公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-29 13:47 UTC

veraPDF / veraPDF-library

Industry supported, open source PDF/A validation library

Java · XSLTGPL-3.0★ 338 星标⑂ 50 复刻始于 2015年4月在 GitHub 上查看 ↗

veraPDF/veraPDF-library 的健康指数为 100 分中的 68 分,处于「中等」区间。 其得分最高的类别是Vitality(83/100),最低的是AI Readiness(44/100)。 最近一次更新在今天。 近期的大部分工作由 2 位贡献者完成。

68
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

68
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

veraPDF组织
170 关注者36 个公开仓库始于 2014年11月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Mavenorg.verapdf:core1.30.2-3451 天前
Mavenorg.verapdf:verapdf-xmp-core1.30.2-2851 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

83良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
15.9/36提交节奏 — 52 周中有 23 周有提交
14.9/18提交量 — 最近一年 45 次提交
10/10OpenSSF Scorecard:Maintained — 13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year45
human_commit_share0.97
days_since_last_push0
active_weeks_last_year23

发布纪律

92优秀
评分方式
27/27有发布版本 — 已发布 46 个发布版本
36/36发布时效 — 最近一次发布版本于 51 天前
19.8/27发布节奏 — 约每 88.6 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count46
latest_release_tagv1.30.2
releases_from_tags
days_since_latest_release51
mean_days_between_releases88.6
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

57中等 · 占总体的 18%
评分方式
41/60星标 — 338 个星标
14.1/25复刻 — 50 个复刻
7.5/15关注者 — 23 位关注者
所用输入
forks50
stars338
watchers23
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(GPL-3.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

77良好 · 占总体的 24%
评分方式
25.2/54巴士系数 — 2 位贡献者贡献了半数提交
14.1/22.5提交分布 — 头号贡献者编写了 37% 的提交
13.5/13.5贡献者广度 — 26 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 7 contributing companies or organizations
所用输入
bus_factor2
contributors_sampled26
top_contributor_share0.374
评分方式
44.6/46.8议题解决 — 95% 的议题已关闭
35/38.3PR 接受 — 已裁定的 PR 中 917/1,003 已合并
1.5/15OpenSSF Scorecard:Code-Review — Found 4/28 approved changesets -- score normalized to 1
所用输入
merged_prs917
open_issues29
closed_issues583
issue_closed_ratio0.953
closed_unmerged_prs86
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
16.1/25所有者影响力 — veraPDF 有 170 位关注者
23.4/25既往记录 — 36 个公开仓库,账户约 11 年
所用输入
followers170
owner_typeOrganization
is_verified
owner_loginveraPDF
public_repos36
account_age_days4,264
评分方式
25/25已发布且可解析 — maven 上有 2 个软件包
35/35发布时效 — 最近一次发布于 51 天前
20/20版本历史 — 34 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesorg.verapdf:core, org.verapdf:verapdf-xmp-core
ecosystemsmaven
any_deprecated
min_days_since_publish51

工程质量

基础的工程与文档实践是否到位?

55中等 · 占总体的 20%

工程实践

48存在风险
评分方式
24/24CI 工作流 — 3 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 0 out of 8 merged PRs checked by a CI test -- score normalized to 0
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

65中等
评分方式
30/30README
0/25文档目录
15/15文档 / 主页站点 — http://verapdf.org/software
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepagehttp://verapdf.org/software
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

60中等 · 占总体的 16%

安全态势

60中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
0/2.5CI-Tests — 0 out of 8 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0.8/7.5Code-Review — Found 4/28 approved changesets -- score normalized to 1
2.5/2.5Contributors — project has 7 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate6
已排除计分(无数据或不适用):branch_protection, packaging, signed_releases。 其余权重已重新归一化。
评分方式
12.3/35直接依赖不含已知公告 — 1 个受影响:com.fasterxml.jackson.core:jackson-databind 2.21.1 (high 8.1)
10/25间接依赖不含已知公告 — 1 个受影响:com.fasterxml.jackson.core:jackson-core 2.21.1 (high 7.5)
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories11
affected_packages2
assessed_packages13
unassessed_packages0
affected_by_severityhigh 2
direct_affected_packages1
比对的是 maven:org.verapdf:core@1.30.2 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 13 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

44存在风险 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
2.7/40可读的提交历史 — 97 次人类提交中有 5 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.052
agent_instruction_files
agent_instruction_max_bytes
评分方式
12.6/18一条命令的引导启动 — core/pom.xml, pom.xml, xmp-core-coverage/pom.xml(工具链约定,无任务运行器)
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Java(静态类型)
0/10可复现环境
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 3 次为自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestscore/pom.xml, pom.xml, xmp-core-coverage/pom.xml, xmp-core/pom.xml
dependency_bot_commit_share0.03
评分方式
45/45可类型检查的代码 — Java(静态类型)
55/55可控的文件大小 — 采样的 387 个源文件中有 0 个超过 60KB
所用输入
primary_languageJava
largest_source_bytes52,179
source_files_sampled387
oversized_source_files0

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — samples
所用输入
example_dirssamples
has_mcp_signal
api_schema_files

关键数据

338GitHub 星标
26贡献者
45最近 12 个月提交数
0距最近推送天数
46发布版本数
2巴士系数(bus factor)
29开放议题
Maven软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch maven package 'org.verapdf:verapdf-xmp-core-coverage' from its registry

更多细节

Star 与 Fork 历史 0 ★ / 50 ⇿
0Star
50Fork
45发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

010203040505022015-052020-112026-05
主版本 0次版本 2修订 33

每个点涵盖 11 天。

OpenSSF Scorecard 6.0 / 10
6.0综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-29 13:47 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
0CI-Tests0 out of 8 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
1Code-ReviewFound 4/28 approved changesets -- score normalized to 1
10Contributorsproject has 7 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
10Vulnerabilities0 existing vulnerabilities detected
直接依赖 17
注册表软件包版本约束清单文件
Mavenorg.verapdf:pdf-modelcore/pom.xml
Mavenorg.verapdf:verapdf-xmp-core${project.version}core/pom.xml
Mavenorg.mozilla:rhino1.7.15.1core/pom.xml
Mavenjavax.xml.bind:jaxb-apicore/pom.xml
Mavencom.sun.xml.bind:jaxb-implcore/pom.xml
Mavencom.sun.xml.bind:jaxb-corecore/pom.xml
Mavennet.sf.saxon:Saxon-HEcore/pom.xml
Mavencom.fasterxml.jackson.core:jackson-databind2.22.1core/pom.xml
Mavennet.java.dev.stax-utils:stax-utils20070216core/pom.xml
Mavenorg.junit:junit-bom5.10.2pom.xml
Mavenorg.mozilla:rhino1.7.14.1pom.xml
Mavenorg.verapdf:pdf-model${verapdf.model.version}pom.xml
Mavenjavax.xml.bind:jaxb-api2.4.0-b180830.0359pom.xml
Mavencom.sun.xml.bind:jaxb-impl2.3.2pom.xml
Mavencom.sun.xml.bind:jaxb-core2.3.0.1pom.xml
Mavennet.sf.saxon:Saxon-HE12.8pom.xml
Mavenorg.verapdf:verapdf-xmp-core${project.version}xmp-core-coverage/pom.xml
全部依赖 31

来自 GitHub 依赖图的完整解析依赖集合:15 个直接依赖与 16 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Mavencom.fasterxml.jackson.core:jackson-databind2.22.1直接
Mavencom.sun.xml.bind:jaxb-core直接
Mavencom.sun.xml.bind:jaxb-core2.3.0.1直接
Mavencom.sun.xml.bind:jaxb-impl直接
Mavencom.sun.xml.bind:jaxb-impl2.3.2直接
Mavenjavax.xml.bind:jaxb-api直接
Mavenjavax.xml.bind:jaxb-api2.4.0-b180830.0359直接
Mavennet.java.dev.stax-utils:stax-utils20070216直接
Mavennet.sf.saxon:Saxon-HE直接
Mavennet.sf.saxon:Saxon-HE12.8直接
Mavenorg.junit:junit-bom5.10.2直接
Mavenorg.mozilla:rhino1.7.14.1直接
Mavenorg.mozilla:rhino1.7.15.1直接
Mavenorg.verapdf:pdf-model直接
Mavenorg.verapdf:verapdf-xmp-core1.31.0-SNAPSHOT直接
Mavencommons-io:commons-io2.14.0间接
Mavenjunit:junit间接
Mavenjunit:junit4.13.2间接
Mavennl.jqno.equalsverifier:equalsverifier间接
Mavennl.jqno.equalsverifier:equalsverifier3.18.2间接
Mavenorg.apache.maven.plugins:maven-compiler-plugin3.12.1间接
Mavenorg.apache.maven.plugins:maven-jar-plugin间接
Mavenorg.apache.maven.plugins:maven-javadoc-plugin间接
Mavenorg.apache.maven.plugins:maven-project-info-reports-plugin间接
Mavenorg.apache.maven.plugins:maven-surefire-plugin3.2.5间接
Mavenorg.codehaus.mojo:versions-maven-plugin2.16.2间接
Mavenorg.jacoco:jacoco-maven-plugin0.8.11间接
Mavenorg.junit.jupiter:junit-jupiter-api5.10.2间接
Mavenorg.junit.jupiter:junit-jupiter-engine5.10.2间接
Mavenorg.junit.vintage:junit-vintage-engine5.10.2间接
Mavenorg.xmlunit:xmlunit-core2.10.0间接
依赖安全公告 2

安装 maven:org.verapdf:core@1.30.2 会引入 13 个包(直接与传递):其中 2 个存在已知公告,1 个为直接依赖。

软件包版本关系严重程度公告数修复版本
com.fasterxml.jackson.core:jackson-databind2.21.1直接103.2.1
com.fasterxml.jackson.core:jackson-core2.21.1间接13.2.1

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 42860,
      "has_wiki": true,
      "homepage": "http://verapdf.org/software",
      "languages": {
        "HTML": 3883,
        "Java": 2035341,
        "XSLT": 266691
      },
      "pushed_at": "2026-07-28T20:28:21Z",
      "created_at": "2015-04-22T10:23:22Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-24T02:28:06Z",
      "description": "Industry supported, open source PDF/A validation library",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "GPL-3.0",
      "default_branch": "integration",
      "license_spdx_raw": "GPL-3.0",
      "primary_language": "Java",
      "significant_languages": [
        "Java",
        "XSLT"
      ]
    },
    "owner": {
      "blog": "http://verapdf.org",
      "name": "veraPDF",
      "type": "Organization",
      "login": "veraPDF",
      "company": null,
      "location": "United Kingdom",
      "followers": 170,
      "avatar_url": "https://avatars.githubusercontent.com/u/9946925?v=4",
      "created_at": "2014-11-25T12:24:40Z",
      "is_verified": null,
      "public_repos": 36,
      "account_age_days": 4264
    },
    "license": {
      "state": "standard",
      "spdx_id": "GPL-3.0",
      "raw_spdx": "GPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.30.2",
          "kind": "patch",
          "published_at": "2026-06-08T12:54:48Z"
        },
        {
          "tag": "v1.30.1",
          "kind": "patch",
          "published_at": "2026-04-21T13:05:29Z"
        },
        {
          "tag": "v1.30.0-RC1",
          "kind": "prerelease",
          "published_at": "2026-04-21T08:32:03Z"
        },
        {
          "tag": "v1.28.2",
          "kind": "patch",
          "published_at": "2025-07-18T09:19:23Z"
        },
        {
          "tag": "v1.28.1",
          "kind": "patch",
          "published_at": "2025-05-08T22:05:58Z"
        },
        {
          "tag": "v1.28.0-RC1",
          "kind": "prerelease",
          "published_at": "2025-02-11T13:31:24Z"
        },
        {
          "tag": "v1.26.5",
          "kind": "patch",
          "published_at": "2024-12-23T15:00:30Z"
        },
        {
          "tag": "v1.26.1",
          "kind": "patch",
          "published_at": "2024-05-29T22:22:26Z"
        },
        {
          "tag": "v1.26.0-RC9",
          "kind": "prerelease",
          "published_at": "2024-04-05T13:24:14Z"
        },
        {
          "tag": "v1.24.2",
          "kind": "patch",
          "published_at": "2024-04-02T07:51:46Z"
        },
        {
          "tag": "v1.26.0-RC4",
          "kind": "prerelease",
          "published_at": "2024-02-15T12:15:35Z"
        },
        {
          "tag": "v1.24.1",
          "kind": "patch",
          "published_at": "2023-06-28T14:19:11Z"
        },
        {
          "tag": "v1.24.0-RC3",
          "kind": "prerelease",
          "published_at": "2023-06-05T09:00:08Z"
        },
        {
          "tag": "v1.24.0-RC2",
          "kind": "prerelease",
          "published_at": "2023-05-03T13:33:29Z"
        },
        {
          "tag": "v1.22.2",
          "kind": "patch",
          "published_at": "2022-09-15T10:12:40Z"
        },
        {
          "tag": "v1.22.0-RC4",
          "kind": "prerelease",
          "published_at": "2022-08-09T08:10:47Z"
        },
        {
          "tag": "v1.20.3",
          "kind": "patch",
          "published_at": "2022-07-08T09:52:00Z"
        },
        {
          "tag": "v1.20.1",
          "kind": "patch",
          "published_at": "2022-01-20T09:16:18Z"
        },
        {
          "tag": "v1.18.11",
          "kind": "patch",
          "published_at": "2021-04-21T06:22:02Z"
        },
        {
          "tag": "v1.18.2-RC",
          "kind": "prerelease",
          "published_at": "2021-02-24T12:37:36Z"
        },
        {
          "tag": "v1.16.1",
          "kind": "patch",
          "published_at": "2020-05-12T09:19:50Z"
        },
        {
          "tag": "v1.16.0-RC1",
          "kind": "prerelease",
          "published_at": "2020-02-20T11:13:54Z"
        },
        {
          "tag": "v1.14.102",
          "kind": "patch",
          "published_at": "2019-07-16T09:47:01Z"
        },
        {
          "tag": "v1.14.6-RC",
          "kind": "prerelease",
          "published_at": "2019-06-10T04:32:59Z"
        },
        {
          "tag": "v1.12.1",
          "kind": "patch",
          "published_at": "2018-05-10T08:57:17Z"
        },
        {
          "tag": "v1.10.2",
          "kind": "patch",
          "published_at": "2017-11-30T12:59:12Z"
        },
        {
          "tag": "v1.8.1",
          "kind": "patch",
          "published_at": "2017-08-09T11:49:01Z"
        },
        {
          "tag": "v1.6.2",
          "kind": "patch",
          "published_at": "2017-06-06T02:23:36Z"
        },
        {
          "tag": "v1.4.1",
          "kind": "patch",
          "published_at": "2017-04-20T07:36:30Z"
        },
        {
          "tag": "v1.2.0",
          "kind": "minor",
          "published_at": "2017-03-01T15:38:36Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2017-01-10T14:00:11Z"
        },
        {
          "tag": "v0.28.1",
          "kind": "patch",
          "published_at": "2017-01-10T13:50:45Z"
        },
        {
          "tag": "v0.26.11",
          "kind": "patch",
          "published_at": "2016-11-17T10:14:08Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2016-10-12T08:09:52Z"
        },
        {
          "tag": "v0.22.1",
          "kind": "patch",
          "published_at": "2016-09-06T23:24:55Z"
        },
        {
          "tag": "v0.20.3",
          "kind": "patch",
          "published_at": "2016-08-01T06:21:20Z"
        },
        {
          "tag": "v0.18.1",
          "kind": "patch",
          "published_at": "2016-07-06T20:42:21Z"
        },
        {
          "tag": "v0.16.2",
          "kind": "patch",
          "published_at": "2016-06-03T10:48:32Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2016-05-05T14:16:35Z"
        },
        {
          "tag": "v0.12.4",
          "kind": "patch",
          "published_at": "2016-04-01T08:39:26Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2016-02-29T14:41:47Z"
        },
        {
          "tag": "v0.8.7",
          "kind": "patch",
          "published_at": "2015-12-22T14:50:45Z"
        },
        {
          "tag": "v0.6.31",
          "kind": "patch",
          "published_at": "2015-11-02T09:44:59Z"
        },
        {
          "tag": "v0.4.10",
          "kind": "patch",
          "published_at": "2015-09-16T13:46:16Z"
        },
        {
          "tag": "v0.2.8",
          "kind": "patch",
          "published_at": "2015-07-16T09:32:50Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2015-07-15T12:08:19Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d1ea72c2cff5028531fe4e2b66e2ff80a205dfe0",
          "body": null,
          "is_bot": false,
          "headline": "Add args to the error PDF-UA/2 8.2.5.20-2",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-07-23T13:05:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "caf4266064de2e39604f9eba92c60f62e07a0854",
          "body": "Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) from 2.22.0 to 2.22.1.\n- [Commits](https://github.com/FasterXML/jackson/commits)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson.core:jackson-databind\n  dependency-version: 2.22.1\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump com.fasterxml.jackson.core:jackson-databind in /core",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T09:56:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3191f4a3eb047b6edd0cb49b85f5288032fcf8d6",
          "body": null,
          "is_bot": false,
          "headline": "Localize progress messages",
          "author_name": "Vladimir",
          "author_login": null,
          "committed_at": "2026-07-08T11:42:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49cef3c2e9a8b4addf3b57ec8c4498875f06dd68",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Improve descriptions for rules 8.2.5.20-1 and 8.9.2.3-1",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-07-02T20:03:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "09a98c9f89c289fa65bb0a97474f37ddcaf22ed0",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Fix error message for rule 8.2.5.20-2",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-07-01T09:57:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "961d9a219ce38671412d9814806fb1ee81440457",
          "body": "Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) from 2.21.1 to 2.22.0.\n- [Commits](https://github.com/FasterXML/jackson/commits)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson.core:jackson-databind\n  dependency-version: 2.22.0\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump com.fasterxml.jackson.core:jackson-databind in /core",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-30T10:52:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b579315dce4ae7849c8b1774729dc7818536e82c",
          "body": null,
          "is_bot": false,
          "headline": "Add 1.30.2 release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-06-03T09:43:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "baf27bdd60c1881c1e89947629444e11af89f752",
          "body": "…ign threads\n\nSigned-off-by: Sai Asish Y <say.apm35@gmail.com>",
          "is_bot": false,
          "headline": "fix: self-initialise XMP container thread-locals to avoid NPE on fore…",
          "author_name": "Sai Asish Y",
          "author_login": "SAY-5",
          "committed_at": "2026-06-03T08:59:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb8e9d78ccf4619ca4c4b61040d59adde0659820",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-1. Update error messages for rules about headings",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-05-30T21:17:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "695b44f1d3a38349eb857a8d047923150cd96e2a",
          "body": null,
          "is_bot": false,
          "headline": "Create class SecureXML for creating safe document builder",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-05-28T12:12:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "acfcc419a5df444e3e8b2a18266d01e249299957",
          "body": null,
          "is_bot": false,
          "headline": "WCAG. Update flavour ids",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-05-11T20:31:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79c2fe543dc9611edfeddfcde7bf7b5c368e842b",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Fix rules 8.2.5.20-1 and 8.9.2.3-1",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-05-11T11:43:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb8c0eb189781e6a37ee4900c968356cb86c223c",
          "body": "update H/Hn error messages",
          "is_bot": false,
          "headline": "update H+Hn tags message",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-05-07T13:04:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4827382f908c1199e99d6fa6a07added6d14002a",
          "body": null,
          "is_bot": false,
          "headline": "Update getProfilePath calculation for WCAG",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-04-27T16:39:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "daa207aac679e511d462df28ca187509e2bbbe31",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-1. Improve rules about headings",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-04-24T15:16:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffc28d558e2f11cac2d2aba67d23eceee768bded",
          "body": null,
          "is_bot": false,
          "headline": "Add addDeclarations method (#1590)",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2026-04-24T12:47:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2a6e22ba3fbf6924321d209491c82171ae64fc0",
          "body": "Adding a Security policy file",
          "is_bot": false,
          "headline": "Create SECURITY.md",
          "author_name": "Boris Doubrov",
          "author_login": "bdoubrov",
          "committed_at": "2026-04-24T09:06:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a001d60539fe7c26ddc2595ee10d3afecb2a7050",
          "body": null,
          "is_bot": false,
          "headline": "Add 1.30.1 release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-04-15T19:34:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e812dd8af2346291595f9ebf85389e02fcbd2e",
          "body": null,
          "is_bot": false,
          "headline": "Update rules messages",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-03-23T13:38:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c4be2becfcf71c88d8b484919bb6657de293187",
          "body": null,
          "is_bot": false,
          "headline": "Update profiles names",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-03-23T07:05:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06f17c90081f1d3f0f09d81bdde4ebe1c9cd8ae6",
          "body": null,
          "is_bot": false,
          "headline": "Update vulnerable rhino and jackson-databind dependencies (#1581)",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2026-03-20T12:15:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "35321f89b8f93b328d19c05c7b49349380b20a4e",
          "body": null,
          "is_bot": false,
          "headline": "DEV: v1.31",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-02-11T14:00:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30176f1f7f9df8c7c5a8275cdeb62a546ae99b55",
          "body": null,
          "is_bot": false,
          "headline": "Added 1.30 RC release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-02-10T13:19:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f9f7b9a4998e5d95408868acd7aefb41dcf1624",
          "body": null,
          "is_bot": false,
          "headline": "Update license headers",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-02-05T09:15:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba747eba0e677395c4c7ab5e5e24bb26d22c0be0",
          "body": null,
          "is_bot": false,
          "headline": "Update app name for html report",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-02-03T18:11:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "767d24fe573ad1b1add039a774264cae529deb24",
          "body": null,
          "is_bot": false,
          "headline": "Add declaration constants",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2026-02-01T18:21:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e797fdca42b5851ee8f016072f8120d05806c22a",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Fix rule about MathML",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-01-18T20:32:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "394d12a9e97deaf9834d0df0415cbd4250982f80",
          "body": null,
          "is_bot": false,
          "headline": "Update descriptions of rules about TrueType fonts",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-01-12T11:59:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "317893ce5d3515444f289891160610227e7697b1",
          "body": null,
          "is_bot": false,
          "headline": "Update descriptions of rules about TrueType fonts",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2026-01-12T11:59:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c54577c665ec0b855d3000526e13d0b74d98c13",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.28' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-20T19:45:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfb11dd48bd13e6f53ddb1afec4b47948423a6b6",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.26' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-20T19:45:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4a862364d9881d58d23650fb92d05ccddd854855",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.24' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-19T21:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5f28b75604c697c7f12190af71d55433b1b6851",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.22' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:39:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "441f1669c4ced8aabb88f2f39c89b80b72cb74e3",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.20' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:39:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "453b25c16d6b18e80020aea5cca46754f58a28e6",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.18' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:38:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6c5c8f30c49f14b1bf67794dc5722a0cfd48fb0",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/pdfua' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:37:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f8d33e246fb757bf4ac3a0db5b48028d1c903d03",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/rel/1.14' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:35:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57361c3640fb502c0e5b8353fa1589c8cc4d8695",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-0.14' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:34:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4762c2e8205f34a3f8661c7ede73d1e88a610657",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-0.4' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T20:34:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7bf102edf51eacf134652242988e6cc13e9cb6fd",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md. Add info about java 25",
          "author_name": "Maxim Pliushchov",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-16T18:35:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63d2094d6f9b12df9a77a564938274cbf78737a7",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Update rules about widget annotations",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-12-11T21:37:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25237da048ddc16dd41d7b217458bdee52b33e6a",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-1.8' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-10T21:59:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "459536e06e42ace50704005fe60858186084e011",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-1.0' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-10T21:58:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e7da544662e7124fe52c279f652b09e8b10455b",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-0.26' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-10T21:58:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "91f8aeeb2c7c9d67dcd0ecabb91604ffe4e34ca8",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-0.20' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-10T21:58:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d03b83ee834d12b2aea370f9673c3bd0e6fad399",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-0.16' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-10T21:58:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "668915c964d64105735b8d8e9d17a4ebff8d2b1c",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/release-0.6' into integration",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-12-10T21:57:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4124bee304d05c7bb217dce859a93958de679e08",
          "body": "Bumps [org.mozilla:rhino](https://github.com/mozilla/rhino) from 1.7.13 to 1.7.14.1.\n- [Release notes](https://github.com/mozilla/rhino/releases)\n- [Changelog](https://github.com/mozilla/rhino/blob/master/RELEASE-NOTES.md)\n- [Commits](https://github.com/mozilla/rhino/commits)\n\n---\nupdated-dependencies:\n- dependency-name: org.mozilla:rhino\n  dependency-version: 1.7.14.1\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump org.mozilla:rhino from 1.7.13 to 1.7.14.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-12-03T21:27:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c48b013877f7917a0bff07a31f4ec9a94927c447",
          "body": null,
          "is_bot": false,
          "headline": "Add WCAG2.2 PDF2.0 flavours",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-11-27T13:26:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34b3c38c068a1b466202348e8583fb647dfe6c51",
          "body": null,
          "is_bot": false,
          "headline": "Change rev value requirement to specific year",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-11-17T18:51:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "885ec8fcaa05b9f1f5c89f75c413718eebe03da8",
          "body": null,
          "is_bot": false,
          "headline": "Change rev value requirement to specific year",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-11-17T18:50:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ed85fcd48321b749eb903c62f399d3d10963349",
          "body": null,
          "is_bot": false,
          "headline": "Fix exception when getdeclarations() returned null (#1561)",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-11-17T10:40:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "963714720e7d5bb05b3838ae5c37c55ba23c8ae6",
          "body": null,
          "is_bot": false,
          "headline": "Update parent pom version",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-11-11T15:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c64c15d4bdaf05ad550bf0e24251e25ddd769ffd",
          "body": null,
          "is_bot": false,
          "headline": "Add <pluginManagement> to root pom.xml",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-11-11T15:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "574fe0f7eecdcaf60c19ebe0d15575f149221d7f",
          "body": null,
          "is_bot": false,
          "headline": "Set maven-jar-plugin version to 3.4.2",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-11-11T15:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90b15a77339c127cbffa2ad21ef34e62e1fed5fc",
          "body": null,
          "is_bot": false,
          "headline": "Add an automatic module name to the MANIFEST",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-11-11T15:11:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ecf7c61c49bf4a3fd043843f4c89a99bf3b4345b",
          "body": null,
          "is_bot": false,
          "headline": "Include WCAG to PDF/UA-2 related flavours",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-10-30T15:44:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10242c64102eb53df67f9edcef22ca836bf83238",
          "body": null,
          "is_bot": false,
          "headline": "Add constants to PDFAFlavours",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-10-28T15:52:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "17ac0dcfa0b11f69f57122761dd172c7f461d089",
          "body": null,
          "is_bot": false,
          "headline": "Update Tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-10-06T14:09:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "145775082bf73d3324ac0d47f4b67bb267a87253",
          "body": null,
          "is_bot": false,
          "headline": "Update equalsverifier dependency",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-09-29T09:27:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3fec3d54c7ea2f16ffe087107c0004b0bb2f39f",
          "body": null,
          "is_bot": false,
          "headline": "Add java25 to github actions",
          "author_name": "Kakhnovich Raman",
          "author_login": "LonelyMidoriya",
          "committed_at": "2025-09-29T09:27:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e16e51136ae40761d14215c1e1aa5e7a9eeb7010",
          "body": null,
          "is_bot": false,
          "headline": "Update Tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-09-18T15:56:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebd471707c07c5a1130e9980e0307c3a19783f82",
          "body": null,
          "is_bot": false,
          "headline": "Include new rules to Tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-08-29T18:30:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c6a13d42f7e90dd026212c9017c573f786ae886",
          "body": null,
          "is_bot": false,
          "headline": "Update typos in CMap names",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-08-21T08:07:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06dc75e3694e7214612fdeeee89c8583f5575398",
          "body": null,
          "is_bot": false,
          "headline": "Update typos in CMap names",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-08-20T21:37:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ef2f3fac3e858eb6268dc3de35932d11949a84e4",
          "body": null,
          "is_bot": false,
          "headline": "Fix exception during applying policy",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-08-19T15:21:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37246f089a33485333c1cdb950158d94dba9415d",
          "body": null,
          "is_bot": false,
          "headline": "Update tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-08-09T20:38:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e41b53780575a92b4e15e49e9ab0a15b25ece75",
          "body": null,
          "is_bot": false,
          "headline": "PDF/A-1. Fix rule 6.4-4",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-07-30T10:54:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9963cbd5ce6bfad4b2aeb80f3aa2bf98f0b9d33",
          "body": null,
          "is_bot": false,
          "headline": "Add 1.28.2 release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-07-15T16:01:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "508d7205775791baadbc6928433361ee9f3943c5",
          "body": null,
          "is_bot": false,
          "headline": "Add 1.28.2 release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-07-15T14:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db17a994b0e95873bbb9f961bc2cb7e6b18e0370",
          "body": null,
          "is_bot": false,
          "headline": "Update rdf parsing",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-07-14T19:59:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9349ed7d181cfd60b6601877b232441550147500",
          "body": null,
          "is_bot": false,
          "headline": "Update jackson dependency version to 2.15.0",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-07-14T19:40:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55cabbadf5a19bcb3788aea0b518925ce02471ad",
          "body": null,
          "is_bot": false,
          "headline": "Add new flavours methods",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-07-14T19:40:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40cf495e0090ef6865092b2d9d7ba96dba538cfd",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Remove rule 8.2.5.20-3",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-07-14T19:39:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f36aed7d8c58fd731924d50dd07c4c11fc2794d",
          "body": null,
          "is_bot": false,
          "headline": "Update parent pom version to 1.28.2",
          "author_name": "Maxim Pliushchov",
          "author_login": "MaximPlusov",
          "committed_at": "2025-07-13T11:51:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b75a016ff64eefc661b3365e7b47186d0d3a62fd",
          "body": null,
          "is_bot": false,
          "headline": "Update jackson dependency version to 2.15.0",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-06-30T20:03:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f1454985c3b28f7de2734c299508ea669357b39d",
          "body": null,
          "is_bot": false,
          "headline": "Add new flavours methods",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-06-15T18:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60e695ff173bccd3b06eb085bdebb2ae768e85f7",
          "body": null,
          "is_bot": false,
          "headline": "Update tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-06-06T13:10:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be2f0fb56b006c74d35ea39064a6ed586c0bec81",
          "body": null,
          "is_bot": false,
          "headline": "Update rdf parsing",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-05-24T12:52:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de3ee51a223d25b9994547446b80bb236f28dd9f",
          "body": null,
          "is_bot": false,
          "headline": "Add WCAG Machine and Human flavours",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-05-13T17:55:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c05a38e95f31d7eaac48ce9715a6cbbeabbdead",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Remove rule 8.2.5.20-3",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-05-12T15:00:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8764fe90b93e0ed613c3dc8c7ac2c9f3d7b74320",
          "body": null,
          "is_bot": false,
          "headline": "Fix release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-04-29T18:48:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f5e9c7063f9124dcf161a73839e150a18865585",
          "body": null,
          "is_bot": false,
          "headline": "Fix release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-04-29T18:46:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0d27e18ddfe6e15d84ec5a42230cee9e7bf41d7f",
          "body": "- bumped minor version to 1.28\n- updated maven dependency\n- updated readme",
          "is_bot": false,
          "headline": "REL - v1.28",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-04-26T22:03:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f26f19a14008289c47abd70480c1b60d76e932ec",
          "body": null,
          "is_bot": false,
          "headline": "Add 1.28 release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-04-26T17:37:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6612386f0fff34d19c37066c19f2f3026165560f",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA. Add rules about Marked entry",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-26T17:37:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dbe0fe777357bff0f05e759d8593ca2a6768e7de",
          "body": null,
          "is_bot": false,
          "headline": "Update tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-26T17:37:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a5a22a7e68456e8a8fcf86abfd384999c23ed13",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Update rule 8.10.3.5-1",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-26T17:37:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3413f96d847015c90801307361708afb930260e4",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Fix rule 8.9.2.2-2",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-26T17:37:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "625048592be1262f7e1bbcfc66b1fb080df36ce2",
          "body": null,
          "is_bot": false,
          "headline": "Fix \"should not present\" typo",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-26T17:37:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bc8b84b30625bb46d18ccdbbc9781f659bd8308",
          "body": null,
          "is_bot": false,
          "headline": "Fix \"should not present\" typo",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-26T17:37:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "996f3be8542ddcd8ea6c47b1535404b3dbdfc56a",
          "body": null,
          "is_bot": false,
          "headline": "Add 1.28 release notes",
          "author_name": "Maxim",
          "author_login": "MaximPlusov",
          "committed_at": "2025-04-26T16:51:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "937376b74a36e4e7c05c022e883ab47e5783f308",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA. Add rules about Marked entry",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-23T21:14:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80e0736325bdbd8d507b2757f87aa9ff4761df07",
          "body": null,
          "is_bot": false,
          "headline": "Update tagged profile",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-23T20:58:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1cd2634e2043edb46603672ae1d3cd85e0ac568",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Update rule 8.10.3.5-1",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-23T17:46:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8487d33896df2351bcfccf15258bfb400d7239c",
          "body": null,
          "is_bot": false,
          "headline": "PDF/UA-2. Fix rule 8.9.2.2-2",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-04-23T17:35:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64aac64cbe1d59d2802488356e736221a1d0f234",
          "body": "* Add synchronization to ValidationProfileImpl methods\n\n* Split ValidationProfileImptl lock into two locks",
          "is_bot": false,
          "headline": "Validationprofileimpl threadsafety (#1514)",
          "author_name": "e-zhavoronok",
          "author_login": "e-zhavoronok",
          "committed_at": "2025-03-26T10:27:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5549bae3ad3326eb0fda13b005d776f606cb812",
          "body": null,
          "is_bot": false,
          "headline": "Fix \"should not present\" typo",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-03-14T20:30:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99e6c4d28a98b85545feb60c71d4a3178cae7792",
          "body": null,
          "is_bot": false,
          "headline": "Fix \"should not present\" typo",
          "author_name": "Git User",
          "author_login": null,
          "committed_at": "2025-03-14T20:28:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3016ebabc30f948b38015f623be0afc51e6eee7",
          "body": null,
          "is_bot": false,
          "headline": "Remove code related to pdfbox",
          "author_name": "e-zhavoronok",
          "author_login": "e-zhavoronok",
          "committed_at": "2025-02-21T10:57:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 46,
      "commits_last_year": 45,
      "latest_release_at": "2026-06-08T12:54:48Z",
      "latest_release_tag": "v1.30.2",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 23,
      "days_since_latest_release": 51,
      "mean_days_between_releases": 88.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "org.verapdf:core",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/org.verapdf/core",
          "is_deprecated": false,
          "latest_version": "1.30.2",
          "repository_url": null,
          "versions_count": 34,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-08T12:22:31Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 51
        },
        {
          "name": "org.verapdf:verapdf-xmp-core",
          "exists": true,
          "license": "BSD 3-Clause License",
          "keywords": [],
          "ecosystem": "maven",
          "matches_repo": null,
          "registry_url": "https://central.sonatype.com/artifact/org.verapdf/verapdf-xmp-core",
          "is_deprecated": false,
          "latest_version": "1.30.2",
          "repository_url": null,
          "versions_count": 28,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-06-08T12:22:44Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 51
        }
      ]
    },
    "popularity": {
      "forks": 50,
      "stars": 338,
      "watchers": 23,
      "fork_history": {
        "days": [
          {
            "date": "2015-05-22",
            "count": 1
          },
          {
            "date": "2015-06-17",
            "count": 1
          },
          {
            "date": "2015-07-08",
            "count": 1
          },
          {
            "date": "2015-07-15",
            "count": 1
          },
          {
            "date": "2015-12-03",
            "count": 1
          },
          {
            "date": "2016-04-07",
            "count": 1
          },
          {
            "date": "2016-06-03",
            "count": 1
          },
          {
            "date": "2016-08-11",
            "count": 1
          },
          {
            "date": "2016-10-17",
            "count": 1
          },
          {
            "date": "2016-11-10",
            "count": 1
          },
          {
            "date": "2016-12-16",
            "count": 1
          },
          {
            "date": "2017-01-12",
            "count": 1
          },
          {
            "date": "2017-01-13",
            "count": 1
          },
          {
            "date": "2017-01-23",
            "count": 1
          },
          {
            "date": "2017-04-16",
            "count": 1
          },
          {
            "date": "2017-05-31",
            "count": 1
          },
          {
            "date": "2017-06-17",
            "count": 1
          },
          {
            "date": "2017-08-10",
            "count": 1
          },
          {
            "date": "2017-12-12",
            "count": 1
          },
          {
            "date": "2018-02-13",
            "count": 1
          },
          {
            "date": "2019-02-22",
            "count": 1
          },
          {
            "date": "2019-03-25",
            "count": 1
          },
          {
            "date": "2019-09-04",
            "count": 1
          },
          {
            "date": "2019-10-15",
            "count": 1
          },
          {
            "date": "2019-11-07",
            "count": 1
          },
          {
            "date": "2019-12-02",
            "count": 1
          },
          {
            "date": "2019-12-10",
            "count": 1
          },
          {
            "date": "2020-01-30",
            "count": 1
          },
          {
            "date": "2020-02-11",
            "count": 1
          },
          {
            "date": "2020-05-15",
            "count": 1
          },
          {
            "date": "2020-08-01",
            "count": 1
          },
          {
            "date": "2021-04-23",
            "count": 1
          },
          {
            "date": "2021-04-26",
            "count": 1
          },
          {
            "date": "2021-05-13",
            "count": 1
          },
          {
            "date": "2021-08-31",
            "count": 1
          },
          {
            "date": "2021-12-02",
            "count": 1
          },
          {
            "date": "2022-04-13",
            "count": 1
          },
          {
            "date": "2022-10-07",
            "count": 1
          },
          {
            "date": "2023-01-30",
            "count": 1
          },
          {
            "date": "2023-06-07",
            "count": 1
          },
          {
            "date": "2024-01-20",
            "count": 1
          },
          {
            "date": "2024-02-12",
            "count": 1
          },
          {
            "date": "2024-05-10",
            "count": 1
          },
          {
            "date": "2025-01-13",
            "count": 1
          },
          {
            "date": "2025-04-01",
            "count": 1
          },
          {
            "date": "2025-07-11",
            "count": 1
          },
          {
            "date": "2025-07-27",
            "count": 1
          },
          {
            "date": "2025-08-11",
            "count": 1
          },
          {
            "date": "2026-01-07",
            "count": 1
          },
          {
            "date": "2026-06-02",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 50,
        "total_forks": 50
      },
      "star_history": null,
      "open_issues_and_prs": 30
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "core/pom.xml",
        "pom.xml",
        "xmp-core-coverage/pom.xml",
        "xmp-core/pom.xml"
      ],
      "largest_source_bytes": 52179,
      "source_files_sampled": 387,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "core/pom.xml",
        "pom.xml",
        "xmp-core-coverage/pom.xml",
        "xmp-core/pom.xml"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": true,
            "version": "2.21.1",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 8.1,
            "advisory_ids": [
              "GHSA-3pjw-73gf-8qr5",
              "GHSA-5gvw-p9qm-jgwh",
              "GHSA-5hh8-q8hv-fr38",
              "GHSA-5jmj-h7xm-6q6v",
              "GHSA-9fxm-vc8v-hj55",
              "GHSA-hgj6-7826-r7m5",
              "GHSA-j3rv-43j4-c7qm",
              "GHSA-mhm7-754m-9p8w",
              "GHSA-rcqc-6cw3-h962",
              "GHSA-rmj7-2vxq-3g9f"
            ],
            "fixed_version": "3.2.1",
            "advisory_count": 10,
            "oldest_advisory_days": 35
          },
          {
            "name": "com.fasterxml.jackson.core:jackson-core",
            "direct": false,
            "version": "2.21.1",
            "severity": "high",
            "ecosystem": "maven",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-r7wm-3cxj-wff9"
            ],
            "fixed_version": "3.2.1",
            "advisory_count": 1,
            "oldest_advisory_days": 7
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "high": 2
        },
        "advisory_count": 11,
        "affected_count": 2,
        "assessed_count": 13,
        "malicious_count": 0,
        "assessed_package": "maven:org.verapdf:core@1.30.2",
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "maven"
      ],
      "dependencies": [
        {
          "name": "org.verapdf:pdf-model",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "org.verapdf:verapdf-xmp-core",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        },
        {
          "name": "org.mozilla:rhino",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.7.15.1"
        },
        {
          "name": "javax.xml.bind:jaxb-api",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.sun.xml.bind:jaxb-impl",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.sun.xml.bind:jaxb-core",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "net.sf.saxon:Saxon-HE",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": null
        },
        {
          "name": "com.fasterxml.jackson.core:jackson-databind",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.22.1"
        },
        {
          "name": "net.java.dev.stax-utils:stax-utils",
          "manifest": "core/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "20070216"
        },
        {
          "name": "org.junit:junit-bom",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "5.10.2"
        },
        {
          "name": "org.mozilla:rhino",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "1.7.14.1"
        },
        {
          "name": "org.verapdf:pdf-model",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${verapdf.model.version}"
        },
        {
          "name": "javax.xml.bind:jaxb-api",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.4.0-b180830.0359"
        },
        {
          "name": "com.sun.xml.bind:jaxb-impl",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.2"
        },
        {
          "name": "com.sun.xml.bind:jaxb-core",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "2.3.0.1"
        },
        {
          "name": "net.sf.saxon:Saxon-HE",
          "manifest": "pom.xml",
          "ecosystem": "maven",
          "version_constraint": "12.8"
        },
        {
          "name": "org.verapdf:verapdf-xmp-core",
          "manifest": "xmp-core-coverage/pom.xml",
          "ecosystem": "maven",
          "version_constraint": "${project.version}"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "com.fasterxml.jackson.core:jackson-databind",
            "direct": true,
            "version": "2.22.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-core",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-core",
            "direct": true,
            "version": "2.3.0.1",
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-impl",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "com.sun.xml.bind:jaxb-impl",
            "direct": true,
            "version": "2.3.2",
            "ecosystem": "maven"
          },
          {
            "name": "javax.xml.bind:jaxb-api",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "javax.xml.bind:jaxb-api",
            "direct": true,
            "version": "2.4.0-b180830.0359",
            "ecosystem": "maven"
          },
          {
            "name": "net.java.dev.stax-utils:stax-utils",
            "direct": true,
            "version": "20070216",
            "ecosystem": "maven"
          },
          {
            "name": "net.sf.saxon:Saxon-HE",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "net.sf.saxon:Saxon-HE",
            "direct": true,
            "version": "12.8",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit:junit-bom",
            "direct": true,
            "version": "5.10.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino",
            "direct": true,
            "version": "1.7.14.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.mozilla:rhino",
            "direct": true,
            "version": "1.7.15.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.verapdf:pdf-model",
            "direct": true,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.verapdf:verapdf-xmp-core",
            "direct": true,
            "version": "1.31.0-SNAPSHOT",
            "ecosystem": "maven"
          },
          {
            "name": "commons-io:commons-io",
            "direct": false,
            "version": "2.14.0",
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "junit:junit",
            "direct": false,
            "version": "4.13.2",
            "ecosystem": "maven"
          },
          {
            "name": "nl.jqno.equalsverifier:equalsverifier",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "nl.jqno.equalsverifier:equalsverifier",
            "direct": false,
            "version": "3.18.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-compiler-plugin",
            "direct": false,
            "version": "3.12.1",
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-jar-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-javadoc-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-project-info-reports-plugin",
            "direct": false,
            "version": null,
            "ecosystem": "maven"
          },
          {
            "name": "org.apache.maven.plugins:maven-surefire-plugin",
            "direct": false,
            "version": "3.2.5",
            "ecosystem": "maven"
          },
          {
            "name": "org.codehaus.mojo:versions-maven-plugin",
            "direct": false,
            "version": "2.16.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.jacoco:jacoco-maven-plugin",
            "direct": false,
            "version": "0.8.11",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-api",
            "direct": false,
            "version": "5.10.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.jupiter:junit-jupiter-engine",
            "direct": false,
            "version": "5.10.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.junit.vintage:junit-vintage-engine",
            "direct": false,
            "version": "5.10.2",
            "ecosystem": "maven"
          },
          {
            "name": "org.xmlunit:xmlunit-core",
            "direct": false,
            "version": "2.10.0",
            "ecosystem": "maven"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 31,
        "direct_count": 15,
        "indirect_count": 16
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 917,
        "open_issues": 29,
        "closed_ratio": 0.953,
        "closed_issues": 583,
        "closed_unmerged_prs": 86
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "carlwilson",
          "commits": 1115,
          "avatar_url": "https://avatars.githubusercontent.com/u/440634?v=4"
        },
        {
          "type": "User",
          "login": "ZhenyaM",
          "commits": 516,
          "avatar_url": "https://avatars.githubusercontent.com/u/10989135?v=4"
        },
        {
          "type": "User",
          "login": "timurkamalov",
          "commits": 451,
          "avatar_url": "https://avatars.githubusercontent.com/u/9675650?v=4"
        },
        {
          "type": "User",
          "login": "BezrukovM",
          "commits": 357,
          "avatar_url": "https://avatars.githubusercontent.com/u/8568933?v=4"
        },
        {
          "type": "User",
          "login": "MaximPlusov",
          "commits": 342,
          "avatar_url": "https://avatars.githubusercontent.com/u/36183885?v=4"
        },
        {
          "type": "User",
          "login": "shem-sergey",
          "commits": 49,
          "avatar_url": "https://avatars.githubusercontent.com/u/11003788?v=4"
        },
        {
          "type": "User",
          "login": "opf-buildmanager",
          "commits": 45,
          "avatar_url": "https://avatars.githubusercontent.com/u/1998307?v=4"
        },
        {
          "type": "User",
          "login": "bdoubrov",
          "commits": 42,
          "avatar_url": "https://avatars.githubusercontent.com/u/10971979?v=4"
        },
        {
          "type": "User",
          "login": "LonelyMidoriya",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/59254003?v=4"
        },
        {
          "type": "User",
          "login": "AnhelinaM",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/61345630?v=4"
        }
      ],
      "contributors_sampled": 26,
      "top_contributor_share": 0.374
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "test-pr.yml",
        "update-arlington-workflow.yml",
        "update-jakarta-workflow.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 8 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 1,
            "reason": "Found 4/28 approved changesets -- score normalized to 1",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 7 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d1ea72c2cff5028531fe4e2b66e2ff80a205dfe0",
        "ran_at": "2026-07-29T13:47:03Z",
        "aggregate_score": 6,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T13:06:18Z",
      "oldest_open_prs": [
        {
          "number": 1578,
          "created_at": "2026-03-02T14:09:50Z",
          "last_comment_at": "2026-03-02T14:10:10Z",
          "last_comment_author": "coderabbitai"
        }
      ],
      "last_merged_pr_at": "2026-07-21T09:56:33Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 443,
          "created_at": "2016-01-26T12:05:02Z",
          "last_comment_at": "2024-11-01T09:25:03Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 684,
          "created_at": "2017-01-13T21:22:43Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1039,
          "created_at": "2019-09-09T15:18:07Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1045,
          "created_at": "2019-11-08T11:21:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 1365,
          "created_at": "2023-07-31T09:18:26Z",
          "last_comment_at": "2024-10-04T11:27:08Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1417,
          "created_at": "2024-03-06T11:12:35Z",
          "last_comment_at": "2026-05-14T08:39:32Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1432,
          "created_at": "2024-04-09T11:17:32Z",
          "last_comment_at": "2025-10-04T06:32:43Z",
          "last_comment_author": "zWhdmB5T"
        },
        {
          "number": 1467,
          "created_at": "2024-07-23T11:42:51Z",
          "last_comment_at": "2024-07-26T09:21:54Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1487,
          "created_at": "2024-10-29T16:15:15Z",
          "last_comment_at": "2024-11-01T09:15:15Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1502,
          "created_at": "2025-02-03T15:24:40Z",
          "last_comment_at": "2025-02-17T00:01:21Z",
          "last_comment_author": "petervwyatt"
        },
        {
          "number": 1516,
          "created_at": "2025-03-26T18:52:12Z",
          "last_comment_at": "2026-06-10T19:36:42Z",
          "last_comment_author": "balazs-szucs"
        },
        {
          "number": 1520,
          "created_at": "2025-04-11T17:21:50Z",
          "last_comment_at": "2025-08-22T09:26:35Z",
          "last_comment_author": "u-fischer"
        },
        {
          "number": 1562,
          "created_at": "2025-11-16T19:18:42Z",
          "last_comment_at": "2025-11-21T13:32:20Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1569,
          "created_at": "2025-12-12T13:48:23Z",
          "last_comment_at": "2026-03-01T01:53:11Z",
          "last_comment_author": "Reissner"
        },
        {
          "number": 1570,
          "created_at": "2025-12-12T13:49:32Z",
          "last_comment_at": "2026-01-01T06:06:51Z",
          "last_comment_author": "petervwyatt"
        },
        {
          "number": 1576,
          "created_at": "2026-02-23T22:45:32Z",
          "last_comment_at": "2026-03-01T01:41:06Z",
          "last_comment_author": "Reissner"
        },
        {
          "number": 1583,
          "created_at": "2026-04-06T23:50:16Z",
          "last_comment_at": "2026-04-09T10:09:56Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1591,
          "created_at": "2026-04-29T00:22:18Z",
          "last_comment_at": "2026-05-07T14:50:07Z",
          "last_comment_author": "petervwyatt"
        },
        {
          "number": 1595,
          "created_at": "2026-05-20T04:23:08Z",
          "last_comment_at": "2026-07-13T16:05:05Z",
          "last_comment_author": "bdoubrov"
        },
        {
          "number": 1597,
          "created_at": "2026-05-20T08:02:57Z",
          "last_comment_at": "2026-05-28T08:49:50Z",
          "last_comment_author": "bdoubrov"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/veraPDF/veraPDF-library",
    "host": "github.com",
    "name": "veraPDF-library",
    "owner": "veraPDF"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 68,
      "inputs": {
        "security": 60,
        "vitality": 83,
        "community": 57,
        "governance": 77,
        "engineering": 55
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "commits_last_year": 45,
              "human_commit_share": 0.97,
              "days_since_last_push": 0,
              "active_weeks_last_year": 23
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "23/52 weeks with commits",
                "points": 15.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 23
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "45 commits in the last year",
                "points": 14.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 45
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 92,
            "inputs": {
              "releases_count": 46,
              "latest_release_tag": "v1.30.2",
              "releases_from_tags": false,
              "days_since_latest_release": 51,
              "mean_days_between_releases": 88.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "46 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 46
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 51 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 51
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~88.6 days",
                "points": 19.8,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 88.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 6,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 6 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 57,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "forks": 50,
              "stars": 338,
              "watchers": 23,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "338 stars",
                "points": 41,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 338
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "50 forks",
                "points": 14.1,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 50
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "23 watchers",
                "points": 7.5,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (GPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "GPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "good",
        "name": "Sustainability & Governance",
        "value": 77,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 63,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 26,
              "top_contributor_share": 0.374
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 37% of commits",
                "points": 14.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 37
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "26 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 7 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 917,
              "open_issues": 29,
              "closed_issues": 583,
              "issue_closed_ratio": 0.953,
              "closed_unmerged_prs": 86
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "95% of issues closed",
                "points": 44.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 95
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "917/1003 decided PRs merged",
                "points": 35,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 917,
                      "decided": 1003
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 4/28 approved changesets -- score normalized to 1",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "good",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "followers": 170,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "veraPDF",
              "public_repos": 36,
              "account_age_days": 4264
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "170 followers of veraPDF",
                "points": 16.1,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 170,
                      "login": "veraPDF"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "36 public repos, account ~11 yr old",
                "points": 23.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 36
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 11
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "org.verapdf:core",
                "org.verapdf:verapdf-xmp-core"
              ],
              "ecosystems": "maven",
              "any_deprecated": false,
              "min_days_since_publish": 51
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on maven",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "maven"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 51 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 51
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "34 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 34
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 55,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "3 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 8 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "http://verapdf.org/software",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "http://verapdf.org/software",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 60,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 6
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 8 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 4/28 approved changesets -- score normalized to 1",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 7 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "13 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Matched the maven:org.verapdf:core@1.30.2 runtime dependency closure — what installing the published package pulls in — 13 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "maven:org.verapdf:core@1.30.2",
                  "assessed": 13
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "source": "osv",
              "advisories": 11,
              "affected_packages": 2,
              "assessed_packages": 13,
              "unassessed_packages": 0,
              "affected_by_severity": "high 2",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: com.fasterxml.jackson.core:jackson-databind 2.21.1 (high 8.1)",
                "points": 12.3,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "com.fasterxml.jackson.core:jackson-databind 2.21.1 (high 8.1)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "1 affected: com.fasterxml.jackson.core:jackson-core 2.21.1 (high 7.5)",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "com.fasterxml.jackson.core:jackson-core 2.21.1 (high 7.5)"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 13,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 9
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "at_risk",
        "name": "AI Readiness",
        "value": 44,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "critical",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 3,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.052,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "5 of 97 human commits state their intent (structured subject or explanatory body)",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 5,
                      "sampled": 97
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "core/pom.xml",
                "pom.xml",
                "xmp-core-coverage/pom.xml",
                "xmp-core/pom.xml"
              ],
              "dependency_bot_commit_share": 0.03
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "core/pom.xml, pom.xml, xmp-core-coverage/pom.xml (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "core/pom.xml, pom.xml, xmp-core-coverage/pom.xml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Java (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Java",
              "largest_source_bytes": 52179,
              "source_files_sampled": 387,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Java (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Java"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/387 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 387,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "samples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch maven package 'org.verapdf:verapdf-xmp-core-coverage' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T13:47:24.456037Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/v/veraPDF/veraPDF-library.svg",
  "full_name": "veraPDF/veraPDF-library",
  "license_state": "standard",
  "license_spdx": "GPL-3.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Maven.