",
"direct": false,
"version": "2.4.1",
"ecosystem": "rubygems"
},
{
"name": "net-http",
"direct": false,
"version": "0.9.1",
"ecosystem": "rubygems"
},
{
"name": "rspec-core",
"direct": false,
"version": "3.13.6",
"ecosystem": "rubygems"
},
{
"name": "rspec-expectations",
"direct": false,
"version": "3.13.5",
"ecosystem": "rubygems"
},
{
"name": "rspec-mocks",
"direct": false,
"version": "3.13.6",
"ecosystem": "rubygems"
},
{
"name": "rspec-support",
"direct": false,
"version": "3.13.6",
"ecosystem": "rubygems"
},
{
"name": "uri",
"direct": false,
"version": "1.1.1",
"ecosystem": "rubygems"
}
],
"collected": true,
"truncated": false,
"total_count": 19,
"direct_count": 2,
"indirect_count": 17
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 127,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 20,
"closed_unmerged_prs": 9
},
"bus_factor": 1,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "lucasmazza",
"commits": 72,
"avatar_url": "https://avatars.githubusercontent.com/u/80978?v=4"
},
{
"type": "User",
"login": "Mattioli",
"commits": 9,
"avatar_url": "https://avatars.githubusercontent.com/u/5321824?v=4"
},
{
"type": "User",
"login": "brianstorti",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/183363?v=4"
},
{
"type": "User",
"login": "CaioIcy",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/4528105?v=4"
}
],
"contributors_sampled": 4,
"top_contributor_share": 0.828
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"dependabot-automerge.yml",
"release.yml",
"test.yml",
"update-sdk.yml",
"zizmor.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Gemfile.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": null,
"reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 6,
"reason": "18 out of 30 merged PRs checked by a CI test -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 10,
"reason": "all changesets reviewed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 1,
"reason": "SAST tool is not run on all commits -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "8d8458ce66e50defdf4fa9f82369b5b9f056f6b4",
"ran_at": "2026-07-23T14:33:36Z",
"aggregate_score": 6.9,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-23T14:29:30Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-23T14:28:33Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/tremendous-rewards/tremendous-ruby",
"host": "github.com",
"name": "tremendous-ruby",
"owner": "tremendous-rewards"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"security": 75,
"vitality": 90,
"community": 54,
"governance": 65,
"engineering": 58
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 90,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"commits_last_year": 81,
"human_commit_share": 0.27,
"days_since_last_push": 0,
"active_weeks_last_year": 28
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "28/52 weeks with commits",
"points": 19.4,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 28
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "81 commits in the last year",
"points": 17.2,
"status": "partial",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 81
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 34,
"latest_release_tag": "tremendous_ruby/v5.28.0",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 11
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "34 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 34
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~11 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 11
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 2,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 2 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 2
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 54,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 30,
"inputs": {
"forks": 19,
"stars": 9,
"watchers": 8,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "9 stars",
"points": 14.6,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 9
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "19 forks",
"points": 10.5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 19
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "8 watchers",
"points": 4.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 8
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 70,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "good",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 70,
"inputs": {
"packages": [
"tremendous_ruby"
],
"dependents": null,
"ecosystems": "rubygems",
"total_downloads": 257457,
"monthly_downloads": null
},
"components": [
{
"key": "total_downloads",
"name": "Total downloads",
"detail": "257,457 downloads all-time across rubygems",
"points": 56.2,
"status": "partial",
"details": [
{
"code": "downloads_total",
"params": {
"count": 257457,
"ecosystems": "rubygems"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 65,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 18,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 4,
"top_contributor_share": 0.828
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 83% of commits",
"points": 3.9,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 83
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "4 contributors",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 4
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "excellent",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 98,
"inputs": {
"merged_prs": 127,
"open_issues": 0,
"closed_issues": 20,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 9
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 46.8,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "127/136 decided PRs merged",
"points": 35.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 127,
"decided": 136
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "all changesets reviewed",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"followers": 16,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "tremendous-rewards",
"public_repos": 20,
"account_age_days": 2481
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "16 followers of tremendous-rewards",
"points": 8.8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 16,
"login": "tremendous-rewards"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "20 public repos, account ~6 yr old",
"points": 21.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 20
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"tremendous_ruby"
],
"ecosystems": "rubygems",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on rubygems",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "rubygems"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "44 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 44
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 58,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "18 out of 30 merged PRs checked by a CI test -- score normalized to 6",
"points": 12,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"topics": [],
"has_wiki": false,
"homepage": "https://developers.tremendous.com",
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://developers.tremendous.com",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 75,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Branch-Protection, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"branch_protection",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 69,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 6.9
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "18 out of 30 merged PRs checked by a CI test -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "all changesets reviewed",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 1",
"points": 0.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 16 resolved dependencies against OSV; 3 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 16
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 3
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 16,
"unassessed_packages": 3,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 16,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 3
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "at_risk",
"name": "AI Readiness",
"value": 49,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "27 of 27 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 27,
"sampled": 27
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "moderate",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 54,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Gemfile.lock"
],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0.02,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.38
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "2 of the last 100 commits agent-authored or agent-credited",
"points": 4,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 2,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "38 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 38,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "Ruby",
"largest_source_bytes": 261410,
"source_files_sampled": 255,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Ruby without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Ruby"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/255 source files over 60KB",
"points": 54.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 255,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
],
"report_type": "repository",
"generated_at": "2026-07-23T14:34:00.597606Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/t/tremendous-rewards/tremendous-ruby.svg",
"full_name": "tremendous-rewards/tremendous-ruby",
"license_state": "standard",
"license_spdx": "MIT"
}