公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-26 01:25 UTC

ufleisch / taglib

TagLib Audio Meta-Data Library

C++LGPL-2.1★ 1 星标⑂ 1 复刻始于 2013年3月复刻在 GitHub 上查看 ↗

ufleisch/taglib 的健康指数为 100 分中的 45 分,处于「存在风险」区间。 其得分最高的类别是Vitality(61/100),最低的是Community & Adoption(12/100)。 最近一次更新在 6 天前。 近期的大部分工作由 2 位贡献者完成。

45
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

45
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Urs Fleisch个人账户
10 关注者12 个公开仓库始于 2012年8月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

61中等 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 6 天前
17.3/36提交节奏 — 52 周中有 25 周有提交
17.5/18提交量 — 最近一年 87 次提交
9/10OpenSSF Scorecard:Maintained — 11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9
所用输入
commits_last_year87
human_commit_share0.98
days_since_last_push6
active_weeks_last_year25

发布纪律

32存在风险
评分方式
16.2/27有发布版本 — 5 个版本标签(无 GitHub 发布版本)
0/36发布时效 — 最近一次发布版本于 5,209 天前
12.6/27发布节奏 — 约每 225.6 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count5
latest_release_tagv1.7.2
releases_from_tags
days_since_latest_release5,209
mean_days_between_releases225.6
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

12危急 · 占总体的 18%
评分方式
0/60星标 — 1 个星标
0/25复刻 — 1 个复刻
0/15关注者 — 2 位关注者
所用输入
forks1
stars1
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

25危急
评分方式
0/22.5README
22.5/22.5许可证 — 可识别的许可证(LGPL-2.1)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

39存在风险 · 占总体的 24%
评分方式
25.2/54巴士系数 — 2 位贡献者贡献了半数提交
15.3/22.5提交分布 — 头号贡献者编写了 32% 的提交
13.5/13.5贡献者广度 — 99 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 25 contributing companies or organizations
所用输入
bus_factor2
contributors_sampled99
top_contributor_share0.32
评分方式
0/46.8议题解决 — 没有议题或无数据
0/38.3PR 接受 — 没有已裁定的拉取请求或无数据
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决, PR 接受。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
7.5/25所有者影响力 — ufleisch 有 10 位关注者
20.1/25既往记录 — 12 个公开仓库,账户约 13 年
所用输入
followers10
owner_typeUser
is_verified
owner_loginufleisch
public_repos12
account_age_days5,098
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。

工程质量

基础的工程与文档实践是否到位?

61中等 · 占总体的 20%

工程实践

68中等
评分方式
24/24CI 工作流 — 1 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
6.4/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

50中等
评分方式
0/30README
25/25文档目录
15/15文档 / 主页站点 — http://taglib.github.com/
0/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepagehttp://taglib.github.com/
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

49存在风险 · 占总体的 16%

安全态势

49存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 25 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
6.8/7.5Maintained — 11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate4.9
已排除计分(无数据或不适用):ci_tests, packaging, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

47存在风险 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
29.4/40可读的提交历史 — 98 次人类提交中有 54 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.551
agent_instruction_files
agent_instruction_max_bytes
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — C++(静态类型)
0/10可复现环境
2/10已体现的代理实践 — 最近 100 次提交中有 1 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 2 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.01
toolchain_manifests
dependency_bot_commit_share0.02
评分方式
45/45可类型检查的代码 — C++(静态类型)
54.6/55可控的文件大小 — 采样的 367 个源文件中有 3 个超过 60KB
所用输入
primary_languageC++
largest_source_bytes84,203
source_files_sampled367
oversized_source_files3

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

1GitHub 星标
99贡献者
87最近 12 个月提交数
6距最近推送天数
5发布版本数
2巴士系数(bus factor)
0开放议题
软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Community profile unavailable
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 4.9 / 10
4.9综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-26 01:24 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 25 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
9Maintained11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 6972,
      "has_wiki": true,
      "homepage": "http://taglib.github.com/",
      "languages": {
        "C": 25165,
        "C++": 2720863,
        "CMake": 57964,
        "Shell": 1052
      },
      "pushed_at": "2026-07-19T17:45:51Z",
      "created_at": "2013-03-23T12:43:39Z",
      "owner_type": "User",
      "updated_at": "2026-05-13T05:37:57Z",
      "description": "TagLib Audio Meta-Data Library",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "LGPL-2.1",
      "default_branch": "master",
      "license_spdx_raw": "LGPL-2.1",
      "primary_language": "C++",
      "significant_languages": [
        "C++"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Urs Fleisch",
      "type": "User",
      "login": "ufleisch",
      "company": null,
      "location": null,
      "followers": 10,
      "avatar_url": "https://avatars.githubusercontent.com/u/2125194?v=4",
      "created_at": "2012-08-09T18:53:21Z",
      "is_verified": null,
      "public_repos": 12,
      "account_age_days": 5098
    },
    "license": {
      "state": "standard",
      "spdx_id": "LGPL-2.1",
      "raw_spdx": "LGPL-2.1",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.7.2",
          "kind": "patch",
          "published_at": "2012-04-20T15:57:13Z"
        },
        {
          "tag": "v1.7.1",
          "kind": "patch",
          "published_at": "2012-03-17T10:02:24Z"
        },
        {
          "tag": "v1.6.3",
          "kind": "patch",
          "published_at": "2010-04-17T11:31:35Z"
        },
        {
          "tag": "v1.6.2",
          "kind": "patch",
          "published_at": "2010-04-09T09:37:51Z"
        },
        {
          "tag": "v1.6.1",
          "kind": "patch",
          "published_at": "2009-10-31T09:57:13Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "54999473a13cef45b4a560aa73aacdebd05b195e",
          "body": null,
          "is_bot": false,
          "headline": "Test with windows-2025-vs2026 instead of windows-2025",
          "author_name": "Urs Fleisch",
          "author_login": null,
          "committed_at": "2026-05-13T05:25:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4793aac5427c4bd1c618de5cf4b0c908081046fc",
          "body": null,
          "is_bot": false,
          "headline": "Test with windows-2025-vs2026 instead of windows-latest",
          "author_name": "Urs Fleisch",
          "author_login": null,
          "committed_at": "2026-05-13T05:21:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b94b93762636ebe5733180c3e825be4621e4c7f",
          "body": null,
          "is_bot": false,
          "headline": "Version 2.3",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-05-10T13:25:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8511827fa13842befb114bbf4b66fd9acce9d94e",
          "body": "When the file is opened in read-only mode, it will not be written and\nthe Cues do not have to be updated. Skipping the Cues will make the\nreading of large Matroska files over network filesystems (SMB/NFS)\nfaster.",
          "is_bot": false,
          "headline": "Skip Matroska Cues with AudioProperties::Fast and read-only mode",
          "author_name": "HomerJau",
          "author_login": "HomerJau",
          "committed_at": "2026-05-09T07:25:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b02ff639169065d3eb31f757e86c0352a20a0caa",
          "body": null,
          "is_bot": false,
          "headline": "Fix -Wconversion size_t to unsigned int warning",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-05-09T06:28:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1e8dac08448c2d414c484c05fce990044637265",
          "body": "Some muxers — notably MakeMKV, and mkvmerge in certain configurations — write a small primary seekHead at the start of the segment that contains a single entry referencing a secondary seekHead near the end of the file. The secondary seekHead carries the actual entries for info, tracks, tags, chapters, and attachments.",
          "is_bot": false,
          "headline": "[Matroska: Follow chained SeekHead entries when parsing segment metadata",
          "author_name": "HomerJau",
          "author_login": "HomerJau",
          "committed_at": "2026-05-08T03:17:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1460b6fbfd0cd49eeb3d701e70051d2e600b7bf",
          "body": null,
          "is_bot": false,
          "headline": "Build fix for Haiku's fcntl.h which can't be found in sys/fcntl.h",
          "author_name": "Luc Schrijvers",
          "author_login": "Begasus",
          "committed_at": "2026-05-07T16:32:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "43190d30edd7868ffd9b8423b629738a48918556",
          "body": null,
          "is_bot": false,
          "headline": "Prepare 2.3 release",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-05-04T11:02:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c43f1c57705822eab5d42e1cb60d92942cd798e",
          "body": "A new Matroska::File::save(WriteStyle style) overload is provided to\ncontrol how tags, attachments and chapters are written to the file.\n\n- Compact: Write tags, attachments and chapters as compact as possible.\n  This is the default mode.\n- DoNotShrink: Do not shrink elements; add void padding when c\n[…]\ne new element at the end of the segment.\n  For very large files and/or slow (network) filesystems, using this\n  mode will reduce write time significantly.\n\nCo-authored-by: Copilot <copilot@github.com>",
          "is_bot": false,
          "headline": "Matroska: Provide different WriteStyle to trade-off size/speed",
          "author_name": "Urs Fleisch",
          "author_login": null,
          "committed_at": "2026-05-04T10:55:17Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "59ed19d12f5dbd8b51244b3cd3a028cf0b6120df",
          "body": "The iXML chunk in BWF/WAV files is specified as UTF-8 (per the EBU\nTech 3285 supplement and the iXML spec). The reader was constructing\nthe String without an encoding hint, which falls back to Latin-1 and\nmangles any non-ASCII bytes (e.g. Unicode in <NOTE>, <PROJECT>, or\n<TRACK_LIST> entries written by Sound Devices, Zaxcom, etc.).",
          "is_bot": false,
          "headline": "[WAV] Decode iXML as UTF-8",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-05-01T04:32:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e7bdae284ae1c72c6b168293c40863caac7096f",
          "body": "Adds 6 public methods on FLAC::File mirroring RIFF::WAV::File's existing\niXML/BEXT API: iXMLData/setiXMLData/hasiXMLData and the BEXT equivalents.\n\nReads APPLICATION blocks (RFC 9639 § 8.4) carrying either the IANA-\nregistered \"riff\" foreign-metadata wrapper or the direct \"iXML\" / \"bext\"\napplication\n[…]\nng files round-trip without churn.\n\nTest coverage: read direct + riff-wrapped for both iXML and BEXT,\nwrite+reread round-trip, empty-clears-block, and an unknown-application-\nblock preservation guard.",
          "is_bot": false,
          "headline": "[FLAC] Add iXML and BEXT support via APPLICATION blocks",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-05-01T04:31:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e07b956fdadc7c3a1012f5293f1843de650585bf",
          "body": "…nID)\n\nFix: Handle orphan ChapterAtom elements not wrapped in EditionEntry\n\nThe Matroska specification requires every ChapterAtom to be inside an\nEditionEntry. However, some muxers (older FFmpeg versions, some streaming\ntools) produce files with ChapterAtom elements directly under Chapters,\nwithout \n[…]\napterAtom() helper\n  to avoid code duplication between the two call sites\n\nNo existing behavior is changed - files that already conform to the spec\n(chapters inside an EditionEntry) parse identically.",
          "is_bot": false,
          "headline": "[Matroska] Allow Orphaned Chapter Reading (when Chapter has no Editio…",
          "author_name": "HomerJau",
          "author_login": "HomerJau",
          "committed_at": "2026-04-26T06:24:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e1cb4081d8f23532b6b3ec2ee173f3d7c64492a",
          "body": null,
          "is_bot": false,
          "headline": "Limit MP4 atom sibling count at top level (#1344)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-26T05:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7e4f0958cb24e10e6fca201b133609961d398b9",
          "body": "ryanfrancesconi/feature/mp4-chapterlist\nryanfrancesconi/fix/qt-chapter-orphaned-mdat",
          "is_bot": false,
          "headline": "Merge pull requests #1325 #1343 from ryanfrancesconi MP4 chapterlist",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-26T05:15:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "497c040f04b888ef235c7cae0d59964c2a62bca6",
          "body": "An equality operator is added for the chapters. The chapters are\nonly written to the file if they were really modified, so just\nreading the chapters without modifying them will not affect\nthe save operation.",
          "is_bot": false,
          "headline": "Set MP4 chapters only if modified",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-25T09:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05c2c8671e49c3fc2d25438db53a264ec688b504",
          "body": "…independence\n\nSix new tests exercise corners of the chapter implementation that the\norphaned-mdat fix did not reach:\n\ntestQTChapterListUnicodeTitles / testChapterListUnicodeTitles --\nRound-trip Japanese, German (umlaut), and Russian titles through the\nQT text-sample serialisation and the Nero lengt\n[…]\ns the other intact.\nValidates the lazy saveChaptersIfModified contract in mp4file.cpp.\n\ntestNeroChaptersAloneWhenNoQT --\nWriting one format must not create atoms for the other.\n\nAll 47 MP4 tests pass.",
          "is_bot": false,
          "headline": "MP4: Add test coverage for chapter unicode, empty titles, and format …",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T19:19:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85b6a9eb93d15b0aa5feaf0187290ef7a5e93eff",
          "body": "The previous fix for orphaned chapter mdats assumed the chapter text\nmdat was dedicated and derived its location from stco[0] - 8.  In\naudiobooks that co-locate chapter text at the start of the primary\naudio mdat (stco[0] == audioMdat.offset + 8), that arithmetic lands\non the audio mdat header, the \n[…]\nwrites a chapter track, patches its\nstco[0] to point into the primary audio mdat (simulating the\naudiobook layout), removes the chapter track, and verifies the\naudio mdat is byte-identical afterwards.",
          "is_bot": false,
          "headline": "MP4: Guard against deleting shared mdat on QT chapter remove",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T19:14:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c70f0071f16f7370042b5e08b2fb2040601cc7a",
          "body": "Adds testQTChapterListNoOrphanedMdat which performs three add/remove\ncycles and asserts that the top-level mdat count is identical before and\nafter.  Without the fix, each cycle leaves an orphaned mdat at EOF, so\nthree cycles produce originalCount + 3 atoms.\n\nUses TagLib's own MP4::Atoms parser as the primary check, with\nAtomicParsley as an optional cross-validation when installed.",
          "is_bot": false,
          "headline": "MP4: Add regression test for orphaned mdat on QT chapter remove",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae171ee237ee9e79962df0c2d791cea3494fb652",
          "body": "write() appends a new mdat at EOF to hold chapter text samples but the\nremoval code (both remove() and the replace-existing path in write())\nonly deleted the chapter trak and tref atoms from inside moov.  Each\nadd/remove cycle left the previous chapter mdat behind, causing orphaned\nmdat atoms to acc\n[…]\nte the mdat.  After removing the trak and tref (both\ninside moov, which precedes the mdat at EOF), it adjusts the mdat offset\nby -(chapterLen + trefLen) and removes the atom, leaving no orphaned data.",
          "is_bot": false,
          "headline": "MP4: Remove orphaned mdat when removing QT chapter track",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "78c7208bc9697e867945e93eeedcd048ab21478a",
          "body": null,
          "is_bot": false,
          "headline": "Integrate MP4 chapters into MP4::File",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0df52e39933c2dbef07db48abc06871159b1f32f",
          "body": "The updateChunkOffsets() function in mp4qtchapterlist.cpp and\nmp4chapterlist.cpp is duplicated code from mp4tag.cpp and needs\nthe patch from mp4tag.cpp too.",
          "is_bot": false,
          "headline": "Apply stco/co64 bounds fix from PR #1333 to MP4 chapter code",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba2441b378eaa0121fbf60bcc540a741c4424939",
          "body": "taglib/mp4/mp4chapterlist.h\n• start​Time doc comment: 100​-nanosecond units → milliseconds\n\ntaglib/mp4/mp4chapterlist.cpp\n• render​Chpl​Data: from​Long​Long(ch​.start​Time) → from​Long​Long(ch​.start​Time * 10000​LL)\n• parse​Chpl​Data: ch​.start​Time = start​Time → ch​.start​Time = start​Time100ns /\n[…]\n build​Stts lambda: time100ns * timescale / 10000000​.0 → time​Ms * timescale / 1000​.0\n\ntests/test_mp4.cpp\n• All start​Time assignments and assertions divided by 10,000 (e.g. 300000000​LL → 30000​LL)",
          "is_bot": false,
          "headline": "corrected nanosecond unit change -> milliseconds",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c5ea13bb34a9781fc40444b5d5ea964440a5283b",
          "body": "Changes made\n\nmp4chapterlist.h\n• Added (​MP4::​File*) overloads for read, write, remove\n• Replaced broken class ​File; forward declaration with #include \"mp4file​.h\" (fixed a subtle C++ name-resolution linker bug where Atoms(​File*) resolved to MP4::​File* instead of Tag​Lib::​File*)\n\nmp4chapterlist\n[…]\nest​QTChapter​List​File​API — exercise the full write/read/remove cycle via the file-based API\n• Updated test bodies to use the simplified (​MP4::​File*) API (no MP4::​Atoms construction in test code)",
          "is_bot": false,
          "headline": "overloads for read, write, remove",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a73d73b20a1ead2cd2c4a37b5eae98ac4908b4f",
          "body": "QuickTime-style chapter tracks are the native chapter format for\nApple's ecosystem. They use a disabled text track (hdlr type \"text\")\nreferenced by a chap track-reference in the audio track's tref box.\nThis format is recognized by QuickTime, iTunes/Music, Final Cut Pro,\nLogic Pro, DaVinci Resolve, V\n[…]\n000 (milliseconds) for chapter track timing\n\n7 new tests covering write/read round-trip, remove, overwrite, tag\npreservation, empty file read, timestamp precision, and non-zero\nfirst chapter handling.",
          "is_bot": false,
          "headline": "MP4: Add QuickTime-style chapter track support",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c56f191e5e3b3daa5eb9e381cc27845e2a731dc",
          "body": "Implement read/write/remove of Nero-style chapter markers (chpl atom)\nin MP4 files. The chpl atom lives at moov/udta/chpl, storing up to 255\nchapter entries with 100-nanosecond timestamps and UTF-8 titles.\n\nIncludes CppUnit tests covering round-trip read/write, remove, tag\npreservation, and reading from files with no chapters.",
          "is_bot": false,
          "headline": "MP4: Add Nero-style chapter marker support",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-23T18:03:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77f6b9add5ffb8fef62f718fbe07369cde3f799a",
          "body": null,
          "is_bot": false,
          "headline": "Drop zero size ID3v2 frames but accept tag (#437)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-20T13:11:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a64e7543f85f5a3a557023ee838ec5921d36159b",
          "body": null,
          "is_bot": false,
          "headline": "Fix DSD/DSF signed integer issues (#1332)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-20T13:08:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d466b72eeafa6bdfa3d59bba4d8b0a2d0947cbed",
          "body": "Make MP4 AtomDataType descriptions visible in the generated documentation.\nConvert the ID3v2 text frame listing into a table.\nConvert the shorten `fileType()` documentation into a table.\nFix some typos.\nAdd link to specification in `EventType` for consistency with other headers.",
          "is_bot": false,
          "headline": "docs: Some improvements to the documentation (#1337)",
          "author_name": "Felipe",
          "author_login": "felipdsa21",
          "committed_at": "2026-04-13T18:05:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3a0e1d0a2d0d1ccaf5b56d27592713f3fa4564f",
          "body": "Limit scan for Matroska seek head to 512 KB in ReadStyle::Fast\n\n---------\n\nCo-authored-by: tolriq <git@leetzone.org>",
          "is_bot": false,
          "headline": "Matroska: Use seek head for faster element lookup (#1321)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-13T17:58:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13751f5a6b2d9de491ef89d6936384e80eafbac3",
          "body": "* Shorten: Reject out-of-range k in getRiceGolombCode\n\nk values outside [0, 31] cause undefined behavior: a left shift by 32\non int32_t (UB in C++) when bitsAvailable reaches 32 after a buffer\nrefill. Guard against this at the top of getRiceGolombCode and return\nfalse (invalid file) for any k outsid\n[…]\n by 32\non int32_t (UB in C++) when bitsAvailable reaches 32 after a buffer\nrefill. Guard against this at the top of getRiceGolombCode and return\nfalse (invalid file) for any k outside the valid range.",
          "is_bot": false,
          "headline": "Fix/shorten rice golomb k bounds (#1335)",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-09T20:03:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4da5ac2de4297433b4d168f59a2574af0379ee83",
          "body": "This will fix a DoS with a crafted MP4 file causing too many offsets\nto be written when updating the stco or co64 tables in MP4 files.\n\nCredits for the discovery of this bug go to Yuen Ying Ng (Ruth)\n(Cyber Security Researcher at PwC Hong Kong).",
          "is_bot": false,
          "headline": "Fix writing too many offsets when updating MP4 stco/co64 atoms (#1332)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-08T18:53:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "193091fe2ebb93ba5961adb5ba3c4632f6c50327",
          "body": "…(#1326)\n\nCredits for fix and reporting go to https://github.com/ericliu-12.",
          "is_bot": false,
          "headline": "Fix unbounded recursion in EBML/Matroska MasterElement and MP4 atoms …",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-04-08T18:52:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d63187a8b8d291cbf4f77d1bb973bc5ee91cf03",
          "body": "Concurrent calls to propertyKeyForName() and handlerTypeForName() (e.g.\nvia batchMap during import) could race on the isEmpty() guard used for\nfirst-call lazy initialization.\n\nReplace isEmpty() guards with std::call_once / std::once_flag so that\neach map is initialized exactly once in a thread-safe \n[…]\nry subclasses to override\nnameHandlerMap() and namePropertyMap() correctly.\n\nBoth property maps are initialized together in a single once_flag since\nnameForPropertyKey is derived from namePropertyMap.",
          "is_bot": false,
          "headline": "MP4: Fix data race in ItemFactory lazy map initialization (#1331)",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-04T15:52:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f32b503f56d3de43d5cc885f0365b1064a1b3ac6",
          "body": "mpegheader.cpp: ADTS bitrate divided by 1024 (binary kilo) instead of\n1000 (decimal kilo), causing ~2.4% underreporting for all AAC streams.\n\nmp4properties.cpp: ESDS averageBitrate double-rounded via both +500 and\n+0.5 before int cast, causing standard bitrates (128000, 192000, etc.)\nto read 1 kbps too high.",
          "is_bot": false,
          "headline": "Fix bitrate calculation unit errors in ADTS and MP4 ESDS parsers (#1330)",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-04T14:34:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d6a2134cf3af577ee63130d400c433cb74cd8694",
          "body": "… (#1329)\n\nSome encoders write a valid data chunk but with a slightly too-large\ndeclared chunkSize, or place the data chunk beyond the declared RIFF\nboundary. The previous behaviour called break, abandoning all remaining\nchunks and making the file appear empty to taglib.\n\nLenient parsers (ffmpeg, Qu\n[…]\ny clamping the\nchunk size to the bytes that actually remain in the file. Adopt the\nsame strategy: when chunkSize would exceed the file length, clamp it\nand continue parsing rather than stopping early.",
          "is_bot": false,
          "headline": "Clamp oversized RIFF chunk to available bytes instead of rejecting it…",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-04T10:47:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abadbb676889f9e5980edc4600b43bc2d2d73355",
          "body": "Read, write, and remove Broadcast Audio Extension (BEXT, EBU Tech 3285)\nand iXML metadata chunks in WAV files. BEXT is widely used in broadcast\nand professional audio for originator, description, time reference, and\nloudness metadata. iXML is used by field recorders and DAWs for scene,\ntake, and track metadata.",
          "is_bot": false,
          "headline": "Add BEXT and iXML chunk support to WAV files (#1323)",
          "author_name": "Ryan Francesconi",
          "author_login": "ryanfrancesconi",
          "committed_at": "2026-04-04T10:14:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49510e7d5a4b341a92ff962d0808bea3d5a0bfc8",
          "body": "MPEG::File::isSupported() scans for frame sync bytes that can appear\nin other files, causing them to be misidentified as MP3.\n\nThis also includes a test with such a file.",
          "is_bot": false,
          "headline": "Move MPEG check to end of content-based detection (#1319)",
          "author_name": "Daniel",
          "author_login": "DanTheMan827",
          "committed_at": "2026-04-04T06:01:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f2f2ddcafb2125f6aad70db79b3e0a3de581212",
          "body": "…1318)\n\nThis covers all 18 formats supported by the content-based detection.",
          "is_bot": false,
          "headline": "Add tests for FileRef content-based detection via ByteVectorStream (#…",
          "author_name": "Daniel",
          "author_login": "DanTheMan827",
          "committed_at": "2026-04-04T05:43:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0368c0239a8ef0be40a2c6fd4c669f59d8fbf28e",
          "body": "git submodule init\ngit submodule update --remote\n(cd 3rdparty/utfcpp && git checkout v4.0.9)\ngit add 3rdparty/utfcpp\ngit commit -m 'Pin submodule utfcpp to tag v4.0.9'",
          "is_bot": false,
          "headline": "Pin submodule utfcpp to tag v4.0.9 (#1315)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-03-31T18:04:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9411bb161f8af5a41d0cb3843c39c3c8d1990d2f",
          "body": null,
          "is_bot": false,
          "headline": "Opus: Read output gain (#1320)",
          "author_name": "Felipe",
          "author_login": "felipdsa21",
          "committed_at": "2026-03-31T16:14:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78298769de7485850613b0589d70503b8a8fc81c",
          "body": null,
          "is_bot": false,
          "headline": "Version 2.2.1",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-03-07T05:41:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c43d2b3fc1a21ed6811b7f154459789dcf1b3429",
          "body": "When using for example\n\nexamples/tagwriter -C GENRE \\\n\"name=GENRE,targetTypeValue=50,value=Soft Rock;name=GENRE,targetTypeValue=50,value=Classic Rock\" \\\npath/to/file.mka\n\nthe GENRE key was included twice and tagreader displayed the two genre\ntags twice.",
          "is_bot": false,
          "headline": "Avoid duplicates in StringList Matroska::Tag::complexPropertyKeys()",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-02-28T06:51:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3db0d48f4bb2b65cb3adcce066f80fb8e6fa8e87",
          "body": "…(#1311)",
          "is_bot": false,
          "headline": "Support edition, chapter and attachment UIDs in Matroska simple tags …",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-02-24T05:53:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de6e2b15c83415abcb6c37573363cdf2b59943c1",
          "body": null,
          "is_bot": false,
          "headline": "Version 2.2",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-02-18T04:15:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7f0225f0def07d6e7e00a2a3ca998067a8a7ba0",
          "body": "This prevents the parsing of frames with specially constructed recursive\nframe hierarchies from taking an extremely long time.",
          "is_bot": false,
          "headline": "Do not allow unknown frames embedded in CTOC and CHAP (#1306)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-02-15T07:38:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4117f873c2cdc7b61553ae27df34364340a37ea",
          "body": "A crafted file can have blockSamples set to 0 and a blockSize so big\nthat when adding 8 it overflows and offset is 0 so it goes back to the\nsame position and loops forever",
          "is_bot": false,
          "headline": "wavpack: Fix infinite loop when reading broken files (#1304)",
          "author_name": "tsdgeos",
          "author_login": "tsdgeos",
          "committed_at": "2026-02-04T16:31:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf86f20b36ac070ed8511540057b1e448a82c6d3",
          "body": null,
          "is_bot": false,
          "headline": "Add DSD information to WavPack properties (#1303)",
          "author_name": "Damien Plisson",
          "author_login": "damien78",
          "committed_at": "2026-02-04T16:31:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74d93db16634cc647501e5eadfab96792e6a13d1",
          "body": null,
          "is_bot": false,
          "headline": "Update changelog for v2.2beta",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-02-01T11:08:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "397b6c1de3f02688b71f50f7f3eec95584948363",
          "body": "Also fix some wrong frame sizes in the unit tests.\n\n---------\n\nCo-authored-by: Urs Fleisch <ufleisch@users.sourceforge.net>",
          "is_bot": false,
          "headline": "Add check for ID3v2 frame data length (#1300)",
          "author_name": "Stephen Booth",
          "author_login": "sbooth",
          "committed_at": "2026-01-31T07:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51f431c96adaa59766bef85b330b206d56198ac9",
          "body": null,
          "is_bot": false,
          "headline": "Verify the ID3v2 version and revision are not 0xFF (#1301)",
          "author_name": "Stephen Booth",
          "author_login": "sbooth",
          "committed_at": "2026-01-31T07:21:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11e3eb05bd8694976d065f37d62ee1a6811daef3",
          "body": null,
          "is_bot": false,
          "headline": "MP4: Add support for NI STEM (#1299)",
          "author_name": "Antoine Colombier",
          "author_login": "acolombier",
          "committed_at": "2026-01-25T12:33:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c01b63433c1cf45dc91929aafd5d4c58b99f491",
          "body": "Another Matroska Attempt",
          "is_bot": false,
          "headline": "Merge pull request #1149 from complexlogic/matroska",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T14:27:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d83d751443051e788be05d87b8bee0d5aed83703",
          "body": "When building for macOS < 10.14, the API for std::optional and\nstd::variant is restricted\n\n    error: 'value' is unavailable: introduced in macOS 10.14\n    error: 'get<..>' is unavailable: introduced in macOS 10.14\n\nThere was also an issue with Android armeabi-v7a where long is not\n64 bit and a static assertion failed.",
          "is_bot": false,
          "headline": "Matroska: Fix build with older macOS and 32-bit Android compilers",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4e7a742c322b2d50e1e1eaef4741273ae6edc75",
          "body": "Make AttachedFile immutable. This is consistent with SimpleTag and\nChapter and avoids using attached files which do not have all required\nattributes.\nProvide methods to insert and remove a single simple tag, so that\nthey can be modified without setting all of them while still not\nexposing internal l\n[…]\ns to the API.\nUse DATE_RECORDED instead of DATE_RELEASED for year() and the \"DATE\"\nproperty. This is more consistent with other tag formats, e.g. for ID3v2\n\"TDRC\" is used, which is the recording time.",
          "is_bot": false,
          "headline": "Improve Matroska API",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68a514f4a056869ecb252ab31576f661336dd2bb",
          "body": null,
          "is_bot": false,
          "headline": "Matroska: Avoid inlined header methods, only install public headers",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "607cd5bdf46d43d8643a424ade1c9e85fb30b139",
          "body": null,
          "is_bot": false,
          "headline": "Matroska: Fix issues reported by static analysis, formatting, docs",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b625be569093d52449d25ad2c5f3d605fa12b4df",
          "body": null,
          "is_bot": false,
          "headline": "Support for Matroska chapters",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2bf7e72d2e753bc2c425b0dbd764b96c7283790",
          "body": null,
          "is_bot": false,
          "headline": "Unit tests for Matroska",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "280d6306d229d3797ef501cf974f579ff3d0f2fa",
          "body": null,
          "is_bot": false,
          "headline": "Update property mapping documentation for Matroska",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aef78068b327fbff184d4a8cba91282aef15054f",
          "body": null,
          "is_bot": false,
          "headline": "Render when tags are modified",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "81815e1091ceec4a875f7789c4fcab460d535e16",
          "body": null,
          "is_bot": false,
          "headline": "Include doc type and version in properties",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9122afaca8cb819789536b5071b674c52529856",
          "body": "Some encoders write track specific DURATION tags, which should not be\nremoved.",
          "is_bot": false,
          "headline": "Preserve track UID in simple tags",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d3a3757658e457a5922f78aa0f849922046f4b6",
          "body": "Some applications like handbrake store the title only in the segment\ninfo element.",
          "is_bot": false,
          "headline": "Use segment title as fallback for returned tag title",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "241b3b2921ce27ce28bb183a39c6c80b97c04824",
          "body": null,
          "is_bot": false,
          "headline": "Remove offset listeners, they are not used",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48104959b24477516989e6fe51292e733433502d",
          "body": null,
          "is_bot": false,
          "headline": "Integrate cues, fix element rendering and resizing",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c817cc0a47e701e299f2166ad3f49284a9c0f605",
          "body": "A complex property can be set with\n\n-C <complex-property-key> <key1=val1,key2=val2,...>\n\nThe second parameter can be set to \"\" to delete complex properties with the\ngiven key. The set complex property values, a simple shorthand syntax can be\nused. Multiple maps are separated by ';', values within a \n[…]\nname=PART_NUMBER,targetTypeValue=20,value=2 file.mka\n\nSet simple tag with binary value in a Matroska file:\nexamples/tagwriter -C BINARY \\\n  name=BINARY,data=file://file.bin,targetTypeValue=60 file.mka",
          "is_bot": false,
          "headline": "tagwriter: Support setting of complex properties",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7a5a10102e447c5fff0731accafec9c5d05ee369",
          "body": "…perties\n\nAlso all attached files can be accessed and modified using complex properties.",
          "is_bot": false,
          "headline": "Set Matroska tags which are not in the property map using complex pro…",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d47d28f0f8a296b177f6c6239cf08ce796c45b92",
          "body": "Avoid use of raw pointers, fix property interface.",
          "is_bot": false,
          "headline": "Fix and simplify Matroska simple tag",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3566b00596110d85060ee33e96286ec9b3924131",
          "body": "Avoid use of raw pointers.",
          "is_bot": false,
          "headline": "Clean up attachments",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98bc68d16efe2538f8ea27b09550a45e9030efb2",
          "body": null,
          "is_bot": false,
          "headline": "Implement complex properties for Matroska",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d02484804e0dd7f3c76c8b3b32e85448c1a14d8",
          "body": "Also improve type safety and consistency.",
          "is_bot": false,
          "headline": "Replace raw pointers by smart pointers",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfade6d0825847bd2d1966ea364f758314382edd",
          "body": null,
          "is_bot": false,
          "headline": "Implement Matroska audio properties",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7ab162514f668fb1cba22e236473401e64a3c19",
          "body": null,
          "is_bot": false,
          "headline": "Make tags and properties more flexible",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a6f1f96f84b9d38773340aecf222fe5d9c6ae45",
          "body": null,
          "is_bot": false,
          "headline": "Apply TagLib code formatting, fix static analysis issues",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fa3db1e51535c49b66a2fb7d6855bea043829a1",
          "body": null,
          "is_bot": false,
          "headline": "C bindings, fileref, fix warnings",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4546c0041798d0b6956929301019cbcdd11c2bc5",
          "body": null,
          "is_bot": false,
          "headline": "Compile time configuration WITH_MATROSKA",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f94843614f1f1b2b87b7e5f95c7dcd5b642592ca",
          "body": null,
          "is_bot": false,
          "headline": "Initial cues work",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "975eaac3ca7f295defa65d23315376970b96bf9a",
          "body": null,
          "is_bot": false,
          "headline": "Fix seekhead",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d019a894ce159f1e305e0255c1b946f11ed3255",
          "body": null,
          "is_bot": false,
          "headline": "Initial attachments support",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6342f00e8bd4eda5c12305abb9b30f0c91c2fa54",
          "body": null,
          "is_bot": false,
          "headline": "Support tag language",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4e79a4a274cd204a6a15c37ef7ed13f6bd26a30",
          "body": null,
          "is_bot": false,
          "headline": "Fix Clang build",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80837485cfe28c4b51fc178c3676d31adf0332f7",
          "body": null,
          "is_bot": false,
          "headline": "Added write support",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47e9b9a17c3eddcf6290d971729d0e7a4be0d63e",
          "body": null,
          "is_bot": false,
          "headline": "Initial matroska support",
          "author_name": "complexlogic",
          "author_login": "complexlogic",
          "committed_at": "2026-01-24T13:59:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c7d3368daa517312604993d90f341e94736aff7",
          "body": "When trying to read a packet from the last page the readPages() method\nwould return false for all packets on the last page.\n\nMove the lastPage check just before trying to create the next page, and\nafter the packetIndex check of the last fetched page.",
          "is_bot": false,
          "headline": "Fix reading of last page in ogg stream",
          "author_name": "Stefan Brüns",
          "author_login": "StefanBruens",
          "committed_at": "2026-01-18T19:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4a4b4225452869af49da0262ed9d1926d2bd118",
          "body": "FLAC in Ogg must have a Vorbis comment Metadata block, but in case\nthe file still has none avoid overwriting the first packet, i.e.\nthe Streaminfo Metadata block.",
          "is_bot": false,
          "headline": "Avoid corrupting an (invalid) FLAC Ogg file without Vorbis comment",
          "author_name": "Stefan Brüns",
          "author_login": "StefanBruens",
          "committed_at": "2026-01-18T19:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70c6a0c75f74ef7057f6acc744e24f16deb76c17",
          "body": "In case the Vorbis comment block is the last one the last block flag\nhas to be set.\n\nAs the other metadata blocks are kept as is, and in original order,\nand no other metadata blocks are added/inserted, these can be kept\nas is.\n\nAlso warn if the header scan loop detects a frame sync sequence (which\ni\n[…]\n packet). Previously, this was\ndetected as the last header packet, but streamStart and streamLength\nare unused, and all packets but the vorbis comment packet are just copied\nin order.\n\nSee taglib#1297",
          "is_bot": false,
          "headline": "Set last header flag in FLAC Metadata block type field",
          "author_name": "Stefan Brüns",
          "author_login": "StefanBruens",
          "committed_at": "2026-01-18T19:08:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c67e434939424903204bb60256495ed8514fb36d",
          "body": null,
          "is_bot": false,
          "headline": "Do not warn when seeing FLAC picture block in Ogg files",
          "author_name": "Stefan Brüns",
          "author_login": "StefanBruens",
          "committed_at": "2026-01-18T19:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5d44f3eeac33c518f77b7a99c5e6463f897f904c",
          "body": "The check for the size of long is no longer needed because since\nTagLib 2.0 the related fields are 64-bit on Windows too.\n\nRelated to https://bugs.kde.org/show_bug.cgi?id=513531",
          "is_bot": false,
          "headline": "MP4: Support 64-bit atoms on Windows",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2026-01-11T19:24:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c042984d26af605a6fd1dac7f12bda05219fee7",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 5 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v5...v6)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 5 to 6 (#1294)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-11-24T12:57:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "49be371caab517a6e2c35a6038b8eeb12c9b82ae",
          "body": "Signed-off-by: Rosen Penev <rosenp@gmail.com>",
          "is_bot": false,
          "headline": "std::accumulate conversion",
          "author_name": "Rosen Penev",
          "author_login": "neheb",
          "committed_at": "2025-10-25T11:00:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbb3de68364e2b2f31461551be26592285d93add",
          "body": "While CMake appears to accept the \"..\" notation, it does not correctly\napply the policy_max version in that case.\n\nAmends ab31d11c8d1e04eb710aab7902d9564b4947de8c\n\nSigned-off-by: Andreas Sturmlechner <asturm@gentoo.org>",
          "is_bot": false,
          "headline": "Fix cmake_minimum_required version range typo",
          "author_name": "Andreas Sturmlechner",
          "author_login": "a17r",
          "committed_at": "2025-10-22T14:37:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11efd2dd1049bb0b04aa6e5b737a1c9c3266724a",
          "body": "Signed-off-by: Rosen Penev <rosenp@gmail.com>",
          "is_bot": false,
          "headline": "std::none_of conversion",
          "author_name": "Rosen Penev",
          "author_login": "neheb",
          "committed_at": "2025-10-21T05:17:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab31d11c8d1e04eb710aab7902d9564b4947de8c",
          "body": "CMake 3.10 was released in 2017.\n\nAmends 967aaf7af2f4aa2e9fed0edb2cbaca98b737eebe, fixes warning since CMake-3.31:\n\nCMake Deprecation Warning at CMakeLists.txt:1 (cmake_minimum_required):\n  Compatibility with CMake < 3.10 will be removed from a future version of\n  CMake.\n\n  Update the VERSION argume\n[…]\nx> syntax\n  to tell CMake that the project requires at least <min> but has been updated\n  to work with policies introduced by <max> or earlier.\n\nSigned-off-by: Andreas Sturmlechner <asturm@gentoo.org>",
          "is_bot": false,
          "headline": "Raise CMake minimum version to 3.10..3.31 range",
          "author_name": "Andreas Sturmlechner",
          "author_login": "a17r",
          "committed_at": "2025-10-18T15:00:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c917caf52b6d14bfb548d4dc27d8601815edbe2",
          "body": "Fix std::ostream not defined on Android NDK 29.0.14033849",
          "is_bot": false,
          "headline": "Fix std::ostream not defined on Android NDK 29.0.14033849",
          "author_name": "Artem Umerov",
          "author_login": "umerov1999",
          "committed_at": "2025-09-04T20:16:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fa96a6458e7ad577cc7bf9d4c6c518a433de0b59",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 5.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v5)\n\n---\nupdated-dependenc\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump actions/checkout from 4 to 5 (#1283)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-08-18T12:03:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e831f0929f25bc581d2106d1f2810f5d8100376e",
          "body": "The C bindings would convert a char* to String using the default\nconstructor, which uses the Latin1 encoding, breaking when a key\ncontains a Unicode character (e.g. an ID3v2 comment description).",
          "is_bot": false,
          "headline": "Fix Unicode property keys in C bindings",
          "author_name": "norma",
          "author_login": "nta",
          "committed_at": "2025-07-04T07:43:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d86716194777e0294453bfdc9dd170bd033e1f4",
          "body": null,
          "is_bot": false,
          "headline": "Version 2.1.1",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2025-06-29T15:35:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb749ac55b64fada379927a77b9f5a612fe72f1c",
          "body": "This will fix \"warning: conversion from ‘long double’ to\n‘double’ may change value [-Wfloat-conversion]\".",
          "is_bot": false,
          "headline": "Use ldexpl() instead of ldexp()",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2025-06-25T20:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "148cc9a92164be5422dbac92316175ca1afb05d3",
          "body": "Using a release build with GCC 14.2.0 and -Wextra -Wconversion -Wall.\nThe generated binaries are not changed by this commit.",
          "is_bot": false,
          "headline": "Fix conversion compiler warnings",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2025-06-25T20:08:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88d6b18b4f587a3bcb1e792fc180bfc5a0261187",
          "body": "The involvement/involvee pairs which are supported for TIPL properties\n(ARRANGER, ENGINEER, PRODUCER, DJ-MIX, MIX) are left in the TIPL\nframe, other pairs are moved to a TMCL frame. This will result in a\nconsistent behavior for both ID3v2.3 and ID3v2.4 tags produced by\nMusicBrainz Picard.",
          "is_bot": false,
          "headline": "Convert IPLS to TIPL and TMCL (#1274)",
          "author_name": "Urs Fleisch",
          "author_login": "ufleisch",
          "committed_at": "2025-06-21T08:45:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 5,
      "commits_last_year": 87,
      "latest_release_at": "2012-04-20T15:57:13Z",
      "latest_release_tag": "v1.7.2",
      "releases_from_tags": true,
      "days_since_last_push": 6,
      "active_weeks_last_year": 25,
      "days_since_latest_release": 5209,
      "mean_days_between_releases": 225.6
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": []
    },
    "popularity": {
      "forks": 1,
      "stars": 1,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2025-03-31",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 84203,
      "source_files_sampled": 367,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "TsudaKageyu",
          "commits": 801,
          "avatar_url": "https://avatars.githubusercontent.com/u/2161941?v=4"
        },
        {
          "type": "User",
          "login": "scotchi",
          "commits": 463,
          "avatar_url": "https://avatars.githubusercontent.com/u/170209?v=4"
        },
        {
          "type": "User",
          "login": "lalinsky",
          "commits": 395,
          "avatar_url": "https://avatars.githubusercontent.com/u/220839?v=4"
        },
        {
          "type": "User",
          "login": "ufleisch",
          "commits": 276,
          "avatar_url": "https://avatars.githubusercontent.com/u/2125194?v=4"
        },
        {
          "type": "User",
          "login": "neheb",
          "commits": 89,
          "avatar_url": "https://avatars.githubusercontent.com/u/2918873?v=4"
        },
        {
          "type": "User",
          "login": "sbooth",
          "commits": 82,
          "avatar_url": "https://avatars.githubusercontent.com/u/9965?v=4"
        },
        {
          "type": "User",
          "login": "panzi",
          "commits": 47,
          "avatar_url": "https://avatars.githubusercontent.com/u/134175?v=4"
        },
        {
          "type": "User",
          "login": "carewolf",
          "commits": 30,
          "avatar_url": "https://avatars.githubusercontent.com/u/1233314?v=4"
        },
        {
          "type": "User",
          "login": "Montel",
          "commits": 22,
          "avatar_url": "https://avatars.githubusercontent.com/u/1503769?v=4"
        },
        {
          "type": "User",
          "login": "FestusHagen",
          "commits": 20,
          "avatar_url": "https://avatars.githubusercontent.com/u/2348136?v=4"
        }
      ],
      "contributors_sampled": 99,
      "top_contributor_share": 0.32
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "build.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": true,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 25 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 9,
            "reason": "11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "54999473a13cef45b4a560aa73aacdebd05b195e",
        "ran_at": "2026-07-26T01:24:49Z",
        "aggregate_score": 4.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-05-13T05:59:00Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/ufleisch/taglib",
    "host": "github.com",
    "name": "taglib",
    "owner": "ufleisch"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 45,
      "inputs": {
        "security": 49,
        "vitality": 61,
        "community": 12,
        "governance": 39,
        "engineering": 61
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "moderate",
        "name": "Vitality",
        "value": 61,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "commits_last_year": 87,
              "human_commit_share": 0.98,
              "days_since_last_push": 6,
              "active_weeks_last_year": 25
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "25/52 weeks with commits",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 25
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "87 commits in the last year",
                "points": 17.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 87
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "at_risk",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 32,
            "inputs": {
              "releases_count": 5,
              "latest_release_tag": "v1.7.2",
              "releases_from_tags": true,
              "days_since_latest_release": 5209,
              "mean_days_between_releases": 225.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "5 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5209 days ago",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5209
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~225.6 days",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 225.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 73,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 73 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 73
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 12,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 1,
              "stars": 1,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (LGPL-2.1)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "LGPL-2.1"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 39,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 99,
              "top_contributor_share": 0.32
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 32% of commits",
                "points": 15.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 32
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "99 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 99
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 25 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 47,
            "inputs": {
              "followers": 10,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "ufleisch",
              "public_repos": 12,
              "account_age_days": 5098
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "10 followers of ufleisch",
                "points": 7.5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 10,
                      "login": "ufleisch"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "12 public repos, account ~13 yr old",
                "points": 20.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 12
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 61,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "http://taglib.github.com/",
              "has_readme": false,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "http://taglib.github.com/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 4.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 25 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 47,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 29,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.551,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "54 of 98 human commits state their intent (structured subject or explanatory body)",
                "points": 29.4,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 54,
                      "sampled": 98
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.01,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.02
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "C++ (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "C++"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "1 of the last 100 commits agent-authored or agent-credited",
                "points": 2,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "2 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "C++",
              "largest_source_bytes": 84203,
              "source_files_sampled": 367,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "C++ (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "C++"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/367 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 367,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Community profile unavailable",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-26T01:25:05.573212Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/u/ufleisch/taglib.svg",
  "full_name": "ufleisch/taglib",
  "license_state": "standard",
  "license_spdx": "LGPL-2.1"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计.